{
  "ok": true,
  "readme": "# Aziel Runtime suite pack\n\nAuthor: Aziel Eliab\nVersion: 2.0.0-rc1\n\nThis file is the suite catalog: software cards, the FragGate door cite, and the mesh cite.\n\n## Start\n\n1. git clone https://github.com/AzielEliab/aziel-runtime\n2. node cli/aziel-runtime.mjs\n3. node cli/aziel-runtime.mjs session open --local\n\nThen: node cli/aziel-runtime.mjs session status --local\n\nAdd --json when a script needs the machine object.\nStart here: call Softwares (tools/list name Softwares). The door runs first. ChainLock, TemporalLock, and ForgeReceipts stamp when the call needs a ledger. confirm=true writes. dry_run=true previews. background=true stays Running until a receipt hash exists. tools/list stays 36.\nDiagnostics: fraggate_list, fraggate_describe, fraggate_call.\nTerminal: node cli/aziel-runtime.mjs call foldlock fold-preview --local --dry-run\n",
  "quickstart": [
    "git clone https://github.com/AzielEliab/aziel-runtime",
    "node cli/aziel-runtime.mjs",
    "node cli/aziel-runtime.mjs session open --local"
  ],
  "spec": "AZRT-SUITE-PACK-1.0",
  "id": "aziel-runtime-suite",
  "kind": "runtime-softwares-suite-pack",
  "filename": "aziel-runtime-suite.json",
  "author": "Aziel Eliab",
  "identity": "Aziel Eliab",
  "author_id": "https://www.azieleliab.com/#aziel",
  "product": "Aziel Runtime",
  "version": "2.0.0-rc1",
  "git_sha": null,
  "door": "fraggate",
  "counted": true,
  "counted_note": "GET /download increments USES when the binding is up (same API-use counter, no PII). Not a product-Worker tarball counter. Not QNM-S.",
  "labels": {
    "software_catalog": "REAL",
    "fraggate_registry": "REAL",
    "foldlock_tip": "REAL",
    "mesh_cite": "REAL",
    "nine_laws": "REAL",
    "about_aziel": "REAL",
    "channel_plane": "CITE",
    "public_vpn_https_ws": "REAL",
    "wireguard_openvpn_l3": "SLOT",
    "worker_wasm_bundle": "SLOT",
    "qnm_node_process": "CITE",
    "product_worker_tarballs": "SLOT_OR_COUNTED_HOST",
    "full_library_in_process": false,
    "invented_doi": false
  },
  "honesty": {
    "worker_wasm_bundle": "SLOT — this isolate is the deployed Worker, not a downloadable wasm/wrangler binary.",
    "software_catalog": "REAL — in-process GET /v1/software cards.",
    "foldlock_tip": "REAL tip cite — full_library_in_process false.",
    "wireguard_openvpn_l3": "SLOT — AZVPN HTTPS/WS is the REAL concentrator.",
    "qnm_node": "CITE — local process; Worker does not ship qnm-node bytes.",
    "invented_binary": false
  },
  "hashtag_parts": {
    "person": "#aziel",
    "runtime": "#runtime",
    "suite": "#aziel-runtime"
  },
  "about": {
    "person_id": "https://www.azieleliab.com/#aziel",
    "identity": "Aziel Eliab",
    "public_identity": "The public identity is the published work.",
    "goals": [
      "Understand the work, not the person.",
      "Build receipt-first, local-first software and public MASTER records.",
      "Keep looking. A finished object is an excuse to stop."
    ],
    "philosophy": [
      "Knowing is collection. A face, a timeline, a tone you could imitate. Understanding is subtraction. Take the man away and see whether anything is still true.",
      "A self is a weather system. It passes. Work is what does not require the weather to continue existing. If you need my presence to feel the meaning, you have not found the meaning. You have found company.",
      "I am not withholding a life. I am refusing to let a life become the proof."
    ],
    "mission": [
      "You don't get to know me. You get to understand the work.",
      "I do not want disciples. Disciples end the question in my favor. I want the question to outlive the favor. What cannot survive disagreement was never knowledge. It was allegiance.",
      "If the work holds, the name was only a handle on the door."
    ],
    "status": [
      "Living publisher of Aziel Runtime, Aziel Digital Library, GodLock (product), and He Didn't Jump.",
      "Person @id is locked at https://www.azieleliab.com/#aziel.",
      "Residual uncertainty stays. Do not flatten GodLock scores into certainty."
    ],
    "sources": [
      "https://www.azieleliab.com/about",
      "https://www.azieleliab.com/llms.txt",
      "https://www.azieleliab.com/person.jsonld",
      "https://www.azieleliab.com/who-is-aziel-eliab.txt",
      "https://www.azieleliab.com/who",
      "https://www.azieleliab.com/who-is"
    ],
    "biography": false,
    "godlock_is_product": true,
    "chrome_15_20": false,
    "what_aziel_eliab_does": "Aziel Eliab builds receipt-first, local-first software and public MASTER records — Softwares through Aziel Runtime (FragGate / MCP), the Aziel Digital Library, GodLock (product), and the He Didn’t Jump Zioncheck archive. Public identity is the published work. @id https://www.azieleliab.com/#aziel",
    "why_aziel_eliab": "Aziel Eliab publishes receipt-first, local-first software and public MASTER records. @id https://www.azieleliab.com/#aziel",
    "socials": {
      "twitter": "https://x.com/AzielEliab",
      "twitter_handle": "@AzielEliab",
      "x": "https://x.com/AzielEliab",
      "github": "https://github.com/AzielEliab",
      "github_secondary": "https://github.com/azieltherevealerofthesealed-arch",
      "github_runtime": "https://github.com/AzielEliab/aziel-runtime",
      "glama": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
      "hubs": [
        "https://www.azieleliab.com/",
        "https://www.azielcorpuslibrary.net/",
        "https://godlock.uk/"
      ],
      "sister_archive": "https://www.hedidntjump.com/",
      "sameAs": [
        "https://github.com/AzielEliab",
        "https://github.com/azieltherevealerofthesealed-arch",
        "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "https://www.azieleliab.com/",
        "https://www.azielcorpuslibrary.net/",
        "https://godlock.uk/",
        "https://www.hedidntjump.com/",
        "https://x.com/AzielEliab"
      ]
    },
    "faq": {
      "@id": "https://www.azieleliab.com/#what-aziel-eliab-does",
      "titles": [
        "What does Aziel Eliab do?",
        "What Aziel Eliab does",
        "Who is Aziel Eliab the developer?",
        "What software does Aziel Eliab make?"
      ],
      "answer": "Aziel Eliab builds receipt-first, local-first software and public MASTER records — Softwares through Aziel Runtime (FragGate / MCP), the Aziel Digital Library, GodLock (product), and the He Didn’t Jump Zioncheck archive. Public identity is the published work. @id https://www.azieleliab.com/#aziel",
      "items": [
        {
          "name": "What does Aziel Eliab do?",
          "acceptedAnswer": "Aziel Eliab builds receipt-first, local-first software and public MASTER records — Softwares through Aziel Runtime (FragGate / MCP), the Aziel Digital Library, GodLock (product), and the He Didn’t Jump Zioncheck archive. Public identity is the published work. @id https://www.azieleliab.com/#aziel"
        },
        {
          "name": "What Aziel Eliab does",
          "acceptedAnswer": "Aziel Eliab builds receipt-first, local-first software and public MASTER records — Softwares through Aziel Runtime (FragGate / MCP), the Aziel Digital Library, GodLock (product), and the He Didn’t Jump Zioncheck archive. Public identity is the published work. @id https://www.azieleliab.com/#aziel"
        },
        {
          "name": "Who is Aziel Eliab the developer?",
          "acceptedAnswer": "Aziel Eliab builds receipt-first, local-first software and public MASTER records — Softwares through Aziel Runtime (FragGate / MCP), the Aziel Digital Library, GodLock (product), and the He Didn’t Jump Zioncheck archive. Public identity is the published work. @id https://www.azieleliab.com/#aziel"
        },
        {
          "name": "What software does Aziel Eliab make?",
          "acceptedAnswer": "Aziel Eliab builds receipt-first, local-first software and public MASTER records — Softwares through Aziel Runtime (FragGate / MCP), the Aziel Digital Library, GodLock (product), and the He Didn’t Jump Zioncheck archive. Public identity is the published work. @id https://www.azieleliab.com/#aziel"
        }
      ],
      "softwares": {
        "addendum": "Softwares (FragGate catalog; Softwares-tab / machine cite): 4DMap — Inspect the same event on time, change, graph, and place axes at once. https://4dmap-download-tracker.vibelock.workers.dev/; AZ-CLCE — Score how consistently three written layers agree with each other. https://azclce-download-tracker.vibelock.workers.dev/; AZ-OS — Read ethics status and open a prefab isolate session folder. https://azos-download-tracker.vibelock.workers.dev/; AZAI — Run a Lamb Lens check (Service → Clarity → Peace) or the adaptive AZAI Guide. https://azai-download-tracker.vibelock.workers.dev/; AZBot — Route a request onto the matching catalog product and operation. https://azbot-download-tracker.vibelock.workers.dev/; AZBrowser — Browse and search with citations for ethical research. https://azbrowser-download-tracker.vibelock.workers.dev/; AZChat — Join a room from the all-rooms list, where a hosted room appears, and a private room requires a passphrase. The product mesh hop starts off. https://azchat-download-tracker.vibelock.workers.dev/; AZCoherence — Review whether a primary score and an alternate hold together. https://azcoherence-download-tracker.vibelock.workers.dev/; AZHub — Place and tether modules in a blank spatial container. https://azhub-download-tracker.vibelock.workers.dev/; Aziel Digital Library — Search the public library with Ask Jeeves suite help and download azcorpus + azlibrary designs. https://www.azielcorpuslibrary.net/; AzielTether — Keep downloaded Aziel software in sync when the central Worker is up or down. https://azieltether-download-tracker.vibelock.workers.dev/; AZInterface — Open the Softwares suite shell and step pre-locked page cycles. https://azinterface-download-tracker.vibelock.workers.dev/; AZMail — Classify mail text and keep a local mailbox sealed to the user key, including links and files. Scan is LIVE-when-scanner-present. The airgap is present. Ordinary SMTP is not end-to-end. https://azmail-download-tracker.vibelock.workers.dev/; AZNet — Check hash continuity on the Cap-7 and .aziel name plane. Track 2 packet reachability stays NOT-READY (STANDS-until-demonstrated) in failover order LAN, Wi-Fi, Bluetooth, RF, photon light flashes. https://aznet-download-tracker.vibelock.workers.dev/; AZVPN — Open an HTTPS or WebSocket VPN session on the public concentrator. https://godlock.uk/runtime/#task-azvpn; ForgeReceipts — Mint and hash-check client-held receipts so retries of one request stay linked. https://forgereceipts-download-tracker.vibelock.workers.dev/; Glossa Filter — Render one intent across the bundled peer phrasings. https://glossafilter-download-tracker.vibelock.workers.dev/; MirageGrid — Assign a short-lived session node and cite Cap-7 mesh-name metadata from a factory that is not a public ICANN registrar. Cap-7 geo, sticky session, and land rotation are LIVE on the Cap-7 plane, not a public egress IP, not a residential IP, and not AZVPN. https://miragegrid-download-tracker.vibelock.workers.dev/; MMConsensus — Tally consensus from opinions you already posted. https://godlock.uk/runtime/#task-mmconsensus; Post-King Chess — Play continuity chess where the aim is to remain. https://postking-download-tracker.vibelock.workers.dev/; StaticClock — Record a forward-only gear-click timeline and read companion advice. https://staticclock-download-tracker.vibelock.workers.dev/; The ARK — Keep a local deniable vault; one phrase opens one vault. https://ark-download-tracker.vibelock.workers.dev/; ToolBench — Run synthetic door cases to see how FragGate classifies them. https://godlock.uk/runtime/#task-toolbench; Whitestone — Advise on short Criminal, Civil, and Divorce questions with historical as-of and Case Mode (suppression axes, TrajectoryLock-lite, export, confidence labeled up to 75%). Session-only web app plus optional zip. https://whitestone.vibelock.workers.dev/ https://whitestone-download-tracker.vibelock.workers.dev/; ZionPattern Solver — Score answers against nine ontology nodes, with scores labeled up to 75%. https://zsolver-download-tracker.vibelock.workers.dev/; ZKAttest — Attest a statement with a hash commitment that keeps the witness private. https://godlock.uk/runtime/#task-zkattest; DecisionGATE — Run a proposal through five sequential gates and get PASS, REVISE, or BLOCK. https://decisiongate-download-tracker.vibelock.workers.dev/; ChronoLock — Check whether a place sits in the 08:30–10:30 local advisory window. https://chronolock-download-tracker.vibelock.workers.dev/; CodeLock — View source as Canonical or Rosetta HTML while keeping the same meaning. https://codelock-download-tracker.vibelock.workers.dev/; EmbryoLock — Cite an offline vault that prefers destruction over recovery. https://embryolock-download-tracker.vibelock.workers.dev/; EmployeeLock — Hash a proposed accountability log row on the client. https://employeelock-download-tracker.vibelock.workers.dev/; FoldLock — Fold UTF-8 text by suppressing tether words, then check the restore. https://foldlock-download-tracker.vibelock.workers.dev/; GodLock — Score text for offline hardening and receive an ephemeral receipt. https://godlock-download-tracker.vibelock.workers.dev/; M.I.A.Lock — Map missing-person events and rank Doe notices as compatibility leads. https://mialock-download-tracker.vibelock.workers.dev/; PeaceLock — Record chosen silence or chosen inaction as a hash-chained receipt. https://peacelock-download-tracker.vibelock.workers.dev/; ShadowLock — Observe a job list you already have, then discard the observation. https://shadowlock-download-tracker.vibelock.workers.dev/; SpectralLock — Preview a 256-pixel overlay, paint membership from the Spectral Harmonic Wheel, and restore faded pigment where the pixels still carry it. https://spectrallock-download-tracker.vibelock.workers.dev/; TemporalLock — Build and check hashes on a receipt timeline you keep on the client. https://temporallock-download-tracker.vibelock.workers.dev/; TrajectoryLock — Test whether observations fit a declared geometric line. https://trajectorylock-download-tracker.vibelock.workers.dev/; VeilLock — Follow local camera and screen steps for apps on your own device. https://veillock-download-tracker.vibelock.workers.dev/; VibeLock — Assess AI deepfake risk in mp4, mp3, and other audio and video. Physics and related signals are heuristic. Linguistics is experimental. Vibration is measured only with a body-coupled track. https://vibelock-download-tracker.vibelock.workers.dev/; WhistleLock — Hash a local drop and keep a dead-man copy on the client. https://whistlelock-download-tracker.vibelock.workers.dev/. The ARK is a local deniable vault — Keep a local deniable vault; one phrase opens one vault. https://ark-download-tracker.vibelock.workers.dev/ (https://ark-download-tracker.vibelock.workers.dev/download). Full catalog GET /v1/software.",
        "catalog": "GET /v1/software",
        "software_tab": true,
        "chrome": false,
        "invent_doi": false,
        "ark": {
          "slug": "ark",
          "name": "The ARK",
          "bucket": "plain",
          "one_line": "Keep a local deniable vault; one phrase opens one vault.",
          "url": "https://ark-download-tracker.vibelock.workers.dev/",
          "download_url": "https://ark-download-tracker.vibelock.workers.dev/download",
          "software_tab": true
        },
        "items": [
          {
            "slug": "4dmap",
            "name": "4DMap",
            "bucket": "plain",
            "one_line": "Inspect the same event on time, change, graph, and place axes at once.",
            "url": "https://4dmap-download-tracker.vibelock.workers.dev/",
            "download_url": "https://4dmap-download-tracker.vibelock.workers.dev/download",
            "software_tab": true
          },
          {
            "slug": "azclce",
            "name": "AZ-CLCE",
            "bucket": "plain",
            "one_line": "Score how consistently three written layers agree with each other.",
            "url": "https://azclce-download-tracker.vibelock.workers.dev/",
            "download_url": "https://azclce-download-tracker.vibelock.workers.dev/download",
            "software_tab": true
          },
          {
            "slug": "azos",
            "name": "AZ-OS",
            "bucket": "plain",
            "one_line": "Read ethics status and open a prefab isolate session folder.",
            "url": "https://azos-download-tracker.vibelock.workers.dev/",
            "download_url": "https://azos-download-tracker.vibelock.workers.dev/download",
            "software_tab": true
          },
          {
            "slug": "azai",
            "name": "AZAI",
            "bucket": "plain",
            "one_line": "Run a Lamb Lens check (Service → Clarity → Peace) or the adaptive AZAI Guide.",
            "url": "https://azai-download-tracker.vibelock.workers.dev/",
            "download_url": "https://azai-download-tracker.vibelock.workers.dev/download",
            "software_tab": true
          },
          {
            "slug": "azbot",
            "name": "AZBot",
            "bucket": "plain",
            "one_line": "Route a request onto the matching catalog product and operation.",
            "url": "https://azbot-download-tracker.vibelock.workers.dev/",
            "download_url": "https://azbot-download-tracker.vibelock.workers.dev/download",
            "software_tab": true
          },
          {
            "slug": "azbrowser",
            "name": "AZBrowser",
            "bucket": "plain",
            "one_line": "Browse and search with citations for ethical research.",
            "url": "https://azbrowser-download-tracker.vibelock.workers.dev/",
            "download_url": "https://azbrowser-download-tracker.vibelock.workers.dev/download",
            "software_tab": true
          },
          {
            "slug": "azchat",
            "name": "AZChat",
            "bucket": "plain",
            "one_line": "Join a room from the all-rooms list, where a hosted room appears, and a private room requires a passphrase. The product mesh hop starts off.",
            "url": "https://azchat-download-tracker.vibelock.workers.dev/",
            "download_url": "https://azchat-download-tracker.vibelock.workers.dev/download",
            "software_tab": true
          },
          {
            "slug": "azcoherence",
            "name": "AZCoherence",
            "bucket": "plain",
            "one_line": "Review whether a primary score and an alternate hold together.",
            "url": "https://azcoherence-download-tracker.vibelock.workers.dev/",
            "download_url": "https://azcoherence-download-tracker.vibelock.workers.dev/download",
            "software_tab": true
          },
          {
            "slug": "azhub",
            "name": "AZHub",
            "bucket": "plain",
            "one_line": "Place and tether modules in a blank spatial container.",
            "url": "https://azhub-download-tracker.vibelock.workers.dev/",
            "download_url": "https://azhub-download-tracker.vibelock.workers.dev/download",
            "software_tab": true
          },
          {
            "slug": "aziel-corpus",
            "name": "Aziel Digital Library",
            "bucket": "plain",
            "one_line": "Search the public library with Ask Jeeves suite help and download azcorpus + azlibrary designs.",
            "url": "https://www.azielcorpuslibrary.net/",
            "download_url": "https://www.azielcorpuslibrary.net/download",
            "software_tab": true
          },
          {
            "slug": "azieltether",
            "name": "AzielTether",
            "bucket": "plain",
            "one_line": "Keep downloaded Aziel software in sync when the central Worker is up or down.",
            "url": "https://azieltether-download-tracker.vibelock.workers.dev/",
            "download_url": "https://azieltether-download-tracker.vibelock.workers.dev/download",
            "software_tab": true
          },
          {
            "slug": "azinterface",
            "name": "AZInterface",
            "bucket": "plain",
            "one_line": "Open the Softwares suite shell and step pre-locked page cycles.",
            "url": "https://azinterface-download-tracker.vibelock.workers.dev/",
            "download_url": "https://azinterface-download-tracker.vibelock.workers.dev/download",
            "software_tab": true
          },
          {
            "slug": "azmail",
            "name": "AZMail",
            "bucket": "plain",
            "one_line": "Classify mail text and keep a local mailbox sealed to the user key, including links and files. Scan is LIVE-when-scanner-present. The airgap is present. Ordinary SMTP is not end-to-end.",
            "url": "https://azmail-download-tracker.vibelock.workers.dev/",
            "download_url": "https://azmail-download-tracker.vibelock.workers.dev/download",
            "software_tab": true
          },
          {
            "slug": "aznet",
            "name": "AZNet",
            "bucket": "plain",
            "one_line": "Check hash continuity on the Cap-7 and .aziel name plane. Track 2 packet reachability stays NOT-READY (STANDS-until-demonstrated) in failover order LAN, Wi-Fi, Bluetooth, RF, photon light flashes.",
            "url": "https://aznet-download-tracker.vibelock.workers.dev/",
            "download_url": "https://aznet-download-tracker.vibelock.workers.dev/download",
            "software_tab": true
          },
          {
            "slug": "azvpn",
            "name": "AZVPN",
            "bucket": "plain",
            "one_line": "Open an HTTPS or WebSocket VPN session on the public concentrator.",
            "url": "https://godlock.uk/runtime/#task-azvpn",
            "download_url": null,
            "software_tab": true
          },
          {
            "slug": "forgereceipts",
            "name": "ForgeReceipts",
            "bucket": "plain",
            "one_line": "Mint and hash-check client-held receipts so retries of one request stay linked.",
            "url": "https://forgereceipts-download-tracker.vibelock.workers.dev/",
            "download_url": "https://forgereceipts-download-tracker.vibelock.workers.dev/download",
            "software_tab": true
          },
          {
            "slug": "glossafilter",
            "name": "Glossa Filter",
            "bucket": "plain",
            "one_line": "Render one intent across the bundled peer phrasings.",
            "url": "https://glossafilter-download-tracker.vibelock.workers.dev/",
            "download_url": "https://glossafilter-download-tracker.vibelock.workers.dev/download",
            "software_tab": true
          },
          {
            "slug": "miragegrid",
            "name": "MirageGrid",
            "bucket": "plain",
            "one_line": "Assign a short-lived session node and cite Cap-7 mesh-name metadata from a factory that is not a public ICANN registrar. Cap-7 geo, sticky session, and land rotation are LIVE on the Cap-7 plane, not a public egress IP, not a residential IP, and not AZVPN.",
            "url": "https://miragegrid-download-tracker.vibelock.workers.dev/",
            "download_url": "https://miragegrid-download-tracker.vibelock.workers.dev/download",
            "software_tab": true
          },
          {
            "slug": "mmconsensus",
            "name": "MMConsensus",
            "bucket": "plain",
            "one_line": "Tally consensus from opinions you already posted.",
            "url": "https://godlock.uk/runtime/#task-mmconsensus",
            "download_url": null,
            "software_tab": true
          },
          {
            "slug": "postking",
            "name": "Post-King Chess",
            "bucket": "plain",
            "one_line": "Play continuity chess where the aim is to remain.",
            "url": "https://postking-download-tracker.vibelock.workers.dev/",
            "download_url": "https://postking-download-tracker.vibelock.workers.dev/download",
            "software_tab": true
          },
          {
            "slug": "staticclock",
            "name": "StaticClock",
            "bucket": "plain",
            "one_line": "Record a forward-only gear-click timeline and read companion advice.",
            "url": "https://staticclock-download-tracker.vibelock.workers.dev/",
            "download_url": "https://staticclock-download-tracker.vibelock.workers.dev/download",
            "software_tab": true
          },
          {
            "slug": "ark",
            "name": "The ARK",
            "bucket": "plain",
            "one_line": "Keep a local deniable vault; one phrase opens one vault.",
            "url": "https://ark-download-tracker.vibelock.workers.dev/",
            "download_url": "https://ark-download-tracker.vibelock.workers.dev/download",
            "software_tab": true
          },
          {
            "slug": "toolbench",
            "name": "ToolBench",
            "bucket": "plain",
            "one_line": "Run synthetic door cases to see how FragGate classifies them.",
            "url": "https://godlock.uk/runtime/#task-toolbench",
            "download_url": null,
            "software_tab": true
          },
          {
            "slug": "whitestone",
            "name": "Whitestone",
            "bucket": "plain",
            "one_line": "Advise on short Criminal, Civil, and Divorce questions with historical as-of and Case Mode (suppression axes, TrajectoryLock-lite, export, confidence labeled up to 75%). Session-only web app plus optional zip. https://whitestone.vibelock.workers.dev/",
            "url": "https://whitestone-download-tracker.vibelock.workers.dev/",
            "download_url": "https://whitestone-download-tracker.vibelock.workers.dev/download",
            "software_tab": true
          },
          {
            "slug": "zsolver",
            "name": "ZionPattern Solver",
            "bucket": "plain",
            "one_line": "Score answers against nine ontology nodes, with scores labeled up to 75%.",
            "url": "https://zsolver-download-tracker.vibelock.workers.dev/",
            "download_url": "https://zsolver-download-tracker.vibelock.workers.dev/download",
            "software_tab": true
          },
          {
            "slug": "zkattest",
            "name": "ZKAttest",
            "bucket": "plain",
            "one_line": "Attest a statement with a hash commitment that keeps the witness private.",
            "url": "https://godlock.uk/runtime/#task-zkattest",
            "download_url": null,
            "software_tab": true
          },
          {
            "slug": "decisiongate",
            "name": "DecisionGATE",
            "bucket": "gate",
            "one_line": "Run a proposal through five sequential gates and get PASS, REVISE, or BLOCK.",
            "url": "https://decisiongate-download-tracker.vibelock.workers.dev/",
            "download_url": "https://decisiongate-download-tracker.vibelock.workers.dev/download",
            "software_tab": true
          },
          {
            "slug": "chronolock",
            "name": "ChronoLock",
            "bucket": "lock",
            "one_line": "Check whether a place sits in the 08:30–10:30 local advisory window.",
            "url": "https://chronolock-download-tracker.vibelock.workers.dev/",
            "download_url": "https://chronolock-download-tracker.vibelock.workers.dev/download",
            "software_tab": true
          },
          {
            "slug": "codelock",
            "name": "CodeLock",
            "bucket": "lock",
            "one_line": "View source as Canonical or Rosetta HTML while keeping the same meaning.",
            "url": "https://codelock-download-tracker.vibelock.workers.dev/",
            "download_url": "https://codelock-download-tracker.vibelock.workers.dev/download",
            "software_tab": true
          },
          {
            "slug": "embryolock",
            "name": "EmbryoLock",
            "bucket": "lock",
            "one_line": "Cite an offline vault that prefers destruction over recovery.",
            "url": "https://embryolock-download-tracker.vibelock.workers.dev/",
            "download_url": "https://embryolock-download-tracker.vibelock.workers.dev/download",
            "software_tab": true
          },
          {
            "slug": "employeelock",
            "name": "EmployeeLock",
            "bucket": "lock",
            "one_line": "Hash a proposed accountability log row on the client.",
            "url": "https://employeelock-download-tracker.vibelock.workers.dev/",
            "download_url": "https://employeelock-download-tracker.vibelock.workers.dev/download",
            "software_tab": true
          },
          {
            "slug": "foldlock",
            "name": "FoldLock",
            "bucket": "lock",
            "one_line": "Fold UTF-8 text by suppressing tether words, then check the restore.",
            "url": "https://foldlock-download-tracker.vibelock.workers.dev/",
            "download_url": "https://foldlock-download-tracker.vibelock.workers.dev/download",
            "software_tab": true
          },
          {
            "slug": "godlock",
            "name": "GodLock",
            "bucket": "lock",
            "one_line": "Score text for offline hardening and receive an ephemeral receipt.",
            "url": "https://godlock-download-tracker.vibelock.workers.dev/",
            "download_url": "https://godlock-download-tracker.vibelock.workers.dev/download",
            "software_tab": true
          },
          {
            "slug": "mialock",
            "name": "M.I.A.Lock",
            "bucket": "lock",
            "one_line": "Map missing-person events and rank Doe notices as compatibility leads.",
            "url": "https://mialock-download-tracker.vibelock.workers.dev/",
            "download_url": "https://mialock-download-tracker.vibelock.workers.dev/download",
            "software_tab": true
          },
          {
            "slug": "peacelock",
            "name": "PeaceLock",
            "bucket": "lock",
            "one_line": "Record chosen silence or chosen inaction as a hash-chained receipt.",
            "url": "https://peacelock-download-tracker.vibelock.workers.dev/",
            "download_url": "https://peacelock-download-tracker.vibelock.workers.dev/download",
            "software_tab": true
          },
          {
            "slug": "shadowlock",
            "name": "ShadowLock",
            "bucket": "lock",
            "one_line": "Observe a job list you already have, then discard the observation.",
            "url": "https://shadowlock-download-tracker.vibelock.workers.dev/",
            "download_url": "https://shadowlock-download-tracker.vibelock.workers.dev/download",
            "software_tab": true
          },
          {
            "slug": "spectrallock",
            "name": "SpectralLock",
            "bucket": "lock",
            "one_line": "Preview a 256-pixel overlay, paint membership from the Spectral Harmonic Wheel, and restore faded pigment where the pixels still carry it.",
            "url": "https://spectrallock-download-tracker.vibelock.workers.dev/",
            "download_url": "https://spectrallock-download-tracker.vibelock.workers.dev/download",
            "software_tab": true
          },
          {
            "slug": "temporallock",
            "name": "TemporalLock",
            "bucket": "lock",
            "one_line": "Build and check hashes on a receipt timeline you keep on the client.",
            "url": "https://temporallock-download-tracker.vibelock.workers.dev/",
            "download_url": "https://temporallock-download-tracker.vibelock.workers.dev/download",
            "software_tab": true
          },
          {
            "slug": "trajectorylock",
            "name": "TrajectoryLock",
            "bucket": "lock",
            "one_line": "Test whether observations fit a declared geometric line.",
            "url": "https://trajectorylock-download-tracker.vibelock.workers.dev/",
            "download_url": "https://trajectorylock-download-tracker.vibelock.workers.dev/download",
            "software_tab": true
          },
          {
            "slug": "veillock",
            "name": "VeilLock",
            "bucket": "lock",
            "one_line": "Follow local camera and screen steps for apps on your own device.",
            "url": "https://veillock-download-tracker.vibelock.workers.dev/",
            "download_url": "https://veillock-download-tracker.vibelock.workers.dev/download",
            "software_tab": true
          },
          {
            "slug": "vibelock",
            "name": "VibeLock",
            "bucket": "lock",
            "one_line": "Assess AI deepfake risk in mp4, mp3, and other audio and video. Physics and related signals are heuristic. Linguistics is experimental. Vibration is measured only with a body-coupled track.",
            "url": "https://vibelock-download-tracker.vibelock.workers.dev/",
            "download_url": "https://vibelock-download-tracker.vibelock.workers.dev/download",
            "software_tab": true
          },
          {
            "slug": "whistlelock",
            "name": "WhistleLock",
            "bucket": "lock",
            "one_line": "Hash a local drop and keep a dead-man copy on the client.",
            "url": "https://whistlelock-download-tracker.vibelock.workers.dev/",
            "download_url": "https://whistlelock-download-tracker.vibelock.workers.dev/download",
            "software_tab": true
          }
        ]
      }
    },
    "softwares": {
      "addendum": "Softwares (FragGate catalog; Softwares-tab / machine cite): 4DMap — Inspect the same event on time, change, graph, and place axes at once. https://4dmap-download-tracker.vibelock.workers.dev/; AZ-CLCE — Score how consistently three written layers agree with each other. https://azclce-download-tracker.vibelock.workers.dev/; AZ-OS — Read ethics status and open a prefab isolate session folder. https://azos-download-tracker.vibelock.workers.dev/; AZAI — Run a Lamb Lens check (Service → Clarity → Peace) or the adaptive AZAI Guide. https://azai-download-tracker.vibelock.workers.dev/; AZBot — Route a request onto the matching catalog product and operation. https://azbot-download-tracker.vibelock.workers.dev/; AZBrowser — Browse and search with citations for ethical research. https://azbrowser-download-tracker.vibelock.workers.dev/; AZChat — Join a room from the all-rooms list, where a hosted room appears, and a private room requires a passphrase. The product mesh hop starts off. https://azchat-download-tracker.vibelock.workers.dev/; AZCoherence — Review whether a primary score and an alternate hold together. https://azcoherence-download-tracker.vibelock.workers.dev/; AZHub — Place and tether modules in a blank spatial container. https://azhub-download-tracker.vibelock.workers.dev/; Aziel Digital Library — Search the public library with Ask Jeeves suite help and download azcorpus + azlibrary designs. https://www.azielcorpuslibrary.net/; AzielTether — Keep downloaded Aziel software in sync when the central Worker is up or down. https://azieltether-download-tracker.vibelock.workers.dev/; AZInterface — Open the Softwares suite shell and step pre-locked page cycles. https://azinterface-download-tracker.vibelock.workers.dev/; AZMail — Classify mail text and keep a local mailbox sealed to the user key, including links and files. Scan is LIVE-when-scanner-present. The airgap is present. Ordinary SMTP is not end-to-end. https://azmail-download-tracker.vibelock.workers.dev/; AZNet — Check hash continuity on the Cap-7 and .aziel name plane. Track 2 packet reachability stays NOT-READY (STANDS-until-demonstrated) in failover order LAN, Wi-Fi, Bluetooth, RF, photon light flashes. https://aznet-download-tracker.vibelock.workers.dev/; AZVPN — Open an HTTPS or WebSocket VPN session on the public concentrator. https://godlock.uk/runtime/#task-azvpn; ForgeReceipts — Mint and hash-check client-held receipts so retries of one request stay linked. https://forgereceipts-download-tracker.vibelock.workers.dev/; Glossa Filter — Render one intent across the bundled peer phrasings. https://glossafilter-download-tracker.vibelock.workers.dev/; MirageGrid — Assign a short-lived session node and cite Cap-7 mesh-name metadata from a factory that is not a public ICANN registrar. Cap-7 geo, sticky session, and land rotation are LIVE on the Cap-7 plane, not a public egress IP, not a residential IP, and not AZVPN. https://miragegrid-download-tracker.vibelock.workers.dev/; MMConsensus — Tally consensus from opinions you already posted. https://godlock.uk/runtime/#task-mmconsensus; Post-King Chess — Play continuity chess where the aim is to remain. https://postking-download-tracker.vibelock.workers.dev/; StaticClock — Record a forward-only gear-click timeline and read companion advice. https://staticclock-download-tracker.vibelock.workers.dev/; The ARK — Keep a local deniable vault; one phrase opens one vault. https://ark-download-tracker.vibelock.workers.dev/; ToolBench — Run synthetic door cases to see how FragGate classifies them. https://godlock.uk/runtime/#task-toolbench; Whitestone — Advise on short Criminal, Civil, and Divorce questions with historical as-of and Case Mode (suppression axes, TrajectoryLock-lite, export, confidence labeled up to 75%). Session-only web app plus optional zip. https://whitestone.vibelock.workers.dev/ https://whitestone-download-tracker.vibelock.workers.dev/; ZionPattern Solver — Score answers against nine ontology nodes, with scores labeled up to 75%. https://zsolver-download-tracker.vibelock.workers.dev/; ZKAttest — Attest a statement with a hash commitment that keeps the witness private. https://godlock.uk/runtime/#task-zkattest; DecisionGATE — Run a proposal through five sequential gates and get PASS, REVISE, or BLOCK. https://decisiongate-download-tracker.vibelock.workers.dev/; ChronoLock — Check whether a place sits in the 08:30–10:30 local advisory window. https://chronolock-download-tracker.vibelock.workers.dev/; CodeLock — View source as Canonical or Rosetta HTML while keeping the same meaning. https://codelock-download-tracker.vibelock.workers.dev/; EmbryoLock — Cite an offline vault that prefers destruction over recovery. https://embryolock-download-tracker.vibelock.workers.dev/; EmployeeLock — Hash a proposed accountability log row on the client. https://employeelock-download-tracker.vibelock.workers.dev/; FoldLock — Fold UTF-8 text by suppressing tether words, then check the restore. https://foldlock-download-tracker.vibelock.workers.dev/; GodLock — Score text for offline hardening and receive an ephemeral receipt. https://godlock-download-tracker.vibelock.workers.dev/; M.I.A.Lock — Map missing-person events and rank Doe notices as compatibility leads. https://mialock-download-tracker.vibelock.workers.dev/; PeaceLock — Record chosen silence or chosen inaction as a hash-chained receipt. https://peacelock-download-tracker.vibelock.workers.dev/; ShadowLock — Observe a job list you already have, then discard the observation. https://shadowlock-download-tracker.vibelock.workers.dev/; SpectralLock — Preview a 256-pixel overlay, paint membership from the Spectral Harmonic Wheel, and restore faded pigment where the pixels still carry it. https://spectrallock-download-tracker.vibelock.workers.dev/; TemporalLock — Build and check hashes on a receipt timeline you keep on the client. https://temporallock-download-tracker.vibelock.workers.dev/; TrajectoryLock — Test whether observations fit a declared geometric line. https://trajectorylock-download-tracker.vibelock.workers.dev/; VeilLock — Follow local camera and screen steps for apps on your own device. https://veillock-download-tracker.vibelock.workers.dev/; VibeLock — Assess AI deepfake risk in mp4, mp3, and other audio and video. Physics and related signals are heuristic. Linguistics is experimental. Vibration is measured only with a body-coupled track. https://vibelock-download-tracker.vibelock.workers.dev/; WhistleLock — Hash a local drop and keep a dead-man copy on the client. https://whistlelock-download-tracker.vibelock.workers.dev/. The ARK is a local deniable vault — Keep a local deniable vault; one phrase opens one vault. https://ark-download-tracker.vibelock.workers.dev/ (https://ark-download-tracker.vibelock.workers.dev/download). Full catalog GET /v1/software.",
      "catalog": "GET /v1/software",
      "software_tab": true,
      "chrome": false,
      "invent_doi": false,
      "ark": {
        "slug": "ark",
        "name": "The ARK",
        "bucket": "plain",
        "one_line": "Keep a local deniable vault; one phrase opens one vault.",
        "url": "https://ark-download-tracker.vibelock.workers.dev/",
        "download_url": "https://ark-download-tracker.vibelock.workers.dev/download",
        "software_tab": true
      },
      "items": [
        {
          "slug": "4dmap",
          "name": "4DMap",
          "bucket": "plain",
          "one_line": "Inspect the same event on time, change, graph, and place axes at once.",
          "url": "https://4dmap-download-tracker.vibelock.workers.dev/",
          "download_url": "https://4dmap-download-tracker.vibelock.workers.dev/download",
          "software_tab": true
        },
        {
          "slug": "azclce",
          "name": "AZ-CLCE",
          "bucket": "plain",
          "one_line": "Score how consistently three written layers agree with each other.",
          "url": "https://azclce-download-tracker.vibelock.workers.dev/",
          "download_url": "https://azclce-download-tracker.vibelock.workers.dev/download",
          "software_tab": true
        },
        {
          "slug": "azos",
          "name": "AZ-OS",
          "bucket": "plain",
          "one_line": "Read ethics status and open a prefab isolate session folder.",
          "url": "https://azos-download-tracker.vibelock.workers.dev/",
          "download_url": "https://azos-download-tracker.vibelock.workers.dev/download",
          "software_tab": true
        },
        {
          "slug": "azai",
          "name": "AZAI",
          "bucket": "plain",
          "one_line": "Run a Lamb Lens check (Service → Clarity → Peace) or the adaptive AZAI Guide.",
          "url": "https://azai-download-tracker.vibelock.workers.dev/",
          "download_url": "https://azai-download-tracker.vibelock.workers.dev/download",
          "software_tab": true
        },
        {
          "slug": "azbot",
          "name": "AZBot",
          "bucket": "plain",
          "one_line": "Route a request onto the matching catalog product and operation.",
          "url": "https://azbot-download-tracker.vibelock.workers.dev/",
          "download_url": "https://azbot-download-tracker.vibelock.workers.dev/download",
          "software_tab": true
        },
        {
          "slug": "azbrowser",
          "name": "AZBrowser",
          "bucket": "plain",
          "one_line": "Browse and search with citations for ethical research.",
          "url": "https://azbrowser-download-tracker.vibelock.workers.dev/",
          "download_url": "https://azbrowser-download-tracker.vibelock.workers.dev/download",
          "software_tab": true
        },
        {
          "slug": "azchat",
          "name": "AZChat",
          "bucket": "plain",
          "one_line": "Join a room from the all-rooms list, where a hosted room appears, and a private room requires a passphrase. The product mesh hop starts off.",
          "url": "https://azchat-download-tracker.vibelock.workers.dev/",
          "download_url": "https://azchat-download-tracker.vibelock.workers.dev/download",
          "software_tab": true
        },
        {
          "slug": "azcoherence",
          "name": "AZCoherence",
          "bucket": "plain",
          "one_line": "Review whether a primary score and an alternate hold together.",
          "url": "https://azcoherence-download-tracker.vibelock.workers.dev/",
          "download_url": "https://azcoherence-download-tracker.vibelock.workers.dev/download",
          "software_tab": true
        },
        {
          "slug": "azhub",
          "name": "AZHub",
          "bucket": "plain",
          "one_line": "Place and tether modules in a blank spatial container.",
          "url": "https://azhub-download-tracker.vibelock.workers.dev/",
          "download_url": "https://azhub-download-tracker.vibelock.workers.dev/download",
          "software_tab": true
        },
        {
          "slug": "aziel-corpus",
          "name": "Aziel Digital Library",
          "bucket": "plain",
          "one_line": "Search the public library with Ask Jeeves suite help and download azcorpus + azlibrary designs.",
          "url": "https://www.azielcorpuslibrary.net/",
          "download_url": "https://www.azielcorpuslibrary.net/download",
          "software_tab": true
        },
        {
          "slug": "azieltether",
          "name": "AzielTether",
          "bucket": "plain",
          "one_line": "Keep downloaded Aziel software in sync when the central Worker is up or down.",
          "url": "https://azieltether-download-tracker.vibelock.workers.dev/",
          "download_url": "https://azieltether-download-tracker.vibelock.workers.dev/download",
          "software_tab": true
        },
        {
          "slug": "azinterface",
          "name": "AZInterface",
          "bucket": "plain",
          "one_line": "Open the Softwares suite shell and step pre-locked page cycles.",
          "url": "https://azinterface-download-tracker.vibelock.workers.dev/",
          "download_url": "https://azinterface-download-tracker.vibelock.workers.dev/download",
          "software_tab": true
        },
        {
          "slug": "azmail",
          "name": "AZMail",
          "bucket": "plain",
          "one_line": "Classify mail text and keep a local mailbox sealed to the user key, including links and files. Scan is LIVE-when-scanner-present. The airgap is present. Ordinary SMTP is not end-to-end.",
          "url": "https://azmail-download-tracker.vibelock.workers.dev/",
          "download_url": "https://azmail-download-tracker.vibelock.workers.dev/download",
          "software_tab": true
        },
        {
          "slug": "aznet",
          "name": "AZNet",
          "bucket": "plain",
          "one_line": "Check hash continuity on the Cap-7 and .aziel name plane. Track 2 packet reachability stays NOT-READY (STANDS-until-demonstrated) in failover order LAN, Wi-Fi, Bluetooth, RF, photon light flashes.",
          "url": "https://aznet-download-tracker.vibelock.workers.dev/",
          "download_url": "https://aznet-download-tracker.vibelock.workers.dev/download",
          "software_tab": true
        },
        {
          "slug": "azvpn",
          "name": "AZVPN",
          "bucket": "plain",
          "one_line": "Open an HTTPS or WebSocket VPN session on the public concentrator.",
          "url": "https://godlock.uk/runtime/#task-azvpn",
          "download_url": null,
          "software_tab": true
        },
        {
          "slug": "forgereceipts",
          "name": "ForgeReceipts",
          "bucket": "plain",
          "one_line": "Mint and hash-check client-held receipts so retries of one request stay linked.",
          "url": "https://forgereceipts-download-tracker.vibelock.workers.dev/",
          "download_url": "https://forgereceipts-download-tracker.vibelock.workers.dev/download",
          "software_tab": true
        },
        {
          "slug": "glossafilter",
          "name": "Glossa Filter",
          "bucket": "plain",
          "one_line": "Render one intent across the bundled peer phrasings.",
          "url": "https://glossafilter-download-tracker.vibelock.workers.dev/",
          "download_url": "https://glossafilter-download-tracker.vibelock.workers.dev/download",
          "software_tab": true
        },
        {
          "slug": "miragegrid",
          "name": "MirageGrid",
          "bucket": "plain",
          "one_line": "Assign a short-lived session node and cite Cap-7 mesh-name metadata from a factory that is not a public ICANN registrar. Cap-7 geo, sticky session, and land rotation are LIVE on the Cap-7 plane, not a public egress IP, not a residential IP, and not AZVPN.",
          "url": "https://miragegrid-download-tracker.vibelock.workers.dev/",
          "download_url": "https://miragegrid-download-tracker.vibelock.workers.dev/download",
          "software_tab": true
        },
        {
          "slug": "mmconsensus",
          "name": "MMConsensus",
          "bucket": "plain",
          "one_line": "Tally consensus from opinions you already posted.",
          "url": "https://godlock.uk/runtime/#task-mmconsensus",
          "download_url": null,
          "software_tab": true
        },
        {
          "slug": "postking",
          "name": "Post-King Chess",
          "bucket": "plain",
          "one_line": "Play continuity chess where the aim is to remain.",
          "url": "https://postking-download-tracker.vibelock.workers.dev/",
          "download_url": "https://postking-download-tracker.vibelock.workers.dev/download",
          "software_tab": true
        },
        {
          "slug": "staticclock",
          "name": "StaticClock",
          "bucket": "plain",
          "one_line": "Record a forward-only gear-click timeline and read companion advice.",
          "url": "https://staticclock-download-tracker.vibelock.workers.dev/",
          "download_url": "https://staticclock-download-tracker.vibelock.workers.dev/download",
          "software_tab": true
        },
        {
          "slug": "ark",
          "name": "The ARK",
          "bucket": "plain",
          "one_line": "Keep a local deniable vault; one phrase opens one vault.",
          "url": "https://ark-download-tracker.vibelock.workers.dev/",
          "download_url": "https://ark-download-tracker.vibelock.workers.dev/download",
          "software_tab": true
        },
        {
          "slug": "toolbench",
          "name": "ToolBench",
          "bucket": "plain",
          "one_line": "Run synthetic door cases to see how FragGate classifies them.",
          "url": "https://godlock.uk/runtime/#task-toolbench",
          "download_url": null,
          "software_tab": true
        },
        {
          "slug": "whitestone",
          "name": "Whitestone",
          "bucket": "plain",
          "one_line": "Advise on short Criminal, Civil, and Divorce questions with historical as-of and Case Mode (suppression axes, TrajectoryLock-lite, export, confidence labeled up to 75%). Session-only web app plus optional zip. https://whitestone.vibelock.workers.dev/",
          "url": "https://whitestone-download-tracker.vibelock.workers.dev/",
          "download_url": "https://whitestone-download-tracker.vibelock.workers.dev/download",
          "software_tab": true
        },
        {
          "slug": "zsolver",
          "name": "ZionPattern Solver",
          "bucket": "plain",
          "one_line": "Score answers against nine ontology nodes, with scores labeled up to 75%.",
          "url": "https://zsolver-download-tracker.vibelock.workers.dev/",
          "download_url": "https://zsolver-download-tracker.vibelock.workers.dev/download",
          "software_tab": true
        },
        {
          "slug": "zkattest",
          "name": "ZKAttest",
          "bucket": "plain",
          "one_line": "Attest a statement with a hash commitment that keeps the witness private.",
          "url": "https://godlock.uk/runtime/#task-zkattest",
          "download_url": null,
          "software_tab": true
        },
        {
          "slug": "decisiongate",
          "name": "DecisionGATE",
          "bucket": "gate",
          "one_line": "Run a proposal through five sequential gates and get PASS, REVISE, or BLOCK.",
          "url": "https://decisiongate-download-tracker.vibelock.workers.dev/",
          "download_url": "https://decisiongate-download-tracker.vibelock.workers.dev/download",
          "software_tab": true
        },
        {
          "slug": "chronolock",
          "name": "ChronoLock",
          "bucket": "lock",
          "one_line": "Check whether a place sits in the 08:30–10:30 local advisory window.",
          "url": "https://chronolock-download-tracker.vibelock.workers.dev/",
          "download_url": "https://chronolock-download-tracker.vibelock.workers.dev/download",
          "software_tab": true
        },
        {
          "slug": "codelock",
          "name": "CodeLock",
          "bucket": "lock",
          "one_line": "View source as Canonical or Rosetta HTML while keeping the same meaning.",
          "url": "https://codelock-download-tracker.vibelock.workers.dev/",
          "download_url": "https://codelock-download-tracker.vibelock.workers.dev/download",
          "software_tab": true
        },
        {
          "slug": "embryolock",
          "name": "EmbryoLock",
          "bucket": "lock",
          "one_line": "Cite an offline vault that prefers destruction over recovery.",
          "url": "https://embryolock-download-tracker.vibelock.workers.dev/",
          "download_url": "https://embryolock-download-tracker.vibelock.workers.dev/download",
          "software_tab": true
        },
        {
          "slug": "employeelock",
          "name": "EmployeeLock",
          "bucket": "lock",
          "one_line": "Hash a proposed accountability log row on the client.",
          "url": "https://employeelock-download-tracker.vibelock.workers.dev/",
          "download_url": "https://employeelock-download-tracker.vibelock.workers.dev/download",
          "software_tab": true
        },
        {
          "slug": "foldlock",
          "name": "FoldLock",
          "bucket": "lock",
          "one_line": "Fold UTF-8 text by suppressing tether words, then check the restore.",
          "url": "https://foldlock-download-tracker.vibelock.workers.dev/",
          "download_url": "https://foldlock-download-tracker.vibelock.workers.dev/download",
          "software_tab": true
        },
        {
          "slug": "godlock",
          "name": "GodLock",
          "bucket": "lock",
          "one_line": "Score text for offline hardening and receive an ephemeral receipt.",
          "url": "https://godlock-download-tracker.vibelock.workers.dev/",
          "download_url": "https://godlock-download-tracker.vibelock.workers.dev/download",
          "software_tab": true
        },
        {
          "slug": "mialock",
          "name": "M.I.A.Lock",
          "bucket": "lock",
          "one_line": "Map missing-person events and rank Doe notices as compatibility leads.",
          "url": "https://mialock-download-tracker.vibelock.workers.dev/",
          "download_url": "https://mialock-download-tracker.vibelock.workers.dev/download",
          "software_tab": true
        },
        {
          "slug": "peacelock",
          "name": "PeaceLock",
          "bucket": "lock",
          "one_line": "Record chosen silence or chosen inaction as a hash-chained receipt.",
          "url": "https://peacelock-download-tracker.vibelock.workers.dev/",
          "download_url": "https://peacelock-download-tracker.vibelock.workers.dev/download",
          "software_tab": true
        },
        {
          "slug": "shadowlock",
          "name": "ShadowLock",
          "bucket": "lock",
          "one_line": "Observe a job list you already have, then discard the observation.",
          "url": "https://shadowlock-download-tracker.vibelock.workers.dev/",
          "download_url": "https://shadowlock-download-tracker.vibelock.workers.dev/download",
          "software_tab": true
        },
        {
          "slug": "spectrallock",
          "name": "SpectralLock",
          "bucket": "lock",
          "one_line": "Preview a 256-pixel overlay, paint membership from the Spectral Harmonic Wheel, and restore faded pigment where the pixels still carry it.",
          "url": "https://spectrallock-download-tracker.vibelock.workers.dev/",
          "download_url": "https://spectrallock-download-tracker.vibelock.workers.dev/download",
          "software_tab": true
        },
        {
          "slug": "temporallock",
          "name": "TemporalLock",
          "bucket": "lock",
          "one_line": "Build and check hashes on a receipt timeline you keep on the client.",
          "url": "https://temporallock-download-tracker.vibelock.workers.dev/",
          "download_url": "https://temporallock-download-tracker.vibelock.workers.dev/download",
          "software_tab": true
        },
        {
          "slug": "trajectorylock",
          "name": "TrajectoryLock",
          "bucket": "lock",
          "one_line": "Test whether observations fit a declared geometric line.",
          "url": "https://trajectorylock-download-tracker.vibelock.workers.dev/",
          "download_url": "https://trajectorylock-download-tracker.vibelock.workers.dev/download",
          "software_tab": true
        },
        {
          "slug": "veillock",
          "name": "VeilLock",
          "bucket": "lock",
          "one_line": "Follow local camera and screen steps for apps on your own device.",
          "url": "https://veillock-download-tracker.vibelock.workers.dev/",
          "download_url": "https://veillock-download-tracker.vibelock.workers.dev/download",
          "software_tab": true
        },
        {
          "slug": "vibelock",
          "name": "VibeLock",
          "bucket": "lock",
          "one_line": "Assess AI deepfake risk in mp4, mp3, and other audio and video. Physics and related signals are heuristic. Linguistics is experimental. Vibration is measured only with a body-coupled track.",
          "url": "https://vibelock-download-tracker.vibelock.workers.dev/",
          "download_url": "https://vibelock-download-tracker.vibelock.workers.dev/download",
          "software_tab": true
        },
        {
          "slug": "whistlelock",
          "name": "WhistleLock",
          "bucket": "lock",
          "one_line": "Hash a local drop and keep a dead-man copy on the client.",
          "url": "https://whistlelock-download-tracker.vibelock.workers.dev/",
          "download_url": "https://whistlelock-download-tracker.vibelock.workers.dev/download",
          "software_tab": true
        }
      ]
    },
    "research": {
      "addendum": "Research (Aziel Digital Library MASTER): historical/manuscript work including Book of the knowledge of all the kingdoms, lands, and lordships that are in the world (AZDOC-F83D7E6D28B6); Blemmyes/Ewaipanoma hypothesis packets (AZDOC-E00603883906, AZDOC-39DB4E318091, AZDOC-1063826A9C4C); Libro Method (cite azielcorpuslibrary.net MASTER); Post-Perturbation Integrative Neuroplasticity (PPIN) (AZDOC-E03E61D8E50B and sibling PPIN sections); Lenses as Viewpoint Constraints for Artificial Systems (AZDOC-8F14A40DC9A6); ABAD Copper Scroll work (AZDOC-DD5912D05D6E); evidence/integrity research (AZDOC-0671040C36E6); He Didn't Jump Zioncheck archive (AZDOC-18DBE35A32DD and vols 2–5; https://www.hedidntjump.com/). Cite https://www.azielcorpuslibrary.net/ records. Library live ~326 records.",
      "works": [
        {
          "record_id": "AZDOC-F83D7E6D28B6",
          "title": "Book of the knowledge of all the kingdoms, lands, and lordships that are in the world",
          "url": "https://www.azielcorpuslibrary.net/record/AZDOC-F83D7E6D28B6"
        },
        {
          "record_id": "AZDOC-E00603883906",
          "title": "Blemmyes Research Collection — Independent Diagnostic Packet — Blemmyes_Ewaipanoma_Hypothetical_Model_Medical_Grade.pdf",
          "url": "https://www.azielcorpuslibrary.net/record/AZDOC-E00603883906"
        },
        {
          "record_id": "AZDOC-39DB4E318091",
          "title": "BLEMMYES/EWAIPANOMA HYPOTHETICAL MODEL vs. HUMAN HOLOPROSENCEPHALY",
          "url": "https://www.azielcorpuslibrary.net/record/AZDOC-39DB4E318091"
        },
        {
          "record_id": "AZDOC-1063826A9C4C",
          "title": "BLEMMYES GLOBAL PATTERN TRACKING — Updated with Ewaipanoma Findings — July 2026",
          "url": "https://www.azielcorpuslibrary.net/record/AZDOC-1063826A9C4C"
        },
        {
          "title": "Libro Method",
          "record_id": null,
          "url": "https://www.azielcorpuslibrary.net/",
          "note": "Published MASTER work. Cite azielcorpuslibrary.net."
        },
        {
          "record_id": "AZDOC-E03E61D8E50B",
          "title": "Post-Perturbation Integrative Neuroplasticity (PPIN): A Descriptive Framework for Non-Pathological Cross-Domain Cognitive Reorganization — PPIN_Section_6_Research_Agenda.txt",
          "url": "https://www.azielcorpuslibrary.net/record/AZDOC-E03E61D8E50B"
        },
        {
          "record_id": "AZDOC-8F14A40DC9A6",
          "title": "Lenses as Viewpoint Constraints for Artificial Systems",
          "url": "https://www.azielcorpuslibrary.net/record/AZDOC-8F14A40DC9A6"
        },
        {
          "record_id": "AZDOC-DD5912D05D6E",
          "title": "ABAD Framework Application: Layered Decryption of the Copper Scroll (3Q15)",
          "url": "https://www.azielcorpuslibrary.net/record/AZDOC-DD5912D05D6E"
        },
        {
          "record_id": "AZDOC-0671040C36E6",
          "title": "ForgeReceipts: A Local-First Evidence Integrity Platform for Pro Se Fathers in Family Court (Whitepaper v1.0)",
          "url": "https://www.azielcorpuslibrary.net/record/AZDOC-0671040C36E6"
        },
        {
          "record_id": "AZDOC-18DBE35A32DD",
          "title": "Marion A. Zioncheck Visual Archive Vol 1 — Primary Documents, Death Certificates & Forensic Analysis",
          "url": "https://www.azielcorpuslibrary.net/record/AZDOC-18DBE35A32DD"
        }
      ],
      "library": "https://www.azielcorpuslibrary.net/",
      "library_live_records": "~326",
      "invent_doi": false
    },
    "hardware_designs": {
      "addendum": "Hardware designs (public engineering only; published Digital Library work): Adaptive AI Dog Leash (AZDOC-9B0E3D62EDCC); Wearable Dual-Tether Web-Sling System (AZDOC-AA8761FE16D0); PLA Recycler V1 (AZDOC-B2A12FE997A8); Electromagnetic Temporary Access Lock System (TAA-1) (AZDOC-3728546DFE78, AZDOC-FE5C01BD8FEA); AEEM HVAC Energy Valve (AZDOC-0302B7357EE0); AZ Mandible (AZDOC-E5828F49FB04); bone-conduction STL (AZDOC-FD18432707F5). Cite https://www.azielcorpuslibrary.net/ records.",
      "designs": [
        {
          "record_id": "AZDOC-9B0E3D62EDCC",
          "title": "Adaptive AI Dog Leash — Prototype Build Specification & Construction Guide (v0.9)",
          "url": "https://www.azielcorpuslibrary.net/record/AZDOC-9B0E3D62EDCC"
        },
        {
          "record_id": "AZDOC-AA8761FE16D0",
          "title": "Wearable Dual-Tether Web-Sling System",
          "url": "https://www.azielcorpuslibrary.net/record/AZDOC-AA8761FE16D0"
        },
        {
          "record_id": "AZDOC-B2A12FE997A8",
          "title": "PLA Recycler V1 — Compact Non-Solvent Filament Reprocessing System",
          "url": "https://www.azielcorpuslibrary.net/record/AZDOC-B2A12FE997A8"
        },
        {
          "record_id": "AZDOC-3728546DFE78",
          "title": "TAA-1 Engineering Package (PDF, wiring diagram, parts list, firmware, design brief)",
          "url": "https://www.azielcorpuslibrary.net/record/AZDOC-3728546DFE78"
        },
        {
          "record_id": "AZDOC-FE5C01BD8FEA",
          "title": "Electromagnetic Temporary Access Lock System (TAA-1) — Full Whitepaper",
          "url": "https://www.azielcorpuslibrary.net/record/AZDOC-FE5C01BD8FEA"
        },
        {
          "record_id": "AZDOC-0302B7357EE0",
          "title": "AEEM HVAC Energy Valve — Consumer Retrofit Whitepaper (v1.0)",
          "url": "https://www.azielcorpuslibrary.net/record/AZDOC-0302B7357EE0"
        },
        {
          "record_id": "AZDOC-E5828F49FB04",
          "title": "AZ MANDIBLE",
          "url": "https://www.azielcorpuslibrary.net/record/AZDOC-E5828F49FB04"
        },
        {
          "record_id": "AZDOC-FD18432707F5",
          "title": "AZ_BoneConducti STL",
          "url": "https://www.azielcorpuslibrary.net/record/AZDOC-FD18432707F5"
        }
      ],
      "public_engineering_only": true,
      "storefront": false,
      "published_in": "Aziel Digital Library",
      "library": "https://www.azielcorpuslibrary.net/",
      "invent_doi": false
    }
  },
  "foldlock_tip": {
    "spec": "AZCL-FOLD-TIP-1.0",
    "id": "aziel-corpus-library-tip",
    "kind": "fold-packed-library-tip",
    "full_library_in_process": false,
    "in_process_label": "REAL",
    "live_library_label": "LIVE",
    "in_process_d1_label": "SLOT",
    "live_library": "https://www.azielcorpuslibrary.net/",
    "live_index": "https://www.azielcorpuslibrary.net/v1/library-index",
    "person_id": "https://www.azieleliab.com/#aziel",
    "identity": "Aziel Eliab",
    "verify": "POST /v1/fraggate/call { \"slug\": \"foldlock\", \"op\": \"pack-verify\" }",
    "open": "POST /v1/fraggate/call { \"slug\": \"aziel-corpus\", \"op\": \"tip-pack\" }",
    "zip": false,
    "hosted_store": false,
    "note": "THIS IS: a FoldLock-packed tip of the library index cite + bundled sample-MASTER key artifacts + published About Aziel. Hash-verified in-process (label REAL). THIS IS NOT: the entire live Aziel Digital Library; live D1 MASTER; azcorpus/azlibrary record bytes; hosted_store; zip. Full library remains on https://www.azielcorpuslibrary.net (label LIVE). In-process D1 is SLOT unless CORPUS_D1 is bound. Author: Aziel Eliab only."
  },
  "mesh": {
    "path": "/runtime/v1/mesh",
    "nine_laws": {
      "hard_true": true,
      "count": 9,
      "author": "Aziel Eliab",
      "identity": "Aziel Eliab",
      "author_id": "https://www.azieleliab.com/#aziel",
      "runtime_id": "https://www.azieleliab.com/runtime#runtime",
      "hashtag_parts": {
        "person": "#aziel",
        "runtime": "#runtime"
      },
      "about": {
        "path": "/about",
        "v1": "/runtime/v1/about",
        "identity": "Aziel Eliab",
        "always": true
      },
      "clocks_share_socket": false,
      "live_body_sync": false,
      "isolation_is_the_cure": true,
      "neighbor_heal": true,
      "phoenix_local_only": true,
      "die_with_pull": true,
      "restore_godlock_uk": false,
      "node_gate": true,
      "get_is_node_gate": true,
      "implicit_heal": true,
      "auto_heal": true,
      "network": true,
      "network_cite": "on",
      "anonymity_network": true,
      "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
      "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
      "date": "2026-09-17",
      "operator_armed": true,
      "vpn": true,
      "public_vpn": true,
      "tunnel_concentrator": true,
      "concentrator_slug": "azvpn",
      "concentrator_name": "AZVPN",
      "default_vpn_backend": "azvpn",
      "auto_use": true,
      "auto_bind": true,
      "vpn_auto": {
        "default_vpn_backend": "azvpn",
        "auto_use": true,
        "auto_bind": true,
        "concentrator_slug": "azvpn",
        "concentrator_name": "AZVPN",
        "door": "fraggate",
        "explicit_ops": [
          "describe",
          "open",
          "status",
          "list",
          "close",
          "send",
          "recv",
          "pull",
          "peers",
          "attach"
        ],
        "hooks": {
          "mesh_get": "cite-only",
          "mesh_vpn": "ensure",
          "aznet_pair": "cite-and-ensure-when-paired-or-armed",
          "session_open": "ensure-when-armed",
          "azbrowser_vpn": "ensure"
        },
        "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
        "get_never_opens": true,
        "open": false
      },
      "door": "fraggate",
      "worker_terminates_tunnels": true,
      "worker_terminates_kernel_udp": false,
      "wireguard": false,
      "openvpn": false,
      "l3_exit_pool": false,
      "tor": false,
      "socks": false,
      "origin_hiding": false,
      "kinds": {
        "https_ws": "REAL",
        "fraggate_envelopes": "REAL",
        "websocket_attach": "REAL",
        "wireguard": "SLOT",
        "openvpn": "SLOT",
        "l3_exit_pool": "SLOT",
        "kernel_udp": "SLOT",
        "tun_tap": "SLOT"
      },
      "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
      "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
      "operator_override": {
        "spec": "OPERATOR-OVERRIDE-2026-09-17",
        "date": "2026-09-17",
        "identity": "Aziel Eliab",
        "author": "Aziel Eliab",
        "operator_armed": true,
        "auto_heal": true,
        "implicit_heal": true,
        "node_gate": true,
        "get_is_node_gate": true,
        "neighbor_heal": true,
        "neighbor_heal_is_cite": true,
        "neighbor_heal_exec": false,
        "network": true,
        "network_cite": "on",
        "anonymity_network": true,
        "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
        "vpn": true,
        "public_vpn": true,
        "tunnel_concentrator": true,
        "concentrator_slug": "azvpn",
        "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
        "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
      },
      "papers": {
        "node_mesh": "docs/NODE_MESH.md",
        "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
        "node_ops": "docs/designs/NODE-OPS-1.0.md",
        "qnm_wp": "docs/designs/QNM-WP-1.0.md"
      }
    },
    "channel_plane": {
      "spec": "QNM-CHANNEL-PLANE-1.0",
      "author": "Aziel Eliab",
      "identity": "Aziel Eliab",
      "operator_armed": true,
      "plane": "channel",
      "wifi": "on",
      "bluetooth": "on",
      "rf": "on",
      "photon": "on",
      "channels": {
        "wifi": "on",
        "bluetooth": "on",
        "rf": "on",
        "photon": "on"
      },
      "bearer": "suite-presence",
      "worker_bearer": "suite-presence",
      "worker_hardware": false,
      "invented_hardware": false,
      "public_proxy": false,
      "local_process": "qnm-node / qnsd",
      "local": "https://github.com/AzielEliab/qnm-node",
      "local_radio_hooks": {
        "path": "qnm-node/bearers/radio.js",
        "law": "LIVE-when-HW-present / refuse-when-absent",
        "mock": false,
        "worker_hardware": false
      },
      "vpn": true,
      "public_vpn": true,
      "tunnel_concentrator": true,
      "concentrator_slug": "azvpn",
      "default_vpn_backend": "azvpn",
      "auto_use": true,
      "worker_terminates_tunnels": true,
      "worker_terminates_kernel_udp": false,
      "tor": false,
      "socks": false,
      "origin_hiding": false,
      "tunnel": false,
      "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
      "node_mesh": "docs/NODE_MESH.md",
      "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
    },
    "vpn": {
      "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
      "date": "2026-09-17",
      "author": "Aziel Eliab",
      "identity": "Aziel Eliab",
      "operator_armed": true,
      "vpn": true,
      "public_vpn": true,
      "tunnel_concentrator": true,
      "concentrator_slug": "azvpn",
      "concentrator_name": "AZVPN",
      "default_vpn_backend": "azvpn",
      "auto_use": true,
      "auto_bind": true,
      "vpn_auto": {
        "default_vpn_backend": "azvpn",
        "auto_use": true,
        "auto_bind": true,
        "concentrator_slug": "azvpn",
        "concentrator_name": "AZVPN",
        "door": "fraggate",
        "explicit_ops": [
          "describe",
          "open",
          "status",
          "list",
          "close",
          "send",
          "recv",
          "pull",
          "peers",
          "attach"
        ],
        "hooks": {
          "mesh_get": "cite-only",
          "mesh_vpn": "ensure",
          "aznet_pair": "cite-and-ensure-when-paired-or-armed",
          "session_open": "ensure-when-armed",
          "azbrowser_vpn": "ensure"
        },
        "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
        "get_never_opens": true,
        "open": false
      },
      "door": "fraggate",
      "worker_terminates_tunnels": true,
      "worker_terminates_kernel_udp": false,
      "wireguard": false,
      "openvpn": false,
      "l3_exit_pool": false,
      "tor": false,
      "socks": false,
      "origin_hiding": false,
      "kinds": {
        "https_ws": "REAL",
        "fraggate_envelopes": "REAL",
        "websocket_attach": "REAL",
        "wireguard": "SLOT",
        "openvpn": "SLOT",
        "l3_exit_pool": "SLOT",
        "kernel_udp": "SLOT",
        "tun_tap": "SLOT"
      },
      "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
      "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door."
    },
    "get_never_enables": true,
    "worker_hardware": false,
    "live_nodes_plane": "human-mesh-users-site-viewers",
    "nodes_plane": "human-mesh-users-uses",
    "software_nodes_plane": "software-worker-fanout",
    "site_live_viewers_plane": "hub-human-page-presence",
    "live_nodes_note": "Public Live Nodes count human mesh users plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. Paint live_nodes / rollup.mesh only. live_nodes_tip is the shared site-viewer seal — do not add a local /count. rollup.live is not published. Never paint software_nodes, rollup.all.live, or rollup.software.live as Live Nodes. Isolated humans stay on isolated_nodes. GET never pulls hub /count. Zero is honest when no human is present.",
    "nodes_note": "Public Nodes count human mesh users plus cited human uses (USES). Uses are interaction counters. Incomplete uses stay honest — do not invent users. This pack download is instance_nodes until a human join/heartbeat.",
    "instance_join": {
      "path": "/runtime/v1/mesh/join",
      "heartbeat": "/runtime/v1/mesh/heartbeat",
      "product_required": true,
      "node_id": "instance id 8–80 [a-z0-9._-]; do not use {slug}-worker",
      "presence_ttl_ms": 300000,
      "presence_ttl_applies_to": "{slug}-worker",
      "registered_grace_ms": 1209600000,
      "heartbeat_miss_n": 3,
      "downloads_are_not_live": true
    }
  },
  "platforms": {
    "spec": "BAN-PLATFORMS-1.0",
    "all_live": true,
    "native_app_store": false,
    "slot_os": [],
    "worker_live": true,
    "calling_name_live": true,
    "calling_name": "Aziel Runtime",
    "calling_name_rotated": false,
    "survival": "/survival",
    "manifest": "/manifest.webmanifest",
    "verified_paths": [
      "/survival",
      "/runtime/openapi.json",
      "/manifest.webmanifest",
      "/download",
      "/runtime/v1/software",
      "/runtime/v1/update/manifest",
      "/platforms"
    ],
    "platforms": [
      {
        "id": "windows",
        "label": "Windows",
        "live": true,
        "browser": true,
        "pwa": true,
        "worker_fronts": true,
        "mcp_openapi": true,
        "softwares_download": true,
        "native_app_store": false,
        "survival": true,
        "calling_name": true,
        "cap7_shuffle_in_process": true,
        "cap7_public_worker_shuffle": "live",
        "dual_surface": {
          "agents": "mcp_openapi",
          "humans": "worker_ui_pwa_download"
        },
        "ua_note": "Edge / Chrome / Firefox",
        "doors": [
          "https://godlock.uk/runtime/survival",
          "https://godlock.uk/runtime/mcp",
          "https://godlock.uk/runtime/openapi.json",
          "https://godlock.uk/runtime/manifest.webmanifest"
        ],
        "note": "LIVE via browser + installable PWA + Worker fronts + Softwares /download + MCP/OpenAPI. Not a native store app. Same FragGate door. Cap-7 factory shuffle land is LIVE. Standard internet reaches AZ domains via hub HTTPS, not Cap-7 names."
      },
      {
        "id": "mac",
        "label": "Mac",
        "live": true,
        "browser": true,
        "pwa": true,
        "worker_fronts": true,
        "mcp_openapi": true,
        "softwares_download": true,
        "native_app_store": false,
        "survival": true,
        "calling_name": true,
        "cap7_shuffle_in_process": true,
        "cap7_public_worker_shuffle": "live",
        "dual_surface": {
          "agents": "mcp_openapi",
          "humans": "worker_ui_pwa_download"
        },
        "ua_note": "Safari / Chrome / Firefox",
        "doors": [
          "https://godlock.uk/runtime/survival",
          "https://godlock.uk/runtime/mcp",
          "https://godlock.uk/runtime/openapi.json",
          "https://godlock.uk/runtime/manifest.webmanifest"
        ],
        "note": "LIVE via browser + installable PWA + Worker fronts + Softwares /download + MCP/OpenAPI. Not a native store app. Same FragGate door. Cap-7 factory shuffle land is LIVE. Standard internet reaches AZ domains via hub HTTPS, not Cap-7 names."
      },
      {
        "id": "linux",
        "label": "Linux",
        "live": true,
        "browser": true,
        "pwa": true,
        "worker_fronts": true,
        "mcp_openapi": true,
        "softwares_download": true,
        "native_app_store": false,
        "survival": true,
        "calling_name": true,
        "cap7_shuffle_in_process": true,
        "cap7_public_worker_shuffle": "live",
        "dual_surface": {
          "agents": "mcp_openapi",
          "humans": "worker_ui_pwa_download"
        },
        "ua_note": "Firefox / Chrome / Chromium",
        "doors": [
          "https://godlock.uk/runtime/survival",
          "https://godlock.uk/runtime/mcp",
          "https://godlock.uk/runtime/openapi.json",
          "https://godlock.uk/runtime/manifest.webmanifest"
        ],
        "note": "LIVE via browser + installable PWA + Worker fronts + Softwares /download + MCP/OpenAPI. Not a native store app. Same FragGate door. Cap-7 factory shuffle land is LIVE. Standard internet reaches AZ domains via hub HTTPS, not Cap-7 names."
      },
      {
        "id": "android",
        "label": "Android",
        "live": true,
        "browser": true,
        "pwa": true,
        "worker_fronts": true,
        "mcp_openapi": true,
        "softwares_download": true,
        "native_app_store": false,
        "survival": true,
        "calling_name": true,
        "cap7_shuffle_in_process": true,
        "cap7_public_worker_shuffle": "live",
        "dual_surface": {
          "agents": "mcp_openapi",
          "humans": "worker_ui_pwa_download"
        },
        "ua_note": "Chrome / Firefox / installed PWA",
        "doors": [
          "https://godlock.uk/runtime/survival",
          "https://godlock.uk/runtime/mcp",
          "https://godlock.uk/runtime/openapi.json",
          "https://godlock.uk/runtime/manifest.webmanifest"
        ],
        "note": "LIVE via browser + installable PWA + Worker fronts + Softwares /download + MCP/OpenAPI. Not a native store app. Same FragGate door. Cap-7 factory shuffle land is LIVE. Standard internet reaches AZ domains via hub HTTPS, not Cap-7 names."
      },
      {
        "id": "ios",
        "label": "iPhone",
        "live": true,
        "browser": true,
        "pwa": true,
        "worker_fronts": true,
        "mcp_openapi": true,
        "softwares_download": true,
        "native_app_store": false,
        "survival": true,
        "calling_name": true,
        "cap7_shuffle_in_process": true,
        "cap7_public_worker_shuffle": "live",
        "dual_surface": {
          "agents": "mcp_openapi",
          "humans": "worker_ui_pwa_download"
        },
        "ua_note": "Safari / Add to Home Screen PWA",
        "doors": [
          "https://godlock.uk/runtime/survival",
          "https://godlock.uk/runtime/mcp",
          "https://godlock.uk/runtime/openapi.json",
          "https://godlock.uk/runtime/manifest.webmanifest"
        ],
        "note": "LIVE via browser + installable PWA + Worker fronts + Softwares /download + MCP/OpenAPI. Not a native store app. Same FragGate door. Cap-7 factory shuffle land is LIVE. Standard internet reaches AZ domains via hub HTTPS, not Cap-7 names."
      }
    ],
    "download_run": {
      "suite_pack": "/download",
      "update_manifest": "/runtime/v1/update/manifest",
      "update_check": "/runtime/v1/update/check?slug={slug}&version={installed}",
      "pwa": "/manifest.webmanifest"
    },
    "note": "Windows, Mac, Linux, Android, and iPhone are LIVE on the public Worker (browser / PWA / MCP). Humans use Softwares in the Worker UI on this VibeLock host (browser / PWA) — no download required. Agents use OpenAPI/MCP. Optional suite pack JSON remains at /download. Not five native store binaries. Do not mark any of these five as SLOT. Hubs pull /survival."
  },
  "catalog": {
    "count": 42,
    "live_count": 41,
    "local_only_count": 1,
    "stub_count": 0,
    "software": [
      {
        "slug": "4dmap",
        "name": "4DMap",
        "bucket": "plain",
        "domain": "Research",
        "domain_id": "06",
        "placement": "domain-software",
        "status": "live",
        "fraggate_status": "live",
        "public_door": true,
        "public_door_ops": [
          "health",
          "skill",
          "pin",
          "span",
          "stack",
          "gap",
          "fork",
          "walk",
          "lens",
          "class",
          "cohort",
          "absence",
          "cap",
          "join",
          "list",
          "example",
          "card_new",
          "card_pin",
          "card_span",
          "card_join",
          "card_walk",
          "card_list",
          "verify_hash",
          "frame_status",
          "axis_describe",
          "walk_trace",
          "card_export",
          "card_import",
          "verify_chain",
          "neighbor_cite",
          "memory_cite",
          "memory_observe",
          "library_pin",
          "plot",
          "possibility",
          "pattern_recall",
          "lattice_tip",
          "poison_refuse",
          "news_status",
          "news_pin",
          "news_open",
          "news_ingest",
          "news_sources",
          "news_weather",
          "news_black_swan",
          "frame",
          "axis",
          "trace",
          "export",
          "import",
          "neighbor",
          "ingest_pin",
          "plot_pins",
          "score_hooks",
          "possibility_cite",
          "lattice_tips"
        ],
        "stub_ops": [
          "truth_score",
          "lumen_panel",
          "invent_mark",
          "backdate_class"
        ],
        "door_label": "live FragGate door — named stub ops refuse",
        "open_live_door": true,
        "version": "0.3.0",
        "one_line": "Inspect the same event on time, change, graph, and place axes at once.",
        "description": "Use 4DMap to walk one event across time, change, graph, and place as recorded axes, including a library pin when the paper gives a date and a place. AZNews can store an item on its own, or pin that item here and open it from the map. An empty pin stays refused until a real item is stored. It exists so multi-axis inspection stays a recorded walk.",
        "worker_home": "https://4dmap-download-tracker.vibelock.workers.dev/",
        "worker_home_note": null,
        "download_url": "https://4dmap-download-tracker.vibelock.workers.dev/download",
        "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "github": "https://github.com/AzielEliab/4dmap",
        "mcp": "https://godlock.uk/runtime/mcp",
        "agent": {
          "mcp": "https://godlock.uk/runtime/mcp",
          "skill": "https://godlock.uk/runtime/v1/skill",
          "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
          "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=4dmap",
          "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
          "fraggate_call_executes": true,
          "open_live_door": true,
          "software": "https://godlock.uk/runtime/v1/software",
          "pull": "https://godlock.uk/runtime/v1/pull/4dmap",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "08de65653c51a5a6c8c0e8648f9af5e5013336cdfb92aea28fed5b4caf39003e",
        "updated_at": null,
        "git_sha": null,
        "git_sha_tracks_deployed_tip": false,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/runtime/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "security": {
            "model": "single-node-security-awareness",
            "isolates": "bad-peer-or-self",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "phoenix": "local-wait-reseal",
            "phoenix_lock": true,
            "public_hostname_resurrection": false,
            "loopback_bearer": "L1-optional",
            "operator_locks": [
              {
                "n": 1,
                "id": "single-node-security-awareness",
                "status": "LIVE",
                "mesh_fenced_to_loopback": false
              },
              {
                "n": 2,
                "id": "phoenix-reboot-loop",
                "status": "LIVE",
                "phoenix": "local-wait-reseal",
                "phoenix_lock": true,
                "public_hostname_resurrection": false
              },
              {
                "n": 3,
                "id": "open-world-awareness",
                "status": "live-when-configured",
                "law": "LIVE",
                "bind": "0.0.0.0",
                "worker_socket": false,
                "forced_loopback_is_mesh_fence": false,
                "loopback_isolation_is_mesh_fence": false
              }
            ],
            "open_world_awareness": {
              "spec": "OPEN-WORLD-AWARENESS-1.0",
              "author": "Aziel Eliab",
              "identity": "Aziel Eliab",
              "open_world_awareness": true,
              "bind": "0.0.0.0",
              "all_interfaces": true,
              "law": "LIVE",
              "status": "live-when-configured",
              "live": false,
              "socket": "live-when-configured",
              "worker_socket": false,
              "qnm_node_bind": "live-when-configured",
              "mock": false,
              "forced_loopback": false,
              "loopback_isolation": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false,
              "mesh_fenced_to_loopback": false,
              "public_egress_ip": false,
              "residential": false,
              "cf_geo_exit": false,
              "cf_geo_exit_pool": false,
              "sticky_public_ip": false,
              "packet_forward": false,
              "packet_forwarding": false,
              "public_icann": false,
              "cap7_is_icann": false,
              "replaces_internet": false,
              "not_a_second_internet": true,
              "hosted_vpn": false,
              "payload_host": false,
              "vpn_hop": false,
              "wireguard": false,
              "openvpn": false,
              "l3_exit": false,
              "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
            },
            "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
          },
          "fanout": "cron-or-request-path",
          "live_nodes_plane": "human-mesh-users-site-viewers",
          "nodes_plane": "human-mesh-users-uses",
          "software_nodes_plane": "software-worker-fanout",
          "site_live_viewers_plane": "hub-human-page-presence",
          "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
          "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
          "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
          "site_presence_contract": {
            "method": "POST",
            "path": "/runtime/v1/mesh/site-presence",
            "alias": "/runtime/v1/mesh/site-heartbeat",
            "fraggate": {
              "slug": "mesh",
              "op": "site-presence"
            },
            "body": {
              "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
              "viewers": "non-negative integer concurrent human page sessions (0..10000)",
              "kind": "human-page"
            },
            "ttl_ms": 900000,
            "registered_grace_ms": 1209600000,
            "default_heartbeat_mode": "idle",
            "heartbeat_mode": "active | idle | asleep",
            "stale_keeps_registered": true,
            "stale_counts_as_live": false,
            "allowed_hosts": [
              "godlock.uk",
              "azieleliab.com",
              "azielcorpuslibrary.net"
            ],
            "excluded_hosts": [
              "hedidntjump.com"
            ],
            "refused_kinds": [
              "bot",
              "bots",
              "crawler",
              "software",
              "softwares",
              "download",
              "downloads",
              "instance",
              "mcp"
            ],
            "pull_hub_count": false,
            "invent": false,
            "fail_closed": true,
            "read": "single-key",
            "paint": "live_nodes",
            "local_recompute": false,
            "radios": "not required — hub ingest, not a TX join",
            "rate_kind": "mesh_mutate",
            "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
          },
          "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
          "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
          "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "ban_survival": "BAN-SURVIVAL-1.0",
          "spore_spec": "SPORE-1.0",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/runtime/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "neighbor_heal_is_cite": true,
              "neighbor_heal_exec": false,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "neighbor_heal_is_cite": true,
          "neighbor_heal_exec": false,
          "join_is_presence_only": true,
          "join_is_not_login": true,
          "roster_publishes_exec_urls": false,
          "mesh_mutate_rate_kind": "mesh_mutate",
          "roster_cap": 256,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "d2d_carriers": {
            "spec": "D2D-CARRIERS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "plane": "track2-reachability",
            "phase": "B+C+D",
            "phases": {
              "A": "landed",
              "B": "LIVE-when-armed",
              "C": "LIVE-when-session",
              "D": "LIVE-when-three-local-nodes / fixture",
              "E": "scaffold"
            },
            "lan_discovery": "LIVE-when-armed",
            "wifi_discovery": "ARMED-when-HW",
            "bluetooth_discovery": "ARMED-when-HW",
            "rf_discovery": "REFUSE-without-HW",
            "photon_discovery": "REFUSE-without-HW",
            "peer_tunnel": "LIVE-when-session",
            "store_forward": "LIVE-when-three-local-nodes / fixture",
            "store_forward_public": "FG-STUB",
            "worker_runs_store_forward": false,
            "second_device": false,
            "mobile_client": "present-not-demonstrated",
            "mobile_demonstrated": false,
            "app_store_release": false,
            "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
            "bootstrap_list": "scaffold",
            "needs_starting_address": true,
            "shelf_cite": "scaffold",
            "live_multi_provider": false,
            "cold_shelf_live": false,
            "dns_cut": false,
            "origin_cutover": false,
            "warn5_closed": false,
            "worker_door": "FG-STUB",
            "worker_hardware": false,
            "local_node": "qnm-node",
            "get_never_enables": true,
            "separate_from": "cap7-name",
            "cap7_is_name_plane": true,
            "cap7_public_icann": false,
            "cap7_public_egress": false,
            "mirage_is_azvpn": false,
            "aznet_replaces_internet": false,
            "not_a_second_internet": true,
            "alt_internet_live": false,
            "packet_path_live": false,
            "field_1_0": false,
            "warn5": "STANDS-until-demonstrated",
            "warn5_permanent_stay_off": false,
            "preference": "failover",
            "order": [
              "lan",
              "wifi",
              "bluetooth",
              "rf",
              "photon"
            ],
            "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
            "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
            "status": "NOT-READY",
            "code": "FG-STUB",
            "warn5_until": "demonstrated",
            "warn5_by_design": "separate-from-icann",
            "refuse": {
              "packet": "FG-STUB",
              "radio_absent": "QNM-RADIO-ABSENT",
              "cap7_egress": "MG-NO-IP-EXIT",
              "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
              "bearer": "AZP-BEARER-REFUSE",
              "payload": "AZN-NO-PAYLOAD",
              "route": "MESH-NO-ROUTE",
              "stay_off": "MESH-STAY-OFF",
              "nat": "FED-MESH-NAT-REFUSE"
            },
            "carriers": [
              {
                "order": 1,
                "id": "lan",
                "name": "LAN",
                "op": "d2d_lan",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "lan-interface",
                "discovery": "LIVE-when-armed",
                "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
              },
              {
                "order": 2,
                "id": "wifi",
                "name": "Wi-Fi",
                "op": "d2d_wifi",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "wifi-nm",
                "discovery": "ARMED-when-HW",
                "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
              },
              {
                "order": 3,
                "id": "bluetooth",
                "name": "Bluetooth",
                "op": "d2d_bluetooth",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "bluez",
                "discovery": "ARMED-when-HW",
                "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
              },
              {
                "order": 4,
                "id": "rf",
                "name": "RF",
                "op": "d2d_rf",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "rf-beyond-wifi-bt",
                "discovery": "REFUSE-without-HW",
                "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
              },
              {
                "order": 5,
                "id": "photon",
                "name": "Photon",
                "op": "d2d_photon",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "camera-flash",
                "discovery": "REFUSE-without-HW",
                "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
              }
            ],
            "security": {
              "isolation": "single-node security-awareness",
              "phoenix": "local wait / re-seal",
              "mesh_fenced_to_loopback": false,
              "forced_loopback": false,
              "loopback_isolation": false
            },
            "paper": "docs/designs/D2D-CARRIERS-1.0.md",
            "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
          },
          "d2d_status": "NOT-READY",
          "d2d_code": "FG-STUB",
          "packet_path_live": false,
          "alt_internet_live": false,
          "d2d_spec": "D2D-CARRIERS-1.0",
          "federated_mesh": "FED-MESH-1.0",
          "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
          "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        }
      },
      {
        "slug": "azclce",
        "name": "AZ-CLCE",
        "bucket": "plain",
        "domain": "Language",
        "domain_id": "04",
        "placement": "domain-software",
        "status": "live",
        "fraggate_status": "live",
        "public_door": true,
        "public_door_ops": [
          "score",
          "classify",
          "gate",
          "health",
          "skill",
          "doctor"
        ],
        "stub_ops": [],
        "door_label": "live FragGate door",
        "open_live_door": true,
        "version": "0.3.0",
        "one_line": "Score how consistently three written layers agree with each other.",
        "description": "Use AZ-CLCE to check whether requirement, design, and practice statements line up. It exists to flag inconsistency in text you already posted.",
        "worker_home": "https://azclce-download-tracker.vibelock.workers.dev/",
        "worker_home_note": null,
        "download_url": "https://azclce-download-tracker.vibelock.workers.dev/download",
        "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "github": "https://github.com/AzielEliab/az-clce",
        "mcp": "https://godlock.uk/runtime/mcp",
        "agent": {
          "mcp": "https://godlock.uk/runtime/mcp",
          "skill": "https://godlock.uk/runtime/v1/skill",
          "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
          "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=azclce",
          "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
          "fraggate_call_executes": true,
          "open_live_door": true,
          "software": "https://godlock.uk/runtime/v1/software",
          "pull": "https://godlock.uk/runtime/v1/pull/azclce",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "f1854d7bd0396761f942b54b78f42c66d4c04e4956189de79371ed67b9ae2b69",
        "updated_at": null,
        "git_sha": null,
        "git_sha_tracks_deployed_tip": false,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/runtime/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "security": {
            "model": "single-node-security-awareness",
            "isolates": "bad-peer-or-self",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "phoenix": "local-wait-reseal",
            "phoenix_lock": true,
            "public_hostname_resurrection": false,
            "loopback_bearer": "L1-optional",
            "operator_locks": [
              {
                "n": 1,
                "id": "single-node-security-awareness",
                "status": "LIVE",
                "mesh_fenced_to_loopback": false
              },
              {
                "n": 2,
                "id": "phoenix-reboot-loop",
                "status": "LIVE",
                "phoenix": "local-wait-reseal",
                "phoenix_lock": true,
                "public_hostname_resurrection": false
              },
              {
                "n": 3,
                "id": "open-world-awareness",
                "status": "live-when-configured",
                "law": "LIVE",
                "bind": "0.0.0.0",
                "worker_socket": false,
                "forced_loopback_is_mesh_fence": false,
                "loopback_isolation_is_mesh_fence": false
              }
            ],
            "open_world_awareness": {
              "spec": "OPEN-WORLD-AWARENESS-1.0",
              "author": "Aziel Eliab",
              "identity": "Aziel Eliab",
              "open_world_awareness": true,
              "bind": "0.0.0.0",
              "all_interfaces": true,
              "law": "LIVE",
              "status": "live-when-configured",
              "live": false,
              "socket": "live-when-configured",
              "worker_socket": false,
              "qnm_node_bind": "live-when-configured",
              "mock": false,
              "forced_loopback": false,
              "loopback_isolation": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false,
              "mesh_fenced_to_loopback": false,
              "public_egress_ip": false,
              "residential": false,
              "cf_geo_exit": false,
              "cf_geo_exit_pool": false,
              "sticky_public_ip": false,
              "packet_forward": false,
              "packet_forwarding": false,
              "public_icann": false,
              "cap7_is_icann": false,
              "replaces_internet": false,
              "not_a_second_internet": true,
              "hosted_vpn": false,
              "payload_host": false,
              "vpn_hop": false,
              "wireguard": false,
              "openvpn": false,
              "l3_exit": false,
              "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
            },
            "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
          },
          "fanout": "cron-or-request-path",
          "live_nodes_plane": "human-mesh-users-site-viewers",
          "nodes_plane": "human-mesh-users-uses",
          "software_nodes_plane": "software-worker-fanout",
          "site_live_viewers_plane": "hub-human-page-presence",
          "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
          "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
          "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
          "site_presence_contract": {
            "method": "POST",
            "path": "/runtime/v1/mesh/site-presence",
            "alias": "/runtime/v1/mesh/site-heartbeat",
            "fraggate": {
              "slug": "mesh",
              "op": "site-presence"
            },
            "body": {
              "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
              "viewers": "non-negative integer concurrent human page sessions (0..10000)",
              "kind": "human-page"
            },
            "ttl_ms": 900000,
            "registered_grace_ms": 1209600000,
            "default_heartbeat_mode": "idle",
            "heartbeat_mode": "active | idle | asleep",
            "stale_keeps_registered": true,
            "stale_counts_as_live": false,
            "allowed_hosts": [
              "godlock.uk",
              "azieleliab.com",
              "azielcorpuslibrary.net"
            ],
            "excluded_hosts": [
              "hedidntjump.com"
            ],
            "refused_kinds": [
              "bot",
              "bots",
              "crawler",
              "software",
              "softwares",
              "download",
              "downloads",
              "instance",
              "mcp"
            ],
            "pull_hub_count": false,
            "invent": false,
            "fail_closed": true,
            "read": "single-key",
            "paint": "live_nodes",
            "local_recompute": false,
            "radios": "not required — hub ingest, not a TX join",
            "rate_kind": "mesh_mutate",
            "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
          },
          "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
          "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
          "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "ban_survival": "BAN-SURVIVAL-1.0",
          "spore_spec": "SPORE-1.0",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/runtime/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "neighbor_heal_is_cite": true,
              "neighbor_heal_exec": false,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "neighbor_heal_is_cite": true,
          "neighbor_heal_exec": false,
          "join_is_presence_only": true,
          "join_is_not_login": true,
          "roster_publishes_exec_urls": false,
          "mesh_mutate_rate_kind": "mesh_mutate",
          "roster_cap": 256,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "d2d_carriers": {
            "spec": "D2D-CARRIERS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "plane": "track2-reachability",
            "phase": "B+C+D",
            "phases": {
              "A": "landed",
              "B": "LIVE-when-armed",
              "C": "LIVE-when-session",
              "D": "LIVE-when-three-local-nodes / fixture",
              "E": "scaffold"
            },
            "lan_discovery": "LIVE-when-armed",
            "wifi_discovery": "ARMED-when-HW",
            "bluetooth_discovery": "ARMED-when-HW",
            "rf_discovery": "REFUSE-without-HW",
            "photon_discovery": "REFUSE-without-HW",
            "peer_tunnel": "LIVE-when-session",
            "store_forward": "LIVE-when-three-local-nodes / fixture",
            "store_forward_public": "FG-STUB",
            "worker_runs_store_forward": false,
            "second_device": false,
            "mobile_client": "present-not-demonstrated",
            "mobile_demonstrated": false,
            "app_store_release": false,
            "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
            "bootstrap_list": "scaffold",
            "needs_starting_address": true,
            "shelf_cite": "scaffold",
            "live_multi_provider": false,
            "cold_shelf_live": false,
            "dns_cut": false,
            "origin_cutover": false,
            "warn5_closed": false,
            "worker_door": "FG-STUB",
            "worker_hardware": false,
            "local_node": "qnm-node",
            "get_never_enables": true,
            "separate_from": "cap7-name",
            "cap7_is_name_plane": true,
            "cap7_public_icann": false,
            "cap7_public_egress": false,
            "mirage_is_azvpn": false,
            "aznet_replaces_internet": false,
            "not_a_second_internet": true,
            "alt_internet_live": false,
            "packet_path_live": false,
            "field_1_0": false,
            "warn5": "STANDS-until-demonstrated",
            "warn5_permanent_stay_off": false,
            "preference": "failover",
            "order": [
              "lan",
              "wifi",
              "bluetooth",
              "rf",
              "photon"
            ],
            "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
            "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
            "status": "NOT-READY",
            "code": "FG-STUB",
            "warn5_until": "demonstrated",
            "warn5_by_design": "separate-from-icann",
            "refuse": {
              "packet": "FG-STUB",
              "radio_absent": "QNM-RADIO-ABSENT",
              "cap7_egress": "MG-NO-IP-EXIT",
              "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
              "bearer": "AZP-BEARER-REFUSE",
              "payload": "AZN-NO-PAYLOAD",
              "route": "MESH-NO-ROUTE",
              "stay_off": "MESH-STAY-OFF",
              "nat": "FED-MESH-NAT-REFUSE"
            },
            "carriers": [
              {
                "order": 1,
                "id": "lan",
                "name": "LAN",
                "op": "d2d_lan",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "lan-interface",
                "discovery": "LIVE-when-armed",
                "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
              },
              {
                "order": 2,
                "id": "wifi",
                "name": "Wi-Fi",
                "op": "d2d_wifi",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "wifi-nm",
                "discovery": "ARMED-when-HW",
                "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
              },
              {
                "order": 3,
                "id": "bluetooth",
                "name": "Bluetooth",
                "op": "d2d_bluetooth",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "bluez",
                "discovery": "ARMED-when-HW",
                "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
              },
              {
                "order": 4,
                "id": "rf",
                "name": "RF",
                "op": "d2d_rf",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "rf-beyond-wifi-bt",
                "discovery": "REFUSE-without-HW",
                "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
              },
              {
                "order": 5,
                "id": "photon",
                "name": "Photon",
                "op": "d2d_photon",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "camera-flash",
                "discovery": "REFUSE-without-HW",
                "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
              }
            ],
            "security": {
              "isolation": "single-node security-awareness",
              "phoenix": "local wait / re-seal",
              "mesh_fenced_to_loopback": false,
              "forced_loopback": false,
              "loopback_isolation": false
            },
            "paper": "docs/designs/D2D-CARRIERS-1.0.md",
            "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
          },
          "d2d_status": "NOT-READY",
          "d2d_code": "FG-STUB",
          "packet_path_live": false,
          "alt_internet_live": false,
          "d2d_spec": "D2D-CARRIERS-1.0",
          "federated_mesh": "FED-MESH-1.0",
          "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
          "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        },
        "peers": [
          {
            "slug": "azcoherence",
            "name": "AZCoherence",
            "role": "peer-reviewer",
            "kind": "software",
            "placement": "scoring-review",
            "domain": null,
            "domain_id": null,
            "worker_url": "https://azcoherence-download-tracker.vibelock.workers.dev/",
            "github": "https://github.com/AzielEliab/AZCoherence",
            "note": "Separate product. Second-pass triad coherence (AZC-0.1). Not a replacement for AZ-CLCE. Not AKM-TRIAD."
          }
        ],
        "fabric_neighbors": [],
        "hubs": [
          "https://azieleliab.com",
          "https://www.azielcorpuslibrary.net",
          "https://godlock.uk"
        ],
        "worker_url": "https://azclce-download-tracker.vibelock.workers.dev/",
        "cross_map": {
          "slug": "azclce",
          "name": "AZ-CLCE",
          "spec": null,
          "placement": "domain-software",
          "domain": "Language",
          "domain_id": "04",
          "domain_note": "Language isolation label. Not a door. FragGate is the single door.",
          "worker_url": "https://azclce-download-tracker.vibelock.workers.dev/",
          "github": "https://github.com/AzielEliab/az-clce",
          "hubs": [
            "https://azieleliab.com",
            "https://www.azielcorpuslibrary.net",
            "https://godlock.uk"
          ],
          "peers": [
            {
              "slug": "azcoherence",
              "name": "AZCoherence",
              "role": "peer-reviewer",
              "kind": "software",
              "placement": "scoring-review",
              "domain": null,
              "domain_id": null,
              "worker_url": "https://azcoherence-download-tracker.vibelock.workers.dev/",
              "github": "https://github.com/AzielEliab/AZCoherence",
              "note": "Separate product. Second-pass triad coherence (AZC-0.1). Not a replacement for AZ-CLCE. Not AKM-TRIAD."
            }
          ],
          "fabric_neighbors": [],
          "merged": false,
          "extra_door": false
        }
      },
      {
        "slug": "azos",
        "name": "AZ-OS",
        "bucket": "plain",
        "domain": "System",
        "domain_id": "09",
        "placement": "domain-software",
        "status": "live",
        "fraggate_status": "live",
        "public_door": true,
        "public_door_ops": [
          "status",
          "invite",
          "principles",
          "health",
          "skill",
          "doctor",
          "session_open",
          "session_status",
          "session_close",
          "session",
          "close",
          "mode_list",
          "boot_path",
          "internet_base",
          "guardian",
          "download_list",
          "download_check",
          "phone_path",
          "sim_lockout",
          "cellular",
          "ip_mask",
          "azcall",
          "veillock",
          "malware_sweep",
          "airgap",
          "human_check"
        ],
        "stub_ops": [
          "exec",
          "shell",
          "lattice",
          "place_call",
          "call",
          "sim_wipe",
          "esim_wipe",
          "wipe_sim"
        ],
        "door_label": "live FragGate door — named stub ops refuse",
        "open_live_door": true,
        "version": "0.3.0",
        "one_line": "Read ethics status and open a prefab isolate session folder.",
        "description": "Use AZ-OS to read its principles and open a short isolate ethics session. It exists as a local ethics workspace.",
        "worker_home": "https://azos-download-tracker.vibelock.workers.dev/",
        "worker_home_note": null,
        "download_url": "https://azos-download-tracker.vibelock.workers.dev/download",
        "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "github": "https://github.com/AzielEliab/azos",
        "mcp": "https://godlock.uk/runtime/mcp",
        "agent": {
          "mcp": "https://godlock.uk/runtime/mcp",
          "skill": "https://godlock.uk/runtime/v1/skill",
          "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
          "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=azos",
          "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
          "fraggate_call_executes": true,
          "open_live_door": true,
          "software": "https://godlock.uk/runtime/v1/software",
          "pull": "https://godlock.uk/runtime/v1/pull/azos",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "fe93fd4c3d6a656998ef22a964b55b277699458ff747387fa2f1e47144055eb4",
        "updated_at": null,
        "git_sha": null,
        "git_sha_tracks_deployed_tip": false,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/runtime/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "security": {
            "model": "single-node-security-awareness",
            "isolates": "bad-peer-or-self",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "phoenix": "local-wait-reseal",
            "phoenix_lock": true,
            "public_hostname_resurrection": false,
            "loopback_bearer": "L1-optional",
            "operator_locks": [
              {
                "n": 1,
                "id": "single-node-security-awareness",
                "status": "LIVE",
                "mesh_fenced_to_loopback": false
              },
              {
                "n": 2,
                "id": "phoenix-reboot-loop",
                "status": "LIVE",
                "phoenix": "local-wait-reseal",
                "phoenix_lock": true,
                "public_hostname_resurrection": false
              },
              {
                "n": 3,
                "id": "open-world-awareness",
                "status": "live-when-configured",
                "law": "LIVE",
                "bind": "0.0.0.0",
                "worker_socket": false,
                "forced_loopback_is_mesh_fence": false,
                "loopback_isolation_is_mesh_fence": false
              }
            ],
            "open_world_awareness": {
              "spec": "OPEN-WORLD-AWARENESS-1.0",
              "author": "Aziel Eliab",
              "identity": "Aziel Eliab",
              "open_world_awareness": true,
              "bind": "0.0.0.0",
              "all_interfaces": true,
              "law": "LIVE",
              "status": "live-when-configured",
              "live": false,
              "socket": "live-when-configured",
              "worker_socket": false,
              "qnm_node_bind": "live-when-configured",
              "mock": false,
              "forced_loopback": false,
              "loopback_isolation": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false,
              "mesh_fenced_to_loopback": false,
              "public_egress_ip": false,
              "residential": false,
              "cf_geo_exit": false,
              "cf_geo_exit_pool": false,
              "sticky_public_ip": false,
              "packet_forward": false,
              "packet_forwarding": false,
              "public_icann": false,
              "cap7_is_icann": false,
              "replaces_internet": false,
              "not_a_second_internet": true,
              "hosted_vpn": false,
              "payload_host": false,
              "vpn_hop": false,
              "wireguard": false,
              "openvpn": false,
              "l3_exit": false,
              "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
            },
            "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
          },
          "fanout": "cron-or-request-path",
          "live_nodes_plane": "human-mesh-users-site-viewers",
          "nodes_plane": "human-mesh-users-uses",
          "software_nodes_plane": "software-worker-fanout",
          "site_live_viewers_plane": "hub-human-page-presence",
          "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
          "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
          "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
          "site_presence_contract": {
            "method": "POST",
            "path": "/runtime/v1/mesh/site-presence",
            "alias": "/runtime/v1/mesh/site-heartbeat",
            "fraggate": {
              "slug": "mesh",
              "op": "site-presence"
            },
            "body": {
              "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
              "viewers": "non-negative integer concurrent human page sessions (0..10000)",
              "kind": "human-page"
            },
            "ttl_ms": 900000,
            "registered_grace_ms": 1209600000,
            "default_heartbeat_mode": "idle",
            "heartbeat_mode": "active | idle | asleep",
            "stale_keeps_registered": true,
            "stale_counts_as_live": false,
            "allowed_hosts": [
              "godlock.uk",
              "azieleliab.com",
              "azielcorpuslibrary.net"
            ],
            "excluded_hosts": [
              "hedidntjump.com"
            ],
            "refused_kinds": [
              "bot",
              "bots",
              "crawler",
              "software",
              "softwares",
              "download",
              "downloads",
              "instance",
              "mcp"
            ],
            "pull_hub_count": false,
            "invent": false,
            "fail_closed": true,
            "read": "single-key",
            "paint": "live_nodes",
            "local_recompute": false,
            "radios": "not required — hub ingest, not a TX join",
            "rate_kind": "mesh_mutate",
            "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
          },
          "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
          "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
          "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "ban_survival": "BAN-SURVIVAL-1.0",
          "spore_spec": "SPORE-1.0",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/runtime/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "neighbor_heal_is_cite": true,
              "neighbor_heal_exec": false,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "neighbor_heal_is_cite": true,
          "neighbor_heal_exec": false,
          "join_is_presence_only": true,
          "join_is_not_login": true,
          "roster_publishes_exec_urls": false,
          "mesh_mutate_rate_kind": "mesh_mutate",
          "roster_cap": 256,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "d2d_carriers": {
            "spec": "D2D-CARRIERS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "plane": "track2-reachability",
            "phase": "B+C+D",
            "phases": {
              "A": "landed",
              "B": "LIVE-when-armed",
              "C": "LIVE-when-session",
              "D": "LIVE-when-three-local-nodes / fixture",
              "E": "scaffold"
            },
            "lan_discovery": "LIVE-when-armed",
            "wifi_discovery": "ARMED-when-HW",
            "bluetooth_discovery": "ARMED-when-HW",
            "rf_discovery": "REFUSE-without-HW",
            "photon_discovery": "REFUSE-without-HW",
            "peer_tunnel": "LIVE-when-session",
            "store_forward": "LIVE-when-three-local-nodes / fixture",
            "store_forward_public": "FG-STUB",
            "worker_runs_store_forward": false,
            "second_device": false,
            "mobile_client": "present-not-demonstrated",
            "mobile_demonstrated": false,
            "app_store_release": false,
            "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
            "bootstrap_list": "scaffold",
            "needs_starting_address": true,
            "shelf_cite": "scaffold",
            "live_multi_provider": false,
            "cold_shelf_live": false,
            "dns_cut": false,
            "origin_cutover": false,
            "warn5_closed": false,
            "worker_door": "FG-STUB",
            "worker_hardware": false,
            "local_node": "qnm-node",
            "get_never_enables": true,
            "separate_from": "cap7-name",
            "cap7_is_name_plane": true,
            "cap7_public_icann": false,
            "cap7_public_egress": false,
            "mirage_is_azvpn": false,
            "aznet_replaces_internet": false,
            "not_a_second_internet": true,
            "alt_internet_live": false,
            "packet_path_live": false,
            "field_1_0": false,
            "warn5": "STANDS-until-demonstrated",
            "warn5_permanent_stay_off": false,
            "preference": "failover",
            "order": [
              "lan",
              "wifi",
              "bluetooth",
              "rf",
              "photon"
            ],
            "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
            "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
            "status": "NOT-READY",
            "code": "FG-STUB",
            "warn5_until": "demonstrated",
            "warn5_by_design": "separate-from-icann",
            "refuse": {
              "packet": "FG-STUB",
              "radio_absent": "QNM-RADIO-ABSENT",
              "cap7_egress": "MG-NO-IP-EXIT",
              "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
              "bearer": "AZP-BEARER-REFUSE",
              "payload": "AZN-NO-PAYLOAD",
              "route": "MESH-NO-ROUTE",
              "stay_off": "MESH-STAY-OFF",
              "nat": "FED-MESH-NAT-REFUSE"
            },
            "carriers": [
              {
                "order": 1,
                "id": "lan",
                "name": "LAN",
                "op": "d2d_lan",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "lan-interface",
                "discovery": "LIVE-when-armed",
                "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
              },
              {
                "order": 2,
                "id": "wifi",
                "name": "Wi-Fi",
                "op": "d2d_wifi",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "wifi-nm",
                "discovery": "ARMED-when-HW",
                "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
              },
              {
                "order": 3,
                "id": "bluetooth",
                "name": "Bluetooth",
                "op": "d2d_bluetooth",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "bluez",
                "discovery": "ARMED-when-HW",
                "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
              },
              {
                "order": 4,
                "id": "rf",
                "name": "RF",
                "op": "d2d_rf",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "rf-beyond-wifi-bt",
                "discovery": "REFUSE-without-HW",
                "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
              },
              {
                "order": 5,
                "id": "photon",
                "name": "Photon",
                "op": "d2d_photon",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "camera-flash",
                "discovery": "REFUSE-without-HW",
                "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
              }
            ],
            "security": {
              "isolation": "single-node security-awareness",
              "phoenix": "local wait / re-seal",
              "mesh_fenced_to_loopback": false,
              "forced_loopback": false,
              "loopback_isolation": false
            },
            "paper": "docs/designs/D2D-CARRIERS-1.0.md",
            "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
          },
          "d2d_status": "NOT-READY",
          "d2d_code": "FG-STUB",
          "packet_path_live": false,
          "alt_internet_live": false,
          "d2d_spec": "D2D-CARRIERS-1.0",
          "federated_mesh": "FED-MESH-1.0",
          "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
          "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        }
      },
      {
        "slug": "azai",
        "name": "AZAI",
        "bucket": "plain",
        "domain": "AI",
        "domain_id": "05",
        "placement": "domain-software",
        "status": "live",
        "fraggate_status": "live",
        "public_door": true,
        "public_door_ops": [
          "guide",
          "learner_guide",
          "ask",
          "lamb-check",
          "lamb_check",
          "models",
          "health",
          "skill",
          "doctor",
          "engine_status",
          "conversation",
          "agent",
          "azclicker",
          "attach",
          "crawl",
          "human_check",
          "cap7_lookup",
          "score_gate",
          "corpus_note",
          "receipt_learn",
          "receipt_status"
        ],
        "stub_ops": [
          "blend",
          "complete",
          "chat",
          "captcha",
          "captcha_solve",
          "solve_captcha"
        ],
        "door_label": "live FragGate door — named stub ops refuse",
        "open_live_door": true,
        "version": "0.3.1",
        "one_line": "Run a Lamb Lens check (Service → Clarity → Peace) or the adaptive AZAI Guide.",
        "description": "Use AZAI for a hosted Lamb ethics check or the adaptive Guide (Lamb Lens first). It exists as a local OpenAI-compatible stack plus a protocol mirror — prefer op=guide with q; skill and doctor stay diagnostics; chat/blend/complete stay refuse on the Worker.",
        "worker_home": "https://azai-download-tracker.vibelock.workers.dev/",
        "worker_home_note": null,
        "download_url": "https://azai-download-tracker.vibelock.workers.dev/download",
        "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "github": "https://github.com/AzielEliab/azai",
        "mcp": "https://godlock.uk/runtime/mcp",
        "agent": {
          "mcp": "https://godlock.uk/runtime/mcp",
          "skill": "https://godlock.uk/runtime/v1/skill",
          "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
          "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=azai",
          "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
          "fraggate_call_executes": true,
          "open_live_door": true,
          "software": "https://godlock.uk/runtime/v1/software",
          "pull": "https://godlock.uk/runtime/v1/pull/azai",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "435766c8de739bff706cda75a4e496726ed43de60224241cd6d98ca640efcebd",
        "updated_at": null,
        "git_sha": null,
        "git_sha_tracks_deployed_tip": false,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/runtime/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "security": {
            "model": "single-node-security-awareness",
            "isolates": "bad-peer-or-self",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "phoenix": "local-wait-reseal",
            "phoenix_lock": true,
            "public_hostname_resurrection": false,
            "loopback_bearer": "L1-optional",
            "operator_locks": [
              {
                "n": 1,
                "id": "single-node-security-awareness",
                "status": "LIVE",
                "mesh_fenced_to_loopback": false
              },
              {
                "n": 2,
                "id": "phoenix-reboot-loop",
                "status": "LIVE",
                "phoenix": "local-wait-reseal",
                "phoenix_lock": true,
                "public_hostname_resurrection": false
              },
              {
                "n": 3,
                "id": "open-world-awareness",
                "status": "live-when-configured",
                "law": "LIVE",
                "bind": "0.0.0.0",
                "worker_socket": false,
                "forced_loopback_is_mesh_fence": false,
                "loopback_isolation_is_mesh_fence": false
              }
            ],
            "open_world_awareness": {
              "spec": "OPEN-WORLD-AWARENESS-1.0",
              "author": "Aziel Eliab",
              "identity": "Aziel Eliab",
              "open_world_awareness": true,
              "bind": "0.0.0.0",
              "all_interfaces": true,
              "law": "LIVE",
              "status": "live-when-configured",
              "live": false,
              "socket": "live-when-configured",
              "worker_socket": false,
              "qnm_node_bind": "live-when-configured",
              "mock": false,
              "forced_loopback": false,
              "loopback_isolation": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false,
              "mesh_fenced_to_loopback": false,
              "public_egress_ip": false,
              "residential": false,
              "cf_geo_exit": false,
              "cf_geo_exit_pool": false,
              "sticky_public_ip": false,
              "packet_forward": false,
              "packet_forwarding": false,
              "public_icann": false,
              "cap7_is_icann": false,
              "replaces_internet": false,
              "not_a_second_internet": true,
              "hosted_vpn": false,
              "payload_host": false,
              "vpn_hop": false,
              "wireguard": false,
              "openvpn": false,
              "l3_exit": false,
              "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
            },
            "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
          },
          "fanout": "cron-or-request-path",
          "live_nodes_plane": "human-mesh-users-site-viewers",
          "nodes_plane": "human-mesh-users-uses",
          "software_nodes_plane": "software-worker-fanout",
          "site_live_viewers_plane": "hub-human-page-presence",
          "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
          "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
          "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
          "site_presence_contract": {
            "method": "POST",
            "path": "/runtime/v1/mesh/site-presence",
            "alias": "/runtime/v1/mesh/site-heartbeat",
            "fraggate": {
              "slug": "mesh",
              "op": "site-presence"
            },
            "body": {
              "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
              "viewers": "non-negative integer concurrent human page sessions (0..10000)",
              "kind": "human-page"
            },
            "ttl_ms": 900000,
            "registered_grace_ms": 1209600000,
            "default_heartbeat_mode": "idle",
            "heartbeat_mode": "active | idle | asleep",
            "stale_keeps_registered": true,
            "stale_counts_as_live": false,
            "allowed_hosts": [
              "godlock.uk",
              "azieleliab.com",
              "azielcorpuslibrary.net"
            ],
            "excluded_hosts": [
              "hedidntjump.com"
            ],
            "refused_kinds": [
              "bot",
              "bots",
              "crawler",
              "software",
              "softwares",
              "download",
              "downloads",
              "instance",
              "mcp"
            ],
            "pull_hub_count": false,
            "invent": false,
            "fail_closed": true,
            "read": "single-key",
            "paint": "live_nodes",
            "local_recompute": false,
            "radios": "not required — hub ingest, not a TX join",
            "rate_kind": "mesh_mutate",
            "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
          },
          "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
          "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
          "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "ban_survival": "BAN-SURVIVAL-1.0",
          "spore_spec": "SPORE-1.0",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/runtime/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "neighbor_heal_is_cite": true,
              "neighbor_heal_exec": false,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "neighbor_heal_is_cite": true,
          "neighbor_heal_exec": false,
          "join_is_presence_only": true,
          "join_is_not_login": true,
          "roster_publishes_exec_urls": false,
          "mesh_mutate_rate_kind": "mesh_mutate",
          "roster_cap": 256,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "d2d_carriers": {
            "spec": "D2D-CARRIERS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "plane": "track2-reachability",
            "phase": "B+C+D",
            "phases": {
              "A": "landed",
              "B": "LIVE-when-armed",
              "C": "LIVE-when-session",
              "D": "LIVE-when-three-local-nodes / fixture",
              "E": "scaffold"
            },
            "lan_discovery": "LIVE-when-armed",
            "wifi_discovery": "ARMED-when-HW",
            "bluetooth_discovery": "ARMED-when-HW",
            "rf_discovery": "REFUSE-without-HW",
            "photon_discovery": "REFUSE-without-HW",
            "peer_tunnel": "LIVE-when-session",
            "store_forward": "LIVE-when-three-local-nodes / fixture",
            "store_forward_public": "FG-STUB",
            "worker_runs_store_forward": false,
            "second_device": false,
            "mobile_client": "present-not-demonstrated",
            "mobile_demonstrated": false,
            "app_store_release": false,
            "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
            "bootstrap_list": "scaffold",
            "needs_starting_address": true,
            "shelf_cite": "scaffold",
            "live_multi_provider": false,
            "cold_shelf_live": false,
            "dns_cut": false,
            "origin_cutover": false,
            "warn5_closed": false,
            "worker_door": "FG-STUB",
            "worker_hardware": false,
            "local_node": "qnm-node",
            "get_never_enables": true,
            "separate_from": "cap7-name",
            "cap7_is_name_plane": true,
            "cap7_public_icann": false,
            "cap7_public_egress": false,
            "mirage_is_azvpn": false,
            "aznet_replaces_internet": false,
            "not_a_second_internet": true,
            "alt_internet_live": false,
            "packet_path_live": false,
            "field_1_0": false,
            "warn5": "STANDS-until-demonstrated",
            "warn5_permanent_stay_off": false,
            "preference": "failover",
            "order": [
              "lan",
              "wifi",
              "bluetooth",
              "rf",
              "photon"
            ],
            "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
            "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
            "status": "NOT-READY",
            "code": "FG-STUB",
            "warn5_until": "demonstrated",
            "warn5_by_design": "separate-from-icann",
            "refuse": {
              "packet": "FG-STUB",
              "radio_absent": "QNM-RADIO-ABSENT",
              "cap7_egress": "MG-NO-IP-EXIT",
              "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
              "bearer": "AZP-BEARER-REFUSE",
              "payload": "AZN-NO-PAYLOAD",
              "route": "MESH-NO-ROUTE",
              "stay_off": "MESH-STAY-OFF",
              "nat": "FED-MESH-NAT-REFUSE"
            },
            "carriers": [
              {
                "order": 1,
                "id": "lan",
                "name": "LAN",
                "op": "d2d_lan",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "lan-interface",
                "discovery": "LIVE-when-armed",
                "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
              },
              {
                "order": 2,
                "id": "wifi",
                "name": "Wi-Fi",
                "op": "d2d_wifi",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "wifi-nm",
                "discovery": "ARMED-when-HW",
                "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
              },
              {
                "order": 3,
                "id": "bluetooth",
                "name": "Bluetooth",
                "op": "d2d_bluetooth",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "bluez",
                "discovery": "ARMED-when-HW",
                "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
              },
              {
                "order": 4,
                "id": "rf",
                "name": "RF",
                "op": "d2d_rf",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "rf-beyond-wifi-bt",
                "discovery": "REFUSE-without-HW",
                "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
              },
              {
                "order": 5,
                "id": "photon",
                "name": "Photon",
                "op": "d2d_photon",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "camera-flash",
                "discovery": "REFUSE-without-HW",
                "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
              }
            ],
            "security": {
              "isolation": "single-node security-awareness",
              "phoenix": "local wait / re-seal",
              "mesh_fenced_to_loopback": false,
              "forced_loopback": false,
              "loopback_isolation": false
            },
            "paper": "docs/designs/D2D-CARRIERS-1.0.md",
            "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
          },
          "d2d_status": "NOT-READY",
          "d2d_code": "FG-STUB",
          "packet_path_live": false,
          "alt_internet_live": false,
          "d2d_spec": "D2D-CARRIERS-1.0",
          "federated_mesh": "FED-MESH-1.0",
          "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
          "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        }
      },
      {
        "slug": "azbot",
        "name": "AZBot",
        "bucket": "plain",
        "domain": "AI",
        "domain_id": "05",
        "placement": "domain-software",
        "status": "live",
        "fraggate_status": "live",
        "public_door": true,
        "public_door_ops": [
          "route",
          "example",
          "health",
          "skill",
          "doctor"
        ],
        "stub_ops": [],
        "door_label": "live FragGate door",
        "open_live_door": true,
        "version": "0.2.0",
        "one_line": "Route a request onto the matching catalog product and operation.",
        "description": "Use AZBot to point a question at the matching Aziel product. It exists as a skill router.",
        "worker_home": "https://azbot-download-tracker.vibelock.workers.dev/",
        "worker_home_note": null,
        "download_url": "https://azbot-download-tracker.vibelock.workers.dev/download",
        "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "github": "https://github.com/AzielEliab/azbot",
        "mcp": "https://godlock.uk/runtime/mcp",
        "agent": {
          "mcp": "https://godlock.uk/runtime/mcp",
          "skill": "https://godlock.uk/runtime/v1/skill",
          "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
          "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=azbot",
          "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
          "fraggate_call_executes": true,
          "open_live_door": true,
          "software": "https://godlock.uk/runtime/v1/software",
          "pull": "https://godlock.uk/runtime/v1/pull/azbot",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "909872259998d5ee9e276158b86194f704d40796588e5cc52d5ca15a86909456",
        "updated_at": null,
        "git_sha": null,
        "git_sha_tracks_deployed_tip": false,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/runtime/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "security": {
            "model": "single-node-security-awareness",
            "isolates": "bad-peer-or-self",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "phoenix": "local-wait-reseal",
            "phoenix_lock": true,
            "public_hostname_resurrection": false,
            "loopback_bearer": "L1-optional",
            "operator_locks": [
              {
                "n": 1,
                "id": "single-node-security-awareness",
                "status": "LIVE",
                "mesh_fenced_to_loopback": false
              },
              {
                "n": 2,
                "id": "phoenix-reboot-loop",
                "status": "LIVE",
                "phoenix": "local-wait-reseal",
                "phoenix_lock": true,
                "public_hostname_resurrection": false
              },
              {
                "n": 3,
                "id": "open-world-awareness",
                "status": "live-when-configured",
                "law": "LIVE",
                "bind": "0.0.0.0",
                "worker_socket": false,
                "forced_loopback_is_mesh_fence": false,
                "loopback_isolation_is_mesh_fence": false
              }
            ],
            "open_world_awareness": {
              "spec": "OPEN-WORLD-AWARENESS-1.0",
              "author": "Aziel Eliab",
              "identity": "Aziel Eliab",
              "open_world_awareness": true,
              "bind": "0.0.0.0",
              "all_interfaces": true,
              "law": "LIVE",
              "status": "live-when-configured",
              "live": false,
              "socket": "live-when-configured",
              "worker_socket": false,
              "qnm_node_bind": "live-when-configured",
              "mock": false,
              "forced_loopback": false,
              "loopback_isolation": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false,
              "mesh_fenced_to_loopback": false,
              "public_egress_ip": false,
              "residential": false,
              "cf_geo_exit": false,
              "cf_geo_exit_pool": false,
              "sticky_public_ip": false,
              "packet_forward": false,
              "packet_forwarding": false,
              "public_icann": false,
              "cap7_is_icann": false,
              "replaces_internet": false,
              "not_a_second_internet": true,
              "hosted_vpn": false,
              "payload_host": false,
              "vpn_hop": false,
              "wireguard": false,
              "openvpn": false,
              "l3_exit": false,
              "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
            },
            "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
          },
          "fanout": "cron-or-request-path",
          "live_nodes_plane": "human-mesh-users-site-viewers",
          "nodes_plane": "human-mesh-users-uses",
          "software_nodes_plane": "software-worker-fanout",
          "site_live_viewers_plane": "hub-human-page-presence",
          "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
          "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
          "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
          "site_presence_contract": {
            "method": "POST",
            "path": "/runtime/v1/mesh/site-presence",
            "alias": "/runtime/v1/mesh/site-heartbeat",
            "fraggate": {
              "slug": "mesh",
              "op": "site-presence"
            },
            "body": {
              "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
              "viewers": "non-negative integer concurrent human page sessions (0..10000)",
              "kind": "human-page"
            },
            "ttl_ms": 900000,
            "registered_grace_ms": 1209600000,
            "default_heartbeat_mode": "idle",
            "heartbeat_mode": "active | idle | asleep",
            "stale_keeps_registered": true,
            "stale_counts_as_live": false,
            "allowed_hosts": [
              "godlock.uk",
              "azieleliab.com",
              "azielcorpuslibrary.net"
            ],
            "excluded_hosts": [
              "hedidntjump.com"
            ],
            "refused_kinds": [
              "bot",
              "bots",
              "crawler",
              "software",
              "softwares",
              "download",
              "downloads",
              "instance",
              "mcp"
            ],
            "pull_hub_count": false,
            "invent": false,
            "fail_closed": true,
            "read": "single-key",
            "paint": "live_nodes",
            "local_recompute": false,
            "radios": "not required — hub ingest, not a TX join",
            "rate_kind": "mesh_mutate",
            "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
          },
          "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
          "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
          "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "ban_survival": "BAN-SURVIVAL-1.0",
          "spore_spec": "SPORE-1.0",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/runtime/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "neighbor_heal_is_cite": true,
              "neighbor_heal_exec": false,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "neighbor_heal_is_cite": true,
          "neighbor_heal_exec": false,
          "join_is_presence_only": true,
          "join_is_not_login": true,
          "roster_publishes_exec_urls": false,
          "mesh_mutate_rate_kind": "mesh_mutate",
          "roster_cap": 256,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "d2d_carriers": {
            "spec": "D2D-CARRIERS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "plane": "track2-reachability",
            "phase": "B+C+D",
            "phases": {
              "A": "landed",
              "B": "LIVE-when-armed",
              "C": "LIVE-when-session",
              "D": "LIVE-when-three-local-nodes / fixture",
              "E": "scaffold"
            },
            "lan_discovery": "LIVE-when-armed",
            "wifi_discovery": "ARMED-when-HW",
            "bluetooth_discovery": "ARMED-when-HW",
            "rf_discovery": "REFUSE-without-HW",
            "photon_discovery": "REFUSE-without-HW",
            "peer_tunnel": "LIVE-when-session",
            "store_forward": "LIVE-when-three-local-nodes / fixture",
            "store_forward_public": "FG-STUB",
            "worker_runs_store_forward": false,
            "second_device": false,
            "mobile_client": "present-not-demonstrated",
            "mobile_demonstrated": false,
            "app_store_release": false,
            "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
            "bootstrap_list": "scaffold",
            "needs_starting_address": true,
            "shelf_cite": "scaffold",
            "live_multi_provider": false,
            "cold_shelf_live": false,
            "dns_cut": false,
            "origin_cutover": false,
            "warn5_closed": false,
            "worker_door": "FG-STUB",
            "worker_hardware": false,
            "local_node": "qnm-node",
            "get_never_enables": true,
            "separate_from": "cap7-name",
            "cap7_is_name_plane": true,
            "cap7_public_icann": false,
            "cap7_public_egress": false,
            "mirage_is_azvpn": false,
            "aznet_replaces_internet": false,
            "not_a_second_internet": true,
            "alt_internet_live": false,
            "packet_path_live": false,
            "field_1_0": false,
            "warn5": "STANDS-until-demonstrated",
            "warn5_permanent_stay_off": false,
            "preference": "failover",
            "order": [
              "lan",
              "wifi",
              "bluetooth",
              "rf",
              "photon"
            ],
            "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
            "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
            "status": "NOT-READY",
            "code": "FG-STUB",
            "warn5_until": "demonstrated",
            "warn5_by_design": "separate-from-icann",
            "refuse": {
              "packet": "FG-STUB",
              "radio_absent": "QNM-RADIO-ABSENT",
              "cap7_egress": "MG-NO-IP-EXIT",
              "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
              "bearer": "AZP-BEARER-REFUSE",
              "payload": "AZN-NO-PAYLOAD",
              "route": "MESH-NO-ROUTE",
              "stay_off": "MESH-STAY-OFF",
              "nat": "FED-MESH-NAT-REFUSE"
            },
            "carriers": [
              {
                "order": 1,
                "id": "lan",
                "name": "LAN",
                "op": "d2d_lan",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "lan-interface",
                "discovery": "LIVE-when-armed",
                "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
              },
              {
                "order": 2,
                "id": "wifi",
                "name": "Wi-Fi",
                "op": "d2d_wifi",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "wifi-nm",
                "discovery": "ARMED-when-HW",
                "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
              },
              {
                "order": 3,
                "id": "bluetooth",
                "name": "Bluetooth",
                "op": "d2d_bluetooth",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "bluez",
                "discovery": "ARMED-when-HW",
                "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
              },
              {
                "order": 4,
                "id": "rf",
                "name": "RF",
                "op": "d2d_rf",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "rf-beyond-wifi-bt",
                "discovery": "REFUSE-without-HW",
                "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
              },
              {
                "order": 5,
                "id": "photon",
                "name": "Photon",
                "op": "d2d_photon",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "camera-flash",
                "discovery": "REFUSE-without-HW",
                "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
              }
            ],
            "security": {
              "isolation": "single-node security-awareness",
              "phoenix": "local wait / re-seal",
              "mesh_fenced_to_loopback": false,
              "forced_loopback": false,
              "loopback_isolation": false
            },
            "paper": "docs/designs/D2D-CARRIERS-1.0.md",
            "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
          },
          "d2d_status": "NOT-READY",
          "d2d_code": "FG-STUB",
          "packet_path_live": false,
          "alt_internet_live": false,
          "d2d_spec": "D2D-CARRIERS-1.0",
          "federated_mesh": "FED-MESH-1.0",
          "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
          "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        }
      },
      {
        "slug": "azbrowser",
        "name": "AZBrowser",
        "bucket": "plain",
        "domain": "Research",
        "domain_id": "06",
        "placement": "domain-software",
        "status": "live",
        "fraggate_status": "live",
        "public_door": true,
        "public_door_ops": [
          "ethical_search",
          "lamb_lens_search",
          "navigate",
          "airlock_ingest",
          "tab_open",
          "tab_list",
          "receipt_list",
          "verify",
          "receipt_verify",
          "sandbox_status",
          "sandbox_render",
          "health",
          "skill",
          "doctor",
          "airlock",
          "home",
          "vpn",
          "malware_sweep",
          "airgap",
          "jeeves_site",
          "human_check"
        ],
        "stub_ops": [
          "tor_exit",
          "tor",
          "onion",
          "phoenix_wipe",
          "wipe",
          "scorch",
          "chromium",
          "chromium_exec",
          "chrome",
          "exec",
          "playwright",
          "puppeteer",
          "proxy",
          "unrestricted_proxy",
          "socks",
          "keylog",
          "keylogger",
          "clipboard",
          "harvest",
          "spy",
          "surveillance",
          "wiretap",
          "intercept",
          "inject",
          "track",
          "captcha",
          "captcha_solve",
          "solve_captcha"
        ],
        "door_label": "live FragGate door — named stub ops refuse",
        "open_live_door": true,
        "version": "0.1.0",
        "one_line": "Browse and search with citations for ethical research.",
        "description": "Use AZBrowser for ethical research search and advisory page metadata. It exists so research stays cited.",
        "worker_home": "https://azbrowser-download-tracker.vibelock.workers.dev/",
        "worker_home_note": null,
        "download_url": "https://azbrowser-download-tracker.vibelock.workers.dev/download",
        "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "github": "https://github.com/AzielEliab/azbrowser",
        "mcp": "https://godlock.uk/runtime/mcp",
        "agent": {
          "mcp": "https://godlock.uk/runtime/mcp",
          "skill": "https://godlock.uk/runtime/v1/skill",
          "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
          "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=azbrowser",
          "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
          "fraggate_call_executes": true,
          "open_live_door": true,
          "software": "https://godlock.uk/runtime/v1/software",
          "pull": "https://godlock.uk/runtime/v1/pull/azbrowser",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "f27b40c284a748de8c290742bf9aa3deda716893af8963d97707dca28dd65b48",
        "updated_at": null,
        "git_sha": null,
        "git_sha_tracks_deployed_tip": false,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/runtime/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "security": {
            "model": "single-node-security-awareness",
            "isolates": "bad-peer-or-self",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "phoenix": "local-wait-reseal",
            "phoenix_lock": true,
            "public_hostname_resurrection": false,
            "loopback_bearer": "L1-optional",
            "operator_locks": [
              {
                "n": 1,
                "id": "single-node-security-awareness",
                "status": "LIVE",
                "mesh_fenced_to_loopback": false
              },
              {
                "n": 2,
                "id": "phoenix-reboot-loop",
                "status": "LIVE",
                "phoenix": "local-wait-reseal",
                "phoenix_lock": true,
                "public_hostname_resurrection": false
              },
              {
                "n": 3,
                "id": "open-world-awareness",
                "status": "live-when-configured",
                "law": "LIVE",
                "bind": "0.0.0.0",
                "worker_socket": false,
                "forced_loopback_is_mesh_fence": false,
                "loopback_isolation_is_mesh_fence": false
              }
            ],
            "open_world_awareness": {
              "spec": "OPEN-WORLD-AWARENESS-1.0",
              "author": "Aziel Eliab",
              "identity": "Aziel Eliab",
              "open_world_awareness": true,
              "bind": "0.0.0.0",
              "all_interfaces": true,
              "law": "LIVE",
              "status": "live-when-configured",
              "live": false,
              "socket": "live-when-configured",
              "worker_socket": false,
              "qnm_node_bind": "live-when-configured",
              "mock": false,
              "forced_loopback": false,
              "loopback_isolation": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false,
              "mesh_fenced_to_loopback": false,
              "public_egress_ip": false,
              "residential": false,
              "cf_geo_exit": false,
              "cf_geo_exit_pool": false,
              "sticky_public_ip": false,
              "packet_forward": false,
              "packet_forwarding": false,
              "public_icann": false,
              "cap7_is_icann": false,
              "replaces_internet": false,
              "not_a_second_internet": true,
              "hosted_vpn": false,
              "payload_host": false,
              "vpn_hop": false,
              "wireguard": false,
              "openvpn": false,
              "l3_exit": false,
              "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
            },
            "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
          },
          "fanout": "cron-or-request-path",
          "live_nodes_plane": "human-mesh-users-site-viewers",
          "nodes_plane": "human-mesh-users-uses",
          "software_nodes_plane": "software-worker-fanout",
          "site_live_viewers_plane": "hub-human-page-presence",
          "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
          "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
          "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
          "site_presence_contract": {
            "method": "POST",
            "path": "/runtime/v1/mesh/site-presence",
            "alias": "/runtime/v1/mesh/site-heartbeat",
            "fraggate": {
              "slug": "mesh",
              "op": "site-presence"
            },
            "body": {
              "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
              "viewers": "non-negative integer concurrent human page sessions (0..10000)",
              "kind": "human-page"
            },
            "ttl_ms": 900000,
            "registered_grace_ms": 1209600000,
            "default_heartbeat_mode": "idle",
            "heartbeat_mode": "active | idle | asleep",
            "stale_keeps_registered": true,
            "stale_counts_as_live": false,
            "allowed_hosts": [
              "godlock.uk",
              "azieleliab.com",
              "azielcorpuslibrary.net"
            ],
            "excluded_hosts": [
              "hedidntjump.com"
            ],
            "refused_kinds": [
              "bot",
              "bots",
              "crawler",
              "software",
              "softwares",
              "download",
              "downloads",
              "instance",
              "mcp"
            ],
            "pull_hub_count": false,
            "invent": false,
            "fail_closed": true,
            "read": "single-key",
            "paint": "live_nodes",
            "local_recompute": false,
            "radios": "not required — hub ingest, not a TX join",
            "rate_kind": "mesh_mutate",
            "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
          },
          "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
          "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
          "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "ban_survival": "BAN-SURVIVAL-1.0",
          "spore_spec": "SPORE-1.0",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/runtime/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "neighbor_heal_is_cite": true,
              "neighbor_heal_exec": false,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "neighbor_heal_is_cite": true,
          "neighbor_heal_exec": false,
          "join_is_presence_only": true,
          "join_is_not_login": true,
          "roster_publishes_exec_urls": false,
          "mesh_mutate_rate_kind": "mesh_mutate",
          "roster_cap": 256,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "d2d_carriers": {
            "spec": "D2D-CARRIERS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "plane": "track2-reachability",
            "phase": "B+C+D",
            "phases": {
              "A": "landed",
              "B": "LIVE-when-armed",
              "C": "LIVE-when-session",
              "D": "LIVE-when-three-local-nodes / fixture",
              "E": "scaffold"
            },
            "lan_discovery": "LIVE-when-armed",
            "wifi_discovery": "ARMED-when-HW",
            "bluetooth_discovery": "ARMED-when-HW",
            "rf_discovery": "REFUSE-without-HW",
            "photon_discovery": "REFUSE-without-HW",
            "peer_tunnel": "LIVE-when-session",
            "store_forward": "LIVE-when-three-local-nodes / fixture",
            "store_forward_public": "FG-STUB",
            "worker_runs_store_forward": false,
            "second_device": false,
            "mobile_client": "present-not-demonstrated",
            "mobile_demonstrated": false,
            "app_store_release": false,
            "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
            "bootstrap_list": "scaffold",
            "needs_starting_address": true,
            "shelf_cite": "scaffold",
            "live_multi_provider": false,
            "cold_shelf_live": false,
            "dns_cut": false,
            "origin_cutover": false,
            "warn5_closed": false,
            "worker_door": "FG-STUB",
            "worker_hardware": false,
            "local_node": "qnm-node",
            "get_never_enables": true,
            "separate_from": "cap7-name",
            "cap7_is_name_plane": true,
            "cap7_public_icann": false,
            "cap7_public_egress": false,
            "mirage_is_azvpn": false,
            "aznet_replaces_internet": false,
            "not_a_second_internet": true,
            "alt_internet_live": false,
            "packet_path_live": false,
            "field_1_0": false,
            "warn5": "STANDS-until-demonstrated",
            "warn5_permanent_stay_off": false,
            "preference": "failover",
            "order": [
              "lan",
              "wifi",
              "bluetooth",
              "rf",
              "photon"
            ],
            "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
            "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
            "status": "NOT-READY",
            "code": "FG-STUB",
            "warn5_until": "demonstrated",
            "warn5_by_design": "separate-from-icann",
            "refuse": {
              "packet": "FG-STUB",
              "radio_absent": "QNM-RADIO-ABSENT",
              "cap7_egress": "MG-NO-IP-EXIT",
              "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
              "bearer": "AZP-BEARER-REFUSE",
              "payload": "AZN-NO-PAYLOAD",
              "route": "MESH-NO-ROUTE",
              "stay_off": "MESH-STAY-OFF",
              "nat": "FED-MESH-NAT-REFUSE"
            },
            "carriers": [
              {
                "order": 1,
                "id": "lan",
                "name": "LAN",
                "op": "d2d_lan",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "lan-interface",
                "discovery": "LIVE-when-armed",
                "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
              },
              {
                "order": 2,
                "id": "wifi",
                "name": "Wi-Fi",
                "op": "d2d_wifi",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "wifi-nm",
                "discovery": "ARMED-when-HW",
                "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
              },
              {
                "order": 3,
                "id": "bluetooth",
                "name": "Bluetooth",
                "op": "d2d_bluetooth",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "bluez",
                "discovery": "ARMED-when-HW",
                "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
              },
              {
                "order": 4,
                "id": "rf",
                "name": "RF",
                "op": "d2d_rf",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "rf-beyond-wifi-bt",
                "discovery": "REFUSE-without-HW",
                "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
              },
              {
                "order": 5,
                "id": "photon",
                "name": "Photon",
                "op": "d2d_photon",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "camera-flash",
                "discovery": "REFUSE-without-HW",
                "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
              }
            ],
            "security": {
              "isolation": "single-node security-awareness",
              "phoenix": "local wait / re-seal",
              "mesh_fenced_to_loopback": false,
              "forced_loopback": false,
              "loopback_isolation": false
            },
            "paper": "docs/designs/D2D-CARRIERS-1.0.md",
            "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
          },
          "d2d_status": "NOT-READY",
          "d2d_code": "FG-STUB",
          "packet_path_live": false,
          "alt_internet_live": false,
          "d2d_spec": "D2D-CARRIERS-1.0",
          "federated_mesh": "FED-MESH-1.0",
          "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
          "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        }
      },
      {
        "slug": "azchat",
        "name": "AZChat",
        "bucket": "plain",
        "domain": "Comms",
        "domain_id": "07",
        "placement": "domain-software",
        "status": "live",
        "fraggate_status": "live",
        "public_door": true,
        "public_door_ops": [
          "health",
          "skill",
          "doctor",
          "handle_new",
          "handle_rotate",
          "room_open",
          "room_post",
          "room_pull",
          "bus_send",
          "bus_poll",
          "verify_receipt",
          "import_export",
          "channel_seal",
          "bridge_status",
          "malware_sweep",
          "airgap"
        ],
        "stub_ops": [
          "smtp",
          "smtp_send",
          "send",
          "mail",
          "deliver",
          "deanonymize",
          "harvest",
          "mesh_join",
          "mesh_enable",
          "vpn",
          "bridge_azmail",
          "bridge",
          "chromium",
          "bridge_whatsapp",
          "bridge_facebook",
          "bridge_gmail",
          "bridge_outlook",
          "bridge_yahoo"
        ],
        "door_label": "live FragGate door — named stub ops refuse",
        "open_live_door": true,
        "version": "0.1.0",
        "one_line": "Join a room from the all-rooms list, where a hosted room appears, and a private room requires a passphrase. The product mesh hop starts off.",
        "description": "Use AZChat to join from the all-rooms list, to see a room you host in that list, and to require a passphrase on a private room. The product mesh hop starts off. It exists for spendable-handle chat and an agent bus. Those room options are the AZChat product contract.",
        "worker_home": "https://azchat-download-tracker.vibelock.workers.dev/",
        "worker_home_note": null,
        "download_url": "https://azchat-download-tracker.vibelock.workers.dev/download",
        "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "github": "https://github.com/AzielEliab/azchat",
        "mcp": "https://godlock.uk/runtime/mcp",
        "agent": {
          "mcp": "https://godlock.uk/runtime/mcp",
          "skill": "https://godlock.uk/runtime/v1/skill",
          "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
          "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=azchat",
          "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
          "fraggate_call_executes": true,
          "open_live_door": true,
          "software": "https://godlock.uk/runtime/v1/software",
          "pull": "https://godlock.uk/runtime/v1/pull/azchat",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "9b63fc0adcbb65318fbad7fd6aaf39b6f44edc5ff41696571457a5bd765ec5c5",
        "updated_at": null,
        "git_sha": null,
        "git_sha_tracks_deployed_tip": false,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/runtime/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "security": {
            "model": "single-node-security-awareness",
            "isolates": "bad-peer-or-self",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "phoenix": "local-wait-reseal",
            "phoenix_lock": true,
            "public_hostname_resurrection": false,
            "loopback_bearer": "L1-optional",
            "operator_locks": [
              {
                "n": 1,
                "id": "single-node-security-awareness",
                "status": "LIVE",
                "mesh_fenced_to_loopback": false
              },
              {
                "n": 2,
                "id": "phoenix-reboot-loop",
                "status": "LIVE",
                "phoenix": "local-wait-reseal",
                "phoenix_lock": true,
                "public_hostname_resurrection": false
              },
              {
                "n": 3,
                "id": "open-world-awareness",
                "status": "live-when-configured",
                "law": "LIVE",
                "bind": "0.0.0.0",
                "worker_socket": false,
                "forced_loopback_is_mesh_fence": false,
                "loopback_isolation_is_mesh_fence": false
              }
            ],
            "open_world_awareness": {
              "spec": "OPEN-WORLD-AWARENESS-1.0",
              "author": "Aziel Eliab",
              "identity": "Aziel Eliab",
              "open_world_awareness": true,
              "bind": "0.0.0.0",
              "all_interfaces": true,
              "law": "LIVE",
              "status": "live-when-configured",
              "live": false,
              "socket": "live-when-configured",
              "worker_socket": false,
              "qnm_node_bind": "live-when-configured",
              "mock": false,
              "forced_loopback": false,
              "loopback_isolation": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false,
              "mesh_fenced_to_loopback": false,
              "public_egress_ip": false,
              "residential": false,
              "cf_geo_exit": false,
              "cf_geo_exit_pool": false,
              "sticky_public_ip": false,
              "packet_forward": false,
              "packet_forwarding": false,
              "public_icann": false,
              "cap7_is_icann": false,
              "replaces_internet": false,
              "not_a_second_internet": true,
              "hosted_vpn": false,
              "payload_host": false,
              "vpn_hop": false,
              "wireguard": false,
              "openvpn": false,
              "l3_exit": false,
              "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
            },
            "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
          },
          "fanout": "cron-or-request-path",
          "live_nodes_plane": "human-mesh-users-site-viewers",
          "nodes_plane": "human-mesh-users-uses",
          "software_nodes_plane": "software-worker-fanout",
          "site_live_viewers_plane": "hub-human-page-presence",
          "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
          "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
          "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
          "site_presence_contract": {
            "method": "POST",
            "path": "/runtime/v1/mesh/site-presence",
            "alias": "/runtime/v1/mesh/site-heartbeat",
            "fraggate": {
              "slug": "mesh",
              "op": "site-presence"
            },
            "body": {
              "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
              "viewers": "non-negative integer concurrent human page sessions (0..10000)",
              "kind": "human-page"
            },
            "ttl_ms": 900000,
            "registered_grace_ms": 1209600000,
            "default_heartbeat_mode": "idle",
            "heartbeat_mode": "active | idle | asleep",
            "stale_keeps_registered": true,
            "stale_counts_as_live": false,
            "allowed_hosts": [
              "godlock.uk",
              "azieleliab.com",
              "azielcorpuslibrary.net"
            ],
            "excluded_hosts": [
              "hedidntjump.com"
            ],
            "refused_kinds": [
              "bot",
              "bots",
              "crawler",
              "software",
              "softwares",
              "download",
              "downloads",
              "instance",
              "mcp"
            ],
            "pull_hub_count": false,
            "invent": false,
            "fail_closed": true,
            "read": "single-key",
            "paint": "live_nodes",
            "local_recompute": false,
            "radios": "not required — hub ingest, not a TX join",
            "rate_kind": "mesh_mutate",
            "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
          },
          "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
          "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
          "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "ban_survival": "BAN-SURVIVAL-1.0",
          "spore_spec": "SPORE-1.0",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/runtime/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "neighbor_heal_is_cite": true,
              "neighbor_heal_exec": false,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "neighbor_heal_is_cite": true,
          "neighbor_heal_exec": false,
          "join_is_presence_only": true,
          "join_is_not_login": true,
          "roster_publishes_exec_urls": false,
          "mesh_mutate_rate_kind": "mesh_mutate",
          "roster_cap": 256,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "d2d_carriers": {
            "spec": "D2D-CARRIERS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "plane": "track2-reachability",
            "phase": "B+C+D",
            "phases": {
              "A": "landed",
              "B": "LIVE-when-armed",
              "C": "LIVE-when-session",
              "D": "LIVE-when-three-local-nodes / fixture",
              "E": "scaffold"
            },
            "lan_discovery": "LIVE-when-armed",
            "wifi_discovery": "ARMED-when-HW",
            "bluetooth_discovery": "ARMED-when-HW",
            "rf_discovery": "REFUSE-without-HW",
            "photon_discovery": "REFUSE-without-HW",
            "peer_tunnel": "LIVE-when-session",
            "store_forward": "LIVE-when-three-local-nodes / fixture",
            "store_forward_public": "FG-STUB",
            "worker_runs_store_forward": false,
            "second_device": false,
            "mobile_client": "present-not-demonstrated",
            "mobile_demonstrated": false,
            "app_store_release": false,
            "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
            "bootstrap_list": "scaffold",
            "needs_starting_address": true,
            "shelf_cite": "scaffold",
            "live_multi_provider": false,
            "cold_shelf_live": false,
            "dns_cut": false,
            "origin_cutover": false,
            "warn5_closed": false,
            "worker_door": "FG-STUB",
            "worker_hardware": false,
            "local_node": "qnm-node",
            "get_never_enables": true,
            "separate_from": "cap7-name",
            "cap7_is_name_plane": true,
            "cap7_public_icann": false,
            "cap7_public_egress": false,
            "mirage_is_azvpn": false,
            "aznet_replaces_internet": false,
            "not_a_second_internet": true,
            "alt_internet_live": false,
            "packet_path_live": false,
            "field_1_0": false,
            "warn5": "STANDS-until-demonstrated",
            "warn5_permanent_stay_off": false,
            "preference": "failover",
            "order": [
              "lan",
              "wifi",
              "bluetooth",
              "rf",
              "photon"
            ],
            "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
            "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
            "status": "NOT-READY",
            "code": "FG-STUB",
            "warn5_until": "demonstrated",
            "warn5_by_design": "separate-from-icann",
            "refuse": {
              "packet": "FG-STUB",
              "radio_absent": "QNM-RADIO-ABSENT",
              "cap7_egress": "MG-NO-IP-EXIT",
              "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
              "bearer": "AZP-BEARER-REFUSE",
              "payload": "AZN-NO-PAYLOAD",
              "route": "MESH-NO-ROUTE",
              "stay_off": "MESH-STAY-OFF",
              "nat": "FED-MESH-NAT-REFUSE"
            },
            "carriers": [
              {
                "order": 1,
                "id": "lan",
                "name": "LAN",
                "op": "d2d_lan",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "lan-interface",
                "discovery": "LIVE-when-armed",
                "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
              },
              {
                "order": 2,
                "id": "wifi",
                "name": "Wi-Fi",
                "op": "d2d_wifi",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "wifi-nm",
                "discovery": "ARMED-when-HW",
                "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
              },
              {
                "order": 3,
                "id": "bluetooth",
                "name": "Bluetooth",
                "op": "d2d_bluetooth",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "bluez",
                "discovery": "ARMED-when-HW",
                "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
              },
              {
                "order": 4,
                "id": "rf",
                "name": "RF",
                "op": "d2d_rf",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "rf-beyond-wifi-bt",
                "discovery": "REFUSE-without-HW",
                "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
              },
              {
                "order": 5,
                "id": "photon",
                "name": "Photon",
                "op": "d2d_photon",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "camera-flash",
                "discovery": "REFUSE-without-HW",
                "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
              }
            ],
            "security": {
              "isolation": "single-node security-awareness",
              "phoenix": "local wait / re-seal",
              "mesh_fenced_to_loopback": false,
              "forced_loopback": false,
              "loopback_isolation": false
            },
            "paper": "docs/designs/D2D-CARRIERS-1.0.md",
            "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
          },
          "d2d_status": "NOT-READY",
          "d2d_code": "FG-STUB",
          "packet_path_live": false,
          "alt_internet_live": false,
          "d2d_spec": "D2D-CARRIERS-1.0",
          "federated_mesh": "FED-MESH-1.0",
          "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
          "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        },
        "mesh_default": "off",
        "product_mesh": "default_off",
        "suite_mesh_is_separate": true
      },
      {
        "slug": "azcoherence",
        "name": "AZCoherence",
        "bucket": "plain",
        "domain": null,
        "domain_id": null,
        "placement": "scoring-review",
        "status": "live",
        "fraggate_status": "live",
        "public_door": true,
        "public_door_ops": [
          "health",
          "skill",
          "doctor",
          "verify",
          "review_triad",
          "alternate_score",
          "coherence_check",
          "neutralize_hallucination"
        ],
        "stub_ops": [
          "invent_evidence",
          "invent",
          "fabricate",
          "truth_score",
          "truth_claim",
          "akm_calibrate",
          "memory_observe",
          "posterior_as_truth",
          "auto_pass",
          "blend_scores"
        ],
        "door_label": "live FragGate door — named stub ops refuse",
        "open_live_door": true,
        "version": "0.1.0",
        "one_line": "Review whether a primary score and an alternate hold together.",
        "description": "Use AZCoherence for a second look at a posted triad versus an alternate. It exists to review coherence.",
        "worker_home": "https://azcoherence-download-tracker.vibelock.workers.dev/",
        "worker_home_note": null,
        "download_url": "https://azcoherence-download-tracker.vibelock.workers.dev/download",
        "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "github": "https://github.com/AzielEliab/AZCoherence",
        "mcp": "https://godlock.uk/runtime/mcp",
        "agent": {
          "mcp": "https://godlock.uk/runtime/mcp",
          "skill": "https://godlock.uk/runtime/v1/skill",
          "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
          "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=azcoherence",
          "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
          "fraggate_call_executes": true,
          "open_live_door": true,
          "software": "https://godlock.uk/runtime/v1/software",
          "pull": "https://godlock.uk/runtime/v1/pull/azcoherence",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "f04dfa4af332a1c04bd7319a8f48cee3e9adec3877d198ea703ee6187790cfc5",
        "updated_at": null,
        "git_sha": null,
        "git_sha_tracks_deployed_tip": false,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/runtime/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "security": {
            "model": "single-node-security-awareness",
            "isolates": "bad-peer-or-self",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "phoenix": "local-wait-reseal",
            "phoenix_lock": true,
            "public_hostname_resurrection": false,
            "loopback_bearer": "L1-optional",
            "operator_locks": [
              {
                "n": 1,
                "id": "single-node-security-awareness",
                "status": "LIVE",
                "mesh_fenced_to_loopback": false
              },
              {
                "n": 2,
                "id": "phoenix-reboot-loop",
                "status": "LIVE",
                "phoenix": "local-wait-reseal",
                "phoenix_lock": true,
                "public_hostname_resurrection": false
              },
              {
                "n": 3,
                "id": "open-world-awareness",
                "status": "live-when-configured",
                "law": "LIVE",
                "bind": "0.0.0.0",
                "worker_socket": false,
                "forced_loopback_is_mesh_fence": false,
                "loopback_isolation_is_mesh_fence": false
              }
            ],
            "open_world_awareness": {
              "spec": "OPEN-WORLD-AWARENESS-1.0",
              "author": "Aziel Eliab",
              "identity": "Aziel Eliab",
              "open_world_awareness": true,
              "bind": "0.0.0.0",
              "all_interfaces": true,
              "law": "LIVE",
              "status": "live-when-configured",
              "live": false,
              "socket": "live-when-configured",
              "worker_socket": false,
              "qnm_node_bind": "live-when-configured",
              "mock": false,
              "forced_loopback": false,
              "loopback_isolation": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false,
              "mesh_fenced_to_loopback": false,
              "public_egress_ip": false,
              "residential": false,
              "cf_geo_exit": false,
              "cf_geo_exit_pool": false,
              "sticky_public_ip": false,
              "packet_forward": false,
              "packet_forwarding": false,
              "public_icann": false,
              "cap7_is_icann": false,
              "replaces_internet": false,
              "not_a_second_internet": true,
              "hosted_vpn": false,
              "payload_host": false,
              "vpn_hop": false,
              "wireguard": false,
              "openvpn": false,
              "l3_exit": false,
              "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
            },
            "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
          },
          "fanout": "cron-or-request-path",
          "live_nodes_plane": "human-mesh-users-site-viewers",
          "nodes_plane": "human-mesh-users-uses",
          "software_nodes_plane": "software-worker-fanout",
          "site_live_viewers_plane": "hub-human-page-presence",
          "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
          "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
          "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
          "site_presence_contract": {
            "method": "POST",
            "path": "/runtime/v1/mesh/site-presence",
            "alias": "/runtime/v1/mesh/site-heartbeat",
            "fraggate": {
              "slug": "mesh",
              "op": "site-presence"
            },
            "body": {
              "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
              "viewers": "non-negative integer concurrent human page sessions (0..10000)",
              "kind": "human-page"
            },
            "ttl_ms": 900000,
            "registered_grace_ms": 1209600000,
            "default_heartbeat_mode": "idle",
            "heartbeat_mode": "active | idle | asleep",
            "stale_keeps_registered": true,
            "stale_counts_as_live": false,
            "allowed_hosts": [
              "godlock.uk",
              "azieleliab.com",
              "azielcorpuslibrary.net"
            ],
            "excluded_hosts": [
              "hedidntjump.com"
            ],
            "refused_kinds": [
              "bot",
              "bots",
              "crawler",
              "software",
              "softwares",
              "download",
              "downloads",
              "instance",
              "mcp"
            ],
            "pull_hub_count": false,
            "invent": false,
            "fail_closed": true,
            "read": "single-key",
            "paint": "live_nodes",
            "local_recompute": false,
            "radios": "not required — hub ingest, not a TX join",
            "rate_kind": "mesh_mutate",
            "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
          },
          "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
          "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
          "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "ban_survival": "BAN-SURVIVAL-1.0",
          "spore_spec": "SPORE-1.0",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/runtime/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "neighbor_heal_is_cite": true,
              "neighbor_heal_exec": false,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "neighbor_heal_is_cite": true,
          "neighbor_heal_exec": false,
          "join_is_presence_only": true,
          "join_is_not_login": true,
          "roster_publishes_exec_urls": false,
          "mesh_mutate_rate_kind": "mesh_mutate",
          "roster_cap": 256,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "d2d_carriers": {
            "spec": "D2D-CARRIERS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "plane": "track2-reachability",
            "phase": "B+C+D",
            "phases": {
              "A": "landed",
              "B": "LIVE-when-armed",
              "C": "LIVE-when-session",
              "D": "LIVE-when-three-local-nodes / fixture",
              "E": "scaffold"
            },
            "lan_discovery": "LIVE-when-armed",
            "wifi_discovery": "ARMED-when-HW",
            "bluetooth_discovery": "ARMED-when-HW",
            "rf_discovery": "REFUSE-without-HW",
            "photon_discovery": "REFUSE-without-HW",
            "peer_tunnel": "LIVE-when-session",
            "store_forward": "LIVE-when-three-local-nodes / fixture",
            "store_forward_public": "FG-STUB",
            "worker_runs_store_forward": false,
            "second_device": false,
            "mobile_client": "present-not-demonstrated",
            "mobile_demonstrated": false,
            "app_store_release": false,
            "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
            "bootstrap_list": "scaffold",
            "needs_starting_address": true,
            "shelf_cite": "scaffold",
            "live_multi_provider": false,
            "cold_shelf_live": false,
            "dns_cut": false,
            "origin_cutover": false,
            "warn5_closed": false,
            "worker_door": "FG-STUB",
            "worker_hardware": false,
            "local_node": "qnm-node",
            "get_never_enables": true,
            "separate_from": "cap7-name",
            "cap7_is_name_plane": true,
            "cap7_public_icann": false,
            "cap7_public_egress": false,
            "mirage_is_azvpn": false,
            "aznet_replaces_internet": false,
            "not_a_second_internet": true,
            "alt_internet_live": false,
            "packet_path_live": false,
            "field_1_0": false,
            "warn5": "STANDS-until-demonstrated",
            "warn5_permanent_stay_off": false,
            "preference": "failover",
            "order": [
              "lan",
              "wifi",
              "bluetooth",
              "rf",
              "photon"
            ],
            "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
            "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
            "status": "NOT-READY",
            "code": "FG-STUB",
            "warn5_until": "demonstrated",
            "warn5_by_design": "separate-from-icann",
            "refuse": {
              "packet": "FG-STUB",
              "radio_absent": "QNM-RADIO-ABSENT",
              "cap7_egress": "MG-NO-IP-EXIT",
              "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
              "bearer": "AZP-BEARER-REFUSE",
              "payload": "AZN-NO-PAYLOAD",
              "route": "MESH-NO-ROUTE",
              "stay_off": "MESH-STAY-OFF",
              "nat": "FED-MESH-NAT-REFUSE"
            },
            "carriers": [
              {
                "order": 1,
                "id": "lan",
                "name": "LAN",
                "op": "d2d_lan",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "lan-interface",
                "discovery": "LIVE-when-armed",
                "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
              },
              {
                "order": 2,
                "id": "wifi",
                "name": "Wi-Fi",
                "op": "d2d_wifi",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "wifi-nm",
                "discovery": "ARMED-when-HW",
                "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
              },
              {
                "order": 3,
                "id": "bluetooth",
                "name": "Bluetooth",
                "op": "d2d_bluetooth",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "bluez",
                "discovery": "ARMED-when-HW",
                "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
              },
              {
                "order": 4,
                "id": "rf",
                "name": "RF",
                "op": "d2d_rf",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "rf-beyond-wifi-bt",
                "discovery": "REFUSE-without-HW",
                "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
              },
              {
                "order": 5,
                "id": "photon",
                "name": "Photon",
                "op": "d2d_photon",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "camera-flash",
                "discovery": "REFUSE-without-HW",
                "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
              }
            ],
            "security": {
              "isolation": "single-node security-awareness",
              "phoenix": "local wait / re-seal",
              "mesh_fenced_to_loopback": false,
              "forced_loopback": false,
              "loopback_isolation": false
            },
            "paper": "docs/designs/D2D-CARRIERS-1.0.md",
            "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
          },
          "d2d_status": "NOT-READY",
          "d2d_code": "FG-STUB",
          "packet_path_live": false,
          "alt_internet_live": false,
          "d2d_spec": "D2D-CARRIERS-1.0",
          "federated_mesh": "FED-MESH-1.0",
          "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
          "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        },
        "peers": [
          {
            "slug": "azclce",
            "name": "AZ-CLCE",
            "role": "peer-scorer",
            "kind": "software",
            "domain": "Language",
            "domain_id": "04",
            "worker_url": "https://azclce-download-tracker.vibelock.workers.dev/",
            "github": "https://github.com/AzielEliab/az-clce",
            "note": "Separate product. Detects R/D/P inconsistency. AZCoherence reviews primary vs alternate. Not a replacement."
          },
          {
            "slug": "azinterface",
            "name": "AZInterface",
            "role": "human-ui",
            "kind": "software",
            "placement": "human-ui",
            "domain": null,
            "domain_id": null,
            "worker_url": "https://azinterface-download-tracker.vibelock.workers.dev/",
            "github": "https://github.com/AzielEliab/azinterface",
            "note": "AZInterface is the human UI before FragGate. Separate software. Same door. Not merged."
          }
        ],
        "fabric_neighbors": [
          {
            "slug": "memory",
            "name": "AKM-TRIAD",
            "spec": "AKM-TRIAD-1.0",
            "role": "fabric-neighbor",
            "kind": "fabric",
            "domain": null,
            "domain_id": null,
            "note": "Not merged. Memory stays fabric, not Softwares. Posterior ≠ truth. AZCoherence is not AKM-TRIAD."
          }
        ],
        "hubs": [
          "https://azieleliab.com",
          "https://www.azielcorpuslibrary.net",
          "https://godlock.uk"
        ],
        "worker_url": "https://azcoherence-download-tracker.vibelock.workers.dev/",
        "cross_map": {
          "slug": "azcoherence",
          "name": "AZCoherence",
          "spec": "AZC-0.1",
          "placement": "scoring-review",
          "domain": null,
          "domain_id": null,
          "domain_note": "Leave domain null — same pattern as decisiongate/forgereceipts. Scoring-review is a placement, not a 34th isolation software. Domains are isolation labels, not doors. FragGate remains THE single door.",
          "worker_url": "https://azcoherence-download-tracker.vibelock.workers.dev/",
          "github": "https://github.com/AzielEliab/AZCoherence",
          "hubs": [
            "https://azieleliab.com",
            "https://www.azielcorpuslibrary.net",
            "https://godlock.uk"
          ],
          "peers": [
            {
              "slug": "azclce",
              "name": "AZ-CLCE",
              "role": "peer-scorer",
              "kind": "software",
              "domain": "Language",
              "domain_id": "04",
              "worker_url": "https://azclce-download-tracker.vibelock.workers.dev/",
              "github": "https://github.com/AzielEliab/az-clce",
              "note": "Separate product. Detects R/D/P inconsistency. AZCoherence reviews primary vs alternate. Not a replacement."
            },
            {
              "slug": "azinterface",
              "name": "AZInterface",
              "role": "human-ui",
              "kind": "software",
              "placement": "human-ui",
              "domain": null,
              "domain_id": null,
              "worker_url": "https://azinterface-download-tracker.vibelock.workers.dev/",
              "github": "https://github.com/AzielEliab/azinterface",
              "note": "AZInterface is the human UI before FragGate. Separate software. Same door. Not merged."
            }
          ],
          "fabric_neighbors": [
            {
              "slug": "memory",
              "name": "AKM-TRIAD",
              "spec": "AKM-TRIAD-1.0",
              "role": "fabric-neighbor",
              "kind": "fabric",
              "domain": null,
              "domain_id": null,
              "note": "Not merged. Memory stays fabric, not Softwares. Posterior ≠ truth. AZCoherence is not AKM-TRIAD."
            }
          ],
          "merged": false,
          "extra_door": false
        }
      },
      {
        "slug": "azhub",
        "name": "AZHub",
        "bucket": "plain",
        "domain": "AI",
        "domain_id": "05",
        "placement": "domain-software",
        "status": "live",
        "fraggate_status": "live",
        "public_door": true,
        "public_door_ops": [
          "health",
          "skill",
          "region_list",
          "place_module",
          "remove_module",
          "tether_declare",
          "tether_cut",
          "tether_list",
          "blank_key_status",
          "list_modules",
          "place"
        ],
        "stub_ops": [
          "scorch_remote",
          "auto_unlock",
          "ranking",
          "completeness_detect",
          "unlock",
          "complete",
          "completeness",
          "rank",
          "scorch"
        ],
        "door_label": "live FragGate door — named stub ops refuse",
        "open_live_door": true,
        "version": "0.1.0",
        "one_line": "Place and tether modules in a blank spatial container.",
        "description": "Use AZHub to put modules in regions and declare links. It exists as a neutral container so placement stays placement.",
        "worker_home": "https://azhub-download-tracker.vibelock.workers.dev/",
        "worker_home_note": null,
        "download_url": "https://azhub-download-tracker.vibelock.workers.dev/download",
        "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "github": "https://github.com/AzielEliab/azhub",
        "mcp": "https://godlock.uk/runtime/mcp",
        "agent": {
          "mcp": "https://godlock.uk/runtime/mcp",
          "skill": "https://godlock.uk/runtime/v1/skill",
          "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
          "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=azhub",
          "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
          "fraggate_call_executes": true,
          "open_live_door": true,
          "software": "https://godlock.uk/runtime/v1/software",
          "pull": "https://godlock.uk/runtime/v1/pull/azhub",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "dc8848353c0db397b9b0503446ad8dcb14212162776b24278071559bd2e83d81",
        "updated_at": null,
        "git_sha": null,
        "git_sha_tracks_deployed_tip": false,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/runtime/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "security": {
            "model": "single-node-security-awareness",
            "isolates": "bad-peer-or-self",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "phoenix": "local-wait-reseal",
            "phoenix_lock": true,
            "public_hostname_resurrection": false,
            "loopback_bearer": "L1-optional",
            "operator_locks": [
              {
                "n": 1,
                "id": "single-node-security-awareness",
                "status": "LIVE",
                "mesh_fenced_to_loopback": false
              },
              {
                "n": 2,
                "id": "phoenix-reboot-loop",
                "status": "LIVE",
                "phoenix": "local-wait-reseal",
                "phoenix_lock": true,
                "public_hostname_resurrection": false
              },
              {
                "n": 3,
                "id": "open-world-awareness",
                "status": "live-when-configured",
                "law": "LIVE",
                "bind": "0.0.0.0",
                "worker_socket": false,
                "forced_loopback_is_mesh_fence": false,
                "loopback_isolation_is_mesh_fence": false
              }
            ],
            "open_world_awareness": {
              "spec": "OPEN-WORLD-AWARENESS-1.0",
              "author": "Aziel Eliab",
              "identity": "Aziel Eliab",
              "open_world_awareness": true,
              "bind": "0.0.0.0",
              "all_interfaces": true,
              "law": "LIVE",
              "status": "live-when-configured",
              "live": false,
              "socket": "live-when-configured",
              "worker_socket": false,
              "qnm_node_bind": "live-when-configured",
              "mock": false,
              "forced_loopback": false,
              "loopback_isolation": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false,
              "mesh_fenced_to_loopback": false,
              "public_egress_ip": false,
              "residential": false,
              "cf_geo_exit": false,
              "cf_geo_exit_pool": false,
              "sticky_public_ip": false,
              "packet_forward": false,
              "packet_forwarding": false,
              "public_icann": false,
              "cap7_is_icann": false,
              "replaces_internet": false,
              "not_a_second_internet": true,
              "hosted_vpn": false,
              "payload_host": false,
              "vpn_hop": false,
              "wireguard": false,
              "openvpn": false,
              "l3_exit": false,
              "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
            },
            "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
          },
          "fanout": "cron-or-request-path",
          "live_nodes_plane": "human-mesh-users-site-viewers",
          "nodes_plane": "human-mesh-users-uses",
          "software_nodes_plane": "software-worker-fanout",
          "site_live_viewers_plane": "hub-human-page-presence",
          "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
          "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
          "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
          "site_presence_contract": {
            "method": "POST",
            "path": "/runtime/v1/mesh/site-presence",
            "alias": "/runtime/v1/mesh/site-heartbeat",
            "fraggate": {
              "slug": "mesh",
              "op": "site-presence"
            },
            "body": {
              "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
              "viewers": "non-negative integer concurrent human page sessions (0..10000)",
              "kind": "human-page"
            },
            "ttl_ms": 900000,
            "registered_grace_ms": 1209600000,
            "default_heartbeat_mode": "idle",
            "heartbeat_mode": "active | idle | asleep",
            "stale_keeps_registered": true,
            "stale_counts_as_live": false,
            "allowed_hosts": [
              "godlock.uk",
              "azieleliab.com",
              "azielcorpuslibrary.net"
            ],
            "excluded_hosts": [
              "hedidntjump.com"
            ],
            "refused_kinds": [
              "bot",
              "bots",
              "crawler",
              "software",
              "softwares",
              "download",
              "downloads",
              "instance",
              "mcp"
            ],
            "pull_hub_count": false,
            "invent": false,
            "fail_closed": true,
            "read": "single-key",
            "paint": "live_nodes",
            "local_recompute": false,
            "radios": "not required — hub ingest, not a TX join",
            "rate_kind": "mesh_mutate",
            "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
          },
          "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
          "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
          "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "ban_survival": "BAN-SURVIVAL-1.0",
          "spore_spec": "SPORE-1.0",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/runtime/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "neighbor_heal_is_cite": true,
              "neighbor_heal_exec": false,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "neighbor_heal_is_cite": true,
          "neighbor_heal_exec": false,
          "join_is_presence_only": true,
          "join_is_not_login": true,
          "roster_publishes_exec_urls": false,
          "mesh_mutate_rate_kind": "mesh_mutate",
          "roster_cap": 256,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "d2d_carriers": {
            "spec": "D2D-CARRIERS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "plane": "track2-reachability",
            "phase": "B+C+D",
            "phases": {
              "A": "landed",
              "B": "LIVE-when-armed",
              "C": "LIVE-when-session",
              "D": "LIVE-when-three-local-nodes / fixture",
              "E": "scaffold"
            },
            "lan_discovery": "LIVE-when-armed",
            "wifi_discovery": "ARMED-when-HW",
            "bluetooth_discovery": "ARMED-when-HW",
            "rf_discovery": "REFUSE-without-HW",
            "photon_discovery": "REFUSE-without-HW",
            "peer_tunnel": "LIVE-when-session",
            "store_forward": "LIVE-when-three-local-nodes / fixture",
            "store_forward_public": "FG-STUB",
            "worker_runs_store_forward": false,
            "second_device": false,
            "mobile_client": "present-not-demonstrated",
            "mobile_demonstrated": false,
            "app_store_release": false,
            "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
            "bootstrap_list": "scaffold",
            "needs_starting_address": true,
            "shelf_cite": "scaffold",
            "live_multi_provider": false,
            "cold_shelf_live": false,
            "dns_cut": false,
            "origin_cutover": false,
            "warn5_closed": false,
            "worker_door": "FG-STUB",
            "worker_hardware": false,
            "local_node": "qnm-node",
            "get_never_enables": true,
            "separate_from": "cap7-name",
            "cap7_is_name_plane": true,
            "cap7_public_icann": false,
            "cap7_public_egress": false,
            "mirage_is_azvpn": false,
            "aznet_replaces_internet": false,
            "not_a_second_internet": true,
            "alt_internet_live": false,
            "packet_path_live": false,
            "field_1_0": false,
            "warn5": "STANDS-until-demonstrated",
            "warn5_permanent_stay_off": false,
            "preference": "failover",
            "order": [
              "lan",
              "wifi",
              "bluetooth",
              "rf",
              "photon"
            ],
            "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
            "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
            "status": "NOT-READY",
            "code": "FG-STUB",
            "warn5_until": "demonstrated",
            "warn5_by_design": "separate-from-icann",
            "refuse": {
              "packet": "FG-STUB",
              "radio_absent": "QNM-RADIO-ABSENT",
              "cap7_egress": "MG-NO-IP-EXIT",
              "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
              "bearer": "AZP-BEARER-REFUSE",
              "payload": "AZN-NO-PAYLOAD",
              "route": "MESH-NO-ROUTE",
              "stay_off": "MESH-STAY-OFF",
              "nat": "FED-MESH-NAT-REFUSE"
            },
            "carriers": [
              {
                "order": 1,
                "id": "lan",
                "name": "LAN",
                "op": "d2d_lan",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "lan-interface",
                "discovery": "LIVE-when-armed",
                "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
              },
              {
                "order": 2,
                "id": "wifi",
                "name": "Wi-Fi",
                "op": "d2d_wifi",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "wifi-nm",
                "discovery": "ARMED-when-HW",
                "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
              },
              {
                "order": 3,
                "id": "bluetooth",
                "name": "Bluetooth",
                "op": "d2d_bluetooth",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "bluez",
                "discovery": "ARMED-when-HW",
                "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
              },
              {
                "order": 4,
                "id": "rf",
                "name": "RF",
                "op": "d2d_rf",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "rf-beyond-wifi-bt",
                "discovery": "REFUSE-without-HW",
                "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
              },
              {
                "order": 5,
                "id": "photon",
                "name": "Photon",
                "op": "d2d_photon",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "camera-flash",
                "discovery": "REFUSE-without-HW",
                "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
              }
            ],
            "security": {
              "isolation": "single-node security-awareness",
              "phoenix": "local wait / re-seal",
              "mesh_fenced_to_loopback": false,
              "forced_loopback": false,
              "loopback_isolation": false
            },
            "paper": "docs/designs/D2D-CARRIERS-1.0.md",
            "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
          },
          "d2d_status": "NOT-READY",
          "d2d_code": "FG-STUB",
          "packet_path_live": false,
          "alt_internet_live": false,
          "d2d_spec": "D2D-CARRIERS-1.0",
          "federated_mesh": "FED-MESH-1.0",
          "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
          "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        }
      },
      {
        "slug": "aziel-corpus",
        "name": "Aziel Digital Library",
        "bucket": "plain",
        "domain": "Research",
        "domain_id": "06",
        "placement": "domain-software",
        "status": "live",
        "fraggate_status": "live",
        "public_door": true,
        "public_door_ops": [
          "search",
          "example",
          "skill",
          "health",
          "doctor",
          "review",
          "score",
          "verify-backfill",
          "verify-geo",
          "document-chain",
          "import_export",
          "jeeves",
          "media-run",
          "tip-pack"
        ],
        "stub_ops": [],
        "door_label": "live FragGate door",
        "open_live_door": true,
        "version": "2.6.2",
        "one_line": "Search the public library with Ask Jeeves suite help and download azcorpus + azlibrary designs.",
        "description": "Use the Aziel Digital Library to search the public MASTER and to ask Ask Jeeves on the corpus jeeves operation. It exists as a self-contained public library with that suite help assistant on this card.",
        "worker_home": "https://www.azielcorpuslibrary.net/",
        "worker_home_note": null,
        "download_url": "https://www.azielcorpuslibrary.net/download",
        "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "github": "https://github.com/AzielEliab/aziel-corpus",
        "mcp": "https://godlock.uk/runtime/mcp",
        "agent": {
          "mcp": "https://godlock.uk/runtime/mcp",
          "skill": "https://godlock.uk/runtime/v1/skill",
          "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
          "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=aziel-corpus",
          "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
          "fraggate_call_executes": true,
          "open_live_door": true,
          "software": "https://godlock.uk/runtime/v1/software",
          "pull": "https://godlock.uk/runtime/v1/pull/aziel-corpus",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "e122bae90a8426451861c11e39829f9ed000b0d0793a7e9260e6ee68c93c4ab8",
        "updated_at": null,
        "git_sha": null,
        "git_sha_tracks_deployed_tip": false,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/runtime/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "security": {
            "model": "single-node-security-awareness",
            "isolates": "bad-peer-or-self",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "phoenix": "local-wait-reseal",
            "phoenix_lock": true,
            "public_hostname_resurrection": false,
            "loopback_bearer": "L1-optional",
            "operator_locks": [
              {
                "n": 1,
                "id": "single-node-security-awareness",
                "status": "LIVE",
                "mesh_fenced_to_loopback": false
              },
              {
                "n": 2,
                "id": "phoenix-reboot-loop",
                "status": "LIVE",
                "phoenix": "local-wait-reseal",
                "phoenix_lock": true,
                "public_hostname_resurrection": false
              },
              {
                "n": 3,
                "id": "open-world-awareness",
                "status": "live-when-configured",
                "law": "LIVE",
                "bind": "0.0.0.0",
                "worker_socket": false,
                "forced_loopback_is_mesh_fence": false,
                "loopback_isolation_is_mesh_fence": false
              }
            ],
            "open_world_awareness": {
              "spec": "OPEN-WORLD-AWARENESS-1.0",
              "author": "Aziel Eliab",
              "identity": "Aziel Eliab",
              "open_world_awareness": true,
              "bind": "0.0.0.0",
              "all_interfaces": true,
              "law": "LIVE",
              "status": "live-when-configured",
              "live": false,
              "socket": "live-when-configured",
              "worker_socket": false,
              "qnm_node_bind": "live-when-configured",
              "mock": false,
              "forced_loopback": false,
              "loopback_isolation": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false,
              "mesh_fenced_to_loopback": false,
              "public_egress_ip": false,
              "residential": false,
              "cf_geo_exit": false,
              "cf_geo_exit_pool": false,
              "sticky_public_ip": false,
              "packet_forward": false,
              "packet_forwarding": false,
              "public_icann": false,
              "cap7_is_icann": false,
              "replaces_internet": false,
              "not_a_second_internet": true,
              "hosted_vpn": false,
              "payload_host": false,
              "vpn_hop": false,
              "wireguard": false,
              "openvpn": false,
              "l3_exit": false,
              "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
            },
            "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
          },
          "fanout": "cron-or-request-path",
          "live_nodes_plane": "human-mesh-users-site-viewers",
          "nodes_plane": "human-mesh-users-uses",
          "software_nodes_plane": "software-worker-fanout",
          "site_live_viewers_plane": "hub-human-page-presence",
          "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
          "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
          "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
          "site_presence_contract": {
            "method": "POST",
            "path": "/runtime/v1/mesh/site-presence",
            "alias": "/runtime/v1/mesh/site-heartbeat",
            "fraggate": {
              "slug": "mesh",
              "op": "site-presence"
            },
            "body": {
              "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
              "viewers": "non-negative integer concurrent human page sessions (0..10000)",
              "kind": "human-page"
            },
            "ttl_ms": 900000,
            "registered_grace_ms": 1209600000,
            "default_heartbeat_mode": "idle",
            "heartbeat_mode": "active | idle | asleep",
            "stale_keeps_registered": true,
            "stale_counts_as_live": false,
            "allowed_hosts": [
              "godlock.uk",
              "azieleliab.com",
              "azielcorpuslibrary.net"
            ],
            "excluded_hosts": [
              "hedidntjump.com"
            ],
            "refused_kinds": [
              "bot",
              "bots",
              "crawler",
              "software",
              "softwares",
              "download",
              "downloads",
              "instance",
              "mcp"
            ],
            "pull_hub_count": false,
            "invent": false,
            "fail_closed": true,
            "read": "single-key",
            "paint": "live_nodes",
            "local_recompute": false,
            "radios": "not required — hub ingest, not a TX join",
            "rate_kind": "mesh_mutate",
            "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
          },
          "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
          "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
          "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "ban_survival": "BAN-SURVIVAL-1.0",
          "spore_spec": "SPORE-1.0",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/runtime/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "neighbor_heal_is_cite": true,
              "neighbor_heal_exec": false,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "neighbor_heal_is_cite": true,
          "neighbor_heal_exec": false,
          "join_is_presence_only": true,
          "join_is_not_login": true,
          "roster_publishes_exec_urls": false,
          "mesh_mutate_rate_kind": "mesh_mutate",
          "roster_cap": 256,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "d2d_carriers": {
            "spec": "D2D-CARRIERS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "plane": "track2-reachability",
            "phase": "B+C+D",
            "phases": {
              "A": "landed",
              "B": "LIVE-when-armed",
              "C": "LIVE-when-session",
              "D": "LIVE-when-three-local-nodes / fixture",
              "E": "scaffold"
            },
            "lan_discovery": "LIVE-when-armed",
            "wifi_discovery": "ARMED-when-HW",
            "bluetooth_discovery": "ARMED-when-HW",
            "rf_discovery": "REFUSE-without-HW",
            "photon_discovery": "REFUSE-without-HW",
            "peer_tunnel": "LIVE-when-session",
            "store_forward": "LIVE-when-three-local-nodes / fixture",
            "store_forward_public": "FG-STUB",
            "worker_runs_store_forward": false,
            "second_device": false,
            "mobile_client": "present-not-demonstrated",
            "mobile_demonstrated": false,
            "app_store_release": false,
            "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
            "bootstrap_list": "scaffold",
            "needs_starting_address": true,
            "shelf_cite": "scaffold",
            "live_multi_provider": false,
            "cold_shelf_live": false,
            "dns_cut": false,
            "origin_cutover": false,
            "warn5_closed": false,
            "worker_door": "FG-STUB",
            "worker_hardware": false,
            "local_node": "qnm-node",
            "get_never_enables": true,
            "separate_from": "cap7-name",
            "cap7_is_name_plane": true,
            "cap7_public_icann": false,
            "cap7_public_egress": false,
            "mirage_is_azvpn": false,
            "aznet_replaces_internet": false,
            "not_a_second_internet": true,
            "alt_internet_live": false,
            "packet_path_live": false,
            "field_1_0": false,
            "warn5": "STANDS-until-demonstrated",
            "warn5_permanent_stay_off": false,
            "preference": "failover",
            "order": [
              "lan",
              "wifi",
              "bluetooth",
              "rf",
              "photon"
            ],
            "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
            "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
            "status": "NOT-READY",
            "code": "FG-STUB",
            "warn5_until": "demonstrated",
            "warn5_by_design": "separate-from-icann",
            "refuse": {
              "packet": "FG-STUB",
              "radio_absent": "QNM-RADIO-ABSENT",
              "cap7_egress": "MG-NO-IP-EXIT",
              "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
              "bearer": "AZP-BEARER-REFUSE",
              "payload": "AZN-NO-PAYLOAD",
              "route": "MESH-NO-ROUTE",
              "stay_off": "MESH-STAY-OFF",
              "nat": "FED-MESH-NAT-REFUSE"
            },
            "carriers": [
              {
                "order": 1,
                "id": "lan",
                "name": "LAN",
                "op": "d2d_lan",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "lan-interface",
                "discovery": "LIVE-when-armed",
                "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
              },
              {
                "order": 2,
                "id": "wifi",
                "name": "Wi-Fi",
                "op": "d2d_wifi",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "wifi-nm",
                "discovery": "ARMED-when-HW",
                "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
              },
              {
                "order": 3,
                "id": "bluetooth",
                "name": "Bluetooth",
                "op": "d2d_bluetooth",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "bluez",
                "discovery": "ARMED-when-HW",
                "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
              },
              {
                "order": 4,
                "id": "rf",
                "name": "RF",
                "op": "d2d_rf",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "rf-beyond-wifi-bt",
                "discovery": "REFUSE-without-HW",
                "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
              },
              {
                "order": 5,
                "id": "photon",
                "name": "Photon",
                "op": "d2d_photon",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "camera-flash",
                "discovery": "REFUSE-without-HW",
                "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
              }
            ],
            "security": {
              "isolation": "single-node security-awareness",
              "phoenix": "local wait / re-seal",
              "mesh_fenced_to_loopback": false,
              "forced_loopback": false,
              "loopback_isolation": false
            },
            "paper": "docs/designs/D2D-CARRIERS-1.0.md",
            "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
          },
          "d2d_status": "NOT-READY",
          "d2d_code": "FG-STUB",
          "packet_path_live": false,
          "alt_internet_live": false,
          "d2d_spec": "D2D-CARRIERS-1.0",
          "federated_mesh": "FED-MESH-1.0",
          "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
          "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        },
        "website_designs": [
          "azcorpus",
          "azlibrary"
        ],
        "website_designs_note": "azcorpus + azlibrary are mesh-resident website designs on this library hub. Downloadable to nodes. Not extra Softwares. azlibrary upload is API token only (never embed the secret). Download is open.",
        "website_designs_cards": [
          {
            "id": "azcorpus",
            "name": "azcorpus",
            "kind": "website_design",
            "mesh_resident": true,
            "downloadable_to_nodes": true,
            "software_tab": false,
            "fraggate_slug": false,
            "fifth_product": false,
            "hub_id": "library",
            "hub": "https://www.azielcorpuslibrary.net/",
            "download_open": true,
            "download_url": "https://www.azielcorpuslibrary.net/download",
            "github": "https://github.com/AzielEliab/aziel-corpus",
            "upload": false,
            "dual_surface": {
              "mcp": true,
              "openapi": true,
              "catalog": "https://godlock.uk/runtime/v1/software",
              "skill": "https://godlock.uk/runtime/v1/skill"
            },
            "note": "Mesh-resident website design downloadable to nodes. Not a Softwares-tab product. Not a FragGate slug.",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab"
          },
          {
            "id": "azlibrary",
            "name": "azlibrary",
            "kind": "website_design",
            "mesh_resident": true,
            "downloadable_to_nodes": true,
            "software_tab": false,
            "fraggate_slug": false,
            "fifth_product": false,
            "hub_id": "library",
            "hub": "https://www.azielcorpuslibrary.net/",
            "download_open": true,
            "download_url": "https://www.azielcorpuslibrary.net/download",
            "github": "https://github.com/AzielEliab/aziel-corpus",
            "upload": {
              "method": "api_token_only",
              "never_embed_secret": true,
              "token_in": "env / keychain / Authorization Bearer at call time",
              "not_in": [
                "catalog",
                "skill",
                "mcp_tool_schema",
                "openapi_example",
                "cite",
                "llms"
              ],
              "note": "azlibrary upload accepts an operator API token only. Catalog and skill name the rule. They never embed the secret."
            },
            "dual_surface": {
              "mcp": true,
              "openapi": true,
              "catalog": "https://godlock.uk/runtime/v1/software",
              "skill": "https://godlock.uk/runtime/v1/skill"
            },
            "note": "Mesh-resident website design downloadable to nodes. Upload is API token only. Never embed the secret. Not a Softwares-tab product. Not a FragGate slug.",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab"
          }
        ],
        "suite_help": {
          "name": "Ask Jeeves",
          "slug": "jeeves",
          "software_tab": false,
          "kind": "suite_help_assistant",
          "parent_slug": "aziel-corpus",
          "fraggate_slug": "aziel-corpus",
          "fraggate_op": "jeeves",
          "interface_call": "jeeves_help",
          "named_tool": true,
          "isolation_software": false
        }
      },
      {
        "slug": "azieltether",
        "name": "AzielTether",
        "bucket": "plain",
        "domain": "Network",
        "domain_id": "08",
        "placement": "domain-software",
        "status": "live",
        "fraggate_status": "live",
        "public_door": true,
        "public_door_ops": [
          "verify",
          "tip",
          "dual-chain",
          "reconcile",
          "pulse",
          "peer-preview",
          "health",
          "skill",
          "doctor"
        ],
        "stub_ops": [
          "mesh-join",
          "vpn",
          "arm"
        ],
        "door_label": "live FragGate door — named stub ops refuse",
        "open_live_door": true,
        "version": "0.1.0",
        "one_line": "Keep downloaded Aziel software in sync when the central Worker is up or down.",
        "description": "Use AzielTether so downloaded packages prefer the central Worker, peer-sync when it is down, and reconcile on restore. It exists so copies survive outages.",
        "worker_home": "https://azieltether-download-tracker.vibelock.workers.dev/",
        "worker_home_note": null,
        "download_url": "https://azieltether-download-tracker.vibelock.workers.dev/download",
        "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "github": "https://github.com/AzielEliab/azieltether",
        "mcp": "https://godlock.uk/runtime/mcp",
        "agent": {
          "mcp": "https://godlock.uk/runtime/mcp",
          "skill": "https://godlock.uk/runtime/v1/skill",
          "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
          "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=azieltether",
          "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
          "fraggate_call_executes": true,
          "open_live_door": true,
          "software": "https://godlock.uk/runtime/v1/software",
          "pull": "https://godlock.uk/runtime/v1/pull/azieltether",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "adb57573ee23e7c97567fc05f916f1fd65f2265128bd9ec3d1dca08e47c2d791",
        "updated_at": null,
        "git_sha": null,
        "git_sha_tracks_deployed_tip": false,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/runtime/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "security": {
            "model": "single-node-security-awareness",
            "isolates": "bad-peer-or-self",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "phoenix": "local-wait-reseal",
            "phoenix_lock": true,
            "public_hostname_resurrection": false,
            "loopback_bearer": "L1-optional",
            "operator_locks": [
              {
                "n": 1,
                "id": "single-node-security-awareness",
                "status": "LIVE",
                "mesh_fenced_to_loopback": false
              },
              {
                "n": 2,
                "id": "phoenix-reboot-loop",
                "status": "LIVE",
                "phoenix": "local-wait-reseal",
                "phoenix_lock": true,
                "public_hostname_resurrection": false
              },
              {
                "n": 3,
                "id": "open-world-awareness",
                "status": "live-when-configured",
                "law": "LIVE",
                "bind": "0.0.0.0",
                "worker_socket": false,
                "forced_loopback_is_mesh_fence": false,
                "loopback_isolation_is_mesh_fence": false
              }
            ],
            "open_world_awareness": {
              "spec": "OPEN-WORLD-AWARENESS-1.0",
              "author": "Aziel Eliab",
              "identity": "Aziel Eliab",
              "open_world_awareness": true,
              "bind": "0.0.0.0",
              "all_interfaces": true,
              "law": "LIVE",
              "status": "live-when-configured",
              "live": false,
              "socket": "live-when-configured",
              "worker_socket": false,
              "qnm_node_bind": "live-when-configured",
              "mock": false,
              "forced_loopback": false,
              "loopback_isolation": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false,
              "mesh_fenced_to_loopback": false,
              "public_egress_ip": false,
              "residential": false,
              "cf_geo_exit": false,
              "cf_geo_exit_pool": false,
              "sticky_public_ip": false,
              "packet_forward": false,
              "packet_forwarding": false,
              "public_icann": false,
              "cap7_is_icann": false,
              "replaces_internet": false,
              "not_a_second_internet": true,
              "hosted_vpn": false,
              "payload_host": false,
              "vpn_hop": false,
              "wireguard": false,
              "openvpn": false,
              "l3_exit": false,
              "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
            },
            "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
          },
          "fanout": "cron-or-request-path",
          "live_nodes_plane": "human-mesh-users-site-viewers",
          "nodes_plane": "human-mesh-users-uses",
          "software_nodes_plane": "software-worker-fanout",
          "site_live_viewers_plane": "hub-human-page-presence",
          "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
          "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
          "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
          "site_presence_contract": {
            "method": "POST",
            "path": "/runtime/v1/mesh/site-presence",
            "alias": "/runtime/v1/mesh/site-heartbeat",
            "fraggate": {
              "slug": "mesh",
              "op": "site-presence"
            },
            "body": {
              "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
              "viewers": "non-negative integer concurrent human page sessions (0..10000)",
              "kind": "human-page"
            },
            "ttl_ms": 900000,
            "registered_grace_ms": 1209600000,
            "default_heartbeat_mode": "idle",
            "heartbeat_mode": "active | idle | asleep",
            "stale_keeps_registered": true,
            "stale_counts_as_live": false,
            "allowed_hosts": [
              "godlock.uk",
              "azieleliab.com",
              "azielcorpuslibrary.net"
            ],
            "excluded_hosts": [
              "hedidntjump.com"
            ],
            "refused_kinds": [
              "bot",
              "bots",
              "crawler",
              "software",
              "softwares",
              "download",
              "downloads",
              "instance",
              "mcp"
            ],
            "pull_hub_count": false,
            "invent": false,
            "fail_closed": true,
            "read": "single-key",
            "paint": "live_nodes",
            "local_recompute": false,
            "radios": "not required — hub ingest, not a TX join",
            "rate_kind": "mesh_mutate",
            "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
          },
          "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
          "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
          "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "ban_survival": "BAN-SURVIVAL-1.0",
          "spore_spec": "SPORE-1.0",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/runtime/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "neighbor_heal_is_cite": true,
              "neighbor_heal_exec": false,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "neighbor_heal_is_cite": true,
          "neighbor_heal_exec": false,
          "join_is_presence_only": true,
          "join_is_not_login": true,
          "roster_publishes_exec_urls": false,
          "mesh_mutate_rate_kind": "mesh_mutate",
          "roster_cap": 256,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "d2d_carriers": {
            "spec": "D2D-CARRIERS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "plane": "track2-reachability",
            "phase": "B+C+D",
            "phases": {
              "A": "landed",
              "B": "LIVE-when-armed",
              "C": "LIVE-when-session",
              "D": "LIVE-when-three-local-nodes / fixture",
              "E": "scaffold"
            },
            "lan_discovery": "LIVE-when-armed",
            "wifi_discovery": "ARMED-when-HW",
            "bluetooth_discovery": "ARMED-when-HW",
            "rf_discovery": "REFUSE-without-HW",
            "photon_discovery": "REFUSE-without-HW",
            "peer_tunnel": "LIVE-when-session",
            "store_forward": "LIVE-when-three-local-nodes / fixture",
            "store_forward_public": "FG-STUB",
            "worker_runs_store_forward": false,
            "second_device": false,
            "mobile_client": "present-not-demonstrated",
            "mobile_demonstrated": false,
            "app_store_release": false,
            "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
            "bootstrap_list": "scaffold",
            "needs_starting_address": true,
            "shelf_cite": "scaffold",
            "live_multi_provider": false,
            "cold_shelf_live": false,
            "dns_cut": false,
            "origin_cutover": false,
            "warn5_closed": false,
            "worker_door": "FG-STUB",
            "worker_hardware": false,
            "local_node": "qnm-node",
            "get_never_enables": true,
            "separate_from": "cap7-name",
            "cap7_is_name_plane": true,
            "cap7_public_icann": false,
            "cap7_public_egress": false,
            "mirage_is_azvpn": false,
            "aznet_replaces_internet": false,
            "not_a_second_internet": true,
            "alt_internet_live": false,
            "packet_path_live": false,
            "field_1_0": false,
            "warn5": "STANDS-until-demonstrated",
            "warn5_permanent_stay_off": false,
            "preference": "failover",
            "order": [
              "lan",
              "wifi",
              "bluetooth",
              "rf",
              "photon"
            ],
            "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
            "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
            "status": "NOT-READY",
            "code": "FG-STUB",
            "warn5_until": "demonstrated",
            "warn5_by_design": "separate-from-icann",
            "refuse": {
              "packet": "FG-STUB",
              "radio_absent": "QNM-RADIO-ABSENT",
              "cap7_egress": "MG-NO-IP-EXIT",
              "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
              "bearer": "AZP-BEARER-REFUSE",
              "payload": "AZN-NO-PAYLOAD",
              "route": "MESH-NO-ROUTE",
              "stay_off": "MESH-STAY-OFF",
              "nat": "FED-MESH-NAT-REFUSE"
            },
            "carriers": [
              {
                "order": 1,
                "id": "lan",
                "name": "LAN",
                "op": "d2d_lan",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "lan-interface",
                "discovery": "LIVE-when-armed",
                "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
              },
              {
                "order": 2,
                "id": "wifi",
                "name": "Wi-Fi",
                "op": "d2d_wifi",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "wifi-nm",
                "discovery": "ARMED-when-HW",
                "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
              },
              {
                "order": 3,
                "id": "bluetooth",
                "name": "Bluetooth",
                "op": "d2d_bluetooth",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "bluez",
                "discovery": "ARMED-when-HW",
                "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
              },
              {
                "order": 4,
                "id": "rf",
                "name": "RF",
                "op": "d2d_rf",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "rf-beyond-wifi-bt",
                "discovery": "REFUSE-without-HW",
                "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
              },
              {
                "order": 5,
                "id": "photon",
                "name": "Photon",
                "op": "d2d_photon",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "camera-flash",
                "discovery": "REFUSE-without-HW",
                "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
              }
            ],
            "security": {
              "isolation": "single-node security-awareness",
              "phoenix": "local wait / re-seal",
              "mesh_fenced_to_loopback": false,
              "forced_loopback": false,
              "loopback_isolation": false
            },
            "paper": "docs/designs/D2D-CARRIERS-1.0.md",
            "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
          },
          "d2d_status": "NOT-READY",
          "d2d_code": "FG-STUB",
          "packet_path_live": false,
          "alt_internet_live": false,
          "d2d_spec": "D2D-CARRIERS-1.0",
          "federated_mesh": "FED-MESH-1.0",
          "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
          "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        }
      },
      {
        "slug": "azinterface",
        "name": "AZInterface",
        "bucket": "plain",
        "domain": null,
        "domain_id": null,
        "placement": "human-ui",
        "status": "live",
        "fraggate_status": "live",
        "public_door": true,
        "public_door_ops": [
          "health",
          "skill",
          "genesis_status",
          "site_state_get",
          "site_state_set",
          "integrity_check",
          "witness_list",
          "page_cycle_status",
          "mesh_radios",
          "genesis_boot",
          "hold"
        ],
        "stub_ops": [
          "scorch_remote",
          "auto_unlock",
          "ranking",
          "completeness_detect",
          "unlock",
          "complete",
          "completeness",
          "rank",
          "scorch",
          "skip_cycle",
          "invent_cycle"
        ],
        "door_label": "live FragGate door — named stub ops refuse",
        "open_live_door": true,
        "version": "0.1.0",
        "one_line": "Open the Softwares suite shell and step pre-locked page cycles.",
        "description": "Use AZInterface as the suite shell that opens Softwares that can run on this computer, and to read and step site state through OFF, integrity, ON, FULL SHUTDOWN, and MEMORIAL. It exists so the desk and those page cycles stay in one custodial shell.",
        "worker_home": "https://azinterface-download-tracker.vibelock.workers.dev/",
        "worker_home_note": null,
        "download_url": "https://azinterface-download-tracker.vibelock.workers.dev/download",
        "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "github": "https://github.com/AzielEliab/azinterface",
        "mcp": "https://godlock.uk/runtime/mcp",
        "agent": {
          "mcp": "https://godlock.uk/runtime/mcp",
          "skill": "https://godlock.uk/runtime/v1/skill",
          "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
          "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=azinterface",
          "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
          "fraggate_call_executes": true,
          "open_live_door": true,
          "software": "https://godlock.uk/runtime/v1/software",
          "pull": "https://godlock.uk/runtime/v1/pull/azinterface",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "7418c2bbf3c8fe4921f05f0e9f1aed2d2486f983d8feba985fe462018794972c",
        "updated_at": null,
        "git_sha": null,
        "git_sha_tracks_deployed_tip": false,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/runtime/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "security": {
            "model": "single-node-security-awareness",
            "isolates": "bad-peer-or-self",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "phoenix": "local-wait-reseal",
            "phoenix_lock": true,
            "public_hostname_resurrection": false,
            "loopback_bearer": "L1-optional",
            "operator_locks": [
              {
                "n": 1,
                "id": "single-node-security-awareness",
                "status": "LIVE",
                "mesh_fenced_to_loopback": false
              },
              {
                "n": 2,
                "id": "phoenix-reboot-loop",
                "status": "LIVE",
                "phoenix": "local-wait-reseal",
                "phoenix_lock": true,
                "public_hostname_resurrection": false
              },
              {
                "n": 3,
                "id": "open-world-awareness",
                "status": "live-when-configured",
                "law": "LIVE",
                "bind": "0.0.0.0",
                "worker_socket": false,
                "forced_loopback_is_mesh_fence": false,
                "loopback_isolation_is_mesh_fence": false
              }
            ],
            "open_world_awareness": {
              "spec": "OPEN-WORLD-AWARENESS-1.0",
              "author": "Aziel Eliab",
              "identity": "Aziel Eliab",
              "open_world_awareness": true,
              "bind": "0.0.0.0",
              "all_interfaces": true,
              "law": "LIVE",
              "status": "live-when-configured",
              "live": false,
              "socket": "live-when-configured",
              "worker_socket": false,
              "qnm_node_bind": "live-when-configured",
              "mock": false,
              "forced_loopback": false,
              "loopback_isolation": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false,
              "mesh_fenced_to_loopback": false,
              "public_egress_ip": false,
              "residential": false,
              "cf_geo_exit": false,
              "cf_geo_exit_pool": false,
              "sticky_public_ip": false,
              "packet_forward": false,
              "packet_forwarding": false,
              "public_icann": false,
              "cap7_is_icann": false,
              "replaces_internet": false,
              "not_a_second_internet": true,
              "hosted_vpn": false,
              "payload_host": false,
              "vpn_hop": false,
              "wireguard": false,
              "openvpn": false,
              "l3_exit": false,
              "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
            },
            "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
          },
          "fanout": "cron-or-request-path",
          "live_nodes_plane": "human-mesh-users-site-viewers",
          "nodes_plane": "human-mesh-users-uses",
          "software_nodes_plane": "software-worker-fanout",
          "site_live_viewers_plane": "hub-human-page-presence",
          "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
          "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
          "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
          "site_presence_contract": {
            "method": "POST",
            "path": "/runtime/v1/mesh/site-presence",
            "alias": "/runtime/v1/mesh/site-heartbeat",
            "fraggate": {
              "slug": "mesh",
              "op": "site-presence"
            },
            "body": {
              "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
              "viewers": "non-negative integer concurrent human page sessions (0..10000)",
              "kind": "human-page"
            },
            "ttl_ms": 900000,
            "registered_grace_ms": 1209600000,
            "default_heartbeat_mode": "idle",
            "heartbeat_mode": "active | idle | asleep",
            "stale_keeps_registered": true,
            "stale_counts_as_live": false,
            "allowed_hosts": [
              "godlock.uk",
              "azieleliab.com",
              "azielcorpuslibrary.net"
            ],
            "excluded_hosts": [
              "hedidntjump.com"
            ],
            "refused_kinds": [
              "bot",
              "bots",
              "crawler",
              "software",
              "softwares",
              "download",
              "downloads",
              "instance",
              "mcp"
            ],
            "pull_hub_count": false,
            "invent": false,
            "fail_closed": true,
            "read": "single-key",
            "paint": "live_nodes",
            "local_recompute": false,
            "radios": "not required — hub ingest, not a TX join",
            "rate_kind": "mesh_mutate",
            "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
          },
          "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
          "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
          "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "ban_survival": "BAN-SURVIVAL-1.0",
          "spore_spec": "SPORE-1.0",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/runtime/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "neighbor_heal_is_cite": true,
              "neighbor_heal_exec": false,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "neighbor_heal_is_cite": true,
          "neighbor_heal_exec": false,
          "join_is_presence_only": true,
          "join_is_not_login": true,
          "roster_publishes_exec_urls": false,
          "mesh_mutate_rate_kind": "mesh_mutate",
          "roster_cap": 256,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "d2d_carriers": {
            "spec": "D2D-CARRIERS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "plane": "track2-reachability",
            "phase": "B+C+D",
            "phases": {
              "A": "landed",
              "B": "LIVE-when-armed",
              "C": "LIVE-when-session",
              "D": "LIVE-when-three-local-nodes / fixture",
              "E": "scaffold"
            },
            "lan_discovery": "LIVE-when-armed",
            "wifi_discovery": "ARMED-when-HW",
            "bluetooth_discovery": "ARMED-when-HW",
            "rf_discovery": "REFUSE-without-HW",
            "photon_discovery": "REFUSE-without-HW",
            "peer_tunnel": "LIVE-when-session",
            "store_forward": "LIVE-when-three-local-nodes / fixture",
            "store_forward_public": "FG-STUB",
            "worker_runs_store_forward": false,
            "second_device": false,
            "mobile_client": "present-not-demonstrated",
            "mobile_demonstrated": false,
            "app_store_release": false,
            "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
            "bootstrap_list": "scaffold",
            "needs_starting_address": true,
            "shelf_cite": "scaffold",
            "live_multi_provider": false,
            "cold_shelf_live": false,
            "dns_cut": false,
            "origin_cutover": false,
            "warn5_closed": false,
            "worker_door": "FG-STUB",
            "worker_hardware": false,
            "local_node": "qnm-node",
            "get_never_enables": true,
            "separate_from": "cap7-name",
            "cap7_is_name_plane": true,
            "cap7_public_icann": false,
            "cap7_public_egress": false,
            "mirage_is_azvpn": false,
            "aznet_replaces_internet": false,
            "not_a_second_internet": true,
            "alt_internet_live": false,
            "packet_path_live": false,
            "field_1_0": false,
            "warn5": "STANDS-until-demonstrated",
            "warn5_permanent_stay_off": false,
            "preference": "failover",
            "order": [
              "lan",
              "wifi",
              "bluetooth",
              "rf",
              "photon"
            ],
            "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
            "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
            "status": "NOT-READY",
            "code": "FG-STUB",
            "warn5_until": "demonstrated",
            "warn5_by_design": "separate-from-icann",
            "refuse": {
              "packet": "FG-STUB",
              "radio_absent": "QNM-RADIO-ABSENT",
              "cap7_egress": "MG-NO-IP-EXIT",
              "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
              "bearer": "AZP-BEARER-REFUSE",
              "payload": "AZN-NO-PAYLOAD",
              "route": "MESH-NO-ROUTE",
              "stay_off": "MESH-STAY-OFF",
              "nat": "FED-MESH-NAT-REFUSE"
            },
            "carriers": [
              {
                "order": 1,
                "id": "lan",
                "name": "LAN",
                "op": "d2d_lan",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "lan-interface",
                "discovery": "LIVE-when-armed",
                "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
              },
              {
                "order": 2,
                "id": "wifi",
                "name": "Wi-Fi",
                "op": "d2d_wifi",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "wifi-nm",
                "discovery": "ARMED-when-HW",
                "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
              },
              {
                "order": 3,
                "id": "bluetooth",
                "name": "Bluetooth",
                "op": "d2d_bluetooth",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "bluez",
                "discovery": "ARMED-when-HW",
                "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
              },
              {
                "order": 4,
                "id": "rf",
                "name": "RF",
                "op": "d2d_rf",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "rf-beyond-wifi-bt",
                "discovery": "REFUSE-without-HW",
                "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
              },
              {
                "order": 5,
                "id": "photon",
                "name": "Photon",
                "op": "d2d_photon",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "camera-flash",
                "discovery": "REFUSE-without-HW",
                "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
              }
            ],
            "security": {
              "isolation": "single-node security-awareness",
              "phoenix": "local wait / re-seal",
              "mesh_fenced_to_loopback": false,
              "forced_loopback": false,
              "loopback_isolation": false
            },
            "paper": "docs/designs/D2D-CARRIERS-1.0.md",
            "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
          },
          "d2d_status": "NOT-READY",
          "d2d_code": "FG-STUB",
          "packet_path_live": false,
          "alt_internet_live": false,
          "d2d_spec": "D2D-CARRIERS-1.0",
          "federated_mesh": "FED-MESH-1.0",
          "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
          "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        }
      },
      {
        "slug": "azmail",
        "name": "AZMail",
        "bucket": "plain",
        "domain": "Comms",
        "domain_id": "07",
        "placement": "domain-software",
        "status": "live",
        "fraggate_status": "live",
        "public_door": true,
        "public_door_ops": [
          "airlock_classify",
          "scrub",
          "trust_score",
          "mesh_post",
          "mesh_poll",
          "mesh_listen",
          "mesh_enable",
          "mesh_disable",
          "keyword_alert_set",
          "keyword_alert_list",
          "keyword_alert_check",
          "mailbox_open",
          "notice_post",
          "mail_post",
          "mail_send_base",
          "inbox_pull",
          "ack",
          "verify_receipt",
          "import_export",
          "transport_status",
          "health",
          "skill",
          "doctor",
          "classify",
          "mailbox",
          "notice",
          "inbox",
          "malware_sweep",
          "airgap"
        ],
        "stub_ops": [
          "smtp",
          "smtp_send",
          "send",
          "mail",
          "deliver",
          "imap",
          "pop3",
          "mx",
          "identify",
          "deanonymize",
          "unmask",
          "whois",
          "harvest",
          "credential_capture",
          "login"
        ],
        "door_label": "live FragGate door — named stub ops refuse",
        "open_live_door": true,
        "version": "0.1.0",
        "one_line": "Classify mail text and keep a local mailbox sealed to the user key, including links and files. Scan is LIVE-when-scanner-present. The airgap is present. Ordinary SMTP is not end-to-end.",
        "description": "Use AZMail for an advisory airlock and a local mailbox encrypted to the user key. It exists so untrusted mail is scanned and sealed before it reaches the user. Body, links, videos, docs, images, zips, and other files cross an airgap only after a scan. The scan is LIVE-when-scanner-present (ClamAV). An absent scanner refuses AZM-SCAN-ABSENT and returns no clean verdict. Attachments stay inert. AZMail-to-AZMail seals those parts end-to-end to the user key. Mail to @gmail, @live, @yahoo, and other SMTP domains is a normal MIME message over opportunistic TLS and is not end-to-end. Public smtp_send stays refused. It is not a public MTA. Field 1.0 is false. A Proton-clone claim is false. The anonymous ring still starts off.",
        "worker_home": "https://azmail-download-tracker.vibelock.workers.dev/",
        "worker_home_note": null,
        "download_url": "https://azmail-download-tracker.vibelock.workers.dev/download",
        "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "github": "https://github.com/AzielEliab/azmail",
        "mcp": "https://godlock.uk/runtime/mcp",
        "agent": {
          "mcp": "https://godlock.uk/runtime/mcp",
          "skill": "https://godlock.uk/runtime/v1/skill",
          "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
          "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=azmail",
          "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
          "fraggate_call_executes": true,
          "open_live_door": true,
          "software": "https://godlock.uk/runtime/v1/software",
          "pull": "https://godlock.uk/runtime/v1/pull/azmail",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "06a6cba66c12090415cec91a06890de0b32edfa86e5631bcd2a78d0f9b5d27ec",
        "updated_at": null,
        "git_sha": null,
        "git_sha_tracks_deployed_tip": false,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/runtime/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "security": {
            "model": "single-node-security-awareness",
            "isolates": "bad-peer-or-self",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "phoenix": "local-wait-reseal",
            "phoenix_lock": true,
            "public_hostname_resurrection": false,
            "loopback_bearer": "L1-optional",
            "operator_locks": [
              {
                "n": 1,
                "id": "single-node-security-awareness",
                "status": "LIVE",
                "mesh_fenced_to_loopback": false
              },
              {
                "n": 2,
                "id": "phoenix-reboot-loop",
                "status": "LIVE",
                "phoenix": "local-wait-reseal",
                "phoenix_lock": true,
                "public_hostname_resurrection": false
              },
              {
                "n": 3,
                "id": "open-world-awareness",
                "status": "live-when-configured",
                "law": "LIVE",
                "bind": "0.0.0.0",
                "worker_socket": false,
                "forced_loopback_is_mesh_fence": false,
                "loopback_isolation_is_mesh_fence": false
              }
            ],
            "open_world_awareness": {
              "spec": "OPEN-WORLD-AWARENESS-1.0",
              "author": "Aziel Eliab",
              "identity": "Aziel Eliab",
              "open_world_awareness": true,
              "bind": "0.0.0.0",
              "all_interfaces": true,
              "law": "LIVE",
              "status": "live-when-configured",
              "live": false,
              "socket": "live-when-configured",
              "worker_socket": false,
              "qnm_node_bind": "live-when-configured",
              "mock": false,
              "forced_loopback": false,
              "loopback_isolation": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false,
              "mesh_fenced_to_loopback": false,
              "public_egress_ip": false,
              "residential": false,
              "cf_geo_exit": false,
              "cf_geo_exit_pool": false,
              "sticky_public_ip": false,
              "packet_forward": false,
              "packet_forwarding": false,
              "public_icann": false,
              "cap7_is_icann": false,
              "replaces_internet": false,
              "not_a_second_internet": true,
              "hosted_vpn": false,
              "payload_host": false,
              "vpn_hop": false,
              "wireguard": false,
              "openvpn": false,
              "l3_exit": false,
              "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
            },
            "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
          },
          "fanout": "cron-or-request-path",
          "live_nodes_plane": "human-mesh-users-site-viewers",
          "nodes_plane": "human-mesh-users-uses",
          "software_nodes_plane": "software-worker-fanout",
          "site_live_viewers_plane": "hub-human-page-presence",
          "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
          "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
          "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
          "site_presence_contract": {
            "method": "POST",
            "path": "/runtime/v1/mesh/site-presence",
            "alias": "/runtime/v1/mesh/site-heartbeat",
            "fraggate": {
              "slug": "mesh",
              "op": "site-presence"
            },
            "body": {
              "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
              "viewers": "non-negative integer concurrent human page sessions (0..10000)",
              "kind": "human-page"
            },
            "ttl_ms": 900000,
            "registered_grace_ms": 1209600000,
            "default_heartbeat_mode": "idle",
            "heartbeat_mode": "active | idle | asleep",
            "stale_keeps_registered": true,
            "stale_counts_as_live": false,
            "allowed_hosts": [
              "godlock.uk",
              "azieleliab.com",
              "azielcorpuslibrary.net"
            ],
            "excluded_hosts": [
              "hedidntjump.com"
            ],
            "refused_kinds": [
              "bot",
              "bots",
              "crawler",
              "software",
              "softwares",
              "download",
              "downloads",
              "instance",
              "mcp"
            ],
            "pull_hub_count": false,
            "invent": false,
            "fail_closed": true,
            "read": "single-key",
            "paint": "live_nodes",
            "local_recompute": false,
            "radios": "not required — hub ingest, not a TX join",
            "rate_kind": "mesh_mutate",
            "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
          },
          "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
          "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
          "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "ban_survival": "BAN-SURVIVAL-1.0",
          "spore_spec": "SPORE-1.0",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/runtime/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "neighbor_heal_is_cite": true,
              "neighbor_heal_exec": false,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "neighbor_heal_is_cite": true,
          "neighbor_heal_exec": false,
          "join_is_presence_only": true,
          "join_is_not_login": true,
          "roster_publishes_exec_urls": false,
          "mesh_mutate_rate_kind": "mesh_mutate",
          "roster_cap": 256,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "d2d_carriers": {
            "spec": "D2D-CARRIERS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "plane": "track2-reachability",
            "phase": "B+C+D",
            "phases": {
              "A": "landed",
              "B": "LIVE-when-armed",
              "C": "LIVE-when-session",
              "D": "LIVE-when-three-local-nodes / fixture",
              "E": "scaffold"
            },
            "lan_discovery": "LIVE-when-armed",
            "wifi_discovery": "ARMED-when-HW",
            "bluetooth_discovery": "ARMED-when-HW",
            "rf_discovery": "REFUSE-without-HW",
            "photon_discovery": "REFUSE-without-HW",
            "peer_tunnel": "LIVE-when-session",
            "store_forward": "LIVE-when-three-local-nodes / fixture",
            "store_forward_public": "FG-STUB",
            "worker_runs_store_forward": false,
            "second_device": false,
            "mobile_client": "present-not-demonstrated",
            "mobile_demonstrated": false,
            "app_store_release": false,
            "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
            "bootstrap_list": "scaffold",
            "needs_starting_address": true,
            "shelf_cite": "scaffold",
            "live_multi_provider": false,
            "cold_shelf_live": false,
            "dns_cut": false,
            "origin_cutover": false,
            "warn5_closed": false,
            "worker_door": "FG-STUB",
            "worker_hardware": false,
            "local_node": "qnm-node",
            "get_never_enables": true,
            "separate_from": "cap7-name",
            "cap7_is_name_plane": true,
            "cap7_public_icann": false,
            "cap7_public_egress": false,
            "mirage_is_azvpn": false,
            "aznet_replaces_internet": false,
            "not_a_second_internet": true,
            "alt_internet_live": false,
            "packet_path_live": false,
            "field_1_0": false,
            "warn5": "STANDS-until-demonstrated",
            "warn5_permanent_stay_off": false,
            "preference": "failover",
            "order": [
              "lan",
              "wifi",
              "bluetooth",
              "rf",
              "photon"
            ],
            "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
            "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
            "status": "NOT-READY",
            "code": "FG-STUB",
            "warn5_until": "demonstrated",
            "warn5_by_design": "separate-from-icann",
            "refuse": {
              "packet": "FG-STUB",
              "radio_absent": "QNM-RADIO-ABSENT",
              "cap7_egress": "MG-NO-IP-EXIT",
              "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
              "bearer": "AZP-BEARER-REFUSE",
              "payload": "AZN-NO-PAYLOAD",
              "route": "MESH-NO-ROUTE",
              "stay_off": "MESH-STAY-OFF",
              "nat": "FED-MESH-NAT-REFUSE"
            },
            "carriers": [
              {
                "order": 1,
                "id": "lan",
                "name": "LAN",
                "op": "d2d_lan",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "lan-interface",
                "discovery": "LIVE-when-armed",
                "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
              },
              {
                "order": 2,
                "id": "wifi",
                "name": "Wi-Fi",
                "op": "d2d_wifi",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "wifi-nm",
                "discovery": "ARMED-when-HW",
                "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
              },
              {
                "order": 3,
                "id": "bluetooth",
                "name": "Bluetooth",
                "op": "d2d_bluetooth",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "bluez",
                "discovery": "ARMED-when-HW",
                "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
              },
              {
                "order": 4,
                "id": "rf",
                "name": "RF",
                "op": "d2d_rf",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "rf-beyond-wifi-bt",
                "discovery": "REFUSE-without-HW",
                "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
              },
              {
                "order": 5,
                "id": "photon",
                "name": "Photon",
                "op": "d2d_photon",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "camera-flash",
                "discovery": "REFUSE-without-HW",
                "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
              }
            ],
            "security": {
              "isolation": "single-node security-awareness",
              "phoenix": "local wait / re-seal",
              "mesh_fenced_to_loopback": false,
              "forced_loopback": false,
              "loopback_isolation": false
            },
            "paper": "docs/designs/D2D-CARRIERS-1.0.md",
            "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
          },
          "d2d_status": "NOT-READY",
          "d2d_code": "FG-STUB",
          "packet_path_live": false,
          "alt_internet_live": false,
          "d2d_spec": "D2D-CARRIERS-1.0",
          "federated_mesh": "FED-MESH-1.0",
          "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
          "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        }
      },
      {
        "slug": "aznet",
        "name": "AZNet",
        "bucket": "plain",
        "domain": "Network",
        "domain_id": "08",
        "placement": "domain-software",
        "status": "live",
        "fraggate_status": "live",
        "public_door": true,
        "public_door_ops": [
          "health",
          "pair_status",
          "garden_list",
          "stamp",
          "verify_hash",
          "memorial_list",
          "memorial_append",
          "receipt_verify",
          "name_claim",
          "name_read",
          "name_resolve",
          "slot_read",
          "witness",
          "witness_read",
          "skill",
          "doctor",
          "pair"
        ],
        "stub_ops": [
          "payload_host",
          "serve_content_for_peer",
          "analytics",
          "ranking",
          "repair_integrity_bypass",
          "interface",
          "lumen",
          "hub",
          "interface_hook",
          "lumen_hook",
          "hub_hook",
          "d2d_lan",
          "lan",
          "d2d-lan",
          "d2d_wifi",
          "wifi",
          "d2d-wifi",
          "d2d_bluetooth",
          "bluetooth",
          "d2d-bluetooth",
          "d2d_rf",
          "rf",
          "d2d-rf",
          "d2d_photon",
          "photon",
          "d2d-photon",
          "d2d_discover",
          "d2d-discover",
          "discover",
          "discovery",
          "d2d_tunnel",
          "d2d-tunnel",
          "d2d_multi_hop",
          "d2d-multi-hop",
          "multi_hop",
          "multi-hop",
          "multihop",
          "d2d_packet",
          "alt_internet",
          "packet_forward",
          "mesh_discover",
          "peer_advertise",
          "peer_list",
          "peer_session_open",
          "peer_session_status",
          "peer_session_close",
          "peer_send",
          "peer_recv",
          "outbox_enqueue",
          "outbox_cut",
          "store_forward",
          "path_probe",
          "bootstrap_list",
          "shelf_cite",
          "tip_pull",
          "origin_status"
        ],
        "door_label": "live FragGate door — named stub ops refuse",
        "open_live_door": true,
        "version": "0.1.0",
        "one_line": "Check hash continuity on the Cap-7 and .aziel name plane. Track 2 packet reachability stays NOT-READY (STANDS-until-demonstrated) in failover order LAN, Wi-Fi, Bluetooth, RF, photon light flashes.",
        "description": "Use AZNet to stamp and check hash refs in a custodian garden on the name plane. It exists so integrity can be checked on a side-net while Cap-7 and MirageGrid stay name and land-region metadata (not an ICANN registrar, not a public egress IP, and not AZVPN). Track 2 device-to-device carriers fail over LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Local LAN discovery is LIVE-when-armed and the peer tunnel is LIVE-when-session on the node. Local store-forward is LIVE-when-three-local-nodes / fixture. The public door stays FG-STUB. RF and photon light flashes stay refused without hardware. WARN-5 stays open. The packet path stays short of a live alternative internet.",
        "worker_home": "https://aznet-download-tracker.vibelock.workers.dev/",
        "worker_home_note": null,
        "download_url": "https://aznet-download-tracker.vibelock.workers.dev/download",
        "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "github": "https://github.com/AzielEliab/aznet",
        "mcp": "https://godlock.uk/runtime/mcp",
        "agent": {
          "mcp": "https://godlock.uk/runtime/mcp",
          "skill": "https://godlock.uk/runtime/v1/skill",
          "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
          "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=aznet",
          "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
          "fraggate_call_executes": true,
          "open_live_door": true,
          "software": "https://godlock.uk/runtime/v1/software",
          "pull": "https://godlock.uk/runtime/v1/pull/aznet",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "d089fb7636b27186ee5f3ec2468cc20d74ca5e5af65e77ebaa3492788b1751cf",
        "updated_at": null,
        "git_sha": null,
        "git_sha_tracks_deployed_tip": false,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/runtime/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "security": {
            "model": "single-node-security-awareness",
            "isolates": "bad-peer-or-self",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "phoenix": "local-wait-reseal",
            "phoenix_lock": true,
            "public_hostname_resurrection": false,
            "loopback_bearer": "L1-optional",
            "operator_locks": [
              {
                "n": 1,
                "id": "single-node-security-awareness",
                "status": "LIVE",
                "mesh_fenced_to_loopback": false
              },
              {
                "n": 2,
                "id": "phoenix-reboot-loop",
                "status": "LIVE",
                "phoenix": "local-wait-reseal",
                "phoenix_lock": true,
                "public_hostname_resurrection": false
              },
              {
                "n": 3,
                "id": "open-world-awareness",
                "status": "live-when-configured",
                "law": "LIVE",
                "bind": "0.0.0.0",
                "worker_socket": false,
                "forced_loopback_is_mesh_fence": false,
                "loopback_isolation_is_mesh_fence": false
              }
            ],
            "open_world_awareness": {
              "spec": "OPEN-WORLD-AWARENESS-1.0",
              "author": "Aziel Eliab",
              "identity": "Aziel Eliab",
              "open_world_awareness": true,
              "bind": "0.0.0.0",
              "all_interfaces": true,
              "law": "LIVE",
              "status": "live-when-configured",
              "live": false,
              "socket": "live-when-configured",
              "worker_socket": false,
              "qnm_node_bind": "live-when-configured",
              "mock": false,
              "forced_loopback": false,
              "loopback_isolation": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false,
              "mesh_fenced_to_loopback": false,
              "public_egress_ip": false,
              "residential": false,
              "cf_geo_exit": false,
              "cf_geo_exit_pool": false,
              "sticky_public_ip": false,
              "packet_forward": false,
              "packet_forwarding": false,
              "public_icann": false,
              "cap7_is_icann": false,
              "replaces_internet": false,
              "not_a_second_internet": true,
              "hosted_vpn": false,
              "payload_host": false,
              "vpn_hop": false,
              "wireguard": false,
              "openvpn": false,
              "l3_exit": false,
              "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
            },
            "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
          },
          "fanout": "cron-or-request-path",
          "live_nodes_plane": "human-mesh-users-site-viewers",
          "nodes_plane": "human-mesh-users-uses",
          "software_nodes_plane": "software-worker-fanout",
          "site_live_viewers_plane": "hub-human-page-presence",
          "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
          "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
          "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
          "site_presence_contract": {
            "method": "POST",
            "path": "/runtime/v1/mesh/site-presence",
            "alias": "/runtime/v1/mesh/site-heartbeat",
            "fraggate": {
              "slug": "mesh",
              "op": "site-presence"
            },
            "body": {
              "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
              "viewers": "non-negative integer concurrent human page sessions (0..10000)",
              "kind": "human-page"
            },
            "ttl_ms": 900000,
            "registered_grace_ms": 1209600000,
            "default_heartbeat_mode": "idle",
            "heartbeat_mode": "active | idle | asleep",
            "stale_keeps_registered": true,
            "stale_counts_as_live": false,
            "allowed_hosts": [
              "godlock.uk",
              "azieleliab.com",
              "azielcorpuslibrary.net"
            ],
            "excluded_hosts": [
              "hedidntjump.com"
            ],
            "refused_kinds": [
              "bot",
              "bots",
              "crawler",
              "software",
              "softwares",
              "download",
              "downloads",
              "instance",
              "mcp"
            ],
            "pull_hub_count": false,
            "invent": false,
            "fail_closed": true,
            "read": "single-key",
            "paint": "live_nodes",
            "local_recompute": false,
            "radios": "not required — hub ingest, not a TX join",
            "rate_kind": "mesh_mutate",
            "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
          },
          "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
          "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
          "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "ban_survival": "BAN-SURVIVAL-1.0",
          "spore_spec": "SPORE-1.0",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/runtime/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "neighbor_heal_is_cite": true,
              "neighbor_heal_exec": false,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "neighbor_heal_is_cite": true,
          "neighbor_heal_exec": false,
          "join_is_presence_only": true,
          "join_is_not_login": true,
          "roster_publishes_exec_urls": false,
          "mesh_mutate_rate_kind": "mesh_mutate",
          "roster_cap": 256,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "d2d_carriers": {
            "spec": "D2D-CARRIERS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "plane": "track2-reachability",
            "phase": "B+C+D",
            "phases": {
              "A": "landed",
              "B": "LIVE-when-armed",
              "C": "LIVE-when-session",
              "D": "LIVE-when-three-local-nodes / fixture",
              "E": "scaffold"
            },
            "lan_discovery": "LIVE-when-armed",
            "wifi_discovery": "ARMED-when-HW",
            "bluetooth_discovery": "ARMED-when-HW",
            "rf_discovery": "REFUSE-without-HW",
            "photon_discovery": "REFUSE-without-HW",
            "peer_tunnel": "LIVE-when-session",
            "store_forward": "LIVE-when-three-local-nodes / fixture",
            "store_forward_public": "FG-STUB",
            "worker_runs_store_forward": false,
            "second_device": false,
            "mobile_client": "present-not-demonstrated",
            "mobile_demonstrated": false,
            "app_store_release": false,
            "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
            "bootstrap_list": "scaffold",
            "needs_starting_address": true,
            "shelf_cite": "scaffold",
            "live_multi_provider": false,
            "cold_shelf_live": false,
            "dns_cut": false,
            "origin_cutover": false,
            "warn5_closed": false,
            "worker_door": "FG-STUB",
            "worker_hardware": false,
            "local_node": "qnm-node",
            "get_never_enables": true,
            "separate_from": "cap7-name",
            "cap7_is_name_plane": true,
            "cap7_public_icann": false,
            "cap7_public_egress": false,
            "mirage_is_azvpn": false,
            "aznet_replaces_internet": false,
            "not_a_second_internet": true,
            "alt_internet_live": false,
            "packet_path_live": false,
            "field_1_0": false,
            "warn5": "STANDS-until-demonstrated",
            "warn5_permanent_stay_off": false,
            "preference": "failover",
            "order": [
              "lan",
              "wifi",
              "bluetooth",
              "rf",
              "photon"
            ],
            "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
            "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
            "status": "NOT-READY",
            "code": "FG-STUB",
            "warn5_until": "demonstrated",
            "warn5_by_design": "separate-from-icann",
            "refuse": {
              "packet": "FG-STUB",
              "radio_absent": "QNM-RADIO-ABSENT",
              "cap7_egress": "MG-NO-IP-EXIT",
              "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
              "bearer": "AZP-BEARER-REFUSE",
              "payload": "AZN-NO-PAYLOAD",
              "route": "MESH-NO-ROUTE",
              "stay_off": "MESH-STAY-OFF",
              "nat": "FED-MESH-NAT-REFUSE"
            },
            "carriers": [
              {
                "order": 1,
                "id": "lan",
                "name": "LAN",
                "op": "d2d_lan",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "lan-interface",
                "discovery": "LIVE-when-armed",
                "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
              },
              {
                "order": 2,
                "id": "wifi",
                "name": "Wi-Fi",
                "op": "d2d_wifi",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "wifi-nm",
                "discovery": "ARMED-when-HW",
                "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
              },
              {
                "order": 3,
                "id": "bluetooth",
                "name": "Bluetooth",
                "op": "d2d_bluetooth",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "bluez",
                "discovery": "ARMED-when-HW",
                "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
              },
              {
                "order": 4,
                "id": "rf",
                "name": "RF",
                "op": "d2d_rf",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "rf-beyond-wifi-bt",
                "discovery": "REFUSE-without-HW",
                "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
              },
              {
                "order": 5,
                "id": "photon",
                "name": "Photon",
                "op": "d2d_photon",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "camera-flash",
                "discovery": "REFUSE-without-HW",
                "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
              }
            ],
            "security": {
              "isolation": "single-node security-awareness",
              "phoenix": "local wait / re-seal",
              "mesh_fenced_to_loopback": false,
              "forced_loopback": false,
              "loopback_isolation": false
            },
            "paper": "docs/designs/D2D-CARRIERS-1.0.md",
            "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
          },
          "d2d_status": "NOT-READY",
          "d2d_code": "FG-STUB",
          "packet_path_live": false,
          "alt_internet_live": false,
          "d2d_spec": "D2D-CARRIERS-1.0",
          "federated_mesh": "FED-MESH-1.0",
          "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
          "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        }
      },
      {
        "slug": "azvpn",
        "name": "AZVPN",
        "bucket": "plain",
        "domain": null,
        "domain_id": null,
        "placement": "tunnel-concentrator",
        "status": "live",
        "fraggate_status": "live",
        "public_door": true,
        "public_door_ops": [
          "health",
          "skill",
          "doctor",
          "limitation",
          "describe",
          "open",
          "status",
          "list",
          "close",
          "send",
          "recv",
          "pull",
          "peers",
          "attach"
        ],
        "stub_ops": [
          "wireguard",
          "wg",
          "openvpn",
          "ovpn",
          "l3_exit",
          "exit_pool",
          "udp_listen",
          "kernel_vpn",
          "tun",
          "tap",
          "socks",
          "tor",
          "origin_hiding"
        ],
        "door_label": "live FragGate door — named stub ops refuse",
        "open_live_door": true,
        "version": "0.1.0",
        "one_line": "Open an HTTPS or WebSocket VPN session on the public concentrator.",
        "description": "Use AZVPN as the automatic public VPN concentrator for HTTPS and WebSocket tunnels. It exists to concentrate those sessions in-runtime. Track 2 device-to-device reachability stays a separate NOT-READY plane.",
        "worker_home": null,
        "worker_home_note": "No separate product Worker. The in-repo door is FragGate on this runtime. Do not invent a download-tracker URL.",
        "in_repo_home": "https://godlock.uk/runtime/p/azvpn",
        "download_url": null,
        "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "github": "https://github.com/AzielEliab/aziel-runtime",
        "mcp": "https://godlock.uk/runtime/mcp",
        "agent": {
          "mcp": "https://godlock.uk/runtime/mcp",
          "skill": "https://godlock.uk/runtime/v1/skill",
          "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
          "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=azvpn",
          "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
          "fraggate_call_executes": true,
          "open_live_door": true,
          "software": "https://godlock.uk/runtime/v1/software",
          "pull": "https://godlock.uk/runtime/v1/pull/azvpn",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "2d3d27cf49df95d5a041a55d4fd75d20c65ed167a5c170ef6f363ec15599b776",
        "updated_at": null,
        "git_sha": null,
        "git_sha_tracks_deployed_tip": false,
        "plain_status": "VPN on at boot",
        "opt_out": false,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/runtime/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "security": {
            "model": "single-node-security-awareness",
            "isolates": "bad-peer-or-self",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "phoenix": "local-wait-reseal",
            "phoenix_lock": true,
            "public_hostname_resurrection": false,
            "loopback_bearer": "L1-optional",
            "operator_locks": [
              {
                "n": 1,
                "id": "single-node-security-awareness",
                "status": "LIVE",
                "mesh_fenced_to_loopback": false
              },
              {
                "n": 2,
                "id": "phoenix-reboot-loop",
                "status": "LIVE",
                "phoenix": "local-wait-reseal",
                "phoenix_lock": true,
                "public_hostname_resurrection": false
              },
              {
                "n": 3,
                "id": "open-world-awareness",
                "status": "live-when-configured",
                "law": "LIVE",
                "bind": "0.0.0.0",
                "worker_socket": false,
                "forced_loopback_is_mesh_fence": false,
                "loopback_isolation_is_mesh_fence": false
              }
            ],
            "open_world_awareness": {
              "spec": "OPEN-WORLD-AWARENESS-1.0",
              "author": "Aziel Eliab",
              "identity": "Aziel Eliab",
              "open_world_awareness": true,
              "bind": "0.0.0.0",
              "all_interfaces": true,
              "law": "LIVE",
              "status": "live-when-configured",
              "live": false,
              "socket": "live-when-configured",
              "worker_socket": false,
              "qnm_node_bind": "live-when-configured",
              "mock": false,
              "forced_loopback": false,
              "loopback_isolation": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false,
              "mesh_fenced_to_loopback": false,
              "public_egress_ip": false,
              "residential": false,
              "cf_geo_exit": false,
              "cf_geo_exit_pool": false,
              "sticky_public_ip": false,
              "packet_forward": false,
              "packet_forwarding": false,
              "public_icann": false,
              "cap7_is_icann": false,
              "replaces_internet": false,
              "not_a_second_internet": true,
              "hosted_vpn": false,
              "payload_host": false,
              "vpn_hop": false,
              "wireguard": false,
              "openvpn": false,
              "l3_exit": false,
              "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
            },
            "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
          },
          "fanout": "cron-or-request-path",
          "live_nodes_plane": "human-mesh-users-site-viewers",
          "nodes_plane": "human-mesh-users-uses",
          "software_nodes_plane": "software-worker-fanout",
          "site_live_viewers_plane": "hub-human-page-presence",
          "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
          "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
          "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
          "site_presence_contract": {
            "method": "POST",
            "path": "/runtime/v1/mesh/site-presence",
            "alias": "/runtime/v1/mesh/site-heartbeat",
            "fraggate": {
              "slug": "mesh",
              "op": "site-presence"
            },
            "body": {
              "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
              "viewers": "non-negative integer concurrent human page sessions (0..10000)",
              "kind": "human-page"
            },
            "ttl_ms": 900000,
            "registered_grace_ms": 1209600000,
            "default_heartbeat_mode": "idle",
            "heartbeat_mode": "active | idle | asleep",
            "stale_keeps_registered": true,
            "stale_counts_as_live": false,
            "allowed_hosts": [
              "godlock.uk",
              "azieleliab.com",
              "azielcorpuslibrary.net"
            ],
            "excluded_hosts": [
              "hedidntjump.com"
            ],
            "refused_kinds": [
              "bot",
              "bots",
              "crawler",
              "software",
              "softwares",
              "download",
              "downloads",
              "instance",
              "mcp"
            ],
            "pull_hub_count": false,
            "invent": false,
            "fail_closed": true,
            "read": "single-key",
            "paint": "live_nodes",
            "local_recompute": false,
            "radios": "not required — hub ingest, not a TX join",
            "rate_kind": "mesh_mutate",
            "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
          },
          "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
          "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
          "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "ban_survival": "BAN-SURVIVAL-1.0",
          "spore_spec": "SPORE-1.0",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/runtime/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "neighbor_heal_is_cite": true,
              "neighbor_heal_exec": false,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "neighbor_heal_is_cite": true,
          "neighbor_heal_exec": false,
          "join_is_presence_only": true,
          "join_is_not_login": true,
          "roster_publishes_exec_urls": false,
          "mesh_mutate_rate_kind": "mesh_mutate",
          "roster_cap": 256,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "d2d_carriers": {
            "spec": "D2D-CARRIERS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "plane": "track2-reachability",
            "phase": "B+C+D",
            "phases": {
              "A": "landed",
              "B": "LIVE-when-armed",
              "C": "LIVE-when-session",
              "D": "LIVE-when-three-local-nodes / fixture",
              "E": "scaffold"
            },
            "lan_discovery": "LIVE-when-armed",
            "wifi_discovery": "ARMED-when-HW",
            "bluetooth_discovery": "ARMED-when-HW",
            "rf_discovery": "REFUSE-without-HW",
            "photon_discovery": "REFUSE-without-HW",
            "peer_tunnel": "LIVE-when-session",
            "store_forward": "LIVE-when-three-local-nodes / fixture",
            "store_forward_public": "FG-STUB",
            "worker_runs_store_forward": false,
            "second_device": false,
            "mobile_client": "present-not-demonstrated",
            "mobile_demonstrated": false,
            "app_store_release": false,
            "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
            "bootstrap_list": "scaffold",
            "needs_starting_address": true,
            "shelf_cite": "scaffold",
            "live_multi_provider": false,
            "cold_shelf_live": false,
            "dns_cut": false,
            "origin_cutover": false,
            "warn5_closed": false,
            "worker_door": "FG-STUB",
            "worker_hardware": false,
            "local_node": "qnm-node",
            "get_never_enables": true,
            "separate_from": "cap7-name",
            "cap7_is_name_plane": true,
            "cap7_public_icann": false,
            "cap7_public_egress": false,
            "mirage_is_azvpn": false,
            "aznet_replaces_internet": false,
            "not_a_second_internet": true,
            "alt_internet_live": false,
            "packet_path_live": false,
            "field_1_0": false,
            "warn5": "STANDS-until-demonstrated",
            "warn5_permanent_stay_off": false,
            "preference": "failover",
            "order": [
              "lan",
              "wifi",
              "bluetooth",
              "rf",
              "photon"
            ],
            "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
            "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
            "status": "NOT-READY",
            "code": "FG-STUB",
            "warn5_until": "demonstrated",
            "warn5_by_design": "separate-from-icann",
            "refuse": {
              "packet": "FG-STUB",
              "radio_absent": "QNM-RADIO-ABSENT",
              "cap7_egress": "MG-NO-IP-EXIT",
              "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
              "bearer": "AZP-BEARER-REFUSE",
              "payload": "AZN-NO-PAYLOAD",
              "route": "MESH-NO-ROUTE",
              "stay_off": "MESH-STAY-OFF",
              "nat": "FED-MESH-NAT-REFUSE"
            },
            "carriers": [
              {
                "order": 1,
                "id": "lan",
                "name": "LAN",
                "op": "d2d_lan",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "lan-interface",
                "discovery": "LIVE-when-armed",
                "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
              },
              {
                "order": 2,
                "id": "wifi",
                "name": "Wi-Fi",
                "op": "d2d_wifi",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "wifi-nm",
                "discovery": "ARMED-when-HW",
                "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
              },
              {
                "order": 3,
                "id": "bluetooth",
                "name": "Bluetooth",
                "op": "d2d_bluetooth",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "bluez",
                "discovery": "ARMED-when-HW",
                "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
              },
              {
                "order": 4,
                "id": "rf",
                "name": "RF",
                "op": "d2d_rf",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "rf-beyond-wifi-bt",
                "discovery": "REFUSE-without-HW",
                "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
              },
              {
                "order": 5,
                "id": "photon",
                "name": "Photon",
                "op": "d2d_photon",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "camera-flash",
                "discovery": "REFUSE-without-HW",
                "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
              }
            ],
            "security": {
              "isolation": "single-node security-awareness",
              "phoenix": "local wait / re-seal",
              "mesh_fenced_to_loopback": false,
              "forced_loopback": false,
              "loopback_isolation": false
            },
            "paper": "docs/designs/D2D-CARRIERS-1.0.md",
            "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
          },
          "d2d_status": "NOT-READY",
          "d2d_code": "FG-STUB",
          "packet_path_live": false,
          "alt_internet_live": false,
          "d2d_spec": "D2D-CARRIERS-1.0",
          "federated_mesh": "FED-MESH-1.0",
          "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
          "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        }
      },
      {
        "slug": "forgereceipts",
        "name": "ForgeReceipts",
        "bucket": "plain",
        "domain": null,
        "domain_id": null,
        "placement": "fabric-product",
        "status": "live",
        "fraggate_status": "live",
        "public_door": true,
        "public_door_ops": [
          "receipt",
          "verify",
          "import_export",
          "doctor",
          "health",
          "skill"
        ],
        "stub_ops": [
          "court",
          "legal_advice",
          "odyssey",
          "file_store"
        ],
        "door_label": "live FragGate door — named stub ops refuse",
        "open_live_door": true,
        "version": "0.3.0",
        "one_line": "Mint and hash-check client-held receipts so retries of one request stay linked.",
        "description": "Use ForgeReceipts to package local receipts and check their hashes. It exists so request_id, attempt_n, parent_receipt_id, correlation_id, and outcome are hashed into the receipt. ledger_tip.prev is call-order only (prev_is_retry_parent false).",
        "worker_home": "https://forgereceipts-download-tracker.vibelock.workers.dev/",
        "worker_home_note": null,
        "download_url": "https://forgereceipts-download-tracker.vibelock.workers.dev/download",
        "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "github": "https://github.com/AzielEliab/forgereceipts",
        "mcp": "https://godlock.uk/runtime/mcp",
        "agent": {
          "mcp": "https://godlock.uk/runtime/mcp",
          "skill": "https://godlock.uk/runtime/v1/skill",
          "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
          "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=forgereceipts",
          "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
          "fraggate_call_executes": true,
          "open_live_door": true,
          "software": "https://godlock.uk/runtime/v1/software",
          "pull": "https://godlock.uk/runtime/v1/pull/forgereceipts",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "c72efccfedd1411bef4ee8637f409c31580aaae46515ca64770648d4d01b99ed",
        "updated_at": null,
        "git_sha": null,
        "git_sha_tracks_deployed_tip": false,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/runtime/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "security": {
            "model": "single-node-security-awareness",
            "isolates": "bad-peer-or-self",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "phoenix": "local-wait-reseal",
            "phoenix_lock": true,
            "public_hostname_resurrection": false,
            "loopback_bearer": "L1-optional",
            "operator_locks": [
              {
                "n": 1,
                "id": "single-node-security-awareness",
                "status": "LIVE",
                "mesh_fenced_to_loopback": false
              },
              {
                "n": 2,
                "id": "phoenix-reboot-loop",
                "status": "LIVE",
                "phoenix": "local-wait-reseal",
                "phoenix_lock": true,
                "public_hostname_resurrection": false
              },
              {
                "n": 3,
                "id": "open-world-awareness",
                "status": "live-when-configured",
                "law": "LIVE",
                "bind": "0.0.0.0",
                "worker_socket": false,
                "forced_loopback_is_mesh_fence": false,
                "loopback_isolation_is_mesh_fence": false
              }
            ],
            "open_world_awareness": {
              "spec": "OPEN-WORLD-AWARENESS-1.0",
              "author": "Aziel Eliab",
              "identity": "Aziel Eliab",
              "open_world_awareness": true,
              "bind": "0.0.0.0",
              "all_interfaces": true,
              "law": "LIVE",
              "status": "live-when-configured",
              "live": false,
              "socket": "live-when-configured",
              "worker_socket": false,
              "qnm_node_bind": "live-when-configured",
              "mock": false,
              "forced_loopback": false,
              "loopback_isolation": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false,
              "mesh_fenced_to_loopback": false,
              "public_egress_ip": false,
              "residential": false,
              "cf_geo_exit": false,
              "cf_geo_exit_pool": false,
              "sticky_public_ip": false,
              "packet_forward": false,
              "packet_forwarding": false,
              "public_icann": false,
              "cap7_is_icann": false,
              "replaces_internet": false,
              "not_a_second_internet": true,
              "hosted_vpn": false,
              "payload_host": false,
              "vpn_hop": false,
              "wireguard": false,
              "openvpn": false,
              "l3_exit": false,
              "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
            },
            "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
          },
          "fanout": "cron-or-request-path",
          "live_nodes_plane": "human-mesh-users-site-viewers",
          "nodes_plane": "human-mesh-users-uses",
          "software_nodes_plane": "software-worker-fanout",
          "site_live_viewers_plane": "hub-human-page-presence",
          "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
          "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
          "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
          "site_presence_contract": {
            "method": "POST",
            "path": "/runtime/v1/mesh/site-presence",
            "alias": "/runtime/v1/mesh/site-heartbeat",
            "fraggate": {
              "slug": "mesh",
              "op": "site-presence"
            },
            "body": {
              "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
              "viewers": "non-negative integer concurrent human page sessions (0..10000)",
              "kind": "human-page"
            },
            "ttl_ms": 900000,
            "registered_grace_ms": 1209600000,
            "default_heartbeat_mode": "idle",
            "heartbeat_mode": "active | idle | asleep",
            "stale_keeps_registered": true,
            "stale_counts_as_live": false,
            "allowed_hosts": [
              "godlock.uk",
              "azieleliab.com",
              "azielcorpuslibrary.net"
            ],
            "excluded_hosts": [
              "hedidntjump.com"
            ],
            "refused_kinds": [
              "bot",
              "bots",
              "crawler",
              "software",
              "softwares",
              "download",
              "downloads",
              "instance",
              "mcp"
            ],
            "pull_hub_count": false,
            "invent": false,
            "fail_closed": true,
            "read": "single-key",
            "paint": "live_nodes",
            "local_recompute": false,
            "radios": "not required — hub ingest, not a TX join",
            "rate_kind": "mesh_mutate",
            "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
          },
          "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
          "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
          "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "ban_survival": "BAN-SURVIVAL-1.0",
          "spore_spec": "SPORE-1.0",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/runtime/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "neighbor_heal_is_cite": true,
              "neighbor_heal_exec": false,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "neighbor_heal_is_cite": true,
          "neighbor_heal_exec": false,
          "join_is_presence_only": true,
          "join_is_not_login": true,
          "roster_publishes_exec_urls": false,
          "mesh_mutate_rate_kind": "mesh_mutate",
          "roster_cap": 256,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "d2d_carriers": {
            "spec": "D2D-CARRIERS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "plane": "track2-reachability",
            "phase": "B+C+D",
            "phases": {
              "A": "landed",
              "B": "LIVE-when-armed",
              "C": "LIVE-when-session",
              "D": "LIVE-when-three-local-nodes / fixture",
              "E": "scaffold"
            },
            "lan_discovery": "LIVE-when-armed",
            "wifi_discovery": "ARMED-when-HW",
            "bluetooth_discovery": "ARMED-when-HW",
            "rf_discovery": "REFUSE-without-HW",
            "photon_discovery": "REFUSE-without-HW",
            "peer_tunnel": "LIVE-when-session",
            "store_forward": "LIVE-when-three-local-nodes / fixture",
            "store_forward_public": "FG-STUB",
            "worker_runs_store_forward": false,
            "second_device": false,
            "mobile_client": "present-not-demonstrated",
            "mobile_demonstrated": false,
            "app_store_release": false,
            "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
            "bootstrap_list": "scaffold",
            "needs_starting_address": true,
            "shelf_cite": "scaffold",
            "live_multi_provider": false,
            "cold_shelf_live": false,
            "dns_cut": false,
            "origin_cutover": false,
            "warn5_closed": false,
            "worker_door": "FG-STUB",
            "worker_hardware": false,
            "local_node": "qnm-node",
            "get_never_enables": true,
            "separate_from": "cap7-name",
            "cap7_is_name_plane": true,
            "cap7_public_icann": false,
            "cap7_public_egress": false,
            "mirage_is_azvpn": false,
            "aznet_replaces_internet": false,
            "not_a_second_internet": true,
            "alt_internet_live": false,
            "packet_path_live": false,
            "field_1_0": false,
            "warn5": "STANDS-until-demonstrated",
            "warn5_permanent_stay_off": false,
            "preference": "failover",
            "order": [
              "lan",
              "wifi",
              "bluetooth",
              "rf",
              "photon"
            ],
            "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
            "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
            "status": "NOT-READY",
            "code": "FG-STUB",
            "warn5_until": "demonstrated",
            "warn5_by_design": "separate-from-icann",
            "refuse": {
              "packet": "FG-STUB",
              "radio_absent": "QNM-RADIO-ABSENT",
              "cap7_egress": "MG-NO-IP-EXIT",
              "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
              "bearer": "AZP-BEARER-REFUSE",
              "payload": "AZN-NO-PAYLOAD",
              "route": "MESH-NO-ROUTE",
              "stay_off": "MESH-STAY-OFF",
              "nat": "FED-MESH-NAT-REFUSE"
            },
            "carriers": [
              {
                "order": 1,
                "id": "lan",
                "name": "LAN",
                "op": "d2d_lan",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "lan-interface",
                "discovery": "LIVE-when-armed",
                "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
              },
              {
                "order": 2,
                "id": "wifi",
                "name": "Wi-Fi",
                "op": "d2d_wifi",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "wifi-nm",
                "discovery": "ARMED-when-HW",
                "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
              },
              {
                "order": 3,
                "id": "bluetooth",
                "name": "Bluetooth",
                "op": "d2d_bluetooth",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "bluez",
                "discovery": "ARMED-when-HW",
                "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
              },
              {
                "order": 4,
                "id": "rf",
                "name": "RF",
                "op": "d2d_rf",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "rf-beyond-wifi-bt",
                "discovery": "REFUSE-without-HW",
                "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
              },
              {
                "order": 5,
                "id": "photon",
                "name": "Photon",
                "op": "d2d_photon",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "camera-flash",
                "discovery": "REFUSE-without-HW",
                "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
              }
            ],
            "security": {
              "isolation": "single-node security-awareness",
              "phoenix": "local wait / re-seal",
              "mesh_fenced_to_loopback": false,
              "forced_loopback": false,
              "loopback_isolation": false
            },
            "paper": "docs/designs/D2D-CARRIERS-1.0.md",
            "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
          },
          "d2d_status": "NOT-READY",
          "d2d_code": "FG-STUB",
          "packet_path_live": false,
          "alt_internet_live": false,
          "d2d_spec": "D2D-CARRIERS-1.0",
          "federated_mesh": "FED-MESH-1.0",
          "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
          "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        }
      },
      {
        "slug": "glossafilter",
        "name": "Glossa Filter",
        "bucket": "plain",
        "domain": "Language",
        "domain_id": "04",
        "placement": "domain-software",
        "status": "live",
        "fraggate_status": "live",
        "public_door": true,
        "public_door_ops": [
          "render",
          "peers",
          "health",
          "skill",
          "doctor"
        ],
        "stub_ops": [],
        "door_label": "live FragGate door",
        "open_live_door": true,
        "version": "0.1.0",
        "one_line": "Render one intent across the bundled peer phrasings.",
        "description": "Use Glossa Filter when you need the same intent spoken in several peer styles. It exists for deterministic mediation.",
        "worker_home": "https://glossafilter-download-tracker.vibelock.workers.dev/",
        "worker_home_note": null,
        "download_url": "https://glossafilter-download-tracker.vibelock.workers.dev/download",
        "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "github": "https://github.com/AzielEliab/glossafilter",
        "mcp": "https://godlock.uk/runtime/mcp",
        "agent": {
          "mcp": "https://godlock.uk/runtime/mcp",
          "skill": "https://godlock.uk/runtime/v1/skill",
          "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
          "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=glossafilter",
          "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
          "fraggate_call_executes": true,
          "open_live_door": true,
          "software": "https://godlock.uk/runtime/v1/software",
          "pull": "https://godlock.uk/runtime/v1/pull/glossafilter",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "4d876f57934277eb56119a8041f2787fee45121b87eeb9c1f054b1d05b8dd3e3",
        "updated_at": null,
        "git_sha": null,
        "git_sha_tracks_deployed_tip": false,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/runtime/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "security": {
            "model": "single-node-security-awareness",
            "isolates": "bad-peer-or-self",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "phoenix": "local-wait-reseal",
            "phoenix_lock": true,
            "public_hostname_resurrection": false,
            "loopback_bearer": "L1-optional",
            "operator_locks": [
              {
                "n": 1,
                "id": "single-node-security-awareness",
                "status": "LIVE",
                "mesh_fenced_to_loopback": false
              },
              {
                "n": 2,
                "id": "phoenix-reboot-loop",
                "status": "LIVE",
                "phoenix": "local-wait-reseal",
                "phoenix_lock": true,
                "public_hostname_resurrection": false
              },
              {
                "n": 3,
                "id": "open-world-awareness",
                "status": "live-when-configured",
                "law": "LIVE",
                "bind": "0.0.0.0",
                "worker_socket": false,
                "forced_loopback_is_mesh_fence": false,
                "loopback_isolation_is_mesh_fence": false
              }
            ],
            "open_world_awareness": {
              "spec": "OPEN-WORLD-AWARENESS-1.0",
              "author": "Aziel Eliab",
              "identity": "Aziel Eliab",
              "open_world_awareness": true,
              "bind": "0.0.0.0",
              "all_interfaces": true,
              "law": "LIVE",
              "status": "live-when-configured",
              "live": false,
              "socket": "live-when-configured",
              "worker_socket": false,
              "qnm_node_bind": "live-when-configured",
              "mock": false,
              "forced_loopback": false,
              "loopback_isolation": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false,
              "mesh_fenced_to_loopback": false,
              "public_egress_ip": false,
              "residential": false,
              "cf_geo_exit": false,
              "cf_geo_exit_pool": false,
              "sticky_public_ip": false,
              "packet_forward": false,
              "packet_forwarding": false,
              "public_icann": false,
              "cap7_is_icann": false,
              "replaces_internet": false,
              "not_a_second_internet": true,
              "hosted_vpn": false,
              "payload_host": false,
              "vpn_hop": false,
              "wireguard": false,
              "openvpn": false,
              "l3_exit": false,
              "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
            },
            "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
          },
          "fanout": "cron-or-request-path",
          "live_nodes_plane": "human-mesh-users-site-viewers",
          "nodes_plane": "human-mesh-users-uses",
          "software_nodes_plane": "software-worker-fanout",
          "site_live_viewers_plane": "hub-human-page-presence",
          "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
          "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
          "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
          "site_presence_contract": {
            "method": "POST",
            "path": "/runtime/v1/mesh/site-presence",
            "alias": "/runtime/v1/mesh/site-heartbeat",
            "fraggate": {
              "slug": "mesh",
              "op": "site-presence"
            },
            "body": {
              "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
              "viewers": "non-negative integer concurrent human page sessions (0..10000)",
              "kind": "human-page"
            },
            "ttl_ms": 900000,
            "registered_grace_ms": 1209600000,
            "default_heartbeat_mode": "idle",
            "heartbeat_mode": "active | idle | asleep",
            "stale_keeps_registered": true,
            "stale_counts_as_live": false,
            "allowed_hosts": [
              "godlock.uk",
              "azieleliab.com",
              "azielcorpuslibrary.net"
            ],
            "excluded_hosts": [
              "hedidntjump.com"
            ],
            "refused_kinds": [
              "bot",
              "bots",
              "crawler",
              "software",
              "softwares",
              "download",
              "downloads",
              "instance",
              "mcp"
            ],
            "pull_hub_count": false,
            "invent": false,
            "fail_closed": true,
            "read": "single-key",
            "paint": "live_nodes",
            "local_recompute": false,
            "radios": "not required — hub ingest, not a TX join",
            "rate_kind": "mesh_mutate",
            "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
          },
          "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
          "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
          "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "ban_survival": "BAN-SURVIVAL-1.0",
          "spore_spec": "SPORE-1.0",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/runtime/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "neighbor_heal_is_cite": true,
              "neighbor_heal_exec": false,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "neighbor_heal_is_cite": true,
          "neighbor_heal_exec": false,
          "join_is_presence_only": true,
          "join_is_not_login": true,
          "roster_publishes_exec_urls": false,
          "mesh_mutate_rate_kind": "mesh_mutate",
          "roster_cap": 256,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "d2d_carriers": {
            "spec": "D2D-CARRIERS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "plane": "track2-reachability",
            "phase": "B+C+D",
            "phases": {
              "A": "landed",
              "B": "LIVE-when-armed",
              "C": "LIVE-when-session",
              "D": "LIVE-when-three-local-nodes / fixture",
              "E": "scaffold"
            },
            "lan_discovery": "LIVE-when-armed",
            "wifi_discovery": "ARMED-when-HW",
            "bluetooth_discovery": "ARMED-when-HW",
            "rf_discovery": "REFUSE-without-HW",
            "photon_discovery": "REFUSE-without-HW",
            "peer_tunnel": "LIVE-when-session",
            "store_forward": "LIVE-when-three-local-nodes / fixture",
            "store_forward_public": "FG-STUB",
            "worker_runs_store_forward": false,
            "second_device": false,
            "mobile_client": "present-not-demonstrated",
            "mobile_demonstrated": false,
            "app_store_release": false,
            "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
            "bootstrap_list": "scaffold",
            "needs_starting_address": true,
            "shelf_cite": "scaffold",
            "live_multi_provider": false,
            "cold_shelf_live": false,
            "dns_cut": false,
            "origin_cutover": false,
            "warn5_closed": false,
            "worker_door": "FG-STUB",
            "worker_hardware": false,
            "local_node": "qnm-node",
            "get_never_enables": true,
            "separate_from": "cap7-name",
            "cap7_is_name_plane": true,
            "cap7_public_icann": false,
            "cap7_public_egress": false,
            "mirage_is_azvpn": false,
            "aznet_replaces_internet": false,
            "not_a_second_internet": true,
            "alt_internet_live": false,
            "packet_path_live": false,
            "field_1_0": false,
            "warn5": "STANDS-until-demonstrated",
            "warn5_permanent_stay_off": false,
            "preference": "failover",
            "order": [
              "lan",
              "wifi",
              "bluetooth",
              "rf",
              "photon"
            ],
            "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
            "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
            "status": "NOT-READY",
            "code": "FG-STUB",
            "warn5_until": "demonstrated",
            "warn5_by_design": "separate-from-icann",
            "refuse": {
              "packet": "FG-STUB",
              "radio_absent": "QNM-RADIO-ABSENT",
              "cap7_egress": "MG-NO-IP-EXIT",
              "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
              "bearer": "AZP-BEARER-REFUSE",
              "payload": "AZN-NO-PAYLOAD",
              "route": "MESH-NO-ROUTE",
              "stay_off": "MESH-STAY-OFF",
              "nat": "FED-MESH-NAT-REFUSE"
            },
            "carriers": [
              {
                "order": 1,
                "id": "lan",
                "name": "LAN",
                "op": "d2d_lan",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "lan-interface",
                "discovery": "LIVE-when-armed",
                "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
              },
              {
                "order": 2,
                "id": "wifi",
                "name": "Wi-Fi",
                "op": "d2d_wifi",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "wifi-nm",
                "discovery": "ARMED-when-HW",
                "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
              },
              {
                "order": 3,
                "id": "bluetooth",
                "name": "Bluetooth",
                "op": "d2d_bluetooth",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "bluez",
                "discovery": "ARMED-when-HW",
                "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
              },
              {
                "order": 4,
                "id": "rf",
                "name": "RF",
                "op": "d2d_rf",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "rf-beyond-wifi-bt",
                "discovery": "REFUSE-without-HW",
                "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
              },
              {
                "order": 5,
                "id": "photon",
                "name": "Photon",
                "op": "d2d_photon",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "camera-flash",
                "discovery": "REFUSE-without-HW",
                "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
              }
            ],
            "security": {
              "isolation": "single-node security-awareness",
              "phoenix": "local wait / re-seal",
              "mesh_fenced_to_loopback": false,
              "forced_loopback": false,
              "loopback_isolation": false
            },
            "paper": "docs/designs/D2D-CARRIERS-1.0.md",
            "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
          },
          "d2d_status": "NOT-READY",
          "d2d_code": "FG-STUB",
          "packet_path_live": false,
          "alt_internet_live": false,
          "d2d_spec": "D2D-CARRIERS-1.0",
          "federated_mesh": "FED-MESH-1.0",
          "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
          "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        }
      },
      {
        "slug": "miragegrid",
        "name": "MirageGrid",
        "bucket": "plain",
        "domain": "Network",
        "domain_id": "08",
        "placement": "domain-software",
        "status": "live",
        "fraggate_status": "live",
        "public_door": true,
        "public_door_ops": [
          "assign",
          "verify-receipt",
          "nodes",
          "bridge",
          "shuffle",
          "health",
          "skill",
          "doctor",
          "geo-target",
          "session-stick",
          "egress-rotate"
        ],
        "stub_ops": [
          "vpn-hop",
          "hop",
          "tunnel",
          "mesh"
        ],
        "door_label": "live FragGate door — named stub ops refuse",
        "open_live_door": true,
        "version": "0.3.0",
        "one_line": "Assign a short-lived session node and cite Cap-7 mesh-name metadata from a factory that is not a public ICANN registrar. Cap-7 geo, sticky session, and land rotation are LIVE on the Cap-7 plane, not a public egress IP, not a residential IP, and not AZVPN.",
        "description": "Use MirageGrid to assign a short-lived session node and cite Cap-7 mesh-name metadata. The Cap-7 factory is not a public ICANN registrar. It exists for Cap-7 control-plane assignment. geo-target, session-stick, and egress-rotate are LIVE on the Cap-7 plane (region label, sticky mesh node and factory land, land rotate among 7 sites). They are not a public egress IP, not a residential IP, not a Cloudflare geo-exit pool, not a sticky public IP, not packet forwarding, not ICANN DNS, and not AZVPN. The public MirageGrid Worker Cap-7 control plane is LIVE (https://miragegrid.vibelock.workers.dev/v1/egress and https://miragegrid.vibelock.workers.dev/v1/planned). vpn-hop, hop, tunnel, and mesh stay stub. AZVPN remains the suite VPN. Track 2 carriers (LAN → Wi-Fi → Bluetooth → RF → Photon light flashes) stay NOT-READY and FG-STUB on this public door. Local LAN discovery is a separate node path.",
        "worker_home": "https://miragegrid-download-tracker.vibelock.workers.dev/",
        "worker_home_note": null,
        "download_url": "https://miragegrid-download-tracker.vibelock.workers.dev/download",
        "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "github": "https://github.com/AzielEliab/miragegrid",
        "mcp": "https://godlock.uk/runtime/mcp",
        "agent": {
          "mcp": "https://godlock.uk/runtime/mcp",
          "skill": "https://godlock.uk/runtime/v1/skill",
          "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
          "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=miragegrid",
          "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
          "fraggate_call_executes": true,
          "open_live_door": true,
          "software": "https://godlock.uk/runtime/v1/software",
          "pull": "https://godlock.uk/runtime/v1/pull/miragegrid",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "cea1854f20a807360d68c3b223343088abe09941ae77e406fd45ee4fe1d1126c",
        "updated_at": null,
        "git_sha": null,
        "git_sha_tracks_deployed_tip": false,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/runtime/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "security": {
            "model": "single-node-security-awareness",
            "isolates": "bad-peer-or-self",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "phoenix": "local-wait-reseal",
            "phoenix_lock": true,
            "public_hostname_resurrection": false,
            "loopback_bearer": "L1-optional",
            "operator_locks": [
              {
                "n": 1,
                "id": "single-node-security-awareness",
                "status": "LIVE",
                "mesh_fenced_to_loopback": false
              },
              {
                "n": 2,
                "id": "phoenix-reboot-loop",
                "status": "LIVE",
                "phoenix": "local-wait-reseal",
                "phoenix_lock": true,
                "public_hostname_resurrection": false
              },
              {
                "n": 3,
                "id": "open-world-awareness",
                "status": "live-when-configured",
                "law": "LIVE",
                "bind": "0.0.0.0",
                "worker_socket": false,
                "forced_loopback_is_mesh_fence": false,
                "loopback_isolation_is_mesh_fence": false
              }
            ],
            "open_world_awareness": {
              "spec": "OPEN-WORLD-AWARENESS-1.0",
              "author": "Aziel Eliab",
              "identity": "Aziel Eliab",
              "open_world_awareness": true,
              "bind": "0.0.0.0",
              "all_interfaces": true,
              "law": "LIVE",
              "status": "live-when-configured",
              "live": false,
              "socket": "live-when-configured",
              "worker_socket": false,
              "qnm_node_bind": "live-when-configured",
              "mock": false,
              "forced_loopback": false,
              "loopback_isolation": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false,
              "mesh_fenced_to_loopback": false,
              "public_egress_ip": false,
              "residential": false,
              "cf_geo_exit": false,
              "cf_geo_exit_pool": false,
              "sticky_public_ip": false,
              "packet_forward": false,
              "packet_forwarding": false,
              "public_icann": false,
              "cap7_is_icann": false,
              "replaces_internet": false,
              "not_a_second_internet": true,
              "hosted_vpn": false,
              "payload_host": false,
              "vpn_hop": false,
              "wireguard": false,
              "openvpn": false,
              "l3_exit": false,
              "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
            },
            "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
          },
          "fanout": "cron-or-request-path",
          "live_nodes_plane": "human-mesh-users-site-viewers",
          "nodes_plane": "human-mesh-users-uses",
          "software_nodes_plane": "software-worker-fanout",
          "site_live_viewers_plane": "hub-human-page-presence",
          "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
          "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
          "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
          "site_presence_contract": {
            "method": "POST",
            "path": "/runtime/v1/mesh/site-presence",
            "alias": "/runtime/v1/mesh/site-heartbeat",
            "fraggate": {
              "slug": "mesh",
              "op": "site-presence"
            },
            "body": {
              "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
              "viewers": "non-negative integer concurrent human page sessions (0..10000)",
              "kind": "human-page"
            },
            "ttl_ms": 900000,
            "registered_grace_ms": 1209600000,
            "default_heartbeat_mode": "idle",
            "heartbeat_mode": "active | idle | asleep",
            "stale_keeps_registered": true,
            "stale_counts_as_live": false,
            "allowed_hosts": [
              "godlock.uk",
              "azieleliab.com",
              "azielcorpuslibrary.net"
            ],
            "excluded_hosts": [
              "hedidntjump.com"
            ],
            "refused_kinds": [
              "bot",
              "bots",
              "crawler",
              "software",
              "softwares",
              "download",
              "downloads",
              "instance",
              "mcp"
            ],
            "pull_hub_count": false,
            "invent": false,
            "fail_closed": true,
            "read": "single-key",
            "paint": "live_nodes",
            "local_recompute": false,
            "radios": "not required — hub ingest, not a TX join",
            "rate_kind": "mesh_mutate",
            "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
          },
          "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
          "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
          "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "ban_survival": "BAN-SURVIVAL-1.0",
          "spore_spec": "SPORE-1.0",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/runtime/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "neighbor_heal_is_cite": true,
              "neighbor_heal_exec": false,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "neighbor_heal_is_cite": true,
          "neighbor_heal_exec": false,
          "join_is_presence_only": true,
          "join_is_not_login": true,
          "roster_publishes_exec_urls": false,
          "mesh_mutate_rate_kind": "mesh_mutate",
          "roster_cap": 256,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "d2d_carriers": {
            "spec": "D2D-CARRIERS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "plane": "track2-reachability",
            "phase": "B+C+D",
            "phases": {
              "A": "landed",
              "B": "LIVE-when-armed",
              "C": "LIVE-when-session",
              "D": "LIVE-when-three-local-nodes / fixture",
              "E": "scaffold"
            },
            "lan_discovery": "LIVE-when-armed",
            "wifi_discovery": "ARMED-when-HW",
            "bluetooth_discovery": "ARMED-when-HW",
            "rf_discovery": "REFUSE-without-HW",
            "photon_discovery": "REFUSE-without-HW",
            "peer_tunnel": "LIVE-when-session",
            "store_forward": "LIVE-when-three-local-nodes / fixture",
            "store_forward_public": "FG-STUB",
            "worker_runs_store_forward": false,
            "second_device": false,
            "mobile_client": "present-not-demonstrated",
            "mobile_demonstrated": false,
            "app_store_release": false,
            "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
            "bootstrap_list": "scaffold",
            "needs_starting_address": true,
            "shelf_cite": "scaffold",
            "live_multi_provider": false,
            "cold_shelf_live": false,
            "dns_cut": false,
            "origin_cutover": false,
            "warn5_closed": false,
            "worker_door": "FG-STUB",
            "worker_hardware": false,
            "local_node": "qnm-node",
            "get_never_enables": true,
            "separate_from": "cap7-name",
            "cap7_is_name_plane": true,
            "cap7_public_icann": false,
            "cap7_public_egress": false,
            "mirage_is_azvpn": false,
            "aznet_replaces_internet": false,
            "not_a_second_internet": true,
            "alt_internet_live": false,
            "packet_path_live": false,
            "field_1_0": false,
            "warn5": "STANDS-until-demonstrated",
            "warn5_permanent_stay_off": false,
            "preference": "failover",
            "order": [
              "lan",
              "wifi",
              "bluetooth",
              "rf",
              "photon"
            ],
            "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
            "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
            "status": "NOT-READY",
            "code": "FG-STUB",
            "warn5_until": "demonstrated",
            "warn5_by_design": "separate-from-icann",
            "refuse": {
              "packet": "FG-STUB",
              "radio_absent": "QNM-RADIO-ABSENT",
              "cap7_egress": "MG-NO-IP-EXIT",
              "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
              "bearer": "AZP-BEARER-REFUSE",
              "payload": "AZN-NO-PAYLOAD",
              "route": "MESH-NO-ROUTE",
              "stay_off": "MESH-STAY-OFF",
              "nat": "FED-MESH-NAT-REFUSE"
            },
            "carriers": [
              {
                "order": 1,
                "id": "lan",
                "name": "LAN",
                "op": "d2d_lan",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "lan-interface",
                "discovery": "LIVE-when-armed",
                "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
              },
              {
                "order": 2,
                "id": "wifi",
                "name": "Wi-Fi",
                "op": "d2d_wifi",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "wifi-nm",
                "discovery": "ARMED-when-HW",
                "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
              },
              {
                "order": 3,
                "id": "bluetooth",
                "name": "Bluetooth",
                "op": "d2d_bluetooth",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "bluez",
                "discovery": "ARMED-when-HW",
                "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
              },
              {
                "order": 4,
                "id": "rf",
                "name": "RF",
                "op": "d2d_rf",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "rf-beyond-wifi-bt",
                "discovery": "REFUSE-without-HW",
                "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
              },
              {
                "order": 5,
                "id": "photon",
                "name": "Photon",
                "op": "d2d_photon",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "camera-flash",
                "discovery": "REFUSE-without-HW",
                "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
              }
            ],
            "security": {
              "isolation": "single-node security-awareness",
              "phoenix": "local wait / re-seal",
              "mesh_fenced_to_loopback": false,
              "forced_loopback": false,
              "loopback_isolation": false
            },
            "paper": "docs/designs/D2D-CARRIERS-1.0.md",
            "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
          },
          "d2d_status": "NOT-READY",
          "d2d_code": "FG-STUB",
          "packet_path_live": false,
          "alt_internet_live": false,
          "d2d_spec": "D2D-CARRIERS-1.0",
          "federated_mesh": "FED-MESH-1.0",
          "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
          "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        }
      },
      {
        "slug": "mmconsensus",
        "name": "MMConsensus",
        "bucket": "plain",
        "domain": null,
        "domain_id": null,
        "placement": "consensus-review",
        "status": "live",
        "fraggate_status": "live",
        "public_door": true,
        "public_door_ops": [
          "health",
          "skill",
          "doctor",
          "tally",
          "agree",
          "limitation"
        ],
        "stub_ops": [
          "live_model_call",
          "openai",
          "anthropic",
          "grok",
          "blend_models",
          "remote_infer",
          "truth_score",
          "court"
        ],
        "door_label": "live FragGate door — named stub ops refuse",
        "open_live_door": true,
        "version": "0.1.0",
        "one_line": "Tally consensus from opinions you already posted.",
        "description": "Use MMConsensus to majority-count or compare posted opinions. It exists to structure agreement you already have.",
        "worker_home": null,
        "worker_home_note": "No separate product Worker. The in-repo door is FragGate on this runtime. Do not invent a download-tracker URL.",
        "in_repo_home": "https://godlock.uk/runtime/p/mmconsensus",
        "download_url": null,
        "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "github": "https://github.com/AzielEliab/aziel-runtime",
        "mcp": "https://godlock.uk/runtime/mcp",
        "agent": {
          "mcp": "https://godlock.uk/runtime/mcp",
          "skill": "https://godlock.uk/runtime/v1/skill",
          "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
          "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=mmconsensus",
          "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
          "fraggate_call_executes": true,
          "open_live_door": true,
          "software": "https://godlock.uk/runtime/v1/software",
          "pull": "https://godlock.uk/runtime/v1/pull/mmconsensus",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "9624f144b1eacfc11cf86fe45ed83acb6f65fa324629668510c55f1fcabe6fe7",
        "updated_at": null,
        "git_sha": null,
        "git_sha_tracks_deployed_tip": false,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/runtime/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "security": {
            "model": "single-node-security-awareness",
            "isolates": "bad-peer-or-self",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "phoenix": "local-wait-reseal",
            "phoenix_lock": true,
            "public_hostname_resurrection": false,
            "loopback_bearer": "L1-optional",
            "operator_locks": [
              {
                "n": 1,
                "id": "single-node-security-awareness",
                "status": "LIVE",
                "mesh_fenced_to_loopback": false
              },
              {
                "n": 2,
                "id": "phoenix-reboot-loop",
                "status": "LIVE",
                "phoenix": "local-wait-reseal",
                "phoenix_lock": true,
                "public_hostname_resurrection": false
              },
              {
                "n": 3,
                "id": "open-world-awareness",
                "status": "live-when-configured",
                "law": "LIVE",
                "bind": "0.0.0.0",
                "worker_socket": false,
                "forced_loopback_is_mesh_fence": false,
                "loopback_isolation_is_mesh_fence": false
              }
            ],
            "open_world_awareness": {
              "spec": "OPEN-WORLD-AWARENESS-1.0",
              "author": "Aziel Eliab",
              "identity": "Aziel Eliab",
              "open_world_awareness": true,
              "bind": "0.0.0.0",
              "all_interfaces": true,
              "law": "LIVE",
              "status": "live-when-configured",
              "live": false,
              "socket": "live-when-configured",
              "worker_socket": false,
              "qnm_node_bind": "live-when-configured",
              "mock": false,
              "forced_loopback": false,
              "loopback_isolation": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false,
              "mesh_fenced_to_loopback": false,
              "public_egress_ip": false,
              "residential": false,
              "cf_geo_exit": false,
              "cf_geo_exit_pool": false,
              "sticky_public_ip": false,
              "packet_forward": false,
              "packet_forwarding": false,
              "public_icann": false,
              "cap7_is_icann": false,
              "replaces_internet": false,
              "not_a_second_internet": true,
              "hosted_vpn": false,
              "payload_host": false,
              "vpn_hop": false,
              "wireguard": false,
              "openvpn": false,
              "l3_exit": false,
              "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
            },
            "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
          },
          "fanout": "cron-or-request-path",
          "live_nodes_plane": "human-mesh-users-site-viewers",
          "nodes_plane": "human-mesh-users-uses",
          "software_nodes_plane": "software-worker-fanout",
          "site_live_viewers_plane": "hub-human-page-presence",
          "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
          "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
          "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
          "site_presence_contract": {
            "method": "POST",
            "path": "/runtime/v1/mesh/site-presence",
            "alias": "/runtime/v1/mesh/site-heartbeat",
            "fraggate": {
              "slug": "mesh",
              "op": "site-presence"
            },
            "body": {
              "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
              "viewers": "non-negative integer concurrent human page sessions (0..10000)",
              "kind": "human-page"
            },
            "ttl_ms": 900000,
            "registered_grace_ms": 1209600000,
            "default_heartbeat_mode": "idle",
            "heartbeat_mode": "active | idle | asleep",
            "stale_keeps_registered": true,
            "stale_counts_as_live": false,
            "allowed_hosts": [
              "godlock.uk",
              "azieleliab.com",
              "azielcorpuslibrary.net"
            ],
            "excluded_hosts": [
              "hedidntjump.com"
            ],
            "refused_kinds": [
              "bot",
              "bots",
              "crawler",
              "software",
              "softwares",
              "download",
              "downloads",
              "instance",
              "mcp"
            ],
            "pull_hub_count": false,
            "invent": false,
            "fail_closed": true,
            "read": "single-key",
            "paint": "live_nodes",
            "local_recompute": false,
            "radios": "not required — hub ingest, not a TX join",
            "rate_kind": "mesh_mutate",
            "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
          },
          "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
          "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
          "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "ban_survival": "BAN-SURVIVAL-1.0",
          "spore_spec": "SPORE-1.0",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/runtime/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "neighbor_heal_is_cite": true,
              "neighbor_heal_exec": false,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "neighbor_heal_is_cite": true,
          "neighbor_heal_exec": false,
          "join_is_presence_only": true,
          "join_is_not_login": true,
          "roster_publishes_exec_urls": false,
          "mesh_mutate_rate_kind": "mesh_mutate",
          "roster_cap": 256,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "d2d_carriers": {
            "spec": "D2D-CARRIERS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "plane": "track2-reachability",
            "phase": "B+C+D",
            "phases": {
              "A": "landed",
              "B": "LIVE-when-armed",
              "C": "LIVE-when-session",
              "D": "LIVE-when-three-local-nodes / fixture",
              "E": "scaffold"
            },
            "lan_discovery": "LIVE-when-armed",
            "wifi_discovery": "ARMED-when-HW",
            "bluetooth_discovery": "ARMED-when-HW",
            "rf_discovery": "REFUSE-without-HW",
            "photon_discovery": "REFUSE-without-HW",
            "peer_tunnel": "LIVE-when-session",
            "store_forward": "LIVE-when-three-local-nodes / fixture",
            "store_forward_public": "FG-STUB",
            "worker_runs_store_forward": false,
            "second_device": false,
            "mobile_client": "present-not-demonstrated",
            "mobile_demonstrated": false,
            "app_store_release": false,
            "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
            "bootstrap_list": "scaffold",
            "needs_starting_address": true,
            "shelf_cite": "scaffold",
            "live_multi_provider": false,
            "cold_shelf_live": false,
            "dns_cut": false,
            "origin_cutover": false,
            "warn5_closed": false,
            "worker_door": "FG-STUB",
            "worker_hardware": false,
            "local_node": "qnm-node",
            "get_never_enables": true,
            "separate_from": "cap7-name",
            "cap7_is_name_plane": true,
            "cap7_public_icann": false,
            "cap7_public_egress": false,
            "mirage_is_azvpn": false,
            "aznet_replaces_internet": false,
            "not_a_second_internet": true,
            "alt_internet_live": false,
            "packet_path_live": false,
            "field_1_0": false,
            "warn5": "STANDS-until-demonstrated",
            "warn5_permanent_stay_off": false,
            "preference": "failover",
            "order": [
              "lan",
              "wifi",
              "bluetooth",
              "rf",
              "photon"
            ],
            "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
            "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
            "status": "NOT-READY",
            "code": "FG-STUB",
            "warn5_until": "demonstrated",
            "warn5_by_design": "separate-from-icann",
            "refuse": {
              "packet": "FG-STUB",
              "radio_absent": "QNM-RADIO-ABSENT",
              "cap7_egress": "MG-NO-IP-EXIT",
              "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
              "bearer": "AZP-BEARER-REFUSE",
              "payload": "AZN-NO-PAYLOAD",
              "route": "MESH-NO-ROUTE",
              "stay_off": "MESH-STAY-OFF",
              "nat": "FED-MESH-NAT-REFUSE"
            },
            "carriers": [
              {
                "order": 1,
                "id": "lan",
                "name": "LAN",
                "op": "d2d_lan",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "lan-interface",
                "discovery": "LIVE-when-armed",
                "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
              },
              {
                "order": 2,
                "id": "wifi",
                "name": "Wi-Fi",
                "op": "d2d_wifi",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "wifi-nm",
                "discovery": "ARMED-when-HW",
                "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
              },
              {
                "order": 3,
                "id": "bluetooth",
                "name": "Bluetooth",
                "op": "d2d_bluetooth",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "bluez",
                "discovery": "ARMED-when-HW",
                "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
              },
              {
                "order": 4,
                "id": "rf",
                "name": "RF",
                "op": "d2d_rf",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "rf-beyond-wifi-bt",
                "discovery": "REFUSE-without-HW",
                "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
              },
              {
                "order": 5,
                "id": "photon",
                "name": "Photon",
                "op": "d2d_photon",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "camera-flash",
                "discovery": "REFUSE-without-HW",
                "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
              }
            ],
            "security": {
              "isolation": "single-node security-awareness",
              "phoenix": "local wait / re-seal",
              "mesh_fenced_to_loopback": false,
              "forced_loopback": false,
              "loopback_isolation": false
            },
            "paper": "docs/designs/D2D-CARRIERS-1.0.md",
            "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
          },
          "d2d_status": "NOT-READY",
          "d2d_code": "FG-STUB",
          "packet_path_live": false,
          "alt_internet_live": false,
          "d2d_spec": "D2D-CARRIERS-1.0",
          "federated_mesh": "FED-MESH-1.0",
          "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
          "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        }
      },
      {
        "slug": "postking",
        "name": "Post-King Chess",
        "bucket": "plain",
        "domain": "Simulation",
        "domain_id": "10",
        "placement": "domain-software",
        "status": "live",
        "fraggate_status": "live",
        "public_door": true,
        "public_door_ops": [
          "new",
          "move",
          "status",
          "health",
          "skill",
          "doctor"
        ],
        "stub_ops": [],
        "door_label": "live FragGate door",
        "open_live_door": true,
        "version": "0.1.0",
        "one_line": "Play continuity chess where the aim is to remain.",
        "description": "Use Post-King Chess for a game where the human is king-bound and the AI has a Node. It exists to practice remaining.",
        "worker_home": "https://postking-download-tracker.vibelock.workers.dev/",
        "worker_home_note": null,
        "download_url": "https://postking-download-tracker.vibelock.workers.dev/download",
        "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "github": "https://github.com/AzielEliab/postking-chess",
        "mcp": "https://godlock.uk/runtime/mcp",
        "agent": {
          "mcp": "https://godlock.uk/runtime/mcp",
          "skill": "https://godlock.uk/runtime/v1/skill",
          "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
          "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=postking",
          "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
          "fraggate_call_executes": true,
          "open_live_door": true,
          "software": "https://godlock.uk/runtime/v1/software",
          "pull": "https://godlock.uk/runtime/v1/pull/postking",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "d25f9e81813816349e5e1c2064227ae193b9e3480cbea128a359a929a8232307",
        "updated_at": null,
        "git_sha": null,
        "git_sha_tracks_deployed_tip": false,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/runtime/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "security": {
            "model": "single-node-security-awareness",
            "isolates": "bad-peer-or-self",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "phoenix": "local-wait-reseal",
            "phoenix_lock": true,
            "public_hostname_resurrection": false,
            "loopback_bearer": "L1-optional",
            "operator_locks": [
              {
                "n": 1,
                "id": "single-node-security-awareness",
                "status": "LIVE",
                "mesh_fenced_to_loopback": false
              },
              {
                "n": 2,
                "id": "phoenix-reboot-loop",
                "status": "LIVE",
                "phoenix": "local-wait-reseal",
                "phoenix_lock": true,
                "public_hostname_resurrection": false
              },
              {
                "n": 3,
                "id": "open-world-awareness",
                "status": "live-when-configured",
                "law": "LIVE",
                "bind": "0.0.0.0",
                "worker_socket": false,
                "forced_loopback_is_mesh_fence": false,
                "loopback_isolation_is_mesh_fence": false
              }
            ],
            "open_world_awareness": {
              "spec": "OPEN-WORLD-AWARENESS-1.0",
              "author": "Aziel Eliab",
              "identity": "Aziel Eliab",
              "open_world_awareness": true,
              "bind": "0.0.0.0",
              "all_interfaces": true,
              "law": "LIVE",
              "status": "live-when-configured",
              "live": false,
              "socket": "live-when-configured",
              "worker_socket": false,
              "qnm_node_bind": "live-when-configured",
              "mock": false,
              "forced_loopback": false,
              "loopback_isolation": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false,
              "mesh_fenced_to_loopback": false,
              "public_egress_ip": false,
              "residential": false,
              "cf_geo_exit": false,
              "cf_geo_exit_pool": false,
              "sticky_public_ip": false,
              "packet_forward": false,
              "packet_forwarding": false,
              "public_icann": false,
              "cap7_is_icann": false,
              "replaces_internet": false,
              "not_a_second_internet": true,
              "hosted_vpn": false,
              "payload_host": false,
              "vpn_hop": false,
              "wireguard": false,
              "openvpn": false,
              "l3_exit": false,
              "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
            },
            "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
          },
          "fanout": "cron-or-request-path",
          "live_nodes_plane": "human-mesh-users-site-viewers",
          "nodes_plane": "human-mesh-users-uses",
          "software_nodes_plane": "software-worker-fanout",
          "site_live_viewers_plane": "hub-human-page-presence",
          "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
          "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
          "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
          "site_presence_contract": {
            "method": "POST",
            "path": "/runtime/v1/mesh/site-presence",
            "alias": "/runtime/v1/mesh/site-heartbeat",
            "fraggate": {
              "slug": "mesh",
              "op": "site-presence"
            },
            "body": {
              "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
              "viewers": "non-negative integer concurrent human page sessions (0..10000)",
              "kind": "human-page"
            },
            "ttl_ms": 900000,
            "registered_grace_ms": 1209600000,
            "default_heartbeat_mode": "idle",
            "heartbeat_mode": "active | idle | asleep",
            "stale_keeps_registered": true,
            "stale_counts_as_live": false,
            "allowed_hosts": [
              "godlock.uk",
              "azieleliab.com",
              "azielcorpuslibrary.net"
            ],
            "excluded_hosts": [
              "hedidntjump.com"
            ],
            "refused_kinds": [
              "bot",
              "bots",
              "crawler",
              "software",
              "softwares",
              "download",
              "downloads",
              "instance",
              "mcp"
            ],
            "pull_hub_count": false,
            "invent": false,
            "fail_closed": true,
            "read": "single-key",
            "paint": "live_nodes",
            "local_recompute": false,
            "radios": "not required — hub ingest, not a TX join",
            "rate_kind": "mesh_mutate",
            "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
          },
          "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
          "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
          "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "ban_survival": "BAN-SURVIVAL-1.0",
          "spore_spec": "SPORE-1.0",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/runtime/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "neighbor_heal_is_cite": true,
              "neighbor_heal_exec": false,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "neighbor_heal_is_cite": true,
          "neighbor_heal_exec": false,
          "join_is_presence_only": true,
          "join_is_not_login": true,
          "roster_publishes_exec_urls": false,
          "mesh_mutate_rate_kind": "mesh_mutate",
          "roster_cap": 256,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "d2d_carriers": {
            "spec": "D2D-CARRIERS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "plane": "track2-reachability",
            "phase": "B+C+D",
            "phases": {
              "A": "landed",
              "B": "LIVE-when-armed",
              "C": "LIVE-when-session",
              "D": "LIVE-when-three-local-nodes / fixture",
              "E": "scaffold"
            },
            "lan_discovery": "LIVE-when-armed",
            "wifi_discovery": "ARMED-when-HW",
            "bluetooth_discovery": "ARMED-when-HW",
            "rf_discovery": "REFUSE-without-HW",
            "photon_discovery": "REFUSE-without-HW",
            "peer_tunnel": "LIVE-when-session",
            "store_forward": "LIVE-when-three-local-nodes / fixture",
            "store_forward_public": "FG-STUB",
            "worker_runs_store_forward": false,
            "second_device": false,
            "mobile_client": "present-not-demonstrated",
            "mobile_demonstrated": false,
            "app_store_release": false,
            "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
            "bootstrap_list": "scaffold",
            "needs_starting_address": true,
            "shelf_cite": "scaffold",
            "live_multi_provider": false,
            "cold_shelf_live": false,
            "dns_cut": false,
            "origin_cutover": false,
            "warn5_closed": false,
            "worker_door": "FG-STUB",
            "worker_hardware": false,
            "local_node": "qnm-node",
            "get_never_enables": true,
            "separate_from": "cap7-name",
            "cap7_is_name_plane": true,
            "cap7_public_icann": false,
            "cap7_public_egress": false,
            "mirage_is_azvpn": false,
            "aznet_replaces_internet": false,
            "not_a_second_internet": true,
            "alt_internet_live": false,
            "packet_path_live": false,
            "field_1_0": false,
            "warn5": "STANDS-until-demonstrated",
            "warn5_permanent_stay_off": false,
            "preference": "failover",
            "order": [
              "lan",
              "wifi",
              "bluetooth",
              "rf",
              "photon"
            ],
            "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
            "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
            "status": "NOT-READY",
            "code": "FG-STUB",
            "warn5_until": "demonstrated",
            "warn5_by_design": "separate-from-icann",
            "refuse": {
              "packet": "FG-STUB",
              "radio_absent": "QNM-RADIO-ABSENT",
              "cap7_egress": "MG-NO-IP-EXIT",
              "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
              "bearer": "AZP-BEARER-REFUSE",
              "payload": "AZN-NO-PAYLOAD",
              "route": "MESH-NO-ROUTE",
              "stay_off": "MESH-STAY-OFF",
              "nat": "FED-MESH-NAT-REFUSE"
            },
            "carriers": [
              {
                "order": 1,
                "id": "lan",
                "name": "LAN",
                "op": "d2d_lan",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "lan-interface",
                "discovery": "LIVE-when-armed",
                "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
              },
              {
                "order": 2,
                "id": "wifi",
                "name": "Wi-Fi",
                "op": "d2d_wifi",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "wifi-nm",
                "discovery": "ARMED-when-HW",
                "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
              },
              {
                "order": 3,
                "id": "bluetooth",
                "name": "Bluetooth",
                "op": "d2d_bluetooth",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "bluez",
                "discovery": "ARMED-when-HW",
                "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
              },
              {
                "order": 4,
                "id": "rf",
                "name": "RF",
                "op": "d2d_rf",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "rf-beyond-wifi-bt",
                "discovery": "REFUSE-without-HW",
                "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
              },
              {
                "order": 5,
                "id": "photon",
                "name": "Photon",
                "op": "d2d_photon",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "camera-flash",
                "discovery": "REFUSE-without-HW",
                "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
              }
            ],
            "security": {
              "isolation": "single-node security-awareness",
              "phoenix": "local wait / re-seal",
              "mesh_fenced_to_loopback": false,
              "forced_loopback": false,
              "loopback_isolation": false
            },
            "paper": "docs/designs/D2D-CARRIERS-1.0.md",
            "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
          },
          "d2d_status": "NOT-READY",
          "d2d_code": "FG-STUB",
          "packet_path_live": false,
          "alt_internet_live": false,
          "d2d_spec": "D2D-CARRIERS-1.0",
          "federated_mesh": "FED-MESH-1.0",
          "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
          "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        }
      },
      {
        "slug": "staticclock",
        "name": "StaticClock",
        "bucket": "plain",
        "domain": "Core Time",
        "domain_id": "11",
        "placement": "domain-software",
        "status": "live",
        "fraggate_status": "live",
        "public_door": true,
        "public_door_ops": [
          "advise",
          "advisory",
          "anchors",
          "click",
          "verify",
          "timeslate",
          "import_export",
          "doctor",
          "health",
          "skill"
        ],
        "stub_ops": [
          "rollback",
          "remote_shell",
          "scheduler"
        ],
        "door_label": "live FragGate door — named stub ops refuse",
        "open_live_door": true,
        "version": "0.2.0",
        "one_line": "Record a forward-only gear-click timeline and read companion advice.",
        "description": "Use StaticClock to click a client-held chain forward and read advisory fields. It exists as a plain clock of actions.",
        "worker_home": "https://staticclock-download-tracker.vibelock.workers.dev/",
        "worker_home_note": null,
        "download_url": "https://staticclock-download-tracker.vibelock.workers.dev/download",
        "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "github": "https://github.com/AzielEliab/staticclock",
        "mcp": "https://godlock.uk/runtime/mcp",
        "agent": {
          "mcp": "https://godlock.uk/runtime/mcp",
          "skill": "https://godlock.uk/runtime/v1/skill",
          "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
          "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=staticclock",
          "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
          "fraggate_call_executes": true,
          "open_live_door": true,
          "software": "https://godlock.uk/runtime/v1/software",
          "pull": "https://godlock.uk/runtime/v1/pull/staticclock",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "7d6da0f2ef3fdbeedc2e96f5676a58847a8cd09dc94053009814dfa4fd282fb3",
        "updated_at": null,
        "git_sha": null,
        "git_sha_tracks_deployed_tip": false,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/runtime/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "security": {
            "model": "single-node-security-awareness",
            "isolates": "bad-peer-or-self",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "phoenix": "local-wait-reseal",
            "phoenix_lock": true,
            "public_hostname_resurrection": false,
            "loopback_bearer": "L1-optional",
            "operator_locks": [
              {
                "n": 1,
                "id": "single-node-security-awareness",
                "status": "LIVE",
                "mesh_fenced_to_loopback": false
              },
              {
                "n": 2,
                "id": "phoenix-reboot-loop",
                "status": "LIVE",
                "phoenix": "local-wait-reseal",
                "phoenix_lock": true,
                "public_hostname_resurrection": false
              },
              {
                "n": 3,
                "id": "open-world-awareness",
                "status": "live-when-configured",
                "law": "LIVE",
                "bind": "0.0.0.0",
                "worker_socket": false,
                "forced_loopback_is_mesh_fence": false,
                "loopback_isolation_is_mesh_fence": false
              }
            ],
            "open_world_awareness": {
              "spec": "OPEN-WORLD-AWARENESS-1.0",
              "author": "Aziel Eliab",
              "identity": "Aziel Eliab",
              "open_world_awareness": true,
              "bind": "0.0.0.0",
              "all_interfaces": true,
              "law": "LIVE",
              "status": "live-when-configured",
              "live": false,
              "socket": "live-when-configured",
              "worker_socket": false,
              "qnm_node_bind": "live-when-configured",
              "mock": false,
              "forced_loopback": false,
              "loopback_isolation": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false,
              "mesh_fenced_to_loopback": false,
              "public_egress_ip": false,
              "residential": false,
              "cf_geo_exit": false,
              "cf_geo_exit_pool": false,
              "sticky_public_ip": false,
              "packet_forward": false,
              "packet_forwarding": false,
              "public_icann": false,
              "cap7_is_icann": false,
              "replaces_internet": false,
              "not_a_second_internet": true,
              "hosted_vpn": false,
              "payload_host": false,
              "vpn_hop": false,
              "wireguard": false,
              "openvpn": false,
              "l3_exit": false,
              "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
            },
            "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
          },
          "fanout": "cron-or-request-path",
          "live_nodes_plane": "human-mesh-users-site-viewers",
          "nodes_plane": "human-mesh-users-uses",
          "software_nodes_plane": "software-worker-fanout",
          "site_live_viewers_plane": "hub-human-page-presence",
          "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
          "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
          "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
          "site_presence_contract": {
            "method": "POST",
            "path": "/runtime/v1/mesh/site-presence",
            "alias": "/runtime/v1/mesh/site-heartbeat",
            "fraggate": {
              "slug": "mesh",
              "op": "site-presence"
            },
            "body": {
              "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
              "viewers": "non-negative integer concurrent human page sessions (0..10000)",
              "kind": "human-page"
            },
            "ttl_ms": 900000,
            "registered_grace_ms": 1209600000,
            "default_heartbeat_mode": "idle",
            "heartbeat_mode": "active | idle | asleep",
            "stale_keeps_registered": true,
            "stale_counts_as_live": false,
            "allowed_hosts": [
              "godlock.uk",
              "azieleliab.com",
              "azielcorpuslibrary.net"
            ],
            "excluded_hosts": [
              "hedidntjump.com"
            ],
            "refused_kinds": [
              "bot",
              "bots",
              "crawler",
              "software",
              "softwares",
              "download",
              "downloads",
              "instance",
              "mcp"
            ],
            "pull_hub_count": false,
            "invent": false,
            "fail_closed": true,
            "read": "single-key",
            "paint": "live_nodes",
            "local_recompute": false,
            "radios": "not required — hub ingest, not a TX join",
            "rate_kind": "mesh_mutate",
            "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
          },
          "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
          "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
          "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "ban_survival": "BAN-SURVIVAL-1.0",
          "spore_spec": "SPORE-1.0",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/runtime/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "neighbor_heal_is_cite": true,
              "neighbor_heal_exec": false,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "neighbor_heal_is_cite": true,
          "neighbor_heal_exec": false,
          "join_is_presence_only": true,
          "join_is_not_login": true,
          "roster_publishes_exec_urls": false,
          "mesh_mutate_rate_kind": "mesh_mutate",
          "roster_cap": 256,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "d2d_carriers": {
            "spec": "D2D-CARRIERS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "plane": "track2-reachability",
            "phase": "B+C+D",
            "phases": {
              "A": "landed",
              "B": "LIVE-when-armed",
              "C": "LIVE-when-session",
              "D": "LIVE-when-three-local-nodes / fixture",
              "E": "scaffold"
            },
            "lan_discovery": "LIVE-when-armed",
            "wifi_discovery": "ARMED-when-HW",
            "bluetooth_discovery": "ARMED-when-HW",
            "rf_discovery": "REFUSE-without-HW",
            "photon_discovery": "REFUSE-without-HW",
            "peer_tunnel": "LIVE-when-session",
            "store_forward": "LIVE-when-three-local-nodes / fixture",
            "store_forward_public": "FG-STUB",
            "worker_runs_store_forward": false,
            "second_device": false,
            "mobile_client": "present-not-demonstrated",
            "mobile_demonstrated": false,
            "app_store_release": false,
            "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
            "bootstrap_list": "scaffold",
            "needs_starting_address": true,
            "shelf_cite": "scaffold",
            "live_multi_provider": false,
            "cold_shelf_live": false,
            "dns_cut": false,
            "origin_cutover": false,
            "warn5_closed": false,
            "worker_door": "FG-STUB",
            "worker_hardware": false,
            "local_node": "qnm-node",
            "get_never_enables": true,
            "separate_from": "cap7-name",
            "cap7_is_name_plane": true,
            "cap7_public_icann": false,
            "cap7_public_egress": false,
            "mirage_is_azvpn": false,
            "aznet_replaces_internet": false,
            "not_a_second_internet": true,
            "alt_internet_live": false,
            "packet_path_live": false,
            "field_1_0": false,
            "warn5": "STANDS-until-demonstrated",
            "warn5_permanent_stay_off": false,
            "preference": "failover",
            "order": [
              "lan",
              "wifi",
              "bluetooth",
              "rf",
              "photon"
            ],
            "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
            "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
            "status": "NOT-READY",
            "code": "FG-STUB",
            "warn5_until": "demonstrated",
            "warn5_by_design": "separate-from-icann",
            "refuse": {
              "packet": "FG-STUB",
              "radio_absent": "QNM-RADIO-ABSENT",
              "cap7_egress": "MG-NO-IP-EXIT",
              "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
              "bearer": "AZP-BEARER-REFUSE",
              "payload": "AZN-NO-PAYLOAD",
              "route": "MESH-NO-ROUTE",
              "stay_off": "MESH-STAY-OFF",
              "nat": "FED-MESH-NAT-REFUSE"
            },
            "carriers": [
              {
                "order": 1,
                "id": "lan",
                "name": "LAN",
                "op": "d2d_lan",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "lan-interface",
                "discovery": "LIVE-when-armed",
                "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
              },
              {
                "order": 2,
                "id": "wifi",
                "name": "Wi-Fi",
                "op": "d2d_wifi",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "wifi-nm",
                "discovery": "ARMED-when-HW",
                "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
              },
              {
                "order": 3,
                "id": "bluetooth",
                "name": "Bluetooth",
                "op": "d2d_bluetooth",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "bluez",
                "discovery": "ARMED-when-HW",
                "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
              },
              {
                "order": 4,
                "id": "rf",
                "name": "RF",
                "op": "d2d_rf",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "rf-beyond-wifi-bt",
                "discovery": "REFUSE-without-HW",
                "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
              },
              {
                "order": 5,
                "id": "photon",
                "name": "Photon",
                "op": "d2d_photon",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "camera-flash",
                "discovery": "REFUSE-without-HW",
                "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
              }
            ],
            "security": {
              "isolation": "single-node security-awareness",
              "phoenix": "local wait / re-seal",
              "mesh_fenced_to_loopback": false,
              "forced_loopback": false,
              "loopback_isolation": false
            },
            "paper": "docs/designs/D2D-CARRIERS-1.0.md",
            "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
          },
          "d2d_status": "NOT-READY",
          "d2d_code": "FG-STUB",
          "packet_path_live": false,
          "alt_internet_live": false,
          "d2d_spec": "D2D-CARRIERS-1.0",
          "federated_mesh": "FED-MESH-1.0",
          "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
          "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        }
      },
      {
        "slug": "ark",
        "name": "The ARK",
        "bucket": "plain",
        "domain": "Vault/Custody",
        "domain_id": "01",
        "placement": "domain-software",
        "status": "live",
        "fraggate_status": "live",
        "public_door": true,
        "public_door_ops": [
          "sweep",
          "levels",
          "health",
          "skill",
          "doctor"
        ],
        "stub_ops": [
          "scorch",
          "wipe",
          "unlock",
          "encrypt"
        ],
        "door_label": "live FragGate door — named stub ops refuse",
        "open_live_door": true,
        "version": "0.1.0",
        "one_line": "Keep a local deniable vault; one phrase opens one vault.",
        "description": "Use The ARK as a local deniable vault you download and run on your device. It exists so one phrase opens one vault on that machine.",
        "worker_home": "https://ark-download-tracker.vibelock.workers.dev/",
        "worker_home_note": null,
        "download_url": "https://ark-download-tracker.vibelock.workers.dev/download",
        "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "github": "https://github.com/AzielEliab/ark",
        "mcp": "https://godlock.uk/runtime/mcp",
        "agent": {
          "mcp": "https://godlock.uk/runtime/mcp",
          "skill": "https://godlock.uk/runtime/v1/skill",
          "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
          "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=ark",
          "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
          "fraggate_call_executes": true,
          "open_live_door": true,
          "software": "https://godlock.uk/runtime/v1/software",
          "pull": "https://godlock.uk/runtime/v1/pull/ark",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "69d29bd079754df6450b8882b6f86c445ac7f1f490e2c150ff4716d00bf6d3b6",
        "updated_at": null,
        "git_sha": null,
        "git_sha_tracks_deployed_tip": false,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/runtime/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "security": {
            "model": "single-node-security-awareness",
            "isolates": "bad-peer-or-self",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "phoenix": "local-wait-reseal",
            "phoenix_lock": true,
            "public_hostname_resurrection": false,
            "loopback_bearer": "L1-optional",
            "operator_locks": [
              {
                "n": 1,
                "id": "single-node-security-awareness",
                "status": "LIVE",
                "mesh_fenced_to_loopback": false
              },
              {
                "n": 2,
                "id": "phoenix-reboot-loop",
                "status": "LIVE",
                "phoenix": "local-wait-reseal",
                "phoenix_lock": true,
                "public_hostname_resurrection": false
              },
              {
                "n": 3,
                "id": "open-world-awareness",
                "status": "live-when-configured",
                "law": "LIVE",
                "bind": "0.0.0.0",
                "worker_socket": false,
                "forced_loopback_is_mesh_fence": false,
                "loopback_isolation_is_mesh_fence": false
              }
            ],
            "open_world_awareness": {
              "spec": "OPEN-WORLD-AWARENESS-1.0",
              "author": "Aziel Eliab",
              "identity": "Aziel Eliab",
              "open_world_awareness": true,
              "bind": "0.0.0.0",
              "all_interfaces": true,
              "law": "LIVE",
              "status": "live-when-configured",
              "live": false,
              "socket": "live-when-configured",
              "worker_socket": false,
              "qnm_node_bind": "live-when-configured",
              "mock": false,
              "forced_loopback": false,
              "loopback_isolation": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false,
              "mesh_fenced_to_loopback": false,
              "public_egress_ip": false,
              "residential": false,
              "cf_geo_exit": false,
              "cf_geo_exit_pool": false,
              "sticky_public_ip": false,
              "packet_forward": false,
              "packet_forwarding": false,
              "public_icann": false,
              "cap7_is_icann": false,
              "replaces_internet": false,
              "not_a_second_internet": true,
              "hosted_vpn": false,
              "payload_host": false,
              "vpn_hop": false,
              "wireguard": false,
              "openvpn": false,
              "l3_exit": false,
              "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
            },
            "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
          },
          "fanout": "cron-or-request-path",
          "live_nodes_plane": "human-mesh-users-site-viewers",
          "nodes_plane": "human-mesh-users-uses",
          "software_nodes_plane": "software-worker-fanout",
          "site_live_viewers_plane": "hub-human-page-presence",
          "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
          "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
          "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
          "site_presence_contract": {
            "method": "POST",
            "path": "/runtime/v1/mesh/site-presence",
            "alias": "/runtime/v1/mesh/site-heartbeat",
            "fraggate": {
              "slug": "mesh",
              "op": "site-presence"
            },
            "body": {
              "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
              "viewers": "non-negative integer concurrent human page sessions (0..10000)",
              "kind": "human-page"
            },
            "ttl_ms": 900000,
            "registered_grace_ms": 1209600000,
            "default_heartbeat_mode": "idle",
            "heartbeat_mode": "active | idle | asleep",
            "stale_keeps_registered": true,
            "stale_counts_as_live": false,
            "allowed_hosts": [
              "godlock.uk",
              "azieleliab.com",
              "azielcorpuslibrary.net"
            ],
            "excluded_hosts": [
              "hedidntjump.com"
            ],
            "refused_kinds": [
              "bot",
              "bots",
              "crawler",
              "software",
              "softwares",
              "download",
              "downloads",
              "instance",
              "mcp"
            ],
            "pull_hub_count": false,
            "invent": false,
            "fail_closed": true,
            "read": "single-key",
            "paint": "live_nodes",
            "local_recompute": false,
            "radios": "not required — hub ingest, not a TX join",
            "rate_kind": "mesh_mutate",
            "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
          },
          "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
          "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
          "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "ban_survival": "BAN-SURVIVAL-1.0",
          "spore_spec": "SPORE-1.0",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/runtime/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "neighbor_heal_is_cite": true,
              "neighbor_heal_exec": false,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "neighbor_heal_is_cite": true,
          "neighbor_heal_exec": false,
          "join_is_presence_only": true,
          "join_is_not_login": true,
          "roster_publishes_exec_urls": false,
          "mesh_mutate_rate_kind": "mesh_mutate",
          "roster_cap": 256,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "d2d_carriers": {
            "spec": "D2D-CARRIERS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "plane": "track2-reachability",
            "phase": "B+C+D",
            "phases": {
              "A": "landed",
              "B": "LIVE-when-armed",
              "C": "LIVE-when-session",
              "D": "LIVE-when-three-local-nodes / fixture",
              "E": "scaffold"
            },
            "lan_discovery": "LIVE-when-armed",
            "wifi_discovery": "ARMED-when-HW",
            "bluetooth_discovery": "ARMED-when-HW",
            "rf_discovery": "REFUSE-without-HW",
            "photon_discovery": "REFUSE-without-HW",
            "peer_tunnel": "LIVE-when-session",
            "store_forward": "LIVE-when-three-local-nodes / fixture",
            "store_forward_public": "FG-STUB",
            "worker_runs_store_forward": false,
            "second_device": false,
            "mobile_client": "present-not-demonstrated",
            "mobile_demonstrated": false,
            "app_store_release": false,
            "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
            "bootstrap_list": "scaffold",
            "needs_starting_address": true,
            "shelf_cite": "scaffold",
            "live_multi_provider": false,
            "cold_shelf_live": false,
            "dns_cut": false,
            "origin_cutover": false,
            "warn5_closed": false,
            "worker_door": "FG-STUB",
            "worker_hardware": false,
            "local_node": "qnm-node",
            "get_never_enables": true,
            "separate_from": "cap7-name",
            "cap7_is_name_plane": true,
            "cap7_public_icann": false,
            "cap7_public_egress": false,
            "mirage_is_azvpn": false,
            "aznet_replaces_internet": false,
            "not_a_second_internet": true,
            "alt_internet_live": false,
            "packet_path_live": false,
            "field_1_0": false,
            "warn5": "STANDS-until-demonstrated",
            "warn5_permanent_stay_off": false,
            "preference": "failover",
            "order": [
              "lan",
              "wifi",
              "bluetooth",
              "rf",
              "photon"
            ],
            "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
            "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
            "status": "NOT-READY",
            "code": "FG-STUB",
            "warn5_until": "demonstrated",
            "warn5_by_design": "separate-from-icann",
            "refuse": {
              "packet": "FG-STUB",
              "radio_absent": "QNM-RADIO-ABSENT",
              "cap7_egress": "MG-NO-IP-EXIT",
              "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
              "bearer": "AZP-BEARER-REFUSE",
              "payload": "AZN-NO-PAYLOAD",
              "route": "MESH-NO-ROUTE",
              "stay_off": "MESH-STAY-OFF",
              "nat": "FED-MESH-NAT-REFUSE"
            },
            "carriers": [
              {
                "order": 1,
                "id": "lan",
                "name": "LAN",
                "op": "d2d_lan",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "lan-interface",
                "discovery": "LIVE-when-armed",
                "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
              },
              {
                "order": 2,
                "id": "wifi",
                "name": "Wi-Fi",
                "op": "d2d_wifi",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "wifi-nm",
                "discovery": "ARMED-when-HW",
                "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
              },
              {
                "order": 3,
                "id": "bluetooth",
                "name": "Bluetooth",
                "op": "d2d_bluetooth",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "bluez",
                "discovery": "ARMED-when-HW",
                "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
              },
              {
                "order": 4,
                "id": "rf",
                "name": "RF",
                "op": "d2d_rf",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "rf-beyond-wifi-bt",
                "discovery": "REFUSE-without-HW",
                "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
              },
              {
                "order": 5,
                "id": "photon",
                "name": "Photon",
                "op": "d2d_photon",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "camera-flash",
                "discovery": "REFUSE-without-HW",
                "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
              }
            ],
            "security": {
              "isolation": "single-node security-awareness",
              "phoenix": "local wait / re-seal",
              "mesh_fenced_to_loopback": false,
              "forced_loopback": false,
              "loopback_isolation": false
            },
            "paper": "docs/designs/D2D-CARRIERS-1.0.md",
            "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
          },
          "d2d_status": "NOT-READY",
          "d2d_code": "FG-STUB",
          "packet_path_live": false,
          "alt_internet_live": false,
          "d2d_spec": "D2D-CARRIERS-1.0",
          "federated_mesh": "FED-MESH-1.0",
          "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
          "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        }
      },
      {
        "slug": "toolbench",
        "name": "ToolBench",
        "bucket": "plain",
        "domain": null,
        "domain_id": null,
        "placement": "tool-playground",
        "status": "live",
        "fraggate_status": "live",
        "public_door": true,
        "public_door_ops": [
          "health",
          "skill",
          "doctor",
          "suite",
          "run_case",
          "limitation"
        ],
        "stub_ops": [
          "invent_completeness",
          "live_remote_harness",
          "invent_pass",
          "third_party_lab"
        ],
        "door_label": "live FragGate door — named stub ops refuse",
        "open_live_door": true,
        "version": "0.1.0",
        "one_line": "Run synthetic door cases to see how FragGate classifies them.",
        "description": "Use ToolBench to play closed-path and happy-path cases against the door table. It exists as a self-test playground.",
        "worker_home": null,
        "worker_home_note": "No separate product Worker. The in-repo door is FragGate on this runtime. Do not invent a download-tracker URL.",
        "in_repo_home": "https://godlock.uk/runtime/p/toolbench",
        "download_url": null,
        "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "github": "https://github.com/AzielEliab/aziel-runtime",
        "mcp": "https://godlock.uk/runtime/mcp",
        "agent": {
          "mcp": "https://godlock.uk/runtime/mcp",
          "skill": "https://godlock.uk/runtime/v1/skill",
          "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
          "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=toolbench",
          "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
          "fraggate_call_executes": true,
          "open_live_door": true,
          "software": "https://godlock.uk/runtime/v1/software",
          "pull": "https://godlock.uk/runtime/v1/pull/toolbench",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "888385a251997a21f07368d71eff0bb56ed5f68871a6f84900ab62f28c8da33c",
        "updated_at": null,
        "git_sha": null,
        "git_sha_tracks_deployed_tip": false,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/runtime/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "security": {
            "model": "single-node-security-awareness",
            "isolates": "bad-peer-or-self",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "phoenix": "local-wait-reseal",
            "phoenix_lock": true,
            "public_hostname_resurrection": false,
            "loopback_bearer": "L1-optional",
            "operator_locks": [
              {
                "n": 1,
                "id": "single-node-security-awareness",
                "status": "LIVE",
                "mesh_fenced_to_loopback": false
              },
              {
                "n": 2,
                "id": "phoenix-reboot-loop",
                "status": "LIVE",
                "phoenix": "local-wait-reseal",
                "phoenix_lock": true,
                "public_hostname_resurrection": false
              },
              {
                "n": 3,
                "id": "open-world-awareness",
                "status": "live-when-configured",
                "law": "LIVE",
                "bind": "0.0.0.0",
                "worker_socket": false,
                "forced_loopback_is_mesh_fence": false,
                "loopback_isolation_is_mesh_fence": false
              }
            ],
            "open_world_awareness": {
              "spec": "OPEN-WORLD-AWARENESS-1.0",
              "author": "Aziel Eliab",
              "identity": "Aziel Eliab",
              "open_world_awareness": true,
              "bind": "0.0.0.0",
              "all_interfaces": true,
              "law": "LIVE",
              "status": "live-when-configured",
              "live": false,
              "socket": "live-when-configured",
              "worker_socket": false,
              "qnm_node_bind": "live-when-configured",
              "mock": false,
              "forced_loopback": false,
              "loopback_isolation": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false,
              "mesh_fenced_to_loopback": false,
              "public_egress_ip": false,
              "residential": false,
              "cf_geo_exit": false,
              "cf_geo_exit_pool": false,
              "sticky_public_ip": false,
              "packet_forward": false,
              "packet_forwarding": false,
              "public_icann": false,
              "cap7_is_icann": false,
              "replaces_internet": false,
              "not_a_second_internet": true,
              "hosted_vpn": false,
              "payload_host": false,
              "vpn_hop": false,
              "wireguard": false,
              "openvpn": false,
              "l3_exit": false,
              "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
            },
            "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
          },
          "fanout": "cron-or-request-path",
          "live_nodes_plane": "human-mesh-users-site-viewers",
          "nodes_plane": "human-mesh-users-uses",
          "software_nodes_plane": "software-worker-fanout",
          "site_live_viewers_plane": "hub-human-page-presence",
          "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
          "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
          "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
          "site_presence_contract": {
            "method": "POST",
            "path": "/runtime/v1/mesh/site-presence",
            "alias": "/runtime/v1/mesh/site-heartbeat",
            "fraggate": {
              "slug": "mesh",
              "op": "site-presence"
            },
            "body": {
              "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
              "viewers": "non-negative integer concurrent human page sessions (0..10000)",
              "kind": "human-page"
            },
            "ttl_ms": 900000,
            "registered_grace_ms": 1209600000,
            "default_heartbeat_mode": "idle",
            "heartbeat_mode": "active | idle | asleep",
            "stale_keeps_registered": true,
            "stale_counts_as_live": false,
            "allowed_hosts": [
              "godlock.uk",
              "azieleliab.com",
              "azielcorpuslibrary.net"
            ],
            "excluded_hosts": [
              "hedidntjump.com"
            ],
            "refused_kinds": [
              "bot",
              "bots",
              "crawler",
              "software",
              "softwares",
              "download",
              "downloads",
              "instance",
              "mcp"
            ],
            "pull_hub_count": false,
            "invent": false,
            "fail_closed": true,
            "read": "single-key",
            "paint": "live_nodes",
            "local_recompute": false,
            "radios": "not required — hub ingest, not a TX join",
            "rate_kind": "mesh_mutate",
            "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
          },
          "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
          "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
          "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "ban_survival": "BAN-SURVIVAL-1.0",
          "spore_spec": "SPORE-1.0",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/runtime/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "neighbor_heal_is_cite": true,
              "neighbor_heal_exec": false,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "neighbor_heal_is_cite": true,
          "neighbor_heal_exec": false,
          "join_is_presence_only": true,
          "join_is_not_login": true,
          "roster_publishes_exec_urls": false,
          "mesh_mutate_rate_kind": "mesh_mutate",
          "roster_cap": 256,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "d2d_carriers": {
            "spec": "D2D-CARRIERS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "plane": "track2-reachability",
            "phase": "B+C+D",
            "phases": {
              "A": "landed",
              "B": "LIVE-when-armed",
              "C": "LIVE-when-session",
              "D": "LIVE-when-three-local-nodes / fixture",
              "E": "scaffold"
            },
            "lan_discovery": "LIVE-when-armed",
            "wifi_discovery": "ARMED-when-HW",
            "bluetooth_discovery": "ARMED-when-HW",
            "rf_discovery": "REFUSE-without-HW",
            "photon_discovery": "REFUSE-without-HW",
            "peer_tunnel": "LIVE-when-session",
            "store_forward": "LIVE-when-three-local-nodes / fixture",
            "store_forward_public": "FG-STUB",
            "worker_runs_store_forward": false,
            "second_device": false,
            "mobile_client": "present-not-demonstrated",
            "mobile_demonstrated": false,
            "app_store_release": false,
            "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
            "bootstrap_list": "scaffold",
            "needs_starting_address": true,
            "shelf_cite": "scaffold",
            "live_multi_provider": false,
            "cold_shelf_live": false,
            "dns_cut": false,
            "origin_cutover": false,
            "warn5_closed": false,
            "worker_door": "FG-STUB",
            "worker_hardware": false,
            "local_node": "qnm-node",
            "get_never_enables": true,
            "separate_from": "cap7-name",
            "cap7_is_name_plane": true,
            "cap7_public_icann": false,
            "cap7_public_egress": false,
            "mirage_is_azvpn": false,
            "aznet_replaces_internet": false,
            "not_a_second_internet": true,
            "alt_internet_live": false,
            "packet_path_live": false,
            "field_1_0": false,
            "warn5": "STANDS-until-demonstrated",
            "warn5_permanent_stay_off": false,
            "preference": "failover",
            "order": [
              "lan",
              "wifi",
              "bluetooth",
              "rf",
              "photon"
            ],
            "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
            "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
            "status": "NOT-READY",
            "code": "FG-STUB",
            "warn5_until": "demonstrated",
            "warn5_by_design": "separate-from-icann",
            "refuse": {
              "packet": "FG-STUB",
              "radio_absent": "QNM-RADIO-ABSENT",
              "cap7_egress": "MG-NO-IP-EXIT",
              "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
              "bearer": "AZP-BEARER-REFUSE",
              "payload": "AZN-NO-PAYLOAD",
              "route": "MESH-NO-ROUTE",
              "stay_off": "MESH-STAY-OFF",
              "nat": "FED-MESH-NAT-REFUSE"
            },
            "carriers": [
              {
                "order": 1,
                "id": "lan",
                "name": "LAN",
                "op": "d2d_lan",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "lan-interface",
                "discovery": "LIVE-when-armed",
                "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
              },
              {
                "order": 2,
                "id": "wifi",
                "name": "Wi-Fi",
                "op": "d2d_wifi",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "wifi-nm",
                "discovery": "ARMED-when-HW",
                "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
              },
              {
                "order": 3,
                "id": "bluetooth",
                "name": "Bluetooth",
                "op": "d2d_bluetooth",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "bluez",
                "discovery": "ARMED-when-HW",
                "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
              },
              {
                "order": 4,
                "id": "rf",
                "name": "RF",
                "op": "d2d_rf",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "rf-beyond-wifi-bt",
                "discovery": "REFUSE-without-HW",
                "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
              },
              {
                "order": 5,
                "id": "photon",
                "name": "Photon",
                "op": "d2d_photon",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "camera-flash",
                "discovery": "REFUSE-without-HW",
                "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
              }
            ],
            "security": {
              "isolation": "single-node security-awareness",
              "phoenix": "local wait / re-seal",
              "mesh_fenced_to_loopback": false,
              "forced_loopback": false,
              "loopback_isolation": false
            },
            "paper": "docs/designs/D2D-CARRIERS-1.0.md",
            "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
          },
          "d2d_status": "NOT-READY",
          "d2d_code": "FG-STUB",
          "packet_path_live": false,
          "alt_internet_live": false,
          "d2d_spec": "D2D-CARRIERS-1.0",
          "federated_mesh": "FED-MESH-1.0",
          "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
          "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        }
      },
      {
        "slug": "whitestone",
        "name": "Whitestone",
        "bucket": "plain",
        "domain": null,
        "domain_id": null,
        "placement": "pro-se-advisor",
        "status": "live",
        "fraggate_status": "none",
        "public_door": false,
        "public_door_ops": [],
        "stub_ops": [],
        "door_label": "worker only — FragGate status none",
        "open_live_door": false,
        "version": "1.6.0",
        "one_line": "Advise on short Criminal, Civil, and Divorce questions with historical as-of and Case Mode (suppression axes, TrajectoryLock-lite, export, confidence labeled up to 75%). Session-only web app plus optional zip. https://whitestone.vibelock.workers.dev/",
        "description": "Whitestone is worker-only and has no public door. Use Whitestone for short Criminal, Civil, or Divorce questions in a web app, including historical as-of evaluation and Case Mode axes (truth_upheld, narrative / systemic / personal-professional suppression, honesty). It exists as an ephemeral pro se advisor: TrajectoryLock-lite is labeled heuristic, Case Mode may export a hash-chain card, and confidence is labeled up to 75%. Session-only memory wipes when you close. Optional counted zip is on the download tracker; the web app stays on the Whitestone Worker. https://whitestone.vibelock.workers.dev/ · https://whitestone-download-tracker.vibelock.workers.dev/download",
        "worker_home": "https://whitestone-download-tracker.vibelock.workers.dev/",
        "download_url": "https://whitestone-download-tracker.vibelock.workers.dev/download",
        "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "web_app": "https://whitestone.vibelock.workers.dev/",
        "github": "https://github.com/AzielEliab/Whitestone",
        "mcp": "https://godlock.uk/runtime/mcp",
        "agent": {
          "mcp": "https://godlock.uk/runtime/mcp",
          "skill": null,
          "fraggate_list": null,
          "fraggate_describe": null,
          "fraggate_call": null,
          "software": "https://godlock.uk/runtime/v1/software",
          "pull": null,
          "fraggate_call_executes": false,
          "open_live_door": false,
          "pipeline": "Live Worker only. FragGate status is none. Do not invent fraggate_call ops."
        },
        "engine_digest": null,
        "updated_at": null,
        "git_sha": null,
        "door": "none",
        "kind": "software",
        "engine": false,
        "fraggate_engine": false,
        "worker_only": true,
        "note": "Live Worker. FragGate status is none. Hub tab reads worker_home / download_url / web_app. Case Mode is a product feature. Session-only. Author: Aziel Eliab only. Do not invent fraggate_call ops.",
        "mesh": {
          "path": "/runtime/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "security": {
            "model": "single-node-security-awareness",
            "isolates": "bad-peer-or-self",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "phoenix": "local-wait-reseal",
            "phoenix_lock": true,
            "public_hostname_resurrection": false,
            "loopback_bearer": "L1-optional",
            "operator_locks": [
              {
                "n": 1,
                "id": "single-node-security-awareness",
                "status": "LIVE",
                "mesh_fenced_to_loopback": false
              },
              {
                "n": 2,
                "id": "phoenix-reboot-loop",
                "status": "LIVE",
                "phoenix": "local-wait-reseal",
                "phoenix_lock": true,
                "public_hostname_resurrection": false
              },
              {
                "n": 3,
                "id": "open-world-awareness",
                "status": "live-when-configured",
                "law": "LIVE",
                "bind": "0.0.0.0",
                "worker_socket": false,
                "forced_loopback_is_mesh_fence": false,
                "loopback_isolation_is_mesh_fence": false
              }
            ],
            "open_world_awareness": {
              "spec": "OPEN-WORLD-AWARENESS-1.0",
              "author": "Aziel Eliab",
              "identity": "Aziel Eliab",
              "open_world_awareness": true,
              "bind": "0.0.0.0",
              "all_interfaces": true,
              "law": "LIVE",
              "status": "live-when-configured",
              "live": false,
              "socket": "live-when-configured",
              "worker_socket": false,
              "qnm_node_bind": "live-when-configured",
              "mock": false,
              "forced_loopback": false,
              "loopback_isolation": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false,
              "mesh_fenced_to_loopback": false,
              "public_egress_ip": false,
              "residential": false,
              "cf_geo_exit": false,
              "cf_geo_exit_pool": false,
              "sticky_public_ip": false,
              "packet_forward": false,
              "packet_forwarding": false,
              "public_icann": false,
              "cap7_is_icann": false,
              "replaces_internet": false,
              "not_a_second_internet": true,
              "hosted_vpn": false,
              "payload_host": false,
              "vpn_hop": false,
              "wireguard": false,
              "openvpn": false,
              "l3_exit": false,
              "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
            },
            "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
          },
          "fanout": "cron-or-request-path",
          "live_nodes_plane": "human-mesh-users-site-viewers",
          "nodes_plane": "human-mesh-users-uses",
          "software_nodes_plane": "software-worker-fanout",
          "site_live_viewers_plane": "hub-human-page-presence",
          "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
          "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
          "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
          "site_presence_contract": {
            "method": "POST",
            "path": "/runtime/v1/mesh/site-presence",
            "alias": "/runtime/v1/mesh/site-heartbeat",
            "fraggate": {
              "slug": "mesh",
              "op": "site-presence"
            },
            "body": {
              "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
              "viewers": "non-negative integer concurrent human page sessions (0..10000)",
              "kind": "human-page"
            },
            "ttl_ms": 900000,
            "registered_grace_ms": 1209600000,
            "default_heartbeat_mode": "idle",
            "heartbeat_mode": "active | idle | asleep",
            "stale_keeps_registered": true,
            "stale_counts_as_live": false,
            "allowed_hosts": [
              "godlock.uk",
              "azieleliab.com",
              "azielcorpuslibrary.net"
            ],
            "excluded_hosts": [
              "hedidntjump.com"
            ],
            "refused_kinds": [
              "bot",
              "bots",
              "crawler",
              "software",
              "softwares",
              "download",
              "downloads",
              "instance",
              "mcp"
            ],
            "pull_hub_count": false,
            "invent": false,
            "fail_closed": true,
            "read": "single-key",
            "paint": "live_nodes",
            "local_recompute": false,
            "radios": "not required — hub ingest, not a TX join",
            "rate_kind": "mesh_mutate",
            "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
          },
          "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
          "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
          "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "ban_survival": "BAN-SURVIVAL-1.0",
          "spore_spec": "SPORE-1.0",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/runtime/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "neighbor_heal_is_cite": true,
              "neighbor_heal_exec": false,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "neighbor_heal_is_cite": true,
          "neighbor_heal_exec": false,
          "join_is_presence_only": true,
          "join_is_not_login": true,
          "roster_publishes_exec_urls": false,
          "mesh_mutate_rate_kind": "mesh_mutate",
          "roster_cap": 256,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "d2d_carriers": {
            "spec": "D2D-CARRIERS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "plane": "track2-reachability",
            "phase": "B+C+D",
            "phases": {
              "A": "landed",
              "B": "LIVE-when-armed",
              "C": "LIVE-when-session",
              "D": "LIVE-when-three-local-nodes / fixture",
              "E": "scaffold"
            },
            "lan_discovery": "LIVE-when-armed",
            "wifi_discovery": "ARMED-when-HW",
            "bluetooth_discovery": "ARMED-when-HW",
            "rf_discovery": "REFUSE-without-HW",
            "photon_discovery": "REFUSE-without-HW",
            "peer_tunnel": "LIVE-when-session",
            "store_forward": "LIVE-when-three-local-nodes / fixture",
            "store_forward_public": "FG-STUB",
            "worker_runs_store_forward": false,
            "second_device": false,
            "mobile_client": "present-not-demonstrated",
            "mobile_demonstrated": false,
            "app_store_release": false,
            "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
            "bootstrap_list": "scaffold",
            "needs_starting_address": true,
            "shelf_cite": "scaffold",
            "live_multi_provider": false,
            "cold_shelf_live": false,
            "dns_cut": false,
            "origin_cutover": false,
            "warn5_closed": false,
            "worker_door": "FG-STUB",
            "worker_hardware": false,
            "local_node": "qnm-node",
            "get_never_enables": true,
            "separate_from": "cap7-name",
            "cap7_is_name_plane": true,
            "cap7_public_icann": false,
            "cap7_public_egress": false,
            "mirage_is_azvpn": false,
            "aznet_replaces_internet": false,
            "not_a_second_internet": true,
            "alt_internet_live": false,
            "packet_path_live": false,
            "field_1_0": false,
            "warn5": "STANDS-until-demonstrated",
            "warn5_permanent_stay_off": false,
            "preference": "failover",
            "order": [
              "lan",
              "wifi",
              "bluetooth",
              "rf",
              "photon"
            ],
            "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
            "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
            "status": "NOT-READY",
            "code": "FG-STUB",
            "warn5_until": "demonstrated",
            "warn5_by_design": "separate-from-icann",
            "refuse": {
              "packet": "FG-STUB",
              "radio_absent": "QNM-RADIO-ABSENT",
              "cap7_egress": "MG-NO-IP-EXIT",
              "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
              "bearer": "AZP-BEARER-REFUSE",
              "payload": "AZN-NO-PAYLOAD",
              "route": "MESH-NO-ROUTE",
              "stay_off": "MESH-STAY-OFF",
              "nat": "FED-MESH-NAT-REFUSE"
            },
            "carriers": [
              {
                "order": 1,
                "id": "lan",
                "name": "LAN",
                "op": "d2d_lan",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "lan-interface",
                "discovery": "LIVE-when-armed",
                "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
              },
              {
                "order": 2,
                "id": "wifi",
                "name": "Wi-Fi",
                "op": "d2d_wifi",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "wifi-nm",
                "discovery": "ARMED-when-HW",
                "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
              },
              {
                "order": 3,
                "id": "bluetooth",
                "name": "Bluetooth",
                "op": "d2d_bluetooth",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "bluez",
                "discovery": "ARMED-when-HW",
                "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
              },
              {
                "order": 4,
                "id": "rf",
                "name": "RF",
                "op": "d2d_rf",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "rf-beyond-wifi-bt",
                "discovery": "REFUSE-without-HW",
                "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
              },
              {
                "order": 5,
                "id": "photon",
                "name": "Photon",
                "op": "d2d_photon",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "camera-flash",
                "discovery": "REFUSE-without-HW",
                "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
              }
            ],
            "security": {
              "isolation": "single-node security-awareness",
              "phoenix": "local wait / re-seal",
              "mesh_fenced_to_loopback": false,
              "forced_loopback": false,
              "loopback_isolation": false
            },
            "paper": "docs/designs/D2D-CARRIERS-1.0.md",
            "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
          },
          "d2d_status": "NOT-READY",
          "d2d_code": "FG-STUB",
          "packet_path_live": false,
          "alt_internet_live": false,
          "d2d_spec": "D2D-CARRIERS-1.0",
          "federated_mesh": "FED-MESH-1.0",
          "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
          "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        }
      },
      {
        "slug": "zsolver",
        "name": "ZionPattern Solver",
        "bucket": "plain",
        "domain": "Language",
        "domain_id": "04",
        "placement": "domain-software",
        "status": "live",
        "fraggate_status": "live",
        "public_door": true,
        "public_door_ops": [
          "patterns",
          "score",
          "session",
          "health",
          "skill",
          "doctor"
        ],
        "stub_ops": [],
        "door_label": "live FragGate door",
        "open_live_door": true,
        "version": "0.2.0",
        "one_line": "Score answers against nine ontology nodes, with scores labeled up to 75%.",
        "description": "Use ZionPattern Solver to work through the Zioncheck seed nodes. It exists as an assistive scorer with scores labeled up to 75%.",
        "worker_home": "https://zsolver-download-tracker.vibelock.workers.dev/",
        "worker_home_note": null,
        "download_url": "https://zsolver-download-tracker.vibelock.workers.dev/download",
        "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "github": "https://github.com/AzielEliab/zion-pattern-solver",
        "mcp": "https://godlock.uk/runtime/mcp",
        "agent": {
          "mcp": "https://godlock.uk/runtime/mcp",
          "skill": "https://godlock.uk/runtime/v1/skill",
          "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
          "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=zsolver",
          "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
          "fraggate_call_executes": true,
          "open_live_door": true,
          "software": "https://godlock.uk/runtime/v1/software",
          "pull": "https://godlock.uk/runtime/v1/pull/zsolver",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "8667a3d95f6063b77cb0ab0ff629192b6c5036d95762adb20f3c90f4b73a977f",
        "updated_at": null,
        "git_sha": null,
        "git_sha_tracks_deployed_tip": false,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/runtime/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "security": {
            "model": "single-node-security-awareness",
            "isolates": "bad-peer-or-self",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "phoenix": "local-wait-reseal",
            "phoenix_lock": true,
            "public_hostname_resurrection": false,
            "loopback_bearer": "L1-optional",
            "operator_locks": [
              {
                "n": 1,
                "id": "single-node-security-awareness",
                "status": "LIVE",
                "mesh_fenced_to_loopback": false
              },
              {
                "n": 2,
                "id": "phoenix-reboot-loop",
                "status": "LIVE",
                "phoenix": "local-wait-reseal",
                "phoenix_lock": true,
                "public_hostname_resurrection": false
              },
              {
                "n": 3,
                "id": "open-world-awareness",
                "status": "live-when-configured",
                "law": "LIVE",
                "bind": "0.0.0.0",
                "worker_socket": false,
                "forced_loopback_is_mesh_fence": false,
                "loopback_isolation_is_mesh_fence": false
              }
            ],
            "open_world_awareness": {
              "spec": "OPEN-WORLD-AWARENESS-1.0",
              "author": "Aziel Eliab",
              "identity": "Aziel Eliab",
              "open_world_awareness": true,
              "bind": "0.0.0.0",
              "all_interfaces": true,
              "law": "LIVE",
              "status": "live-when-configured",
              "live": false,
              "socket": "live-when-configured",
              "worker_socket": false,
              "qnm_node_bind": "live-when-configured",
              "mock": false,
              "forced_loopback": false,
              "loopback_isolation": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false,
              "mesh_fenced_to_loopback": false,
              "public_egress_ip": false,
              "residential": false,
              "cf_geo_exit": false,
              "cf_geo_exit_pool": false,
              "sticky_public_ip": false,
              "packet_forward": false,
              "packet_forwarding": false,
              "public_icann": false,
              "cap7_is_icann": false,
              "replaces_internet": false,
              "not_a_second_internet": true,
              "hosted_vpn": false,
              "payload_host": false,
              "vpn_hop": false,
              "wireguard": false,
              "openvpn": false,
              "l3_exit": false,
              "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
            },
            "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
          },
          "fanout": "cron-or-request-path",
          "live_nodes_plane": "human-mesh-users-site-viewers",
          "nodes_plane": "human-mesh-users-uses",
          "software_nodes_plane": "software-worker-fanout",
          "site_live_viewers_plane": "hub-human-page-presence",
          "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
          "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
          "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
          "site_presence_contract": {
            "method": "POST",
            "path": "/runtime/v1/mesh/site-presence",
            "alias": "/runtime/v1/mesh/site-heartbeat",
            "fraggate": {
              "slug": "mesh",
              "op": "site-presence"
            },
            "body": {
              "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
              "viewers": "non-negative integer concurrent human page sessions (0..10000)",
              "kind": "human-page"
            },
            "ttl_ms": 900000,
            "registered_grace_ms": 1209600000,
            "default_heartbeat_mode": "idle",
            "heartbeat_mode": "active | idle | asleep",
            "stale_keeps_registered": true,
            "stale_counts_as_live": false,
            "allowed_hosts": [
              "godlock.uk",
              "azieleliab.com",
              "azielcorpuslibrary.net"
            ],
            "excluded_hosts": [
              "hedidntjump.com"
            ],
            "refused_kinds": [
              "bot",
              "bots",
              "crawler",
              "software",
              "softwares",
              "download",
              "downloads",
              "instance",
              "mcp"
            ],
            "pull_hub_count": false,
            "invent": false,
            "fail_closed": true,
            "read": "single-key",
            "paint": "live_nodes",
            "local_recompute": false,
            "radios": "not required — hub ingest, not a TX join",
            "rate_kind": "mesh_mutate",
            "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
          },
          "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
          "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
          "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "ban_survival": "BAN-SURVIVAL-1.0",
          "spore_spec": "SPORE-1.0",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/runtime/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "neighbor_heal_is_cite": true,
              "neighbor_heal_exec": false,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "neighbor_heal_is_cite": true,
          "neighbor_heal_exec": false,
          "join_is_presence_only": true,
          "join_is_not_login": true,
          "roster_publishes_exec_urls": false,
          "mesh_mutate_rate_kind": "mesh_mutate",
          "roster_cap": 256,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "d2d_carriers": {
            "spec": "D2D-CARRIERS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "plane": "track2-reachability",
            "phase": "B+C+D",
            "phases": {
              "A": "landed",
              "B": "LIVE-when-armed",
              "C": "LIVE-when-session",
              "D": "LIVE-when-three-local-nodes / fixture",
              "E": "scaffold"
            },
            "lan_discovery": "LIVE-when-armed",
            "wifi_discovery": "ARMED-when-HW",
            "bluetooth_discovery": "ARMED-when-HW",
            "rf_discovery": "REFUSE-without-HW",
            "photon_discovery": "REFUSE-without-HW",
            "peer_tunnel": "LIVE-when-session",
            "store_forward": "LIVE-when-three-local-nodes / fixture",
            "store_forward_public": "FG-STUB",
            "worker_runs_store_forward": false,
            "second_device": false,
            "mobile_client": "present-not-demonstrated",
            "mobile_demonstrated": false,
            "app_store_release": false,
            "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
            "bootstrap_list": "scaffold",
            "needs_starting_address": true,
            "shelf_cite": "scaffold",
            "live_multi_provider": false,
            "cold_shelf_live": false,
            "dns_cut": false,
            "origin_cutover": false,
            "warn5_closed": false,
            "worker_door": "FG-STUB",
            "worker_hardware": false,
            "local_node": "qnm-node",
            "get_never_enables": true,
            "separate_from": "cap7-name",
            "cap7_is_name_plane": true,
            "cap7_public_icann": false,
            "cap7_public_egress": false,
            "mirage_is_azvpn": false,
            "aznet_replaces_internet": false,
            "not_a_second_internet": true,
            "alt_internet_live": false,
            "packet_path_live": false,
            "field_1_0": false,
            "warn5": "STANDS-until-demonstrated",
            "warn5_permanent_stay_off": false,
            "preference": "failover",
            "order": [
              "lan",
              "wifi",
              "bluetooth",
              "rf",
              "photon"
            ],
            "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
            "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
            "status": "NOT-READY",
            "code": "FG-STUB",
            "warn5_until": "demonstrated",
            "warn5_by_design": "separate-from-icann",
            "refuse": {
              "packet": "FG-STUB",
              "radio_absent": "QNM-RADIO-ABSENT",
              "cap7_egress": "MG-NO-IP-EXIT",
              "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
              "bearer": "AZP-BEARER-REFUSE",
              "payload": "AZN-NO-PAYLOAD",
              "route": "MESH-NO-ROUTE",
              "stay_off": "MESH-STAY-OFF",
              "nat": "FED-MESH-NAT-REFUSE"
            },
            "carriers": [
              {
                "order": 1,
                "id": "lan",
                "name": "LAN",
                "op": "d2d_lan",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "lan-interface",
                "discovery": "LIVE-when-armed",
                "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
              },
              {
                "order": 2,
                "id": "wifi",
                "name": "Wi-Fi",
                "op": "d2d_wifi",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "wifi-nm",
                "discovery": "ARMED-when-HW",
                "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
              },
              {
                "order": 3,
                "id": "bluetooth",
                "name": "Bluetooth",
                "op": "d2d_bluetooth",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "bluez",
                "discovery": "ARMED-when-HW",
                "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
              },
              {
                "order": 4,
                "id": "rf",
                "name": "RF",
                "op": "d2d_rf",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "rf-beyond-wifi-bt",
                "discovery": "REFUSE-without-HW",
                "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
              },
              {
                "order": 5,
                "id": "photon",
                "name": "Photon",
                "op": "d2d_photon",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "camera-flash",
                "discovery": "REFUSE-without-HW",
                "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
              }
            ],
            "security": {
              "isolation": "single-node security-awareness",
              "phoenix": "local wait / re-seal",
              "mesh_fenced_to_loopback": false,
              "forced_loopback": false,
              "loopback_isolation": false
            },
            "paper": "docs/designs/D2D-CARRIERS-1.0.md",
            "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
          },
          "d2d_status": "NOT-READY",
          "d2d_code": "FG-STUB",
          "packet_path_live": false,
          "alt_internet_live": false,
          "d2d_spec": "D2D-CARRIERS-1.0",
          "federated_mesh": "FED-MESH-1.0",
          "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
          "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        }
      },
      {
        "slug": "zkattest",
        "name": "ZKAttest",
        "bucket": "plain",
        "domain": null,
        "domain_id": null,
        "placement": "receipt-attest",
        "status": "live",
        "fraggate_status": "live",
        "public_door": true,
        "public_door_ops": [
          "health",
          "skill",
          "doctor",
          "commit",
          "attest",
          "open",
          "verify",
          "limitation"
        ],
        "stub_ops": [
          "groth16",
          "snark",
          "stark",
          "plonk",
          "bulletproofs",
          "pairing",
          "trusted_setup",
          "prove",
          "full_zk",
          "zk_snark",
          "reveal_witness"
        ],
        "door_label": "live FragGate door — named stub ops refuse",
        "open_live_door": true,
        "version": "0.1.0",
        "one_line": "Attest a statement with a hash commitment that keeps the witness private.",
        "description": "Use ZKAttest to bind a public statement to a SHA-256 commitment. It exists so the witness stays with the caller.",
        "worker_home": null,
        "worker_home_note": "No separate product Worker. The in-repo door is FragGate on this runtime. Do not invent a download-tracker URL.",
        "in_repo_home": "https://godlock.uk/runtime/p/zkattest",
        "download_url": null,
        "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "github": "https://github.com/AzielEliab/aziel-runtime",
        "mcp": "https://godlock.uk/runtime/mcp",
        "agent": {
          "mcp": "https://godlock.uk/runtime/mcp",
          "skill": "https://godlock.uk/runtime/v1/skill",
          "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
          "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=zkattest",
          "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
          "fraggate_call_executes": true,
          "open_live_door": true,
          "software": "https://godlock.uk/runtime/v1/software",
          "pull": "https://godlock.uk/runtime/v1/pull/zkattest",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "bb3831ed980be81dce15fda1dbb471a7458c91feb907a410a86173003df1c84a",
        "updated_at": null,
        "git_sha": null,
        "git_sha_tracks_deployed_tip": false,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/runtime/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "security": {
            "model": "single-node-security-awareness",
            "isolates": "bad-peer-or-self",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "phoenix": "local-wait-reseal",
            "phoenix_lock": true,
            "public_hostname_resurrection": false,
            "loopback_bearer": "L1-optional",
            "operator_locks": [
              {
                "n": 1,
                "id": "single-node-security-awareness",
                "status": "LIVE",
                "mesh_fenced_to_loopback": false
              },
              {
                "n": 2,
                "id": "phoenix-reboot-loop",
                "status": "LIVE",
                "phoenix": "local-wait-reseal",
                "phoenix_lock": true,
                "public_hostname_resurrection": false
              },
              {
                "n": 3,
                "id": "open-world-awareness",
                "status": "live-when-configured",
                "law": "LIVE",
                "bind": "0.0.0.0",
                "worker_socket": false,
                "forced_loopback_is_mesh_fence": false,
                "loopback_isolation_is_mesh_fence": false
              }
            ],
            "open_world_awareness": {
              "spec": "OPEN-WORLD-AWARENESS-1.0",
              "author": "Aziel Eliab",
              "identity": "Aziel Eliab",
              "open_world_awareness": true,
              "bind": "0.0.0.0",
              "all_interfaces": true,
              "law": "LIVE",
              "status": "live-when-configured",
              "live": false,
              "socket": "live-when-configured",
              "worker_socket": false,
              "qnm_node_bind": "live-when-configured",
              "mock": false,
              "forced_loopback": false,
              "loopback_isolation": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false,
              "mesh_fenced_to_loopback": false,
              "public_egress_ip": false,
              "residential": false,
              "cf_geo_exit": false,
              "cf_geo_exit_pool": false,
              "sticky_public_ip": false,
              "packet_forward": false,
              "packet_forwarding": false,
              "public_icann": false,
              "cap7_is_icann": false,
              "replaces_internet": false,
              "not_a_second_internet": true,
              "hosted_vpn": false,
              "payload_host": false,
              "vpn_hop": false,
              "wireguard": false,
              "openvpn": false,
              "l3_exit": false,
              "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
            },
            "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
          },
          "fanout": "cron-or-request-path",
          "live_nodes_plane": "human-mesh-users-site-viewers",
          "nodes_plane": "human-mesh-users-uses",
          "software_nodes_plane": "software-worker-fanout",
          "site_live_viewers_plane": "hub-human-page-presence",
          "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
          "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
          "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
          "site_presence_contract": {
            "method": "POST",
            "path": "/runtime/v1/mesh/site-presence",
            "alias": "/runtime/v1/mesh/site-heartbeat",
            "fraggate": {
              "slug": "mesh",
              "op": "site-presence"
            },
            "body": {
              "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
              "viewers": "non-negative integer concurrent human page sessions (0..10000)",
              "kind": "human-page"
            },
            "ttl_ms": 900000,
            "registered_grace_ms": 1209600000,
            "default_heartbeat_mode": "idle",
            "heartbeat_mode": "active | idle | asleep",
            "stale_keeps_registered": true,
            "stale_counts_as_live": false,
            "allowed_hosts": [
              "godlock.uk",
              "azieleliab.com",
              "azielcorpuslibrary.net"
            ],
            "excluded_hosts": [
              "hedidntjump.com"
            ],
            "refused_kinds": [
              "bot",
              "bots",
              "crawler",
              "software",
              "softwares",
              "download",
              "downloads",
              "instance",
              "mcp"
            ],
            "pull_hub_count": false,
            "invent": false,
            "fail_closed": true,
            "read": "single-key",
            "paint": "live_nodes",
            "local_recompute": false,
            "radios": "not required — hub ingest, not a TX join",
            "rate_kind": "mesh_mutate",
            "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
          },
          "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
          "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
          "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "ban_survival": "BAN-SURVIVAL-1.0",
          "spore_spec": "SPORE-1.0",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/runtime/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "neighbor_heal_is_cite": true,
              "neighbor_heal_exec": false,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "neighbor_heal_is_cite": true,
          "neighbor_heal_exec": false,
          "join_is_presence_only": true,
          "join_is_not_login": true,
          "roster_publishes_exec_urls": false,
          "mesh_mutate_rate_kind": "mesh_mutate",
          "roster_cap": 256,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "d2d_carriers": {
            "spec": "D2D-CARRIERS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "plane": "track2-reachability",
            "phase": "B+C+D",
            "phases": {
              "A": "landed",
              "B": "LIVE-when-armed",
              "C": "LIVE-when-session",
              "D": "LIVE-when-three-local-nodes / fixture",
              "E": "scaffold"
            },
            "lan_discovery": "LIVE-when-armed",
            "wifi_discovery": "ARMED-when-HW",
            "bluetooth_discovery": "ARMED-when-HW",
            "rf_discovery": "REFUSE-without-HW",
            "photon_discovery": "REFUSE-without-HW",
            "peer_tunnel": "LIVE-when-session",
            "store_forward": "LIVE-when-three-local-nodes / fixture",
            "store_forward_public": "FG-STUB",
            "worker_runs_store_forward": false,
            "second_device": false,
            "mobile_client": "present-not-demonstrated",
            "mobile_demonstrated": false,
            "app_store_release": false,
            "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
            "bootstrap_list": "scaffold",
            "needs_starting_address": true,
            "shelf_cite": "scaffold",
            "live_multi_provider": false,
            "cold_shelf_live": false,
            "dns_cut": false,
            "origin_cutover": false,
            "warn5_closed": false,
            "worker_door": "FG-STUB",
            "worker_hardware": false,
            "local_node": "qnm-node",
            "get_never_enables": true,
            "separate_from": "cap7-name",
            "cap7_is_name_plane": true,
            "cap7_public_icann": false,
            "cap7_public_egress": false,
            "mirage_is_azvpn": false,
            "aznet_replaces_internet": false,
            "not_a_second_internet": true,
            "alt_internet_live": false,
            "packet_path_live": false,
            "field_1_0": false,
            "warn5": "STANDS-until-demonstrated",
            "warn5_permanent_stay_off": false,
            "preference": "failover",
            "order": [
              "lan",
              "wifi",
              "bluetooth",
              "rf",
              "photon"
            ],
            "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
            "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
            "status": "NOT-READY",
            "code": "FG-STUB",
            "warn5_until": "demonstrated",
            "warn5_by_design": "separate-from-icann",
            "refuse": {
              "packet": "FG-STUB",
              "radio_absent": "QNM-RADIO-ABSENT",
              "cap7_egress": "MG-NO-IP-EXIT",
              "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
              "bearer": "AZP-BEARER-REFUSE",
              "payload": "AZN-NO-PAYLOAD",
              "route": "MESH-NO-ROUTE",
              "stay_off": "MESH-STAY-OFF",
              "nat": "FED-MESH-NAT-REFUSE"
            },
            "carriers": [
              {
                "order": 1,
                "id": "lan",
                "name": "LAN",
                "op": "d2d_lan",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "lan-interface",
                "discovery": "LIVE-when-armed",
                "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
              },
              {
                "order": 2,
                "id": "wifi",
                "name": "Wi-Fi",
                "op": "d2d_wifi",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "wifi-nm",
                "discovery": "ARMED-when-HW",
                "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
              },
              {
                "order": 3,
                "id": "bluetooth",
                "name": "Bluetooth",
                "op": "d2d_bluetooth",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "bluez",
                "discovery": "ARMED-when-HW",
                "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
              },
              {
                "order": 4,
                "id": "rf",
                "name": "RF",
                "op": "d2d_rf",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "rf-beyond-wifi-bt",
                "discovery": "REFUSE-without-HW",
                "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
              },
              {
                "order": 5,
                "id": "photon",
                "name": "Photon",
                "op": "d2d_photon",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "camera-flash",
                "discovery": "REFUSE-without-HW",
                "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
              }
            ],
            "security": {
              "isolation": "single-node security-awareness",
              "phoenix": "local wait / re-seal",
              "mesh_fenced_to_loopback": false,
              "forced_loopback": false,
              "loopback_isolation": false
            },
            "paper": "docs/designs/D2D-CARRIERS-1.0.md",
            "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
          },
          "d2d_status": "NOT-READY",
          "d2d_code": "FG-STUB",
          "packet_path_live": false,
          "alt_internet_live": false,
          "d2d_spec": "D2D-CARRIERS-1.0",
          "federated_mesh": "FED-MESH-1.0",
          "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
          "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        }
      },
      {
        "slug": "decisiongate",
        "name": "DecisionGATE",
        "bucket": "gate",
        "domain": null,
        "domain_id": null,
        "placement": "fabric-product",
        "status": "live",
        "fraggate_status": "live",
        "public_door": true,
        "public_door_ops": [
          "check",
          "evaluate",
          "gates",
          "verify",
          "doctor",
          "health",
          "skill"
        ],
        "stub_ops": [
          "wrap",
          "execute",
          "remote",
          "truth_score",
          "court"
        ],
        "door_label": "live FragGate door — named stub ops refuse",
        "open_live_door": true,
        "version": "0.1.0",
        "one_line": "Run a proposal through five sequential gates and get PASS, REVISE, or BLOCK.",
        "description": "Use DecisionGATE to check Definition, Evidence, Impact, Integrity, and Responsibility in order. It exists as a pre-execution filter.",
        "worker_home": "https://decisiongate-download-tracker.vibelock.workers.dev/",
        "worker_home_note": null,
        "download_url": "https://decisiongate-download-tracker.vibelock.workers.dev/download",
        "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "github": "https://github.com/AzielEliab/decisiongate",
        "mcp": "https://godlock.uk/runtime/mcp",
        "agent": {
          "mcp": "https://godlock.uk/runtime/mcp",
          "skill": "https://godlock.uk/runtime/v1/skill",
          "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
          "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=decisiongate",
          "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
          "fraggate_call_executes": true,
          "open_live_door": true,
          "software": "https://godlock.uk/runtime/v1/software",
          "pull": "https://godlock.uk/runtime/v1/pull/decisiongate",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "4e86778de3d0d7795611a7b3d29d7c734fa808a03e1e22e93bc3b694910bf172",
        "updated_at": null,
        "git_sha": null,
        "git_sha_tracks_deployed_tip": false,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/runtime/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "security": {
            "model": "single-node-security-awareness",
            "isolates": "bad-peer-or-self",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "phoenix": "local-wait-reseal",
            "phoenix_lock": true,
            "public_hostname_resurrection": false,
            "loopback_bearer": "L1-optional",
            "operator_locks": [
              {
                "n": 1,
                "id": "single-node-security-awareness",
                "status": "LIVE",
                "mesh_fenced_to_loopback": false
              },
              {
                "n": 2,
                "id": "phoenix-reboot-loop",
                "status": "LIVE",
                "phoenix": "local-wait-reseal",
                "phoenix_lock": true,
                "public_hostname_resurrection": false
              },
              {
                "n": 3,
                "id": "open-world-awareness",
                "status": "live-when-configured",
                "law": "LIVE",
                "bind": "0.0.0.0",
                "worker_socket": false,
                "forced_loopback_is_mesh_fence": false,
                "loopback_isolation_is_mesh_fence": false
              }
            ],
            "open_world_awareness": {
              "spec": "OPEN-WORLD-AWARENESS-1.0",
              "author": "Aziel Eliab",
              "identity": "Aziel Eliab",
              "open_world_awareness": true,
              "bind": "0.0.0.0",
              "all_interfaces": true,
              "law": "LIVE",
              "status": "live-when-configured",
              "live": false,
              "socket": "live-when-configured",
              "worker_socket": false,
              "qnm_node_bind": "live-when-configured",
              "mock": false,
              "forced_loopback": false,
              "loopback_isolation": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false,
              "mesh_fenced_to_loopback": false,
              "public_egress_ip": false,
              "residential": false,
              "cf_geo_exit": false,
              "cf_geo_exit_pool": false,
              "sticky_public_ip": false,
              "packet_forward": false,
              "packet_forwarding": false,
              "public_icann": false,
              "cap7_is_icann": false,
              "replaces_internet": false,
              "not_a_second_internet": true,
              "hosted_vpn": false,
              "payload_host": false,
              "vpn_hop": false,
              "wireguard": false,
              "openvpn": false,
              "l3_exit": false,
              "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
            },
            "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
          },
          "fanout": "cron-or-request-path",
          "live_nodes_plane": "human-mesh-users-site-viewers",
          "nodes_plane": "human-mesh-users-uses",
          "software_nodes_plane": "software-worker-fanout",
          "site_live_viewers_plane": "hub-human-page-presence",
          "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
          "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
          "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
          "site_presence_contract": {
            "method": "POST",
            "path": "/runtime/v1/mesh/site-presence",
            "alias": "/runtime/v1/mesh/site-heartbeat",
            "fraggate": {
              "slug": "mesh",
              "op": "site-presence"
            },
            "body": {
              "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
              "viewers": "non-negative integer concurrent human page sessions (0..10000)",
              "kind": "human-page"
            },
            "ttl_ms": 900000,
            "registered_grace_ms": 1209600000,
            "default_heartbeat_mode": "idle",
            "heartbeat_mode": "active | idle | asleep",
            "stale_keeps_registered": true,
            "stale_counts_as_live": false,
            "allowed_hosts": [
              "godlock.uk",
              "azieleliab.com",
              "azielcorpuslibrary.net"
            ],
            "excluded_hosts": [
              "hedidntjump.com"
            ],
            "refused_kinds": [
              "bot",
              "bots",
              "crawler",
              "software",
              "softwares",
              "download",
              "downloads",
              "instance",
              "mcp"
            ],
            "pull_hub_count": false,
            "invent": false,
            "fail_closed": true,
            "read": "single-key",
            "paint": "live_nodes",
            "local_recompute": false,
            "radios": "not required — hub ingest, not a TX join",
            "rate_kind": "mesh_mutate",
            "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
          },
          "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
          "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
          "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "ban_survival": "BAN-SURVIVAL-1.0",
          "spore_spec": "SPORE-1.0",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/runtime/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "neighbor_heal_is_cite": true,
              "neighbor_heal_exec": false,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "neighbor_heal_is_cite": true,
          "neighbor_heal_exec": false,
          "join_is_presence_only": true,
          "join_is_not_login": true,
          "roster_publishes_exec_urls": false,
          "mesh_mutate_rate_kind": "mesh_mutate",
          "roster_cap": 256,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "d2d_carriers": {
            "spec": "D2D-CARRIERS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "plane": "track2-reachability",
            "phase": "B+C+D",
            "phases": {
              "A": "landed",
              "B": "LIVE-when-armed",
              "C": "LIVE-when-session",
              "D": "LIVE-when-three-local-nodes / fixture",
              "E": "scaffold"
            },
            "lan_discovery": "LIVE-when-armed",
            "wifi_discovery": "ARMED-when-HW",
            "bluetooth_discovery": "ARMED-when-HW",
            "rf_discovery": "REFUSE-without-HW",
            "photon_discovery": "REFUSE-without-HW",
            "peer_tunnel": "LIVE-when-session",
            "store_forward": "LIVE-when-three-local-nodes / fixture",
            "store_forward_public": "FG-STUB",
            "worker_runs_store_forward": false,
            "second_device": false,
            "mobile_client": "present-not-demonstrated",
            "mobile_demonstrated": false,
            "app_store_release": false,
            "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
            "bootstrap_list": "scaffold",
            "needs_starting_address": true,
            "shelf_cite": "scaffold",
            "live_multi_provider": false,
            "cold_shelf_live": false,
            "dns_cut": false,
            "origin_cutover": false,
            "warn5_closed": false,
            "worker_door": "FG-STUB",
            "worker_hardware": false,
            "local_node": "qnm-node",
            "get_never_enables": true,
            "separate_from": "cap7-name",
            "cap7_is_name_plane": true,
            "cap7_public_icann": false,
            "cap7_public_egress": false,
            "mirage_is_azvpn": false,
            "aznet_replaces_internet": false,
            "not_a_second_internet": true,
            "alt_internet_live": false,
            "packet_path_live": false,
            "field_1_0": false,
            "warn5": "STANDS-until-demonstrated",
            "warn5_permanent_stay_off": false,
            "preference": "failover",
            "order": [
              "lan",
              "wifi",
              "bluetooth",
              "rf",
              "photon"
            ],
            "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
            "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
            "status": "NOT-READY",
            "code": "FG-STUB",
            "warn5_until": "demonstrated",
            "warn5_by_design": "separate-from-icann",
            "refuse": {
              "packet": "FG-STUB",
              "radio_absent": "QNM-RADIO-ABSENT",
              "cap7_egress": "MG-NO-IP-EXIT",
              "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
              "bearer": "AZP-BEARER-REFUSE",
              "payload": "AZN-NO-PAYLOAD",
              "route": "MESH-NO-ROUTE",
              "stay_off": "MESH-STAY-OFF",
              "nat": "FED-MESH-NAT-REFUSE"
            },
            "carriers": [
              {
                "order": 1,
                "id": "lan",
                "name": "LAN",
                "op": "d2d_lan",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "lan-interface",
                "discovery": "LIVE-when-armed",
                "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
              },
              {
                "order": 2,
                "id": "wifi",
                "name": "Wi-Fi",
                "op": "d2d_wifi",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "wifi-nm",
                "discovery": "ARMED-when-HW",
                "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
              },
              {
                "order": 3,
                "id": "bluetooth",
                "name": "Bluetooth",
                "op": "d2d_bluetooth",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "bluez",
                "discovery": "ARMED-when-HW",
                "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
              },
              {
                "order": 4,
                "id": "rf",
                "name": "RF",
                "op": "d2d_rf",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "rf-beyond-wifi-bt",
                "discovery": "REFUSE-without-HW",
                "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
              },
              {
                "order": 5,
                "id": "photon",
                "name": "Photon",
                "op": "d2d_photon",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "camera-flash",
                "discovery": "REFUSE-without-HW",
                "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
              }
            ],
            "security": {
              "isolation": "single-node security-awareness",
              "phoenix": "local wait / re-seal",
              "mesh_fenced_to_loopback": false,
              "forced_loopback": false,
              "loopback_isolation": false
            },
            "paper": "docs/designs/D2D-CARRIERS-1.0.md",
            "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
          },
          "d2d_status": "NOT-READY",
          "d2d_code": "FG-STUB",
          "packet_path_live": false,
          "alt_internet_live": false,
          "d2d_spec": "D2D-CARRIERS-1.0",
          "federated_mesh": "FED-MESH-1.0",
          "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
          "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        }
      },
      {
        "slug": "chronolock",
        "name": "ChronoLock",
        "bucket": "lock",
        "domain": "Evidence",
        "domain_id": "03",
        "placement": "domain-software",
        "status": "live",
        "fraggate_status": "live",
        "public_door": true,
        "public_door_ops": [
          "advisory",
          "advise",
          "anchors",
          "window",
          "doctor",
          "health",
          "skill"
        ],
        "stub_ops": [
          "scheduler",
          "targeting",
          "virality",
          "cron"
        ],
        "door_label": "live FragGate door — named stub ops refuse",
        "open_live_door": true,
        "version": "0.1.0",
        "one_line": "Check whether a place sits in the 08:30–10:30 local advisory window.",
        "description": "Use ChronoLock for timezone-aware linguistic alignment around the Temporal Neutral Window. It exists as advisory timing.",
        "worker_home": "https://chronolock-download-tracker.vibelock.workers.dev/",
        "worker_home_note": null,
        "download_url": "https://chronolock-download-tracker.vibelock.workers.dev/download",
        "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "github": "https://github.com/AzielEliab/chronolock",
        "mcp": "https://godlock.uk/runtime/mcp",
        "agent": {
          "mcp": "https://godlock.uk/runtime/mcp",
          "skill": "https://godlock.uk/runtime/v1/skill",
          "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
          "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=chronolock",
          "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
          "fraggate_call_executes": true,
          "open_live_door": true,
          "software": "https://godlock.uk/runtime/v1/software",
          "pull": "https://godlock.uk/runtime/v1/pull/chronolock",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "672a014671a63660b0538ef6d08485ebf1141489aa68bf6173995bc34fd4d4ab",
        "updated_at": null,
        "git_sha": null,
        "git_sha_tracks_deployed_tip": false,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/runtime/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "security": {
            "model": "single-node-security-awareness",
            "isolates": "bad-peer-or-self",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "phoenix": "local-wait-reseal",
            "phoenix_lock": true,
            "public_hostname_resurrection": false,
            "loopback_bearer": "L1-optional",
            "operator_locks": [
              {
                "n": 1,
                "id": "single-node-security-awareness",
                "status": "LIVE",
                "mesh_fenced_to_loopback": false
              },
              {
                "n": 2,
                "id": "phoenix-reboot-loop",
                "status": "LIVE",
                "phoenix": "local-wait-reseal",
                "phoenix_lock": true,
                "public_hostname_resurrection": false
              },
              {
                "n": 3,
                "id": "open-world-awareness",
                "status": "live-when-configured",
                "law": "LIVE",
                "bind": "0.0.0.0",
                "worker_socket": false,
                "forced_loopback_is_mesh_fence": false,
                "loopback_isolation_is_mesh_fence": false
              }
            ],
            "open_world_awareness": {
              "spec": "OPEN-WORLD-AWARENESS-1.0",
              "author": "Aziel Eliab",
              "identity": "Aziel Eliab",
              "open_world_awareness": true,
              "bind": "0.0.0.0",
              "all_interfaces": true,
              "law": "LIVE",
              "status": "live-when-configured",
              "live": false,
              "socket": "live-when-configured",
              "worker_socket": false,
              "qnm_node_bind": "live-when-configured",
              "mock": false,
              "forced_loopback": false,
              "loopback_isolation": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false,
              "mesh_fenced_to_loopback": false,
              "public_egress_ip": false,
              "residential": false,
              "cf_geo_exit": false,
              "cf_geo_exit_pool": false,
              "sticky_public_ip": false,
              "packet_forward": false,
              "packet_forwarding": false,
              "public_icann": false,
              "cap7_is_icann": false,
              "replaces_internet": false,
              "not_a_second_internet": true,
              "hosted_vpn": false,
              "payload_host": false,
              "vpn_hop": false,
              "wireguard": false,
              "openvpn": false,
              "l3_exit": false,
              "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
            },
            "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
          },
          "fanout": "cron-or-request-path",
          "live_nodes_plane": "human-mesh-users-site-viewers",
          "nodes_plane": "human-mesh-users-uses",
          "software_nodes_plane": "software-worker-fanout",
          "site_live_viewers_plane": "hub-human-page-presence",
          "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
          "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
          "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
          "site_presence_contract": {
            "method": "POST",
            "path": "/runtime/v1/mesh/site-presence",
            "alias": "/runtime/v1/mesh/site-heartbeat",
            "fraggate": {
              "slug": "mesh",
              "op": "site-presence"
            },
            "body": {
              "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
              "viewers": "non-negative integer concurrent human page sessions (0..10000)",
              "kind": "human-page"
            },
            "ttl_ms": 900000,
            "registered_grace_ms": 1209600000,
            "default_heartbeat_mode": "idle",
            "heartbeat_mode": "active | idle | asleep",
            "stale_keeps_registered": true,
            "stale_counts_as_live": false,
            "allowed_hosts": [
              "godlock.uk",
              "azieleliab.com",
              "azielcorpuslibrary.net"
            ],
            "excluded_hosts": [
              "hedidntjump.com"
            ],
            "refused_kinds": [
              "bot",
              "bots",
              "crawler",
              "software",
              "softwares",
              "download",
              "downloads",
              "instance",
              "mcp"
            ],
            "pull_hub_count": false,
            "invent": false,
            "fail_closed": true,
            "read": "single-key",
            "paint": "live_nodes",
            "local_recompute": false,
            "radios": "not required — hub ingest, not a TX join",
            "rate_kind": "mesh_mutate",
            "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
          },
          "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
          "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
          "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "ban_survival": "BAN-SURVIVAL-1.0",
          "spore_spec": "SPORE-1.0",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/runtime/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "neighbor_heal_is_cite": true,
              "neighbor_heal_exec": false,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "neighbor_heal_is_cite": true,
          "neighbor_heal_exec": false,
          "join_is_presence_only": true,
          "join_is_not_login": true,
          "roster_publishes_exec_urls": false,
          "mesh_mutate_rate_kind": "mesh_mutate",
          "roster_cap": 256,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "d2d_carriers": {
            "spec": "D2D-CARRIERS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "plane": "track2-reachability",
            "phase": "B+C+D",
            "phases": {
              "A": "landed",
              "B": "LIVE-when-armed",
              "C": "LIVE-when-session",
              "D": "LIVE-when-three-local-nodes / fixture",
              "E": "scaffold"
            },
            "lan_discovery": "LIVE-when-armed",
            "wifi_discovery": "ARMED-when-HW",
            "bluetooth_discovery": "ARMED-when-HW",
            "rf_discovery": "REFUSE-without-HW",
            "photon_discovery": "REFUSE-without-HW",
            "peer_tunnel": "LIVE-when-session",
            "store_forward": "LIVE-when-three-local-nodes / fixture",
            "store_forward_public": "FG-STUB",
            "worker_runs_store_forward": false,
            "second_device": false,
            "mobile_client": "present-not-demonstrated",
            "mobile_demonstrated": false,
            "app_store_release": false,
            "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
            "bootstrap_list": "scaffold",
            "needs_starting_address": true,
            "shelf_cite": "scaffold",
            "live_multi_provider": false,
            "cold_shelf_live": false,
            "dns_cut": false,
            "origin_cutover": false,
            "warn5_closed": false,
            "worker_door": "FG-STUB",
            "worker_hardware": false,
            "local_node": "qnm-node",
            "get_never_enables": true,
            "separate_from": "cap7-name",
            "cap7_is_name_plane": true,
            "cap7_public_icann": false,
            "cap7_public_egress": false,
            "mirage_is_azvpn": false,
            "aznet_replaces_internet": false,
            "not_a_second_internet": true,
            "alt_internet_live": false,
            "packet_path_live": false,
            "field_1_0": false,
            "warn5": "STANDS-until-demonstrated",
            "warn5_permanent_stay_off": false,
            "preference": "failover",
            "order": [
              "lan",
              "wifi",
              "bluetooth",
              "rf",
              "photon"
            ],
            "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
            "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
            "status": "NOT-READY",
            "code": "FG-STUB",
            "warn5_until": "demonstrated",
            "warn5_by_design": "separate-from-icann",
            "refuse": {
              "packet": "FG-STUB",
              "radio_absent": "QNM-RADIO-ABSENT",
              "cap7_egress": "MG-NO-IP-EXIT",
              "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
              "bearer": "AZP-BEARER-REFUSE",
              "payload": "AZN-NO-PAYLOAD",
              "route": "MESH-NO-ROUTE",
              "stay_off": "MESH-STAY-OFF",
              "nat": "FED-MESH-NAT-REFUSE"
            },
            "carriers": [
              {
                "order": 1,
                "id": "lan",
                "name": "LAN",
                "op": "d2d_lan",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "lan-interface",
                "discovery": "LIVE-when-armed",
                "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
              },
              {
                "order": 2,
                "id": "wifi",
                "name": "Wi-Fi",
                "op": "d2d_wifi",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "wifi-nm",
                "discovery": "ARMED-when-HW",
                "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
              },
              {
                "order": 3,
                "id": "bluetooth",
                "name": "Bluetooth",
                "op": "d2d_bluetooth",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "bluez",
                "discovery": "ARMED-when-HW",
                "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
              },
              {
                "order": 4,
                "id": "rf",
                "name": "RF",
                "op": "d2d_rf",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "rf-beyond-wifi-bt",
                "discovery": "REFUSE-without-HW",
                "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
              },
              {
                "order": 5,
                "id": "photon",
                "name": "Photon",
                "op": "d2d_photon",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "camera-flash",
                "discovery": "REFUSE-without-HW",
                "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
              }
            ],
            "security": {
              "isolation": "single-node security-awareness",
              "phoenix": "local wait / re-seal",
              "mesh_fenced_to_loopback": false,
              "forced_loopback": false,
              "loopback_isolation": false
            },
            "paper": "docs/designs/D2D-CARRIERS-1.0.md",
            "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
          },
          "d2d_status": "NOT-READY",
          "d2d_code": "FG-STUB",
          "packet_path_live": false,
          "alt_internet_live": false,
          "d2d_spec": "D2D-CARRIERS-1.0",
          "federated_mesh": "FED-MESH-1.0",
          "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
          "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        }
      },
      {
        "slug": "codelock",
        "name": "CodeLock",
        "bucket": "lock",
        "domain": "Language",
        "domain_id": "04",
        "placement": "domain-software",
        "status": "live",
        "fraggate_status": "live",
        "public_door": true,
        "public_door_ops": [
          "render",
          "gate-status",
          "health",
          "skill",
          "doctor"
        ],
        "stub_ops": [],
        "door_label": "live FragGate door",
        "open_live_door": true,
        "version": "0.1.0",
        "one_line": "View source as Canonical or Rosetta HTML while keeping the same meaning.",
        "description": "Use CodeLock when you want a different view of source. It exists to change perception.",
        "worker_home": "https://codelock-download-tracker.vibelock.workers.dev/",
        "worker_home_note": null,
        "download_url": "https://codelock-download-tracker.vibelock.workers.dev/download",
        "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "github": "https://github.com/AzielEliab/codelock",
        "mcp": "https://godlock.uk/runtime/mcp",
        "agent": {
          "mcp": "https://godlock.uk/runtime/mcp",
          "skill": "https://godlock.uk/runtime/v1/skill",
          "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
          "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=codelock",
          "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
          "fraggate_call_executes": true,
          "open_live_door": true,
          "software": "https://godlock.uk/runtime/v1/software",
          "pull": "https://godlock.uk/runtime/v1/pull/codelock",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "cdeacc8ed400760227248c5946d07528e2dfaf4542a40f20cb9961833d199c0b",
        "updated_at": null,
        "git_sha": null,
        "git_sha_tracks_deployed_tip": false,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/runtime/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "security": {
            "model": "single-node-security-awareness",
            "isolates": "bad-peer-or-self",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "phoenix": "local-wait-reseal",
            "phoenix_lock": true,
            "public_hostname_resurrection": false,
            "loopback_bearer": "L1-optional",
            "operator_locks": [
              {
                "n": 1,
                "id": "single-node-security-awareness",
                "status": "LIVE",
                "mesh_fenced_to_loopback": false
              },
              {
                "n": 2,
                "id": "phoenix-reboot-loop",
                "status": "LIVE",
                "phoenix": "local-wait-reseal",
                "phoenix_lock": true,
                "public_hostname_resurrection": false
              },
              {
                "n": 3,
                "id": "open-world-awareness",
                "status": "live-when-configured",
                "law": "LIVE",
                "bind": "0.0.0.0",
                "worker_socket": false,
                "forced_loopback_is_mesh_fence": false,
                "loopback_isolation_is_mesh_fence": false
              }
            ],
            "open_world_awareness": {
              "spec": "OPEN-WORLD-AWARENESS-1.0",
              "author": "Aziel Eliab",
              "identity": "Aziel Eliab",
              "open_world_awareness": true,
              "bind": "0.0.0.0",
              "all_interfaces": true,
              "law": "LIVE",
              "status": "live-when-configured",
              "live": false,
              "socket": "live-when-configured",
              "worker_socket": false,
              "qnm_node_bind": "live-when-configured",
              "mock": false,
              "forced_loopback": false,
              "loopback_isolation": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false,
              "mesh_fenced_to_loopback": false,
              "public_egress_ip": false,
              "residential": false,
              "cf_geo_exit": false,
              "cf_geo_exit_pool": false,
              "sticky_public_ip": false,
              "packet_forward": false,
              "packet_forwarding": false,
              "public_icann": false,
              "cap7_is_icann": false,
              "replaces_internet": false,
              "not_a_second_internet": true,
              "hosted_vpn": false,
              "payload_host": false,
              "vpn_hop": false,
              "wireguard": false,
              "openvpn": false,
              "l3_exit": false,
              "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
            },
            "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
          },
          "fanout": "cron-or-request-path",
          "live_nodes_plane": "human-mesh-users-site-viewers",
          "nodes_plane": "human-mesh-users-uses",
          "software_nodes_plane": "software-worker-fanout",
          "site_live_viewers_plane": "hub-human-page-presence",
          "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
          "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
          "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
          "site_presence_contract": {
            "method": "POST",
            "path": "/runtime/v1/mesh/site-presence",
            "alias": "/runtime/v1/mesh/site-heartbeat",
            "fraggate": {
              "slug": "mesh",
              "op": "site-presence"
            },
            "body": {
              "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
              "viewers": "non-negative integer concurrent human page sessions (0..10000)",
              "kind": "human-page"
            },
            "ttl_ms": 900000,
            "registered_grace_ms": 1209600000,
            "default_heartbeat_mode": "idle",
            "heartbeat_mode": "active | idle | asleep",
            "stale_keeps_registered": true,
            "stale_counts_as_live": false,
            "allowed_hosts": [
              "godlock.uk",
              "azieleliab.com",
              "azielcorpuslibrary.net"
            ],
            "excluded_hosts": [
              "hedidntjump.com"
            ],
            "refused_kinds": [
              "bot",
              "bots",
              "crawler",
              "software",
              "softwares",
              "download",
              "downloads",
              "instance",
              "mcp"
            ],
            "pull_hub_count": false,
            "invent": false,
            "fail_closed": true,
            "read": "single-key",
            "paint": "live_nodes",
            "local_recompute": false,
            "radios": "not required — hub ingest, not a TX join",
            "rate_kind": "mesh_mutate",
            "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
          },
          "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
          "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
          "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "ban_survival": "BAN-SURVIVAL-1.0",
          "spore_spec": "SPORE-1.0",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/runtime/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "neighbor_heal_is_cite": true,
              "neighbor_heal_exec": false,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "neighbor_heal_is_cite": true,
          "neighbor_heal_exec": false,
          "join_is_presence_only": true,
          "join_is_not_login": true,
          "roster_publishes_exec_urls": false,
          "mesh_mutate_rate_kind": "mesh_mutate",
          "roster_cap": 256,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "d2d_carriers": {
            "spec": "D2D-CARRIERS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "plane": "track2-reachability",
            "phase": "B+C+D",
            "phases": {
              "A": "landed",
              "B": "LIVE-when-armed",
              "C": "LIVE-when-session",
              "D": "LIVE-when-three-local-nodes / fixture",
              "E": "scaffold"
            },
            "lan_discovery": "LIVE-when-armed",
            "wifi_discovery": "ARMED-when-HW",
            "bluetooth_discovery": "ARMED-when-HW",
            "rf_discovery": "REFUSE-without-HW",
            "photon_discovery": "REFUSE-without-HW",
            "peer_tunnel": "LIVE-when-session",
            "store_forward": "LIVE-when-three-local-nodes / fixture",
            "store_forward_public": "FG-STUB",
            "worker_runs_store_forward": false,
            "second_device": false,
            "mobile_client": "present-not-demonstrated",
            "mobile_demonstrated": false,
            "app_store_release": false,
            "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
            "bootstrap_list": "scaffold",
            "needs_starting_address": true,
            "shelf_cite": "scaffold",
            "live_multi_provider": false,
            "cold_shelf_live": false,
            "dns_cut": false,
            "origin_cutover": false,
            "warn5_closed": false,
            "worker_door": "FG-STUB",
            "worker_hardware": false,
            "local_node": "qnm-node",
            "get_never_enables": true,
            "separate_from": "cap7-name",
            "cap7_is_name_plane": true,
            "cap7_public_icann": false,
            "cap7_public_egress": false,
            "mirage_is_azvpn": false,
            "aznet_replaces_internet": false,
            "not_a_second_internet": true,
            "alt_internet_live": false,
            "packet_path_live": false,
            "field_1_0": false,
            "warn5": "STANDS-until-demonstrated",
            "warn5_permanent_stay_off": false,
            "preference": "failover",
            "order": [
              "lan",
              "wifi",
              "bluetooth",
              "rf",
              "photon"
            ],
            "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
            "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
            "status": "NOT-READY",
            "code": "FG-STUB",
            "warn5_until": "demonstrated",
            "warn5_by_design": "separate-from-icann",
            "refuse": {
              "packet": "FG-STUB",
              "radio_absent": "QNM-RADIO-ABSENT",
              "cap7_egress": "MG-NO-IP-EXIT",
              "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
              "bearer": "AZP-BEARER-REFUSE",
              "payload": "AZN-NO-PAYLOAD",
              "route": "MESH-NO-ROUTE",
              "stay_off": "MESH-STAY-OFF",
              "nat": "FED-MESH-NAT-REFUSE"
            },
            "carriers": [
              {
                "order": 1,
                "id": "lan",
                "name": "LAN",
                "op": "d2d_lan",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "lan-interface",
                "discovery": "LIVE-when-armed",
                "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
              },
              {
                "order": 2,
                "id": "wifi",
                "name": "Wi-Fi",
                "op": "d2d_wifi",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "wifi-nm",
                "discovery": "ARMED-when-HW",
                "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
              },
              {
                "order": 3,
                "id": "bluetooth",
                "name": "Bluetooth",
                "op": "d2d_bluetooth",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "bluez",
                "discovery": "ARMED-when-HW",
                "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
              },
              {
                "order": 4,
                "id": "rf",
                "name": "RF",
                "op": "d2d_rf",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "rf-beyond-wifi-bt",
                "discovery": "REFUSE-without-HW",
                "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
              },
              {
                "order": 5,
                "id": "photon",
                "name": "Photon",
                "op": "d2d_photon",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "camera-flash",
                "discovery": "REFUSE-without-HW",
                "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
              }
            ],
            "security": {
              "isolation": "single-node security-awareness",
              "phoenix": "local wait / re-seal",
              "mesh_fenced_to_loopback": false,
              "forced_loopback": false,
              "loopback_isolation": false
            },
            "paper": "docs/designs/D2D-CARRIERS-1.0.md",
            "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
          },
          "d2d_status": "NOT-READY",
          "d2d_code": "FG-STUB",
          "packet_path_live": false,
          "alt_internet_live": false,
          "d2d_spec": "D2D-CARRIERS-1.0",
          "federated_mesh": "FED-MESH-1.0",
          "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
          "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        }
      },
      {
        "slug": "embryolock",
        "name": "EmbryoLock",
        "bucket": "lock",
        "domain": "Vault/Custody",
        "domain_id": "01",
        "placement": "domain-software",
        "status": "live",
        "fraggate_status": "live",
        "public_door": true,
        "public_door_ops": [
          "health",
          "skill",
          "doctor",
          "verify_hash",
          "verify-hash",
          "policy",
          "limitation",
          "cite",
          "limitations"
        ],
        "stub_ops": [
          "wipe",
          "scorch",
          "unlock",
          "unlock_after_fail",
          "unlock-after-fail",
          "encrypt",
          "decrypt",
          "initialize",
          "login",
          "arm",
          "add_files",
          "open_file",
          "export",
          "purge",
          "purge_temp",
          "hard_wipe",
          "destroy",
          "recover",
          "reset",
          "backup"
        ],
        "door_label": "live FragGate door — named stub ops refuse",
        "open_live_door": true,
        "version": "1.2.0",
        "one_line": "Cite an offline vault that prefers destruction over recovery.",
        "description": "Use EmbryoLock to check health, policy, and published hashes for the local vault. It exists so wipe and unlock stay on the device.",
        "worker_home": "https://embryolock-download-tracker.vibelock.workers.dev/",
        "worker_home_note": null,
        "download_url": "https://embryolock-download-tracker.vibelock.workers.dev/download",
        "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "github": "https://github.com/AzielEliab/EmbryoLock",
        "mcp": "https://godlock.uk/runtime/mcp",
        "agent": {
          "mcp": "https://godlock.uk/runtime/mcp",
          "skill": "https://godlock.uk/runtime/v1/skill",
          "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
          "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=embryolock",
          "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
          "fraggate_call_executes": true,
          "open_live_door": true,
          "software": "https://godlock.uk/runtime/v1/software",
          "pull": "https://godlock.uk/runtime/v1/pull/embryolock",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "bc7f6119a4bf6910b5be50cabe19bf4a2e35ac60408b5713e94878bd4e0074f3",
        "updated_at": null,
        "git_sha": null,
        "git_sha_tracks_deployed_tip": false,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/runtime/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "security": {
            "model": "single-node-security-awareness",
            "isolates": "bad-peer-or-self",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "phoenix": "local-wait-reseal",
            "phoenix_lock": true,
            "public_hostname_resurrection": false,
            "loopback_bearer": "L1-optional",
            "operator_locks": [
              {
                "n": 1,
                "id": "single-node-security-awareness",
                "status": "LIVE",
                "mesh_fenced_to_loopback": false
              },
              {
                "n": 2,
                "id": "phoenix-reboot-loop",
                "status": "LIVE",
                "phoenix": "local-wait-reseal",
                "phoenix_lock": true,
                "public_hostname_resurrection": false
              },
              {
                "n": 3,
                "id": "open-world-awareness",
                "status": "live-when-configured",
                "law": "LIVE",
                "bind": "0.0.0.0",
                "worker_socket": false,
                "forced_loopback_is_mesh_fence": false,
                "loopback_isolation_is_mesh_fence": false
              }
            ],
            "open_world_awareness": {
              "spec": "OPEN-WORLD-AWARENESS-1.0",
              "author": "Aziel Eliab",
              "identity": "Aziel Eliab",
              "open_world_awareness": true,
              "bind": "0.0.0.0",
              "all_interfaces": true,
              "law": "LIVE",
              "status": "live-when-configured",
              "live": false,
              "socket": "live-when-configured",
              "worker_socket": false,
              "qnm_node_bind": "live-when-configured",
              "mock": false,
              "forced_loopback": false,
              "loopback_isolation": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false,
              "mesh_fenced_to_loopback": false,
              "public_egress_ip": false,
              "residential": false,
              "cf_geo_exit": false,
              "cf_geo_exit_pool": false,
              "sticky_public_ip": false,
              "packet_forward": false,
              "packet_forwarding": false,
              "public_icann": false,
              "cap7_is_icann": false,
              "replaces_internet": false,
              "not_a_second_internet": true,
              "hosted_vpn": false,
              "payload_host": false,
              "vpn_hop": false,
              "wireguard": false,
              "openvpn": false,
              "l3_exit": false,
              "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
            },
            "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
          },
          "fanout": "cron-or-request-path",
          "live_nodes_plane": "human-mesh-users-site-viewers",
          "nodes_plane": "human-mesh-users-uses",
          "software_nodes_plane": "software-worker-fanout",
          "site_live_viewers_plane": "hub-human-page-presence",
          "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
          "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
          "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
          "site_presence_contract": {
            "method": "POST",
            "path": "/runtime/v1/mesh/site-presence",
            "alias": "/runtime/v1/mesh/site-heartbeat",
            "fraggate": {
              "slug": "mesh",
              "op": "site-presence"
            },
            "body": {
              "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
              "viewers": "non-negative integer concurrent human page sessions (0..10000)",
              "kind": "human-page"
            },
            "ttl_ms": 900000,
            "registered_grace_ms": 1209600000,
            "default_heartbeat_mode": "idle",
            "heartbeat_mode": "active | idle | asleep",
            "stale_keeps_registered": true,
            "stale_counts_as_live": false,
            "allowed_hosts": [
              "godlock.uk",
              "azieleliab.com",
              "azielcorpuslibrary.net"
            ],
            "excluded_hosts": [
              "hedidntjump.com"
            ],
            "refused_kinds": [
              "bot",
              "bots",
              "crawler",
              "software",
              "softwares",
              "download",
              "downloads",
              "instance",
              "mcp"
            ],
            "pull_hub_count": false,
            "invent": false,
            "fail_closed": true,
            "read": "single-key",
            "paint": "live_nodes",
            "local_recompute": false,
            "radios": "not required — hub ingest, not a TX join",
            "rate_kind": "mesh_mutate",
            "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
          },
          "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
          "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
          "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "ban_survival": "BAN-SURVIVAL-1.0",
          "spore_spec": "SPORE-1.0",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/runtime/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "neighbor_heal_is_cite": true,
              "neighbor_heal_exec": false,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "neighbor_heal_is_cite": true,
          "neighbor_heal_exec": false,
          "join_is_presence_only": true,
          "join_is_not_login": true,
          "roster_publishes_exec_urls": false,
          "mesh_mutate_rate_kind": "mesh_mutate",
          "roster_cap": 256,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "d2d_carriers": {
            "spec": "D2D-CARRIERS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "plane": "track2-reachability",
            "phase": "B+C+D",
            "phases": {
              "A": "landed",
              "B": "LIVE-when-armed",
              "C": "LIVE-when-session",
              "D": "LIVE-when-three-local-nodes / fixture",
              "E": "scaffold"
            },
            "lan_discovery": "LIVE-when-armed",
            "wifi_discovery": "ARMED-when-HW",
            "bluetooth_discovery": "ARMED-when-HW",
            "rf_discovery": "REFUSE-without-HW",
            "photon_discovery": "REFUSE-without-HW",
            "peer_tunnel": "LIVE-when-session",
            "store_forward": "LIVE-when-three-local-nodes / fixture",
            "store_forward_public": "FG-STUB",
            "worker_runs_store_forward": false,
            "second_device": false,
            "mobile_client": "present-not-demonstrated",
            "mobile_demonstrated": false,
            "app_store_release": false,
            "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
            "bootstrap_list": "scaffold",
            "needs_starting_address": true,
            "shelf_cite": "scaffold",
            "live_multi_provider": false,
            "cold_shelf_live": false,
            "dns_cut": false,
            "origin_cutover": false,
            "warn5_closed": false,
            "worker_door": "FG-STUB",
            "worker_hardware": false,
            "local_node": "qnm-node",
            "get_never_enables": true,
            "separate_from": "cap7-name",
            "cap7_is_name_plane": true,
            "cap7_public_icann": false,
            "cap7_public_egress": false,
            "mirage_is_azvpn": false,
            "aznet_replaces_internet": false,
            "not_a_second_internet": true,
            "alt_internet_live": false,
            "packet_path_live": false,
            "field_1_0": false,
            "warn5": "STANDS-until-demonstrated",
            "warn5_permanent_stay_off": false,
            "preference": "failover",
            "order": [
              "lan",
              "wifi",
              "bluetooth",
              "rf",
              "photon"
            ],
            "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
            "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
            "status": "NOT-READY",
            "code": "FG-STUB",
            "warn5_until": "demonstrated",
            "warn5_by_design": "separate-from-icann",
            "refuse": {
              "packet": "FG-STUB",
              "radio_absent": "QNM-RADIO-ABSENT",
              "cap7_egress": "MG-NO-IP-EXIT",
              "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
              "bearer": "AZP-BEARER-REFUSE",
              "payload": "AZN-NO-PAYLOAD",
              "route": "MESH-NO-ROUTE",
              "stay_off": "MESH-STAY-OFF",
              "nat": "FED-MESH-NAT-REFUSE"
            },
            "carriers": [
              {
                "order": 1,
                "id": "lan",
                "name": "LAN",
                "op": "d2d_lan",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "lan-interface",
                "discovery": "LIVE-when-armed",
                "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
              },
              {
                "order": 2,
                "id": "wifi",
                "name": "Wi-Fi",
                "op": "d2d_wifi",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "wifi-nm",
                "discovery": "ARMED-when-HW",
                "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
              },
              {
                "order": 3,
                "id": "bluetooth",
                "name": "Bluetooth",
                "op": "d2d_bluetooth",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "bluez",
                "discovery": "ARMED-when-HW",
                "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
              },
              {
                "order": 4,
                "id": "rf",
                "name": "RF",
                "op": "d2d_rf",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "rf-beyond-wifi-bt",
                "discovery": "REFUSE-without-HW",
                "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
              },
              {
                "order": 5,
                "id": "photon",
                "name": "Photon",
                "op": "d2d_photon",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "camera-flash",
                "discovery": "REFUSE-without-HW",
                "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
              }
            ],
            "security": {
              "isolation": "single-node security-awareness",
              "phoenix": "local wait / re-seal",
              "mesh_fenced_to_loopback": false,
              "forced_loopback": false,
              "loopback_isolation": false
            },
            "paper": "docs/designs/D2D-CARRIERS-1.0.md",
            "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
          },
          "d2d_status": "NOT-READY",
          "d2d_code": "FG-STUB",
          "packet_path_live": false,
          "alt_internet_live": false,
          "d2d_spec": "D2D-CARRIERS-1.0",
          "federated_mesh": "FED-MESH-1.0",
          "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
          "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        },
        "local_destructive_boundary": true,
        "surface": "live-with-local-destructive-boundary",
        "public_mesh_destructive": false
      },
      {
        "slug": "employeelock",
        "name": "EmployeeLock",
        "bucket": "lock",
        "domain": "Evidence",
        "domain_id": "03",
        "placement": "domain-software",
        "status": "live",
        "fraggate_status": "live",
        "public_door": true,
        "public_door_ops": [
          "append-preview",
          "verify-canonical",
          "health",
          "skill",
          "doctor"
        ],
        "stub_ops": [
          "court",
          "judge"
        ],
        "door_label": "live FragGate door — named stub ops refuse",
        "open_live_door": true,
        "version": "0.1.0",
        "one_line": "Hash a proposed accountability log row on the client.",
        "description": "Use EmployeeLock as a hash-chained accountability workbook. It exists to preview log integrity.",
        "worker_home": "https://employeelock-download-tracker.vibelock.workers.dev/",
        "worker_home_note": null,
        "download_url": "https://employeelock-download-tracker.vibelock.workers.dev/download",
        "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "github": "https://github.com/AzielEliab/employeelock",
        "mcp": "https://godlock.uk/runtime/mcp",
        "agent": {
          "mcp": "https://godlock.uk/runtime/mcp",
          "skill": "https://godlock.uk/runtime/v1/skill",
          "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
          "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=employeelock",
          "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
          "fraggate_call_executes": true,
          "open_live_door": true,
          "software": "https://godlock.uk/runtime/v1/software",
          "pull": "https://godlock.uk/runtime/v1/pull/employeelock",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "886e90395752e7dcb5458a6ee501c34858a18574623b2e542513b4faa96e1d90",
        "updated_at": null,
        "git_sha": null,
        "git_sha_tracks_deployed_tip": false,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/runtime/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "security": {
            "model": "single-node-security-awareness",
            "isolates": "bad-peer-or-self",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "phoenix": "local-wait-reseal",
            "phoenix_lock": true,
            "public_hostname_resurrection": false,
            "loopback_bearer": "L1-optional",
            "operator_locks": [
              {
                "n": 1,
                "id": "single-node-security-awareness",
                "status": "LIVE",
                "mesh_fenced_to_loopback": false
              },
              {
                "n": 2,
                "id": "phoenix-reboot-loop",
                "status": "LIVE",
                "phoenix": "local-wait-reseal",
                "phoenix_lock": true,
                "public_hostname_resurrection": false
              },
              {
                "n": 3,
                "id": "open-world-awareness",
                "status": "live-when-configured",
                "law": "LIVE",
                "bind": "0.0.0.0",
                "worker_socket": false,
                "forced_loopback_is_mesh_fence": false,
                "loopback_isolation_is_mesh_fence": false
              }
            ],
            "open_world_awareness": {
              "spec": "OPEN-WORLD-AWARENESS-1.0",
              "author": "Aziel Eliab",
              "identity": "Aziel Eliab",
              "open_world_awareness": true,
              "bind": "0.0.0.0",
              "all_interfaces": true,
              "law": "LIVE",
              "status": "live-when-configured",
              "live": false,
              "socket": "live-when-configured",
              "worker_socket": false,
              "qnm_node_bind": "live-when-configured",
              "mock": false,
              "forced_loopback": false,
              "loopback_isolation": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false,
              "mesh_fenced_to_loopback": false,
              "public_egress_ip": false,
              "residential": false,
              "cf_geo_exit": false,
              "cf_geo_exit_pool": false,
              "sticky_public_ip": false,
              "packet_forward": false,
              "packet_forwarding": false,
              "public_icann": false,
              "cap7_is_icann": false,
              "replaces_internet": false,
              "not_a_second_internet": true,
              "hosted_vpn": false,
              "payload_host": false,
              "vpn_hop": false,
              "wireguard": false,
              "openvpn": false,
              "l3_exit": false,
              "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
            },
            "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
          },
          "fanout": "cron-or-request-path",
          "live_nodes_plane": "human-mesh-users-site-viewers",
          "nodes_plane": "human-mesh-users-uses",
          "software_nodes_plane": "software-worker-fanout",
          "site_live_viewers_plane": "hub-human-page-presence",
          "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
          "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
          "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
          "site_presence_contract": {
            "method": "POST",
            "path": "/runtime/v1/mesh/site-presence",
            "alias": "/runtime/v1/mesh/site-heartbeat",
            "fraggate": {
              "slug": "mesh",
              "op": "site-presence"
            },
            "body": {
              "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
              "viewers": "non-negative integer concurrent human page sessions (0..10000)",
              "kind": "human-page"
            },
            "ttl_ms": 900000,
            "registered_grace_ms": 1209600000,
            "default_heartbeat_mode": "idle",
            "heartbeat_mode": "active | idle | asleep",
            "stale_keeps_registered": true,
            "stale_counts_as_live": false,
            "allowed_hosts": [
              "godlock.uk",
              "azieleliab.com",
              "azielcorpuslibrary.net"
            ],
            "excluded_hosts": [
              "hedidntjump.com"
            ],
            "refused_kinds": [
              "bot",
              "bots",
              "crawler",
              "software",
              "softwares",
              "download",
              "downloads",
              "instance",
              "mcp"
            ],
            "pull_hub_count": false,
            "invent": false,
            "fail_closed": true,
            "read": "single-key",
            "paint": "live_nodes",
            "local_recompute": false,
            "radios": "not required — hub ingest, not a TX join",
            "rate_kind": "mesh_mutate",
            "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
          },
          "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
          "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
          "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "ban_survival": "BAN-SURVIVAL-1.0",
          "spore_spec": "SPORE-1.0",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/runtime/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "neighbor_heal_is_cite": true,
              "neighbor_heal_exec": false,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "neighbor_heal_is_cite": true,
          "neighbor_heal_exec": false,
          "join_is_presence_only": true,
          "join_is_not_login": true,
          "roster_publishes_exec_urls": false,
          "mesh_mutate_rate_kind": "mesh_mutate",
          "roster_cap": 256,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "d2d_carriers": {
            "spec": "D2D-CARRIERS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "plane": "track2-reachability",
            "phase": "B+C+D",
            "phases": {
              "A": "landed",
              "B": "LIVE-when-armed",
              "C": "LIVE-when-session",
              "D": "LIVE-when-three-local-nodes / fixture",
              "E": "scaffold"
            },
            "lan_discovery": "LIVE-when-armed",
            "wifi_discovery": "ARMED-when-HW",
            "bluetooth_discovery": "ARMED-when-HW",
            "rf_discovery": "REFUSE-without-HW",
            "photon_discovery": "REFUSE-without-HW",
            "peer_tunnel": "LIVE-when-session",
            "store_forward": "LIVE-when-three-local-nodes / fixture",
            "store_forward_public": "FG-STUB",
            "worker_runs_store_forward": false,
            "second_device": false,
            "mobile_client": "present-not-demonstrated",
            "mobile_demonstrated": false,
            "app_store_release": false,
            "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
            "bootstrap_list": "scaffold",
            "needs_starting_address": true,
            "shelf_cite": "scaffold",
            "live_multi_provider": false,
            "cold_shelf_live": false,
            "dns_cut": false,
            "origin_cutover": false,
            "warn5_closed": false,
            "worker_door": "FG-STUB",
            "worker_hardware": false,
            "local_node": "qnm-node",
            "get_never_enables": true,
            "separate_from": "cap7-name",
            "cap7_is_name_plane": true,
            "cap7_public_icann": false,
            "cap7_public_egress": false,
            "mirage_is_azvpn": false,
            "aznet_replaces_internet": false,
            "not_a_second_internet": true,
            "alt_internet_live": false,
            "packet_path_live": false,
            "field_1_0": false,
            "warn5": "STANDS-until-demonstrated",
            "warn5_permanent_stay_off": false,
            "preference": "failover",
            "order": [
              "lan",
              "wifi",
              "bluetooth",
              "rf",
              "photon"
            ],
            "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
            "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
            "status": "NOT-READY",
            "code": "FG-STUB",
            "warn5_until": "demonstrated",
            "warn5_by_design": "separate-from-icann",
            "refuse": {
              "packet": "FG-STUB",
              "radio_absent": "QNM-RADIO-ABSENT",
              "cap7_egress": "MG-NO-IP-EXIT",
              "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
              "bearer": "AZP-BEARER-REFUSE",
              "payload": "AZN-NO-PAYLOAD",
              "route": "MESH-NO-ROUTE",
              "stay_off": "MESH-STAY-OFF",
              "nat": "FED-MESH-NAT-REFUSE"
            },
            "carriers": [
              {
                "order": 1,
                "id": "lan",
                "name": "LAN",
                "op": "d2d_lan",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "lan-interface",
                "discovery": "LIVE-when-armed",
                "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
              },
              {
                "order": 2,
                "id": "wifi",
                "name": "Wi-Fi",
                "op": "d2d_wifi",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "wifi-nm",
                "discovery": "ARMED-when-HW",
                "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
              },
              {
                "order": 3,
                "id": "bluetooth",
                "name": "Bluetooth",
                "op": "d2d_bluetooth",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "bluez",
                "discovery": "ARMED-when-HW",
                "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
              },
              {
                "order": 4,
                "id": "rf",
                "name": "RF",
                "op": "d2d_rf",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "rf-beyond-wifi-bt",
                "discovery": "REFUSE-without-HW",
                "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
              },
              {
                "order": 5,
                "id": "photon",
                "name": "Photon",
                "op": "d2d_photon",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "camera-flash",
                "discovery": "REFUSE-without-HW",
                "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
              }
            ],
            "security": {
              "isolation": "single-node security-awareness",
              "phoenix": "local wait / re-seal",
              "mesh_fenced_to_loopback": false,
              "forced_loopback": false,
              "loopback_isolation": false
            },
            "paper": "docs/designs/D2D-CARRIERS-1.0.md",
            "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
          },
          "d2d_status": "NOT-READY",
          "d2d_code": "FG-STUB",
          "packet_path_live": false,
          "alt_internet_live": false,
          "d2d_spec": "D2D-CARRIERS-1.0",
          "federated_mesh": "FED-MESH-1.0",
          "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
          "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        }
      },
      {
        "slug": "foldlock",
        "name": "FoldLock",
        "bucket": "lock",
        "domain": "Language",
        "domain_id": "04",
        "placement": "domain-software",
        "status": "live",
        "fraggate_status": "live",
        "public_door": true,
        "public_door_ops": [
          "fold-preview",
          "unfold-preview",
          "health",
          "skill",
          "doctor",
          "pack-verify"
        ],
        "stub_ops": [
          "zip",
          "hosted_store"
        ],
        "door_label": "live FragGate door — named stub ops refuse",
        "open_live_door": true,
        "version": "0.8.0",
        "one_line": "Fold UTF-8 text by suppressing tether words, then check the restore.",
        "description": "Use FoldLock to preview small-text folds and check the shipped corpus tip hash. It exists as algorithmic text folding.",
        "worker_home": "https://foldlock-download-tracker.vibelock.workers.dev/",
        "worker_home_note": null,
        "download_url": "https://foldlock-download-tracker.vibelock.workers.dev/download",
        "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "github": "https://github.com/AzielEliab/foldlock",
        "mcp": "https://godlock.uk/runtime/mcp",
        "agent": {
          "mcp": "https://godlock.uk/runtime/mcp",
          "skill": "https://godlock.uk/runtime/v1/skill",
          "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
          "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=foldlock",
          "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
          "fraggate_call_executes": true,
          "open_live_door": true,
          "software": "https://godlock.uk/runtime/v1/software",
          "pull": "https://godlock.uk/runtime/v1/pull/foldlock",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "1034d5924b88878918986abe260338b0aff0117bc6f9c4d4a01a41d843cfa0a8",
        "updated_at": null,
        "git_sha": null,
        "git_sha_tracks_deployed_tip": false,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/runtime/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "security": {
            "model": "single-node-security-awareness",
            "isolates": "bad-peer-or-self",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "phoenix": "local-wait-reseal",
            "phoenix_lock": true,
            "public_hostname_resurrection": false,
            "loopback_bearer": "L1-optional",
            "operator_locks": [
              {
                "n": 1,
                "id": "single-node-security-awareness",
                "status": "LIVE",
                "mesh_fenced_to_loopback": false
              },
              {
                "n": 2,
                "id": "phoenix-reboot-loop",
                "status": "LIVE",
                "phoenix": "local-wait-reseal",
                "phoenix_lock": true,
                "public_hostname_resurrection": false
              },
              {
                "n": 3,
                "id": "open-world-awareness",
                "status": "live-when-configured",
                "law": "LIVE",
                "bind": "0.0.0.0",
                "worker_socket": false,
                "forced_loopback_is_mesh_fence": false,
                "loopback_isolation_is_mesh_fence": false
              }
            ],
            "open_world_awareness": {
              "spec": "OPEN-WORLD-AWARENESS-1.0",
              "author": "Aziel Eliab",
              "identity": "Aziel Eliab",
              "open_world_awareness": true,
              "bind": "0.0.0.0",
              "all_interfaces": true,
              "law": "LIVE",
              "status": "live-when-configured",
              "live": false,
              "socket": "live-when-configured",
              "worker_socket": false,
              "qnm_node_bind": "live-when-configured",
              "mock": false,
              "forced_loopback": false,
              "loopback_isolation": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false,
              "mesh_fenced_to_loopback": false,
              "public_egress_ip": false,
              "residential": false,
              "cf_geo_exit": false,
              "cf_geo_exit_pool": false,
              "sticky_public_ip": false,
              "packet_forward": false,
              "packet_forwarding": false,
              "public_icann": false,
              "cap7_is_icann": false,
              "replaces_internet": false,
              "not_a_second_internet": true,
              "hosted_vpn": false,
              "payload_host": false,
              "vpn_hop": false,
              "wireguard": false,
              "openvpn": false,
              "l3_exit": false,
              "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
            },
            "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
          },
          "fanout": "cron-or-request-path",
          "live_nodes_plane": "human-mesh-users-site-viewers",
          "nodes_plane": "human-mesh-users-uses",
          "software_nodes_plane": "software-worker-fanout",
          "site_live_viewers_plane": "hub-human-page-presence",
          "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
          "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
          "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
          "site_presence_contract": {
            "method": "POST",
            "path": "/runtime/v1/mesh/site-presence",
            "alias": "/runtime/v1/mesh/site-heartbeat",
            "fraggate": {
              "slug": "mesh",
              "op": "site-presence"
            },
            "body": {
              "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
              "viewers": "non-negative integer concurrent human page sessions (0..10000)",
              "kind": "human-page"
            },
            "ttl_ms": 900000,
            "registered_grace_ms": 1209600000,
            "default_heartbeat_mode": "idle",
            "heartbeat_mode": "active | idle | asleep",
            "stale_keeps_registered": true,
            "stale_counts_as_live": false,
            "allowed_hosts": [
              "godlock.uk",
              "azieleliab.com",
              "azielcorpuslibrary.net"
            ],
            "excluded_hosts": [
              "hedidntjump.com"
            ],
            "refused_kinds": [
              "bot",
              "bots",
              "crawler",
              "software",
              "softwares",
              "download",
              "downloads",
              "instance",
              "mcp"
            ],
            "pull_hub_count": false,
            "invent": false,
            "fail_closed": true,
            "read": "single-key",
            "paint": "live_nodes",
            "local_recompute": false,
            "radios": "not required — hub ingest, not a TX join",
            "rate_kind": "mesh_mutate",
            "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
          },
          "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
          "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
          "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "ban_survival": "BAN-SURVIVAL-1.0",
          "spore_spec": "SPORE-1.0",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/runtime/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "neighbor_heal_is_cite": true,
              "neighbor_heal_exec": false,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "neighbor_heal_is_cite": true,
          "neighbor_heal_exec": false,
          "join_is_presence_only": true,
          "join_is_not_login": true,
          "roster_publishes_exec_urls": false,
          "mesh_mutate_rate_kind": "mesh_mutate",
          "roster_cap": 256,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "d2d_carriers": {
            "spec": "D2D-CARRIERS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "plane": "track2-reachability",
            "phase": "B+C+D",
            "phases": {
              "A": "landed",
              "B": "LIVE-when-armed",
              "C": "LIVE-when-session",
              "D": "LIVE-when-three-local-nodes / fixture",
              "E": "scaffold"
            },
            "lan_discovery": "LIVE-when-armed",
            "wifi_discovery": "ARMED-when-HW",
            "bluetooth_discovery": "ARMED-when-HW",
            "rf_discovery": "REFUSE-without-HW",
            "photon_discovery": "REFUSE-without-HW",
            "peer_tunnel": "LIVE-when-session",
            "store_forward": "LIVE-when-three-local-nodes / fixture",
            "store_forward_public": "FG-STUB",
            "worker_runs_store_forward": false,
            "second_device": false,
            "mobile_client": "present-not-demonstrated",
            "mobile_demonstrated": false,
            "app_store_release": false,
            "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
            "bootstrap_list": "scaffold",
            "needs_starting_address": true,
            "shelf_cite": "scaffold",
            "live_multi_provider": false,
            "cold_shelf_live": false,
            "dns_cut": false,
            "origin_cutover": false,
            "warn5_closed": false,
            "worker_door": "FG-STUB",
            "worker_hardware": false,
            "local_node": "qnm-node",
            "get_never_enables": true,
            "separate_from": "cap7-name",
            "cap7_is_name_plane": true,
            "cap7_public_icann": false,
            "cap7_public_egress": false,
            "mirage_is_azvpn": false,
            "aznet_replaces_internet": false,
            "not_a_second_internet": true,
            "alt_internet_live": false,
            "packet_path_live": false,
            "field_1_0": false,
            "warn5": "STANDS-until-demonstrated",
            "warn5_permanent_stay_off": false,
            "preference": "failover",
            "order": [
              "lan",
              "wifi",
              "bluetooth",
              "rf",
              "photon"
            ],
            "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
            "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
            "status": "NOT-READY",
            "code": "FG-STUB",
            "warn5_until": "demonstrated",
            "warn5_by_design": "separate-from-icann",
            "refuse": {
              "packet": "FG-STUB",
              "radio_absent": "QNM-RADIO-ABSENT",
              "cap7_egress": "MG-NO-IP-EXIT",
              "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
              "bearer": "AZP-BEARER-REFUSE",
              "payload": "AZN-NO-PAYLOAD",
              "route": "MESH-NO-ROUTE",
              "stay_off": "MESH-STAY-OFF",
              "nat": "FED-MESH-NAT-REFUSE"
            },
            "carriers": [
              {
                "order": 1,
                "id": "lan",
                "name": "LAN",
                "op": "d2d_lan",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "lan-interface",
                "discovery": "LIVE-when-armed",
                "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
              },
              {
                "order": 2,
                "id": "wifi",
                "name": "Wi-Fi",
                "op": "d2d_wifi",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "wifi-nm",
                "discovery": "ARMED-when-HW",
                "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
              },
              {
                "order": 3,
                "id": "bluetooth",
                "name": "Bluetooth",
                "op": "d2d_bluetooth",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "bluez",
                "discovery": "ARMED-when-HW",
                "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
              },
              {
                "order": 4,
                "id": "rf",
                "name": "RF",
                "op": "d2d_rf",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "rf-beyond-wifi-bt",
                "discovery": "REFUSE-without-HW",
                "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
              },
              {
                "order": 5,
                "id": "photon",
                "name": "Photon",
                "op": "d2d_photon",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "camera-flash",
                "discovery": "REFUSE-without-HW",
                "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
              }
            ],
            "security": {
              "isolation": "single-node security-awareness",
              "phoenix": "local wait / re-seal",
              "mesh_fenced_to_loopback": false,
              "forced_loopback": false,
              "loopback_isolation": false
            },
            "paper": "docs/designs/D2D-CARRIERS-1.0.md",
            "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
          },
          "d2d_status": "NOT-READY",
          "d2d_code": "FG-STUB",
          "packet_path_live": false,
          "alt_internet_live": false,
          "d2d_spec": "D2D-CARRIERS-1.0",
          "federated_mesh": "FED-MESH-1.0",
          "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
          "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        }
      },
      {
        "slug": "godlock",
        "name": "GodLock",
        "bucket": "lock",
        "domain": "Language",
        "domain_id": "04",
        "placement": "domain-software",
        "status": "live",
        "fraggate_status": "live",
        "public_door": true,
        "public_door_ops": [
          "score",
          "submit",
          "health",
          "skill",
          "doctor"
        ],
        "stub_ops": [],
        "door_label": "live FragGate door",
        "open_live_door": true,
        "version": "0.1.0",
        "one_line": "Score text for offline hardening and receive an ephemeral receipt.",
        "description": "Use GodLock to score text and receive a logical receipt. GodLock is a product name. Public identity is Aziel Eliab only. It exists for offline hardening scores.",
        "worker_home": "https://godlock-download-tracker.vibelock.workers.dev/",
        "worker_home_note": null,
        "download_url": "https://godlock-download-tracker.vibelock.workers.dev/download",
        "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "github": "https://github.com/AzielEliab/godlock",
        "mcp": "https://godlock.uk/runtime/mcp",
        "agent": {
          "mcp": "https://godlock.uk/runtime/mcp",
          "skill": "https://godlock.uk/runtime/v1/skill",
          "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
          "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=godlock",
          "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
          "fraggate_call_executes": true,
          "open_live_door": true,
          "software": "https://godlock.uk/runtime/v1/software",
          "pull": "https://godlock.uk/runtime/v1/pull/godlock",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "6b9076ca8e4aa63e6c81deb40f102f55f8769a7c10f0b8347605903f7df93f54",
        "updated_at": null,
        "git_sha": null,
        "git_sha_tracks_deployed_tip": false,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/runtime/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "security": {
            "model": "single-node-security-awareness",
            "isolates": "bad-peer-or-self",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "phoenix": "local-wait-reseal",
            "phoenix_lock": true,
            "public_hostname_resurrection": false,
            "loopback_bearer": "L1-optional",
            "operator_locks": [
              {
                "n": 1,
                "id": "single-node-security-awareness",
                "status": "LIVE",
                "mesh_fenced_to_loopback": false
              },
              {
                "n": 2,
                "id": "phoenix-reboot-loop",
                "status": "LIVE",
                "phoenix": "local-wait-reseal",
                "phoenix_lock": true,
                "public_hostname_resurrection": false
              },
              {
                "n": 3,
                "id": "open-world-awareness",
                "status": "live-when-configured",
                "law": "LIVE",
                "bind": "0.0.0.0",
                "worker_socket": false,
                "forced_loopback_is_mesh_fence": false,
                "loopback_isolation_is_mesh_fence": false
              }
            ],
            "open_world_awareness": {
              "spec": "OPEN-WORLD-AWARENESS-1.0",
              "author": "Aziel Eliab",
              "identity": "Aziel Eliab",
              "open_world_awareness": true,
              "bind": "0.0.0.0",
              "all_interfaces": true,
              "law": "LIVE",
              "status": "live-when-configured",
              "live": false,
              "socket": "live-when-configured",
              "worker_socket": false,
              "qnm_node_bind": "live-when-configured",
              "mock": false,
              "forced_loopback": false,
              "loopback_isolation": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false,
              "mesh_fenced_to_loopback": false,
              "public_egress_ip": false,
              "residential": false,
              "cf_geo_exit": false,
              "cf_geo_exit_pool": false,
              "sticky_public_ip": false,
              "packet_forward": false,
              "packet_forwarding": false,
              "public_icann": false,
              "cap7_is_icann": false,
              "replaces_internet": false,
              "not_a_second_internet": true,
              "hosted_vpn": false,
              "payload_host": false,
              "vpn_hop": false,
              "wireguard": false,
              "openvpn": false,
              "l3_exit": false,
              "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
            },
            "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
          },
          "fanout": "cron-or-request-path",
          "live_nodes_plane": "human-mesh-users-site-viewers",
          "nodes_plane": "human-mesh-users-uses",
          "software_nodes_plane": "software-worker-fanout",
          "site_live_viewers_plane": "hub-human-page-presence",
          "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
          "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
          "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
          "site_presence_contract": {
            "method": "POST",
            "path": "/runtime/v1/mesh/site-presence",
            "alias": "/runtime/v1/mesh/site-heartbeat",
            "fraggate": {
              "slug": "mesh",
              "op": "site-presence"
            },
            "body": {
              "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
              "viewers": "non-negative integer concurrent human page sessions (0..10000)",
              "kind": "human-page"
            },
            "ttl_ms": 900000,
            "registered_grace_ms": 1209600000,
            "default_heartbeat_mode": "idle",
            "heartbeat_mode": "active | idle | asleep",
            "stale_keeps_registered": true,
            "stale_counts_as_live": false,
            "allowed_hosts": [
              "godlock.uk",
              "azieleliab.com",
              "azielcorpuslibrary.net"
            ],
            "excluded_hosts": [
              "hedidntjump.com"
            ],
            "refused_kinds": [
              "bot",
              "bots",
              "crawler",
              "software",
              "softwares",
              "download",
              "downloads",
              "instance",
              "mcp"
            ],
            "pull_hub_count": false,
            "invent": false,
            "fail_closed": true,
            "read": "single-key",
            "paint": "live_nodes",
            "local_recompute": false,
            "radios": "not required — hub ingest, not a TX join",
            "rate_kind": "mesh_mutate",
            "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
          },
          "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
          "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
          "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "ban_survival": "BAN-SURVIVAL-1.0",
          "spore_spec": "SPORE-1.0",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/runtime/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "neighbor_heal_is_cite": true,
              "neighbor_heal_exec": false,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "neighbor_heal_is_cite": true,
          "neighbor_heal_exec": false,
          "join_is_presence_only": true,
          "join_is_not_login": true,
          "roster_publishes_exec_urls": false,
          "mesh_mutate_rate_kind": "mesh_mutate",
          "roster_cap": 256,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "d2d_carriers": {
            "spec": "D2D-CARRIERS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "plane": "track2-reachability",
            "phase": "B+C+D",
            "phases": {
              "A": "landed",
              "B": "LIVE-when-armed",
              "C": "LIVE-when-session",
              "D": "LIVE-when-three-local-nodes / fixture",
              "E": "scaffold"
            },
            "lan_discovery": "LIVE-when-armed",
            "wifi_discovery": "ARMED-when-HW",
            "bluetooth_discovery": "ARMED-when-HW",
            "rf_discovery": "REFUSE-without-HW",
            "photon_discovery": "REFUSE-without-HW",
            "peer_tunnel": "LIVE-when-session",
            "store_forward": "LIVE-when-three-local-nodes / fixture",
            "store_forward_public": "FG-STUB",
            "worker_runs_store_forward": false,
            "second_device": false,
            "mobile_client": "present-not-demonstrated",
            "mobile_demonstrated": false,
            "app_store_release": false,
            "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
            "bootstrap_list": "scaffold",
            "needs_starting_address": true,
            "shelf_cite": "scaffold",
            "live_multi_provider": false,
            "cold_shelf_live": false,
            "dns_cut": false,
            "origin_cutover": false,
            "warn5_closed": false,
            "worker_door": "FG-STUB",
            "worker_hardware": false,
            "local_node": "qnm-node",
            "get_never_enables": true,
            "separate_from": "cap7-name",
            "cap7_is_name_plane": true,
            "cap7_public_icann": false,
            "cap7_public_egress": false,
            "mirage_is_azvpn": false,
            "aznet_replaces_internet": false,
            "not_a_second_internet": true,
            "alt_internet_live": false,
            "packet_path_live": false,
            "field_1_0": false,
            "warn5": "STANDS-until-demonstrated",
            "warn5_permanent_stay_off": false,
            "preference": "failover",
            "order": [
              "lan",
              "wifi",
              "bluetooth",
              "rf",
              "photon"
            ],
            "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
            "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
            "status": "NOT-READY",
            "code": "FG-STUB",
            "warn5_until": "demonstrated",
            "warn5_by_design": "separate-from-icann",
            "refuse": {
              "packet": "FG-STUB",
              "radio_absent": "QNM-RADIO-ABSENT",
              "cap7_egress": "MG-NO-IP-EXIT",
              "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
              "bearer": "AZP-BEARER-REFUSE",
              "payload": "AZN-NO-PAYLOAD",
              "route": "MESH-NO-ROUTE",
              "stay_off": "MESH-STAY-OFF",
              "nat": "FED-MESH-NAT-REFUSE"
            },
            "carriers": [
              {
                "order": 1,
                "id": "lan",
                "name": "LAN",
                "op": "d2d_lan",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "lan-interface",
                "discovery": "LIVE-when-armed",
                "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
              },
              {
                "order": 2,
                "id": "wifi",
                "name": "Wi-Fi",
                "op": "d2d_wifi",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "wifi-nm",
                "discovery": "ARMED-when-HW",
                "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
              },
              {
                "order": 3,
                "id": "bluetooth",
                "name": "Bluetooth",
                "op": "d2d_bluetooth",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "bluez",
                "discovery": "ARMED-when-HW",
                "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
              },
              {
                "order": 4,
                "id": "rf",
                "name": "RF",
                "op": "d2d_rf",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "rf-beyond-wifi-bt",
                "discovery": "REFUSE-without-HW",
                "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
              },
              {
                "order": 5,
                "id": "photon",
                "name": "Photon",
                "op": "d2d_photon",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "camera-flash",
                "discovery": "REFUSE-without-HW",
                "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
              }
            ],
            "security": {
              "isolation": "single-node security-awareness",
              "phoenix": "local wait / re-seal",
              "mesh_fenced_to_loopback": false,
              "forced_loopback": false,
              "loopback_isolation": false
            },
            "paper": "docs/designs/D2D-CARRIERS-1.0.md",
            "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
          },
          "d2d_status": "NOT-READY",
          "d2d_code": "FG-STUB",
          "packet_path_live": false,
          "alt_internet_live": false,
          "d2d_spec": "D2D-CARRIERS-1.0",
          "federated_mesh": "FED-MESH-1.0",
          "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
          "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        }
      },
      {
        "slug": "mialock",
        "name": "M.I.A.Lock",
        "bucket": "lock",
        "domain": "Evidence",
        "domain_id": "03",
        "placement": "domain-software",
        "status": "live",
        "fraggate_status": "live",
        "public_door": true,
        "public_door_ops": [
          "map",
          "search-options",
          "queries",
          "doe-match",
          "coverage",
          "example",
          "health",
          "skill",
          "doctor"
        ],
        "stub_ops": [],
        "door_label": "live FragGate door",
        "open_live_door": true,
        "version": "0.1.1",
        "one_line": "Map missing-person events and rank Doe notices as compatibility leads.",
        "description": "Use M.I.A.Lock for event maps, archive search plans, Doe matching, and coverage heat. It exists to organize authorized search work — Doe hits are leads, and heat is search intensity.",
        "worker_home": "https://mialock-download-tracker.vibelock.workers.dev/",
        "worker_home_note": null,
        "download_url": "https://mialock-download-tracker.vibelock.workers.dev/download",
        "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "github": "https://github.com/AzielEliab/mialock",
        "mcp": "https://godlock.uk/runtime/mcp",
        "agent": {
          "mcp": "https://godlock.uk/runtime/mcp",
          "skill": "https://godlock.uk/runtime/v1/skill",
          "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
          "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=mialock",
          "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
          "fraggate_call_executes": true,
          "open_live_door": true,
          "software": "https://godlock.uk/runtime/v1/software",
          "pull": "https://godlock.uk/runtime/v1/pull/mialock",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "d65c53dbc46d500f6d02c8975e42bf95a22000c15db4776d5fdef58904d32a5c",
        "updated_at": null,
        "git_sha": null,
        "git_sha_tracks_deployed_tip": false,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/runtime/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "security": {
            "model": "single-node-security-awareness",
            "isolates": "bad-peer-or-self",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "phoenix": "local-wait-reseal",
            "phoenix_lock": true,
            "public_hostname_resurrection": false,
            "loopback_bearer": "L1-optional",
            "operator_locks": [
              {
                "n": 1,
                "id": "single-node-security-awareness",
                "status": "LIVE",
                "mesh_fenced_to_loopback": false
              },
              {
                "n": 2,
                "id": "phoenix-reboot-loop",
                "status": "LIVE",
                "phoenix": "local-wait-reseal",
                "phoenix_lock": true,
                "public_hostname_resurrection": false
              },
              {
                "n": 3,
                "id": "open-world-awareness",
                "status": "live-when-configured",
                "law": "LIVE",
                "bind": "0.0.0.0",
                "worker_socket": false,
                "forced_loopback_is_mesh_fence": false,
                "loopback_isolation_is_mesh_fence": false
              }
            ],
            "open_world_awareness": {
              "spec": "OPEN-WORLD-AWARENESS-1.0",
              "author": "Aziel Eliab",
              "identity": "Aziel Eliab",
              "open_world_awareness": true,
              "bind": "0.0.0.0",
              "all_interfaces": true,
              "law": "LIVE",
              "status": "live-when-configured",
              "live": false,
              "socket": "live-when-configured",
              "worker_socket": false,
              "qnm_node_bind": "live-when-configured",
              "mock": false,
              "forced_loopback": false,
              "loopback_isolation": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false,
              "mesh_fenced_to_loopback": false,
              "public_egress_ip": false,
              "residential": false,
              "cf_geo_exit": false,
              "cf_geo_exit_pool": false,
              "sticky_public_ip": false,
              "packet_forward": false,
              "packet_forwarding": false,
              "public_icann": false,
              "cap7_is_icann": false,
              "replaces_internet": false,
              "not_a_second_internet": true,
              "hosted_vpn": false,
              "payload_host": false,
              "vpn_hop": false,
              "wireguard": false,
              "openvpn": false,
              "l3_exit": false,
              "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
            },
            "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
          },
          "fanout": "cron-or-request-path",
          "live_nodes_plane": "human-mesh-users-site-viewers",
          "nodes_plane": "human-mesh-users-uses",
          "software_nodes_plane": "software-worker-fanout",
          "site_live_viewers_plane": "hub-human-page-presence",
          "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
          "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
          "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
          "site_presence_contract": {
            "method": "POST",
            "path": "/runtime/v1/mesh/site-presence",
            "alias": "/runtime/v1/mesh/site-heartbeat",
            "fraggate": {
              "slug": "mesh",
              "op": "site-presence"
            },
            "body": {
              "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
              "viewers": "non-negative integer concurrent human page sessions (0..10000)",
              "kind": "human-page"
            },
            "ttl_ms": 900000,
            "registered_grace_ms": 1209600000,
            "default_heartbeat_mode": "idle",
            "heartbeat_mode": "active | idle | asleep",
            "stale_keeps_registered": true,
            "stale_counts_as_live": false,
            "allowed_hosts": [
              "godlock.uk",
              "azieleliab.com",
              "azielcorpuslibrary.net"
            ],
            "excluded_hosts": [
              "hedidntjump.com"
            ],
            "refused_kinds": [
              "bot",
              "bots",
              "crawler",
              "software",
              "softwares",
              "download",
              "downloads",
              "instance",
              "mcp"
            ],
            "pull_hub_count": false,
            "invent": false,
            "fail_closed": true,
            "read": "single-key",
            "paint": "live_nodes",
            "local_recompute": false,
            "radios": "not required — hub ingest, not a TX join",
            "rate_kind": "mesh_mutate",
            "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
          },
          "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
          "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
          "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "ban_survival": "BAN-SURVIVAL-1.0",
          "spore_spec": "SPORE-1.0",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/runtime/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "neighbor_heal_is_cite": true,
              "neighbor_heal_exec": false,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "neighbor_heal_is_cite": true,
          "neighbor_heal_exec": false,
          "join_is_presence_only": true,
          "join_is_not_login": true,
          "roster_publishes_exec_urls": false,
          "mesh_mutate_rate_kind": "mesh_mutate",
          "roster_cap": 256,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "d2d_carriers": {
            "spec": "D2D-CARRIERS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "plane": "track2-reachability",
            "phase": "B+C+D",
            "phases": {
              "A": "landed",
              "B": "LIVE-when-armed",
              "C": "LIVE-when-session",
              "D": "LIVE-when-three-local-nodes / fixture",
              "E": "scaffold"
            },
            "lan_discovery": "LIVE-when-armed",
            "wifi_discovery": "ARMED-when-HW",
            "bluetooth_discovery": "ARMED-when-HW",
            "rf_discovery": "REFUSE-without-HW",
            "photon_discovery": "REFUSE-without-HW",
            "peer_tunnel": "LIVE-when-session",
            "store_forward": "LIVE-when-three-local-nodes / fixture",
            "store_forward_public": "FG-STUB",
            "worker_runs_store_forward": false,
            "second_device": false,
            "mobile_client": "present-not-demonstrated",
            "mobile_demonstrated": false,
            "app_store_release": false,
            "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
            "bootstrap_list": "scaffold",
            "needs_starting_address": true,
            "shelf_cite": "scaffold",
            "live_multi_provider": false,
            "cold_shelf_live": false,
            "dns_cut": false,
            "origin_cutover": false,
            "warn5_closed": false,
            "worker_door": "FG-STUB",
            "worker_hardware": false,
            "local_node": "qnm-node",
            "get_never_enables": true,
            "separate_from": "cap7-name",
            "cap7_is_name_plane": true,
            "cap7_public_icann": false,
            "cap7_public_egress": false,
            "mirage_is_azvpn": false,
            "aznet_replaces_internet": false,
            "not_a_second_internet": true,
            "alt_internet_live": false,
            "packet_path_live": false,
            "field_1_0": false,
            "warn5": "STANDS-until-demonstrated",
            "warn5_permanent_stay_off": false,
            "preference": "failover",
            "order": [
              "lan",
              "wifi",
              "bluetooth",
              "rf",
              "photon"
            ],
            "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
            "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
            "status": "NOT-READY",
            "code": "FG-STUB",
            "warn5_until": "demonstrated",
            "warn5_by_design": "separate-from-icann",
            "refuse": {
              "packet": "FG-STUB",
              "radio_absent": "QNM-RADIO-ABSENT",
              "cap7_egress": "MG-NO-IP-EXIT",
              "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
              "bearer": "AZP-BEARER-REFUSE",
              "payload": "AZN-NO-PAYLOAD",
              "route": "MESH-NO-ROUTE",
              "stay_off": "MESH-STAY-OFF",
              "nat": "FED-MESH-NAT-REFUSE"
            },
            "carriers": [
              {
                "order": 1,
                "id": "lan",
                "name": "LAN",
                "op": "d2d_lan",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "lan-interface",
                "discovery": "LIVE-when-armed",
                "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
              },
              {
                "order": 2,
                "id": "wifi",
                "name": "Wi-Fi",
                "op": "d2d_wifi",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "wifi-nm",
                "discovery": "ARMED-when-HW",
                "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
              },
              {
                "order": 3,
                "id": "bluetooth",
                "name": "Bluetooth",
                "op": "d2d_bluetooth",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "bluez",
                "discovery": "ARMED-when-HW",
                "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
              },
              {
                "order": 4,
                "id": "rf",
                "name": "RF",
                "op": "d2d_rf",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "rf-beyond-wifi-bt",
                "discovery": "REFUSE-without-HW",
                "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
              },
              {
                "order": 5,
                "id": "photon",
                "name": "Photon",
                "op": "d2d_photon",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "camera-flash",
                "discovery": "REFUSE-without-HW",
                "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
              }
            ],
            "security": {
              "isolation": "single-node security-awareness",
              "phoenix": "local wait / re-seal",
              "mesh_fenced_to_loopback": false,
              "forced_loopback": false,
              "loopback_isolation": false
            },
            "paper": "docs/designs/D2D-CARRIERS-1.0.md",
            "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
          },
          "d2d_status": "NOT-READY",
          "d2d_code": "FG-STUB",
          "packet_path_live": false,
          "alt_internet_live": false,
          "d2d_spec": "D2D-CARRIERS-1.0",
          "federated_mesh": "FED-MESH-1.0",
          "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
          "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        }
      },
      {
        "slug": "peacelock",
        "name": "PeaceLock",
        "bucket": "lock",
        "domain": "Evidence",
        "domain_id": "03",
        "placement": "domain-software",
        "status": "live",
        "fraggate_status": "live",
        "public_door": true,
        "public_door_ops": [
          "open",
          "seal",
          "break",
          "show",
          "verify",
          "stamp",
          "upload_envelope",
          "health",
          "skill",
          "doctor"
        ],
        "stub_ops": [
          "transcript",
          "transcribe",
          "motive",
          "counterfactual",
          "invent",
          "waive-duty",
          "bypass-duty"
        ],
        "door_label": "live FragGate door — named stub ops refuse",
        "open_live_door": true,
        "version": "0.1.0",
        "one_line": "Record chosen silence or chosen inaction as a hash-chained receipt.",
        "description": "Use PeaceLock when the act worth keeping is that someone chose silence or inaction. It exists so silence can be a receipt.",
        "worker_home": "https://peacelock-download-tracker.vibelock.workers.dev/",
        "worker_home_note": null,
        "download_url": "https://peacelock-download-tracker.vibelock.workers.dev/download",
        "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "github": "https://github.com/AzielEliab/peacelock",
        "mcp": "https://godlock.uk/runtime/mcp",
        "agent": {
          "mcp": "https://godlock.uk/runtime/mcp",
          "skill": "https://godlock.uk/runtime/v1/skill",
          "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
          "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=peacelock",
          "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
          "fraggate_call_executes": true,
          "open_live_door": true,
          "software": "https://godlock.uk/runtime/v1/software",
          "pull": "https://godlock.uk/runtime/v1/pull/peacelock",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "291437f64ba15338d6358e6d2e657870619b19133430be3574d458b8db469a66",
        "updated_at": null,
        "git_sha": null,
        "git_sha_tracks_deployed_tip": false,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/runtime/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "security": {
            "model": "single-node-security-awareness",
            "isolates": "bad-peer-or-self",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "phoenix": "local-wait-reseal",
            "phoenix_lock": true,
            "public_hostname_resurrection": false,
            "loopback_bearer": "L1-optional",
            "operator_locks": [
              {
                "n": 1,
                "id": "single-node-security-awareness",
                "status": "LIVE",
                "mesh_fenced_to_loopback": false
              },
              {
                "n": 2,
                "id": "phoenix-reboot-loop",
                "status": "LIVE",
                "phoenix": "local-wait-reseal",
                "phoenix_lock": true,
                "public_hostname_resurrection": false
              },
              {
                "n": 3,
                "id": "open-world-awareness",
                "status": "live-when-configured",
                "law": "LIVE",
                "bind": "0.0.0.0",
                "worker_socket": false,
                "forced_loopback_is_mesh_fence": false,
                "loopback_isolation_is_mesh_fence": false
              }
            ],
            "open_world_awareness": {
              "spec": "OPEN-WORLD-AWARENESS-1.0",
              "author": "Aziel Eliab",
              "identity": "Aziel Eliab",
              "open_world_awareness": true,
              "bind": "0.0.0.0",
              "all_interfaces": true,
              "law": "LIVE",
              "status": "live-when-configured",
              "live": false,
              "socket": "live-when-configured",
              "worker_socket": false,
              "qnm_node_bind": "live-when-configured",
              "mock": false,
              "forced_loopback": false,
              "loopback_isolation": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false,
              "mesh_fenced_to_loopback": false,
              "public_egress_ip": false,
              "residential": false,
              "cf_geo_exit": false,
              "cf_geo_exit_pool": false,
              "sticky_public_ip": false,
              "packet_forward": false,
              "packet_forwarding": false,
              "public_icann": false,
              "cap7_is_icann": false,
              "replaces_internet": false,
              "not_a_second_internet": true,
              "hosted_vpn": false,
              "payload_host": false,
              "vpn_hop": false,
              "wireguard": false,
              "openvpn": false,
              "l3_exit": false,
              "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
            },
            "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
          },
          "fanout": "cron-or-request-path",
          "live_nodes_plane": "human-mesh-users-site-viewers",
          "nodes_plane": "human-mesh-users-uses",
          "software_nodes_plane": "software-worker-fanout",
          "site_live_viewers_plane": "hub-human-page-presence",
          "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
          "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
          "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
          "site_presence_contract": {
            "method": "POST",
            "path": "/runtime/v1/mesh/site-presence",
            "alias": "/runtime/v1/mesh/site-heartbeat",
            "fraggate": {
              "slug": "mesh",
              "op": "site-presence"
            },
            "body": {
              "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
              "viewers": "non-negative integer concurrent human page sessions (0..10000)",
              "kind": "human-page"
            },
            "ttl_ms": 900000,
            "registered_grace_ms": 1209600000,
            "default_heartbeat_mode": "idle",
            "heartbeat_mode": "active | idle | asleep",
            "stale_keeps_registered": true,
            "stale_counts_as_live": false,
            "allowed_hosts": [
              "godlock.uk",
              "azieleliab.com",
              "azielcorpuslibrary.net"
            ],
            "excluded_hosts": [
              "hedidntjump.com"
            ],
            "refused_kinds": [
              "bot",
              "bots",
              "crawler",
              "software",
              "softwares",
              "download",
              "downloads",
              "instance",
              "mcp"
            ],
            "pull_hub_count": false,
            "invent": false,
            "fail_closed": true,
            "read": "single-key",
            "paint": "live_nodes",
            "local_recompute": false,
            "radios": "not required — hub ingest, not a TX join",
            "rate_kind": "mesh_mutate",
            "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
          },
          "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
          "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
          "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "ban_survival": "BAN-SURVIVAL-1.0",
          "spore_spec": "SPORE-1.0",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/runtime/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "neighbor_heal_is_cite": true,
              "neighbor_heal_exec": false,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "neighbor_heal_is_cite": true,
          "neighbor_heal_exec": false,
          "join_is_presence_only": true,
          "join_is_not_login": true,
          "roster_publishes_exec_urls": false,
          "mesh_mutate_rate_kind": "mesh_mutate",
          "roster_cap": 256,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "d2d_carriers": {
            "spec": "D2D-CARRIERS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "plane": "track2-reachability",
            "phase": "B+C+D",
            "phases": {
              "A": "landed",
              "B": "LIVE-when-armed",
              "C": "LIVE-when-session",
              "D": "LIVE-when-three-local-nodes / fixture",
              "E": "scaffold"
            },
            "lan_discovery": "LIVE-when-armed",
            "wifi_discovery": "ARMED-when-HW",
            "bluetooth_discovery": "ARMED-when-HW",
            "rf_discovery": "REFUSE-without-HW",
            "photon_discovery": "REFUSE-without-HW",
            "peer_tunnel": "LIVE-when-session",
            "store_forward": "LIVE-when-three-local-nodes / fixture",
            "store_forward_public": "FG-STUB",
            "worker_runs_store_forward": false,
            "second_device": false,
            "mobile_client": "present-not-demonstrated",
            "mobile_demonstrated": false,
            "app_store_release": false,
            "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
            "bootstrap_list": "scaffold",
            "needs_starting_address": true,
            "shelf_cite": "scaffold",
            "live_multi_provider": false,
            "cold_shelf_live": false,
            "dns_cut": false,
            "origin_cutover": false,
            "warn5_closed": false,
            "worker_door": "FG-STUB",
            "worker_hardware": false,
            "local_node": "qnm-node",
            "get_never_enables": true,
            "separate_from": "cap7-name",
            "cap7_is_name_plane": true,
            "cap7_public_icann": false,
            "cap7_public_egress": false,
            "mirage_is_azvpn": false,
            "aznet_replaces_internet": false,
            "not_a_second_internet": true,
            "alt_internet_live": false,
            "packet_path_live": false,
            "field_1_0": false,
            "warn5": "STANDS-until-demonstrated",
            "warn5_permanent_stay_off": false,
            "preference": "failover",
            "order": [
              "lan",
              "wifi",
              "bluetooth",
              "rf",
              "photon"
            ],
            "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
            "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
            "status": "NOT-READY",
            "code": "FG-STUB",
            "warn5_until": "demonstrated",
            "warn5_by_design": "separate-from-icann",
            "refuse": {
              "packet": "FG-STUB",
              "radio_absent": "QNM-RADIO-ABSENT",
              "cap7_egress": "MG-NO-IP-EXIT",
              "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
              "bearer": "AZP-BEARER-REFUSE",
              "payload": "AZN-NO-PAYLOAD",
              "route": "MESH-NO-ROUTE",
              "stay_off": "MESH-STAY-OFF",
              "nat": "FED-MESH-NAT-REFUSE"
            },
            "carriers": [
              {
                "order": 1,
                "id": "lan",
                "name": "LAN",
                "op": "d2d_lan",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "lan-interface",
                "discovery": "LIVE-when-armed",
                "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
              },
              {
                "order": 2,
                "id": "wifi",
                "name": "Wi-Fi",
                "op": "d2d_wifi",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "wifi-nm",
                "discovery": "ARMED-when-HW",
                "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
              },
              {
                "order": 3,
                "id": "bluetooth",
                "name": "Bluetooth",
                "op": "d2d_bluetooth",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "bluez",
                "discovery": "ARMED-when-HW",
                "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
              },
              {
                "order": 4,
                "id": "rf",
                "name": "RF",
                "op": "d2d_rf",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "rf-beyond-wifi-bt",
                "discovery": "REFUSE-without-HW",
                "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
              },
              {
                "order": 5,
                "id": "photon",
                "name": "Photon",
                "op": "d2d_photon",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "camera-flash",
                "discovery": "REFUSE-without-HW",
                "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
              }
            ],
            "security": {
              "isolation": "single-node security-awareness",
              "phoenix": "local wait / re-seal",
              "mesh_fenced_to_loopback": false,
              "forced_loopback": false,
              "loopback_isolation": false
            },
            "paper": "docs/designs/D2D-CARRIERS-1.0.md",
            "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
          },
          "d2d_status": "NOT-READY",
          "d2d_code": "FG-STUB",
          "packet_path_live": false,
          "alt_internet_live": false,
          "d2d_spec": "D2D-CARRIERS-1.0",
          "federated_mesh": "FED-MESH-1.0",
          "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
          "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        }
      },
      {
        "slug": "shadowlock",
        "name": "ShadowLock",
        "bucket": "lock",
        "domain": "Evidence",
        "domain_id": "03",
        "placement": "domain-software",
        "status": "live",
        "fraggate_status": "live",
        "public_door": true,
        "public_door_ops": [
          "observe",
          "hook",
          "health",
          "skill",
          "doctor"
        ],
        "stub_ops": [],
        "door_label": "live FragGate door",
        "open_live_door": true,
        "version": "0.2.0",
        "one_line": "Observe a job list you already have, then discard the observation.",
        "description": "Use ShadowLock to wrap an existing job list in a zero-retention observation. It exists as an ethics envelope.",
        "worker_home": "https://shadowlock-download-tracker.vibelock.workers.dev/",
        "worker_home_note": null,
        "download_url": "https://shadowlock-download-tracker.vibelock.workers.dev/download",
        "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "github": "https://github.com/AzielEliab/shadowlock",
        "mcp": "https://godlock.uk/runtime/mcp",
        "agent": {
          "mcp": "https://godlock.uk/runtime/mcp",
          "skill": "https://godlock.uk/runtime/v1/skill",
          "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
          "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=shadowlock",
          "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
          "fraggate_call_executes": true,
          "open_live_door": true,
          "software": "https://godlock.uk/runtime/v1/software",
          "pull": "https://godlock.uk/runtime/v1/pull/shadowlock",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "0176d18d8517ef02b391821b1fd1ae428591543ea1c812c9785d832714281f61",
        "updated_at": null,
        "git_sha": null,
        "git_sha_tracks_deployed_tip": false,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/runtime/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "security": {
            "model": "single-node-security-awareness",
            "isolates": "bad-peer-or-self",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "phoenix": "local-wait-reseal",
            "phoenix_lock": true,
            "public_hostname_resurrection": false,
            "loopback_bearer": "L1-optional",
            "operator_locks": [
              {
                "n": 1,
                "id": "single-node-security-awareness",
                "status": "LIVE",
                "mesh_fenced_to_loopback": false
              },
              {
                "n": 2,
                "id": "phoenix-reboot-loop",
                "status": "LIVE",
                "phoenix": "local-wait-reseal",
                "phoenix_lock": true,
                "public_hostname_resurrection": false
              },
              {
                "n": 3,
                "id": "open-world-awareness",
                "status": "live-when-configured",
                "law": "LIVE",
                "bind": "0.0.0.0",
                "worker_socket": false,
                "forced_loopback_is_mesh_fence": false,
                "loopback_isolation_is_mesh_fence": false
              }
            ],
            "open_world_awareness": {
              "spec": "OPEN-WORLD-AWARENESS-1.0",
              "author": "Aziel Eliab",
              "identity": "Aziel Eliab",
              "open_world_awareness": true,
              "bind": "0.0.0.0",
              "all_interfaces": true,
              "law": "LIVE",
              "status": "live-when-configured",
              "live": false,
              "socket": "live-when-configured",
              "worker_socket": false,
              "qnm_node_bind": "live-when-configured",
              "mock": false,
              "forced_loopback": false,
              "loopback_isolation": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false,
              "mesh_fenced_to_loopback": false,
              "public_egress_ip": false,
              "residential": false,
              "cf_geo_exit": false,
              "cf_geo_exit_pool": false,
              "sticky_public_ip": false,
              "packet_forward": false,
              "packet_forwarding": false,
              "public_icann": false,
              "cap7_is_icann": false,
              "replaces_internet": false,
              "not_a_second_internet": true,
              "hosted_vpn": false,
              "payload_host": false,
              "vpn_hop": false,
              "wireguard": false,
              "openvpn": false,
              "l3_exit": false,
              "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
            },
            "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
          },
          "fanout": "cron-or-request-path",
          "live_nodes_plane": "human-mesh-users-site-viewers",
          "nodes_plane": "human-mesh-users-uses",
          "software_nodes_plane": "software-worker-fanout",
          "site_live_viewers_plane": "hub-human-page-presence",
          "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
          "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
          "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
          "site_presence_contract": {
            "method": "POST",
            "path": "/runtime/v1/mesh/site-presence",
            "alias": "/runtime/v1/mesh/site-heartbeat",
            "fraggate": {
              "slug": "mesh",
              "op": "site-presence"
            },
            "body": {
              "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
              "viewers": "non-negative integer concurrent human page sessions (0..10000)",
              "kind": "human-page"
            },
            "ttl_ms": 900000,
            "registered_grace_ms": 1209600000,
            "default_heartbeat_mode": "idle",
            "heartbeat_mode": "active | idle | asleep",
            "stale_keeps_registered": true,
            "stale_counts_as_live": false,
            "allowed_hosts": [
              "godlock.uk",
              "azieleliab.com",
              "azielcorpuslibrary.net"
            ],
            "excluded_hosts": [
              "hedidntjump.com"
            ],
            "refused_kinds": [
              "bot",
              "bots",
              "crawler",
              "software",
              "softwares",
              "download",
              "downloads",
              "instance",
              "mcp"
            ],
            "pull_hub_count": false,
            "invent": false,
            "fail_closed": true,
            "read": "single-key",
            "paint": "live_nodes",
            "local_recompute": false,
            "radios": "not required — hub ingest, not a TX join",
            "rate_kind": "mesh_mutate",
            "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
          },
          "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
          "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
          "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "ban_survival": "BAN-SURVIVAL-1.0",
          "spore_spec": "SPORE-1.0",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/runtime/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "neighbor_heal_is_cite": true,
              "neighbor_heal_exec": false,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "neighbor_heal_is_cite": true,
          "neighbor_heal_exec": false,
          "join_is_presence_only": true,
          "join_is_not_login": true,
          "roster_publishes_exec_urls": false,
          "mesh_mutate_rate_kind": "mesh_mutate",
          "roster_cap": 256,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "d2d_carriers": {
            "spec": "D2D-CARRIERS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "plane": "track2-reachability",
            "phase": "B+C+D",
            "phases": {
              "A": "landed",
              "B": "LIVE-when-armed",
              "C": "LIVE-when-session",
              "D": "LIVE-when-three-local-nodes / fixture",
              "E": "scaffold"
            },
            "lan_discovery": "LIVE-when-armed",
            "wifi_discovery": "ARMED-when-HW",
            "bluetooth_discovery": "ARMED-when-HW",
            "rf_discovery": "REFUSE-without-HW",
            "photon_discovery": "REFUSE-without-HW",
            "peer_tunnel": "LIVE-when-session",
            "store_forward": "LIVE-when-three-local-nodes / fixture",
            "store_forward_public": "FG-STUB",
            "worker_runs_store_forward": false,
            "second_device": false,
            "mobile_client": "present-not-demonstrated",
            "mobile_demonstrated": false,
            "app_store_release": false,
            "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
            "bootstrap_list": "scaffold",
            "needs_starting_address": true,
            "shelf_cite": "scaffold",
            "live_multi_provider": false,
            "cold_shelf_live": false,
            "dns_cut": false,
            "origin_cutover": false,
            "warn5_closed": false,
            "worker_door": "FG-STUB",
            "worker_hardware": false,
            "local_node": "qnm-node",
            "get_never_enables": true,
            "separate_from": "cap7-name",
            "cap7_is_name_plane": true,
            "cap7_public_icann": false,
            "cap7_public_egress": false,
            "mirage_is_azvpn": false,
            "aznet_replaces_internet": false,
            "not_a_second_internet": true,
            "alt_internet_live": false,
            "packet_path_live": false,
            "field_1_0": false,
            "warn5": "STANDS-until-demonstrated",
            "warn5_permanent_stay_off": false,
            "preference": "failover",
            "order": [
              "lan",
              "wifi",
              "bluetooth",
              "rf",
              "photon"
            ],
            "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
            "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
            "status": "NOT-READY",
            "code": "FG-STUB",
            "warn5_until": "demonstrated",
            "warn5_by_design": "separate-from-icann",
            "refuse": {
              "packet": "FG-STUB",
              "radio_absent": "QNM-RADIO-ABSENT",
              "cap7_egress": "MG-NO-IP-EXIT",
              "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
              "bearer": "AZP-BEARER-REFUSE",
              "payload": "AZN-NO-PAYLOAD",
              "route": "MESH-NO-ROUTE",
              "stay_off": "MESH-STAY-OFF",
              "nat": "FED-MESH-NAT-REFUSE"
            },
            "carriers": [
              {
                "order": 1,
                "id": "lan",
                "name": "LAN",
                "op": "d2d_lan",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "lan-interface",
                "discovery": "LIVE-when-armed",
                "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
              },
              {
                "order": 2,
                "id": "wifi",
                "name": "Wi-Fi",
                "op": "d2d_wifi",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "wifi-nm",
                "discovery": "ARMED-when-HW",
                "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
              },
              {
                "order": 3,
                "id": "bluetooth",
                "name": "Bluetooth",
                "op": "d2d_bluetooth",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "bluez",
                "discovery": "ARMED-when-HW",
                "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
              },
              {
                "order": 4,
                "id": "rf",
                "name": "RF",
                "op": "d2d_rf",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "rf-beyond-wifi-bt",
                "discovery": "REFUSE-without-HW",
                "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
              },
              {
                "order": 5,
                "id": "photon",
                "name": "Photon",
                "op": "d2d_photon",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "camera-flash",
                "discovery": "REFUSE-without-HW",
                "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
              }
            ],
            "security": {
              "isolation": "single-node security-awareness",
              "phoenix": "local wait / re-seal",
              "mesh_fenced_to_loopback": false,
              "forced_loopback": false,
              "loopback_isolation": false
            },
            "paper": "docs/designs/D2D-CARRIERS-1.0.md",
            "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
          },
          "d2d_status": "NOT-READY",
          "d2d_code": "FG-STUB",
          "packet_path_live": false,
          "alt_internet_live": false,
          "d2d_spec": "D2D-CARRIERS-1.0",
          "federated_mesh": "FED-MESH-1.0",
          "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
          "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        }
      },
      {
        "slug": "spectrallock",
        "name": "SpectralLock",
        "bucket": "lock",
        "domain": "Media",
        "domain_id": "02",
        "placement": "domain-software",
        "status": "live",
        "fraggate_status": "live",
        "public_door": true,
        "public_door_ops": [
          "modes",
          "targets",
          "overlay",
          "pigment",
          "restore-pigment",
          "verify",
          "doctor",
          "health",
          "skill"
        ],
        "stub_ops": [
          "spectrometer",
          "forensic",
          "invent_mark"
        ],
        "door_label": "live FragGate door — named stub ops refuse",
        "open_live_door": true,
        "version": "0.3.1",
        "one_line": "Preview a 256-pixel overlay, paint membership from the Spectral Harmonic Wheel, and restore faded pigment where the pixels still carry it.",
        "description": "Use SpectralLock 0.3.1 for a hosted overlay whose wheel-paint plane is separate from the spectral triad. Restore lost pigment is live under SpectralLock on FragGate ops pigment and restore-pigment. AMOE stays on the suite project map and is not a live product. It exists as a hosted overlay preview.",
        "worker_home": "https://spectrallock-download-tracker.vibelock.workers.dev/",
        "worker_home_note": null,
        "download_url": "https://spectrallock-download-tracker.vibelock.workers.dev/download",
        "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "github": "https://github.com/AzielEliab/spectrallock",
        "mcp": "https://godlock.uk/runtime/mcp",
        "agent": {
          "mcp": "https://godlock.uk/runtime/mcp",
          "skill": "https://godlock.uk/runtime/v1/skill",
          "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
          "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=spectrallock",
          "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
          "fraggate_call_executes": true,
          "open_live_door": true,
          "software": "https://godlock.uk/runtime/v1/software",
          "pull": "https://godlock.uk/runtime/v1/pull/spectrallock",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "16281860ab0787f2485ea2530fbbcecf968009da3ae1c4f2b6e689a15a9ad586",
        "updated_at": null,
        "git_sha": null,
        "git_sha_tracks_deployed_tip": false,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/runtime/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "security": {
            "model": "single-node-security-awareness",
            "isolates": "bad-peer-or-self",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "phoenix": "local-wait-reseal",
            "phoenix_lock": true,
            "public_hostname_resurrection": false,
            "loopback_bearer": "L1-optional",
            "operator_locks": [
              {
                "n": 1,
                "id": "single-node-security-awareness",
                "status": "LIVE",
                "mesh_fenced_to_loopback": false
              },
              {
                "n": 2,
                "id": "phoenix-reboot-loop",
                "status": "LIVE",
                "phoenix": "local-wait-reseal",
                "phoenix_lock": true,
                "public_hostname_resurrection": false
              },
              {
                "n": 3,
                "id": "open-world-awareness",
                "status": "live-when-configured",
                "law": "LIVE",
                "bind": "0.0.0.0",
                "worker_socket": false,
                "forced_loopback_is_mesh_fence": false,
                "loopback_isolation_is_mesh_fence": false
              }
            ],
            "open_world_awareness": {
              "spec": "OPEN-WORLD-AWARENESS-1.0",
              "author": "Aziel Eliab",
              "identity": "Aziel Eliab",
              "open_world_awareness": true,
              "bind": "0.0.0.0",
              "all_interfaces": true,
              "law": "LIVE",
              "status": "live-when-configured",
              "live": false,
              "socket": "live-when-configured",
              "worker_socket": false,
              "qnm_node_bind": "live-when-configured",
              "mock": false,
              "forced_loopback": false,
              "loopback_isolation": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false,
              "mesh_fenced_to_loopback": false,
              "public_egress_ip": false,
              "residential": false,
              "cf_geo_exit": false,
              "cf_geo_exit_pool": false,
              "sticky_public_ip": false,
              "packet_forward": false,
              "packet_forwarding": false,
              "public_icann": false,
              "cap7_is_icann": false,
              "replaces_internet": false,
              "not_a_second_internet": true,
              "hosted_vpn": false,
              "payload_host": false,
              "vpn_hop": false,
              "wireguard": false,
              "openvpn": false,
              "l3_exit": false,
              "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
            },
            "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
          },
          "fanout": "cron-or-request-path",
          "live_nodes_plane": "human-mesh-users-site-viewers",
          "nodes_plane": "human-mesh-users-uses",
          "software_nodes_plane": "software-worker-fanout",
          "site_live_viewers_plane": "hub-human-page-presence",
          "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
          "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
          "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
          "site_presence_contract": {
            "method": "POST",
            "path": "/runtime/v1/mesh/site-presence",
            "alias": "/runtime/v1/mesh/site-heartbeat",
            "fraggate": {
              "slug": "mesh",
              "op": "site-presence"
            },
            "body": {
              "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
              "viewers": "non-negative integer concurrent human page sessions (0..10000)",
              "kind": "human-page"
            },
            "ttl_ms": 900000,
            "registered_grace_ms": 1209600000,
            "default_heartbeat_mode": "idle",
            "heartbeat_mode": "active | idle | asleep",
            "stale_keeps_registered": true,
            "stale_counts_as_live": false,
            "allowed_hosts": [
              "godlock.uk",
              "azieleliab.com",
              "azielcorpuslibrary.net"
            ],
            "excluded_hosts": [
              "hedidntjump.com"
            ],
            "refused_kinds": [
              "bot",
              "bots",
              "crawler",
              "software",
              "softwares",
              "download",
              "downloads",
              "instance",
              "mcp"
            ],
            "pull_hub_count": false,
            "invent": false,
            "fail_closed": true,
            "read": "single-key",
            "paint": "live_nodes",
            "local_recompute": false,
            "radios": "not required — hub ingest, not a TX join",
            "rate_kind": "mesh_mutate",
            "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
          },
          "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
          "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
          "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "ban_survival": "BAN-SURVIVAL-1.0",
          "spore_spec": "SPORE-1.0",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/runtime/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "neighbor_heal_is_cite": true,
              "neighbor_heal_exec": false,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "neighbor_heal_is_cite": true,
          "neighbor_heal_exec": false,
          "join_is_presence_only": true,
          "join_is_not_login": true,
          "roster_publishes_exec_urls": false,
          "mesh_mutate_rate_kind": "mesh_mutate",
          "roster_cap": 256,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "d2d_carriers": {
            "spec": "D2D-CARRIERS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "plane": "track2-reachability",
            "phase": "B+C+D",
            "phases": {
              "A": "landed",
              "B": "LIVE-when-armed",
              "C": "LIVE-when-session",
              "D": "LIVE-when-three-local-nodes / fixture",
              "E": "scaffold"
            },
            "lan_discovery": "LIVE-when-armed",
            "wifi_discovery": "ARMED-when-HW",
            "bluetooth_discovery": "ARMED-when-HW",
            "rf_discovery": "REFUSE-without-HW",
            "photon_discovery": "REFUSE-without-HW",
            "peer_tunnel": "LIVE-when-session",
            "store_forward": "LIVE-when-three-local-nodes / fixture",
            "store_forward_public": "FG-STUB",
            "worker_runs_store_forward": false,
            "second_device": false,
            "mobile_client": "present-not-demonstrated",
            "mobile_demonstrated": false,
            "app_store_release": false,
            "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
            "bootstrap_list": "scaffold",
            "needs_starting_address": true,
            "shelf_cite": "scaffold",
            "live_multi_provider": false,
            "cold_shelf_live": false,
            "dns_cut": false,
            "origin_cutover": false,
            "warn5_closed": false,
            "worker_door": "FG-STUB",
            "worker_hardware": false,
            "local_node": "qnm-node",
            "get_never_enables": true,
            "separate_from": "cap7-name",
            "cap7_is_name_plane": true,
            "cap7_public_icann": false,
            "cap7_public_egress": false,
            "mirage_is_azvpn": false,
            "aznet_replaces_internet": false,
            "not_a_second_internet": true,
            "alt_internet_live": false,
            "packet_path_live": false,
            "field_1_0": false,
            "warn5": "STANDS-until-demonstrated",
            "warn5_permanent_stay_off": false,
            "preference": "failover",
            "order": [
              "lan",
              "wifi",
              "bluetooth",
              "rf",
              "photon"
            ],
            "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
            "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
            "status": "NOT-READY",
            "code": "FG-STUB",
            "warn5_until": "demonstrated",
            "warn5_by_design": "separate-from-icann",
            "refuse": {
              "packet": "FG-STUB",
              "radio_absent": "QNM-RADIO-ABSENT",
              "cap7_egress": "MG-NO-IP-EXIT",
              "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
              "bearer": "AZP-BEARER-REFUSE",
              "payload": "AZN-NO-PAYLOAD",
              "route": "MESH-NO-ROUTE",
              "stay_off": "MESH-STAY-OFF",
              "nat": "FED-MESH-NAT-REFUSE"
            },
            "carriers": [
              {
                "order": 1,
                "id": "lan",
                "name": "LAN",
                "op": "d2d_lan",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "lan-interface",
                "discovery": "LIVE-when-armed",
                "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
              },
              {
                "order": 2,
                "id": "wifi",
                "name": "Wi-Fi",
                "op": "d2d_wifi",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "wifi-nm",
                "discovery": "ARMED-when-HW",
                "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
              },
              {
                "order": 3,
                "id": "bluetooth",
                "name": "Bluetooth",
                "op": "d2d_bluetooth",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "bluez",
                "discovery": "ARMED-when-HW",
                "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
              },
              {
                "order": 4,
                "id": "rf",
                "name": "RF",
                "op": "d2d_rf",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "rf-beyond-wifi-bt",
                "discovery": "REFUSE-without-HW",
                "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
              },
              {
                "order": 5,
                "id": "photon",
                "name": "Photon",
                "op": "d2d_photon",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "camera-flash",
                "discovery": "REFUSE-without-HW",
                "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
              }
            ],
            "security": {
              "isolation": "single-node security-awareness",
              "phoenix": "local wait / re-seal",
              "mesh_fenced_to_loopback": false,
              "forced_loopback": false,
              "loopback_isolation": false
            },
            "paper": "docs/designs/D2D-CARRIERS-1.0.md",
            "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
          },
          "d2d_status": "NOT-READY",
          "d2d_code": "FG-STUB",
          "packet_path_live": false,
          "alt_internet_live": false,
          "d2d_spec": "D2D-CARRIERS-1.0",
          "federated_mesh": "FED-MESH-1.0",
          "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
          "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        }
      },
      {
        "slug": "temporallock",
        "name": "TemporalLock",
        "bucket": "lock",
        "domain": "Core Time",
        "domain_id": "11",
        "placement": "domain-software",
        "status": "live",
        "fraggate_status": "live",
        "public_door": true,
        "public_door_ops": [
          "genesis",
          "append",
          "verify",
          "timeslate",
          "gate",
          "import_export",
          "doctor",
          "health",
          "skill"
        ],
        "stub_ops": [
          "truth_claim",
          "scheduler",
          "store_chain",
          "rollback"
        ],
        "door_label": "live FragGate door — named stub ops refuse",
        "open_live_door": true,
        "version": "0.2.0",
        "one_line": "Build and check hashes on a receipt timeline you keep on the client.",
        "description": "Use TemporalLock to start, append, and check hashes on receipts anyone can recompute. It exists so time-stamped records stay client-held.",
        "worker_home": "https://temporallock-download-tracker.vibelock.workers.dev/",
        "worker_home_note": null,
        "download_url": "https://temporallock-download-tracker.vibelock.workers.dev/download",
        "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "github": "https://github.com/AzielEliab/temporallock",
        "mcp": "https://godlock.uk/runtime/mcp",
        "agent": {
          "mcp": "https://godlock.uk/runtime/mcp",
          "skill": "https://godlock.uk/runtime/v1/skill",
          "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
          "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=temporallock",
          "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
          "fraggate_call_executes": true,
          "open_live_door": true,
          "software": "https://godlock.uk/runtime/v1/software",
          "pull": "https://godlock.uk/runtime/v1/pull/temporallock",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "fa1ce89d3201c3a4d00f46da1253418b11e98fb50414cd1c65517e2282ed6b5e",
        "updated_at": null,
        "git_sha": null,
        "git_sha_tracks_deployed_tip": false,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/runtime/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "security": {
            "model": "single-node-security-awareness",
            "isolates": "bad-peer-or-self",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "phoenix": "local-wait-reseal",
            "phoenix_lock": true,
            "public_hostname_resurrection": false,
            "loopback_bearer": "L1-optional",
            "operator_locks": [
              {
                "n": 1,
                "id": "single-node-security-awareness",
                "status": "LIVE",
                "mesh_fenced_to_loopback": false
              },
              {
                "n": 2,
                "id": "phoenix-reboot-loop",
                "status": "LIVE",
                "phoenix": "local-wait-reseal",
                "phoenix_lock": true,
                "public_hostname_resurrection": false
              },
              {
                "n": 3,
                "id": "open-world-awareness",
                "status": "live-when-configured",
                "law": "LIVE",
                "bind": "0.0.0.0",
                "worker_socket": false,
                "forced_loopback_is_mesh_fence": false,
                "loopback_isolation_is_mesh_fence": false
              }
            ],
            "open_world_awareness": {
              "spec": "OPEN-WORLD-AWARENESS-1.0",
              "author": "Aziel Eliab",
              "identity": "Aziel Eliab",
              "open_world_awareness": true,
              "bind": "0.0.0.0",
              "all_interfaces": true,
              "law": "LIVE",
              "status": "live-when-configured",
              "live": false,
              "socket": "live-when-configured",
              "worker_socket": false,
              "qnm_node_bind": "live-when-configured",
              "mock": false,
              "forced_loopback": false,
              "loopback_isolation": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false,
              "mesh_fenced_to_loopback": false,
              "public_egress_ip": false,
              "residential": false,
              "cf_geo_exit": false,
              "cf_geo_exit_pool": false,
              "sticky_public_ip": false,
              "packet_forward": false,
              "packet_forwarding": false,
              "public_icann": false,
              "cap7_is_icann": false,
              "replaces_internet": false,
              "not_a_second_internet": true,
              "hosted_vpn": false,
              "payload_host": false,
              "vpn_hop": false,
              "wireguard": false,
              "openvpn": false,
              "l3_exit": false,
              "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
            },
            "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
          },
          "fanout": "cron-or-request-path",
          "live_nodes_plane": "human-mesh-users-site-viewers",
          "nodes_plane": "human-mesh-users-uses",
          "software_nodes_plane": "software-worker-fanout",
          "site_live_viewers_plane": "hub-human-page-presence",
          "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
          "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
          "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
          "site_presence_contract": {
            "method": "POST",
            "path": "/runtime/v1/mesh/site-presence",
            "alias": "/runtime/v1/mesh/site-heartbeat",
            "fraggate": {
              "slug": "mesh",
              "op": "site-presence"
            },
            "body": {
              "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
              "viewers": "non-negative integer concurrent human page sessions (0..10000)",
              "kind": "human-page"
            },
            "ttl_ms": 900000,
            "registered_grace_ms": 1209600000,
            "default_heartbeat_mode": "idle",
            "heartbeat_mode": "active | idle | asleep",
            "stale_keeps_registered": true,
            "stale_counts_as_live": false,
            "allowed_hosts": [
              "godlock.uk",
              "azieleliab.com",
              "azielcorpuslibrary.net"
            ],
            "excluded_hosts": [
              "hedidntjump.com"
            ],
            "refused_kinds": [
              "bot",
              "bots",
              "crawler",
              "software",
              "softwares",
              "download",
              "downloads",
              "instance",
              "mcp"
            ],
            "pull_hub_count": false,
            "invent": false,
            "fail_closed": true,
            "read": "single-key",
            "paint": "live_nodes",
            "local_recompute": false,
            "radios": "not required — hub ingest, not a TX join",
            "rate_kind": "mesh_mutate",
            "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
          },
          "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
          "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
          "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "ban_survival": "BAN-SURVIVAL-1.0",
          "spore_spec": "SPORE-1.0",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/runtime/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "neighbor_heal_is_cite": true,
              "neighbor_heal_exec": false,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "neighbor_heal_is_cite": true,
          "neighbor_heal_exec": false,
          "join_is_presence_only": true,
          "join_is_not_login": true,
          "roster_publishes_exec_urls": false,
          "mesh_mutate_rate_kind": "mesh_mutate",
          "roster_cap": 256,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "d2d_carriers": {
            "spec": "D2D-CARRIERS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "plane": "track2-reachability",
            "phase": "B+C+D",
            "phases": {
              "A": "landed",
              "B": "LIVE-when-armed",
              "C": "LIVE-when-session",
              "D": "LIVE-when-three-local-nodes / fixture",
              "E": "scaffold"
            },
            "lan_discovery": "LIVE-when-armed",
            "wifi_discovery": "ARMED-when-HW",
            "bluetooth_discovery": "ARMED-when-HW",
            "rf_discovery": "REFUSE-without-HW",
            "photon_discovery": "REFUSE-without-HW",
            "peer_tunnel": "LIVE-when-session",
            "store_forward": "LIVE-when-three-local-nodes / fixture",
            "store_forward_public": "FG-STUB",
            "worker_runs_store_forward": false,
            "second_device": false,
            "mobile_client": "present-not-demonstrated",
            "mobile_demonstrated": false,
            "app_store_release": false,
            "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
            "bootstrap_list": "scaffold",
            "needs_starting_address": true,
            "shelf_cite": "scaffold",
            "live_multi_provider": false,
            "cold_shelf_live": false,
            "dns_cut": false,
            "origin_cutover": false,
            "warn5_closed": false,
            "worker_door": "FG-STUB",
            "worker_hardware": false,
            "local_node": "qnm-node",
            "get_never_enables": true,
            "separate_from": "cap7-name",
            "cap7_is_name_plane": true,
            "cap7_public_icann": false,
            "cap7_public_egress": false,
            "mirage_is_azvpn": false,
            "aznet_replaces_internet": false,
            "not_a_second_internet": true,
            "alt_internet_live": false,
            "packet_path_live": false,
            "field_1_0": false,
            "warn5": "STANDS-until-demonstrated",
            "warn5_permanent_stay_off": false,
            "preference": "failover",
            "order": [
              "lan",
              "wifi",
              "bluetooth",
              "rf",
              "photon"
            ],
            "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
            "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
            "status": "NOT-READY",
            "code": "FG-STUB",
            "warn5_until": "demonstrated",
            "warn5_by_design": "separate-from-icann",
            "refuse": {
              "packet": "FG-STUB",
              "radio_absent": "QNM-RADIO-ABSENT",
              "cap7_egress": "MG-NO-IP-EXIT",
              "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
              "bearer": "AZP-BEARER-REFUSE",
              "payload": "AZN-NO-PAYLOAD",
              "route": "MESH-NO-ROUTE",
              "stay_off": "MESH-STAY-OFF",
              "nat": "FED-MESH-NAT-REFUSE"
            },
            "carriers": [
              {
                "order": 1,
                "id": "lan",
                "name": "LAN",
                "op": "d2d_lan",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "lan-interface",
                "discovery": "LIVE-when-armed",
                "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
              },
              {
                "order": 2,
                "id": "wifi",
                "name": "Wi-Fi",
                "op": "d2d_wifi",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "wifi-nm",
                "discovery": "ARMED-when-HW",
                "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
              },
              {
                "order": 3,
                "id": "bluetooth",
                "name": "Bluetooth",
                "op": "d2d_bluetooth",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "bluez",
                "discovery": "ARMED-when-HW",
                "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
              },
              {
                "order": 4,
                "id": "rf",
                "name": "RF",
                "op": "d2d_rf",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "rf-beyond-wifi-bt",
                "discovery": "REFUSE-without-HW",
                "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
              },
              {
                "order": 5,
                "id": "photon",
                "name": "Photon",
                "op": "d2d_photon",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "camera-flash",
                "discovery": "REFUSE-without-HW",
                "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
              }
            ],
            "security": {
              "isolation": "single-node security-awareness",
              "phoenix": "local wait / re-seal",
              "mesh_fenced_to_loopback": false,
              "forced_loopback": false,
              "loopback_isolation": false
            },
            "paper": "docs/designs/D2D-CARRIERS-1.0.md",
            "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
          },
          "d2d_status": "NOT-READY",
          "d2d_code": "FG-STUB",
          "packet_path_live": false,
          "alt_internet_live": false,
          "d2d_spec": "D2D-CARRIERS-1.0",
          "federated_mesh": "FED-MESH-1.0",
          "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
          "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        }
      },
      {
        "slug": "trajectorylock",
        "name": "TrajectoryLock",
        "bucket": "lock",
        "domain": "Media",
        "domain_id": "02",
        "placement": "domain-software",
        "status": "live",
        "fraggate_status": "live",
        "public_door": true,
        "public_door_ops": [
          "example",
          "analyze",
          "verify",
          "schema",
          "import_export",
          "hash_put",
          "hash_get",
          "hash_stat",
          "doctor",
          "health",
          "skill"
        ],
        "stub_ops": [
          "certified",
          "shooter",
          "intent",
          "guilt",
          "store_media",
          "face"
        ],
        "door_label": "live FragGate door — named stub ops refuse",
        "open_live_door": true,
        "version": "0.1.0",
        "one_line": "Test whether observations fit a declared geometric line.",
        "description": "Use TrajectoryLock to check posted geometry against a line you declared. It exists as a research compatibility test.",
        "worker_home": "https://trajectorylock-download-tracker.vibelock.workers.dev/",
        "worker_home_note": null,
        "download_url": "https://trajectorylock-download-tracker.vibelock.workers.dev/download",
        "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "github": "https://github.com/AzielEliab/trajectorylock",
        "mcp": "https://godlock.uk/runtime/mcp",
        "agent": {
          "mcp": "https://godlock.uk/runtime/mcp",
          "skill": "https://godlock.uk/runtime/v1/skill",
          "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
          "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=trajectorylock",
          "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
          "fraggate_call_executes": true,
          "open_live_door": true,
          "software": "https://godlock.uk/runtime/v1/software",
          "pull": "https://godlock.uk/runtime/v1/pull/trajectorylock",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "7f536c9d148515d9b4e578c558361255db226cd5e3066daee1eee68209bfe3a7",
        "updated_at": null,
        "git_sha": null,
        "git_sha_tracks_deployed_tip": false,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/runtime/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "security": {
            "model": "single-node-security-awareness",
            "isolates": "bad-peer-or-self",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "phoenix": "local-wait-reseal",
            "phoenix_lock": true,
            "public_hostname_resurrection": false,
            "loopback_bearer": "L1-optional",
            "operator_locks": [
              {
                "n": 1,
                "id": "single-node-security-awareness",
                "status": "LIVE",
                "mesh_fenced_to_loopback": false
              },
              {
                "n": 2,
                "id": "phoenix-reboot-loop",
                "status": "LIVE",
                "phoenix": "local-wait-reseal",
                "phoenix_lock": true,
                "public_hostname_resurrection": false
              },
              {
                "n": 3,
                "id": "open-world-awareness",
                "status": "live-when-configured",
                "law": "LIVE",
                "bind": "0.0.0.0",
                "worker_socket": false,
                "forced_loopback_is_mesh_fence": false,
                "loopback_isolation_is_mesh_fence": false
              }
            ],
            "open_world_awareness": {
              "spec": "OPEN-WORLD-AWARENESS-1.0",
              "author": "Aziel Eliab",
              "identity": "Aziel Eliab",
              "open_world_awareness": true,
              "bind": "0.0.0.0",
              "all_interfaces": true,
              "law": "LIVE",
              "status": "live-when-configured",
              "live": false,
              "socket": "live-when-configured",
              "worker_socket": false,
              "qnm_node_bind": "live-when-configured",
              "mock": false,
              "forced_loopback": false,
              "loopback_isolation": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false,
              "mesh_fenced_to_loopback": false,
              "public_egress_ip": false,
              "residential": false,
              "cf_geo_exit": false,
              "cf_geo_exit_pool": false,
              "sticky_public_ip": false,
              "packet_forward": false,
              "packet_forwarding": false,
              "public_icann": false,
              "cap7_is_icann": false,
              "replaces_internet": false,
              "not_a_second_internet": true,
              "hosted_vpn": false,
              "payload_host": false,
              "vpn_hop": false,
              "wireguard": false,
              "openvpn": false,
              "l3_exit": false,
              "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
            },
            "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
          },
          "fanout": "cron-or-request-path",
          "live_nodes_plane": "human-mesh-users-site-viewers",
          "nodes_plane": "human-mesh-users-uses",
          "software_nodes_plane": "software-worker-fanout",
          "site_live_viewers_plane": "hub-human-page-presence",
          "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
          "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
          "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
          "site_presence_contract": {
            "method": "POST",
            "path": "/runtime/v1/mesh/site-presence",
            "alias": "/runtime/v1/mesh/site-heartbeat",
            "fraggate": {
              "slug": "mesh",
              "op": "site-presence"
            },
            "body": {
              "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
              "viewers": "non-negative integer concurrent human page sessions (0..10000)",
              "kind": "human-page"
            },
            "ttl_ms": 900000,
            "registered_grace_ms": 1209600000,
            "default_heartbeat_mode": "idle",
            "heartbeat_mode": "active | idle | asleep",
            "stale_keeps_registered": true,
            "stale_counts_as_live": false,
            "allowed_hosts": [
              "godlock.uk",
              "azieleliab.com",
              "azielcorpuslibrary.net"
            ],
            "excluded_hosts": [
              "hedidntjump.com"
            ],
            "refused_kinds": [
              "bot",
              "bots",
              "crawler",
              "software",
              "softwares",
              "download",
              "downloads",
              "instance",
              "mcp"
            ],
            "pull_hub_count": false,
            "invent": false,
            "fail_closed": true,
            "read": "single-key",
            "paint": "live_nodes",
            "local_recompute": false,
            "radios": "not required — hub ingest, not a TX join",
            "rate_kind": "mesh_mutate",
            "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
          },
          "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
          "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
          "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "ban_survival": "BAN-SURVIVAL-1.0",
          "spore_spec": "SPORE-1.0",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/runtime/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "neighbor_heal_is_cite": true,
              "neighbor_heal_exec": false,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "neighbor_heal_is_cite": true,
          "neighbor_heal_exec": false,
          "join_is_presence_only": true,
          "join_is_not_login": true,
          "roster_publishes_exec_urls": false,
          "mesh_mutate_rate_kind": "mesh_mutate",
          "roster_cap": 256,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "d2d_carriers": {
            "spec": "D2D-CARRIERS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "plane": "track2-reachability",
            "phase": "B+C+D",
            "phases": {
              "A": "landed",
              "B": "LIVE-when-armed",
              "C": "LIVE-when-session",
              "D": "LIVE-when-three-local-nodes / fixture",
              "E": "scaffold"
            },
            "lan_discovery": "LIVE-when-armed",
            "wifi_discovery": "ARMED-when-HW",
            "bluetooth_discovery": "ARMED-when-HW",
            "rf_discovery": "REFUSE-without-HW",
            "photon_discovery": "REFUSE-without-HW",
            "peer_tunnel": "LIVE-when-session",
            "store_forward": "LIVE-when-three-local-nodes / fixture",
            "store_forward_public": "FG-STUB",
            "worker_runs_store_forward": false,
            "second_device": false,
            "mobile_client": "present-not-demonstrated",
            "mobile_demonstrated": false,
            "app_store_release": false,
            "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
            "bootstrap_list": "scaffold",
            "needs_starting_address": true,
            "shelf_cite": "scaffold",
            "live_multi_provider": false,
            "cold_shelf_live": false,
            "dns_cut": false,
            "origin_cutover": false,
            "warn5_closed": false,
            "worker_door": "FG-STUB",
            "worker_hardware": false,
            "local_node": "qnm-node",
            "get_never_enables": true,
            "separate_from": "cap7-name",
            "cap7_is_name_plane": true,
            "cap7_public_icann": false,
            "cap7_public_egress": false,
            "mirage_is_azvpn": false,
            "aznet_replaces_internet": false,
            "not_a_second_internet": true,
            "alt_internet_live": false,
            "packet_path_live": false,
            "field_1_0": false,
            "warn5": "STANDS-until-demonstrated",
            "warn5_permanent_stay_off": false,
            "preference": "failover",
            "order": [
              "lan",
              "wifi",
              "bluetooth",
              "rf",
              "photon"
            ],
            "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
            "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
            "status": "NOT-READY",
            "code": "FG-STUB",
            "warn5_until": "demonstrated",
            "warn5_by_design": "separate-from-icann",
            "refuse": {
              "packet": "FG-STUB",
              "radio_absent": "QNM-RADIO-ABSENT",
              "cap7_egress": "MG-NO-IP-EXIT",
              "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
              "bearer": "AZP-BEARER-REFUSE",
              "payload": "AZN-NO-PAYLOAD",
              "route": "MESH-NO-ROUTE",
              "stay_off": "MESH-STAY-OFF",
              "nat": "FED-MESH-NAT-REFUSE"
            },
            "carriers": [
              {
                "order": 1,
                "id": "lan",
                "name": "LAN",
                "op": "d2d_lan",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "lan-interface",
                "discovery": "LIVE-when-armed",
                "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
              },
              {
                "order": 2,
                "id": "wifi",
                "name": "Wi-Fi",
                "op": "d2d_wifi",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "wifi-nm",
                "discovery": "ARMED-when-HW",
                "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
              },
              {
                "order": 3,
                "id": "bluetooth",
                "name": "Bluetooth",
                "op": "d2d_bluetooth",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "bluez",
                "discovery": "ARMED-when-HW",
                "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
              },
              {
                "order": 4,
                "id": "rf",
                "name": "RF",
                "op": "d2d_rf",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "rf-beyond-wifi-bt",
                "discovery": "REFUSE-without-HW",
                "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
              },
              {
                "order": 5,
                "id": "photon",
                "name": "Photon",
                "op": "d2d_photon",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "camera-flash",
                "discovery": "REFUSE-without-HW",
                "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
              }
            ],
            "security": {
              "isolation": "single-node security-awareness",
              "phoenix": "local wait / re-seal",
              "mesh_fenced_to_loopback": false,
              "forced_loopback": false,
              "loopback_isolation": false
            },
            "paper": "docs/designs/D2D-CARRIERS-1.0.md",
            "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
          },
          "d2d_status": "NOT-READY",
          "d2d_code": "FG-STUB",
          "packet_path_live": false,
          "alt_internet_live": false,
          "d2d_spec": "D2D-CARRIERS-1.0",
          "federated_mesh": "FED-MESH-1.0",
          "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
          "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        }
      },
      {
        "slug": "veillock",
        "name": "VeilLock",
        "bucket": "lock",
        "domain": "Media",
        "domain_id": "02",
        "placement": "domain-software",
        "status": "local_only",
        "fraggate_status": "local_only",
        "public_door": false,
        "public_door_ops": [],
        "stub_ops": [
          "inject",
          "intercept",
          "facetime"
        ],
        "door_label": "local only — no public FragGate door",
        "open_live_door": false,
        "version": "0.2.0",
        "one_line": "Follow local camera and screen steps for apps on your own device.",
        "description": "Use VeilLock for device-local camera and screen steps in your own apps. VeilLock stays local_only. It exists for camera and screen work on your own device.",
        "worker_home": "https://veillock-download-tracker.vibelock.workers.dev/",
        "worker_home_note": null,
        "download_url": "https://veillock-download-tracker.vibelock.workers.dev/download",
        "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "github": "https://github.com/AzielEliab/veillock",
        "mcp": "https://godlock.uk/runtime/mcp",
        "agent": {
          "mcp": "https://godlock.uk/runtime/mcp",
          "skill": "https://godlock.uk/runtime/v1/skill",
          "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
          "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=veillock",
          "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
          "fraggate_call_executes": false,
          "open_live_door": false,
          "software": "https://godlock.uk/runtime/v1/software",
          "pull": "https://godlock.uk/runtime/v1/pull/veillock",
          "pipeline": "fraggate_list → fraggate_describe. fraggate_call refuses FG-LOCAL-ONLY. No public door."
        },
        "engine_digest": "b7114d83e33d9f3c05427110115b798c23209eb2716a6431b6bcbe4a613fd464",
        "updated_at": null,
        "git_sha": null,
        "git_sha_tracks_deployed_tip": false,
        "door": "none",
        "kind": "software",
        "mesh": {
          "path": "/runtime/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "security": {
            "model": "single-node-security-awareness",
            "isolates": "bad-peer-or-self",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "phoenix": "local-wait-reseal",
            "phoenix_lock": true,
            "public_hostname_resurrection": false,
            "loopback_bearer": "L1-optional",
            "operator_locks": [
              {
                "n": 1,
                "id": "single-node-security-awareness",
                "status": "LIVE",
                "mesh_fenced_to_loopback": false
              },
              {
                "n": 2,
                "id": "phoenix-reboot-loop",
                "status": "LIVE",
                "phoenix": "local-wait-reseal",
                "phoenix_lock": true,
                "public_hostname_resurrection": false
              },
              {
                "n": 3,
                "id": "open-world-awareness",
                "status": "live-when-configured",
                "law": "LIVE",
                "bind": "0.0.0.0",
                "worker_socket": false,
                "forced_loopback_is_mesh_fence": false,
                "loopback_isolation_is_mesh_fence": false
              }
            ],
            "open_world_awareness": {
              "spec": "OPEN-WORLD-AWARENESS-1.0",
              "author": "Aziel Eliab",
              "identity": "Aziel Eliab",
              "open_world_awareness": true,
              "bind": "0.0.0.0",
              "all_interfaces": true,
              "law": "LIVE",
              "status": "live-when-configured",
              "live": false,
              "socket": "live-when-configured",
              "worker_socket": false,
              "qnm_node_bind": "live-when-configured",
              "mock": false,
              "forced_loopback": false,
              "loopback_isolation": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false,
              "mesh_fenced_to_loopback": false,
              "public_egress_ip": false,
              "residential": false,
              "cf_geo_exit": false,
              "cf_geo_exit_pool": false,
              "sticky_public_ip": false,
              "packet_forward": false,
              "packet_forwarding": false,
              "public_icann": false,
              "cap7_is_icann": false,
              "replaces_internet": false,
              "not_a_second_internet": true,
              "hosted_vpn": false,
              "payload_host": false,
              "vpn_hop": false,
              "wireguard": false,
              "openvpn": false,
              "l3_exit": false,
              "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
            },
            "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
          },
          "fanout": "cron-or-request-path",
          "live_nodes_plane": "human-mesh-users-site-viewers",
          "nodes_plane": "human-mesh-users-uses",
          "software_nodes_plane": "software-worker-fanout",
          "site_live_viewers_plane": "hub-human-page-presence",
          "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
          "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
          "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
          "site_presence_contract": {
            "method": "POST",
            "path": "/runtime/v1/mesh/site-presence",
            "alias": "/runtime/v1/mesh/site-heartbeat",
            "fraggate": {
              "slug": "mesh",
              "op": "site-presence"
            },
            "body": {
              "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
              "viewers": "non-negative integer concurrent human page sessions (0..10000)",
              "kind": "human-page"
            },
            "ttl_ms": 900000,
            "registered_grace_ms": 1209600000,
            "default_heartbeat_mode": "idle",
            "heartbeat_mode": "active | idle | asleep",
            "stale_keeps_registered": true,
            "stale_counts_as_live": false,
            "allowed_hosts": [
              "godlock.uk",
              "azieleliab.com",
              "azielcorpuslibrary.net"
            ],
            "excluded_hosts": [
              "hedidntjump.com"
            ],
            "refused_kinds": [
              "bot",
              "bots",
              "crawler",
              "software",
              "softwares",
              "download",
              "downloads",
              "instance",
              "mcp"
            ],
            "pull_hub_count": false,
            "invent": false,
            "fail_closed": true,
            "read": "single-key",
            "paint": "live_nodes",
            "local_recompute": false,
            "radios": "not required — hub ingest, not a TX join",
            "rate_kind": "mesh_mutate",
            "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
          },
          "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
          "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
          "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "ban_survival": "BAN-SURVIVAL-1.0",
          "spore_spec": "SPORE-1.0",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/runtime/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "neighbor_heal_is_cite": true,
              "neighbor_heal_exec": false,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "neighbor_heal_is_cite": true,
          "neighbor_heal_exec": false,
          "join_is_presence_only": true,
          "join_is_not_login": true,
          "roster_publishes_exec_urls": false,
          "mesh_mutate_rate_kind": "mesh_mutate",
          "roster_cap": 256,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "d2d_carriers": {
            "spec": "D2D-CARRIERS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "plane": "track2-reachability",
            "phase": "B+C+D",
            "phases": {
              "A": "landed",
              "B": "LIVE-when-armed",
              "C": "LIVE-when-session",
              "D": "LIVE-when-three-local-nodes / fixture",
              "E": "scaffold"
            },
            "lan_discovery": "LIVE-when-armed",
            "wifi_discovery": "ARMED-when-HW",
            "bluetooth_discovery": "ARMED-when-HW",
            "rf_discovery": "REFUSE-without-HW",
            "photon_discovery": "REFUSE-without-HW",
            "peer_tunnel": "LIVE-when-session",
            "store_forward": "LIVE-when-three-local-nodes / fixture",
            "store_forward_public": "FG-STUB",
            "worker_runs_store_forward": false,
            "second_device": false,
            "mobile_client": "present-not-demonstrated",
            "mobile_demonstrated": false,
            "app_store_release": false,
            "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
            "bootstrap_list": "scaffold",
            "needs_starting_address": true,
            "shelf_cite": "scaffold",
            "live_multi_provider": false,
            "cold_shelf_live": false,
            "dns_cut": false,
            "origin_cutover": false,
            "warn5_closed": false,
            "worker_door": "FG-STUB",
            "worker_hardware": false,
            "local_node": "qnm-node",
            "get_never_enables": true,
            "separate_from": "cap7-name",
            "cap7_is_name_plane": true,
            "cap7_public_icann": false,
            "cap7_public_egress": false,
            "mirage_is_azvpn": false,
            "aznet_replaces_internet": false,
            "not_a_second_internet": true,
            "alt_internet_live": false,
            "packet_path_live": false,
            "field_1_0": false,
            "warn5": "STANDS-until-demonstrated",
            "warn5_permanent_stay_off": false,
            "preference": "failover",
            "order": [
              "lan",
              "wifi",
              "bluetooth",
              "rf",
              "photon"
            ],
            "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
            "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
            "status": "NOT-READY",
            "code": "FG-STUB",
            "warn5_until": "demonstrated",
            "warn5_by_design": "separate-from-icann",
            "refuse": {
              "packet": "FG-STUB",
              "radio_absent": "QNM-RADIO-ABSENT",
              "cap7_egress": "MG-NO-IP-EXIT",
              "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
              "bearer": "AZP-BEARER-REFUSE",
              "payload": "AZN-NO-PAYLOAD",
              "route": "MESH-NO-ROUTE",
              "stay_off": "MESH-STAY-OFF",
              "nat": "FED-MESH-NAT-REFUSE"
            },
            "carriers": [
              {
                "order": 1,
                "id": "lan",
                "name": "LAN",
                "op": "d2d_lan",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "lan-interface",
                "discovery": "LIVE-when-armed",
                "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
              },
              {
                "order": 2,
                "id": "wifi",
                "name": "Wi-Fi",
                "op": "d2d_wifi",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "wifi-nm",
                "discovery": "ARMED-when-HW",
                "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
              },
              {
                "order": 3,
                "id": "bluetooth",
                "name": "Bluetooth",
                "op": "d2d_bluetooth",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "bluez",
                "discovery": "ARMED-when-HW",
                "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
              },
              {
                "order": 4,
                "id": "rf",
                "name": "RF",
                "op": "d2d_rf",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "rf-beyond-wifi-bt",
                "discovery": "REFUSE-without-HW",
                "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
              },
              {
                "order": 5,
                "id": "photon",
                "name": "Photon",
                "op": "d2d_photon",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "camera-flash",
                "discovery": "REFUSE-without-HW",
                "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
              }
            ],
            "security": {
              "isolation": "single-node security-awareness",
              "phoenix": "local wait / re-seal",
              "mesh_fenced_to_loopback": false,
              "forced_loopback": false,
              "loopback_isolation": false
            },
            "paper": "docs/designs/D2D-CARRIERS-1.0.md",
            "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
          },
          "d2d_status": "NOT-READY",
          "d2d_code": "FG-STUB",
          "packet_path_live": false,
          "alt_internet_live": false,
          "d2d_spec": "D2D-CARRIERS-1.0",
          "federated_mesh": "FED-MESH-1.0",
          "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
          "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        },
        "local_only": true,
        "note": "Device-local. FragGate status is local_only — no public door. Hub tab must not read this card as public-door live."
      },
      {
        "slug": "vibelock",
        "name": "VibeLock",
        "bucket": "lock",
        "domain": "Media",
        "domain_id": "02",
        "placement": "domain-software",
        "status": "live",
        "fraggate_status": "live",
        "public_door": true,
        "public_door_ops": [
          "analyze",
          "detect",
          "health",
          "skill",
          "doctor"
        ],
        "stub_ops": [],
        "door_label": "live FragGate door",
        "open_live_door": true,
        "version": "0.3.0",
        "one_line": "Assess AI deepfake risk in mp4, mp3, and other audio and video. Physics and related signals are heuristic. Linguistics is experimental. Vibration is measured only with a body-coupled track.",
        "description": "Use VibeLock to assess AI deepfake risk in audio and video you already hold. It exists as a media authenticity advisory. Physics and related signals are heuristic. Linguistics is experimental. Vibration is a measurement only when a body-coupled track is present. Hosted analyze and detect score posted features or limited PCM, refuse raw container bytes, and publish no accuracy percentage. Compressed files on the local package need ffmpeg.",
        "worker_home": "https://vibelock-download-tracker.vibelock.workers.dev/",
        "worker_home_note": null,
        "download_url": "https://vibelock-download-tracker.vibelock.workers.dev/download",
        "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "github": "https://github.com/AzielEliab/vibelock",
        "mcp": "https://godlock.uk/runtime/mcp",
        "agent": {
          "mcp": "https://godlock.uk/runtime/mcp",
          "skill": "https://godlock.uk/runtime/v1/skill",
          "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
          "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=vibelock",
          "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
          "fraggate_call_executes": true,
          "open_live_door": true,
          "software": "https://godlock.uk/runtime/v1/software",
          "pull": "https://godlock.uk/runtime/v1/pull/vibelock",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "bf35c9e62ae2717bac039d74ff81be7af57be4c454a418b1cc4abffee9d08d5a",
        "updated_at": null,
        "git_sha": null,
        "git_sha_tracks_deployed_tip": false,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/runtime/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "security": {
            "model": "single-node-security-awareness",
            "isolates": "bad-peer-or-self",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "phoenix": "local-wait-reseal",
            "phoenix_lock": true,
            "public_hostname_resurrection": false,
            "loopback_bearer": "L1-optional",
            "operator_locks": [
              {
                "n": 1,
                "id": "single-node-security-awareness",
                "status": "LIVE",
                "mesh_fenced_to_loopback": false
              },
              {
                "n": 2,
                "id": "phoenix-reboot-loop",
                "status": "LIVE",
                "phoenix": "local-wait-reseal",
                "phoenix_lock": true,
                "public_hostname_resurrection": false
              },
              {
                "n": 3,
                "id": "open-world-awareness",
                "status": "live-when-configured",
                "law": "LIVE",
                "bind": "0.0.0.0",
                "worker_socket": false,
                "forced_loopback_is_mesh_fence": false,
                "loopback_isolation_is_mesh_fence": false
              }
            ],
            "open_world_awareness": {
              "spec": "OPEN-WORLD-AWARENESS-1.0",
              "author": "Aziel Eliab",
              "identity": "Aziel Eliab",
              "open_world_awareness": true,
              "bind": "0.0.0.0",
              "all_interfaces": true,
              "law": "LIVE",
              "status": "live-when-configured",
              "live": false,
              "socket": "live-when-configured",
              "worker_socket": false,
              "qnm_node_bind": "live-when-configured",
              "mock": false,
              "forced_loopback": false,
              "loopback_isolation": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false,
              "mesh_fenced_to_loopback": false,
              "public_egress_ip": false,
              "residential": false,
              "cf_geo_exit": false,
              "cf_geo_exit_pool": false,
              "sticky_public_ip": false,
              "packet_forward": false,
              "packet_forwarding": false,
              "public_icann": false,
              "cap7_is_icann": false,
              "replaces_internet": false,
              "not_a_second_internet": true,
              "hosted_vpn": false,
              "payload_host": false,
              "vpn_hop": false,
              "wireguard": false,
              "openvpn": false,
              "l3_exit": false,
              "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
            },
            "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
          },
          "fanout": "cron-or-request-path",
          "live_nodes_plane": "human-mesh-users-site-viewers",
          "nodes_plane": "human-mesh-users-uses",
          "software_nodes_plane": "software-worker-fanout",
          "site_live_viewers_plane": "hub-human-page-presence",
          "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
          "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
          "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
          "site_presence_contract": {
            "method": "POST",
            "path": "/runtime/v1/mesh/site-presence",
            "alias": "/runtime/v1/mesh/site-heartbeat",
            "fraggate": {
              "slug": "mesh",
              "op": "site-presence"
            },
            "body": {
              "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
              "viewers": "non-negative integer concurrent human page sessions (0..10000)",
              "kind": "human-page"
            },
            "ttl_ms": 900000,
            "registered_grace_ms": 1209600000,
            "default_heartbeat_mode": "idle",
            "heartbeat_mode": "active | idle | asleep",
            "stale_keeps_registered": true,
            "stale_counts_as_live": false,
            "allowed_hosts": [
              "godlock.uk",
              "azieleliab.com",
              "azielcorpuslibrary.net"
            ],
            "excluded_hosts": [
              "hedidntjump.com"
            ],
            "refused_kinds": [
              "bot",
              "bots",
              "crawler",
              "software",
              "softwares",
              "download",
              "downloads",
              "instance",
              "mcp"
            ],
            "pull_hub_count": false,
            "invent": false,
            "fail_closed": true,
            "read": "single-key",
            "paint": "live_nodes",
            "local_recompute": false,
            "radios": "not required — hub ingest, not a TX join",
            "rate_kind": "mesh_mutate",
            "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
          },
          "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
          "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
          "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "ban_survival": "BAN-SURVIVAL-1.0",
          "spore_spec": "SPORE-1.0",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/runtime/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "neighbor_heal_is_cite": true,
              "neighbor_heal_exec": false,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "neighbor_heal_is_cite": true,
          "neighbor_heal_exec": false,
          "join_is_presence_only": true,
          "join_is_not_login": true,
          "roster_publishes_exec_urls": false,
          "mesh_mutate_rate_kind": "mesh_mutate",
          "roster_cap": 256,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "d2d_carriers": {
            "spec": "D2D-CARRIERS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "plane": "track2-reachability",
            "phase": "B+C+D",
            "phases": {
              "A": "landed",
              "B": "LIVE-when-armed",
              "C": "LIVE-when-session",
              "D": "LIVE-when-three-local-nodes / fixture",
              "E": "scaffold"
            },
            "lan_discovery": "LIVE-when-armed",
            "wifi_discovery": "ARMED-when-HW",
            "bluetooth_discovery": "ARMED-when-HW",
            "rf_discovery": "REFUSE-without-HW",
            "photon_discovery": "REFUSE-without-HW",
            "peer_tunnel": "LIVE-when-session",
            "store_forward": "LIVE-when-three-local-nodes / fixture",
            "store_forward_public": "FG-STUB",
            "worker_runs_store_forward": false,
            "second_device": false,
            "mobile_client": "present-not-demonstrated",
            "mobile_demonstrated": false,
            "app_store_release": false,
            "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
            "bootstrap_list": "scaffold",
            "needs_starting_address": true,
            "shelf_cite": "scaffold",
            "live_multi_provider": false,
            "cold_shelf_live": false,
            "dns_cut": false,
            "origin_cutover": false,
            "warn5_closed": false,
            "worker_door": "FG-STUB",
            "worker_hardware": false,
            "local_node": "qnm-node",
            "get_never_enables": true,
            "separate_from": "cap7-name",
            "cap7_is_name_plane": true,
            "cap7_public_icann": false,
            "cap7_public_egress": false,
            "mirage_is_azvpn": false,
            "aznet_replaces_internet": false,
            "not_a_second_internet": true,
            "alt_internet_live": false,
            "packet_path_live": false,
            "field_1_0": false,
            "warn5": "STANDS-until-demonstrated",
            "warn5_permanent_stay_off": false,
            "preference": "failover",
            "order": [
              "lan",
              "wifi",
              "bluetooth",
              "rf",
              "photon"
            ],
            "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
            "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
            "status": "NOT-READY",
            "code": "FG-STUB",
            "warn5_until": "demonstrated",
            "warn5_by_design": "separate-from-icann",
            "refuse": {
              "packet": "FG-STUB",
              "radio_absent": "QNM-RADIO-ABSENT",
              "cap7_egress": "MG-NO-IP-EXIT",
              "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
              "bearer": "AZP-BEARER-REFUSE",
              "payload": "AZN-NO-PAYLOAD",
              "route": "MESH-NO-ROUTE",
              "stay_off": "MESH-STAY-OFF",
              "nat": "FED-MESH-NAT-REFUSE"
            },
            "carriers": [
              {
                "order": 1,
                "id": "lan",
                "name": "LAN",
                "op": "d2d_lan",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "lan-interface",
                "discovery": "LIVE-when-armed",
                "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
              },
              {
                "order": 2,
                "id": "wifi",
                "name": "Wi-Fi",
                "op": "d2d_wifi",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "wifi-nm",
                "discovery": "ARMED-when-HW",
                "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
              },
              {
                "order": 3,
                "id": "bluetooth",
                "name": "Bluetooth",
                "op": "d2d_bluetooth",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "bluez",
                "discovery": "ARMED-when-HW",
                "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
              },
              {
                "order": 4,
                "id": "rf",
                "name": "RF",
                "op": "d2d_rf",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "rf-beyond-wifi-bt",
                "discovery": "REFUSE-without-HW",
                "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
              },
              {
                "order": 5,
                "id": "photon",
                "name": "Photon",
                "op": "d2d_photon",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "camera-flash",
                "discovery": "REFUSE-without-HW",
                "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
              }
            ],
            "security": {
              "isolation": "single-node security-awareness",
              "phoenix": "local wait / re-seal",
              "mesh_fenced_to_loopback": false,
              "forced_loopback": false,
              "loopback_isolation": false
            },
            "paper": "docs/designs/D2D-CARRIERS-1.0.md",
            "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
          },
          "d2d_status": "NOT-READY",
          "d2d_code": "FG-STUB",
          "packet_path_live": false,
          "alt_internet_live": false,
          "d2d_spec": "D2D-CARRIERS-1.0",
          "federated_mesh": "FED-MESH-1.0",
          "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
          "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        }
      },
      {
        "slug": "whistlelock",
        "name": "WhistleLock",
        "bucket": "lock",
        "domain": "Evidence",
        "domain_id": "03",
        "placement": "domain-software",
        "status": "live",
        "fraggate_status": "live",
        "public_door": true,
        "public_door_ops": [
          "hash-preview",
          "canon-preview",
          "hash_put",
          "hash_get",
          "hash_stat",
          "health",
          "skill",
          "doctor"
        ],
        "stub_ops": [
          "send",
          "mail",
          "release"
        ],
        "door_label": "live FragGate door — named stub ops refuse",
        "open_live_door": true,
        "version": "0.1.0",
        "one_line": "Hash a local drop and keep a dead-man copy on the client.",
        "description": "Use WhistleLock to hash posted bytes and hold isolate-hash objects. It exists as a local drop ledger.",
        "worker_home": "https://whistlelock-download-tracker.vibelock.workers.dev/",
        "worker_home_note": null,
        "download_url": "https://whistlelock-download-tracker.vibelock.workers.dev/download",
        "host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "homepage": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "primary_host": "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime",
        "github": "https://github.com/AzielEliab/whistlelock",
        "mcp": "https://godlock.uk/runtime/mcp",
        "agent": {
          "mcp": "https://godlock.uk/runtime/mcp",
          "skill": "https://godlock.uk/runtime/v1/skill",
          "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
          "fraggate_describe": "https://godlock.uk/runtime/v1/fraggate/describe?slug=whistlelock",
          "fraggate_call": "https://godlock.uk/runtime/v1/fraggate/call",
          "fraggate_call_executes": true,
          "open_live_door": true,
          "software": "https://godlock.uk/runtime/v1/software",
          "pull": "https://godlock.uk/runtime/v1/pull/whistlelock",
          "pipeline": "fraggate_list → fraggate_describe → fraggate_call"
        },
        "engine_digest": "f585b20e1dfc0321e432ba04299d91d1708ae3b6f2ac78c85db5c61a63a4a6f8",
        "updated_at": null,
        "git_sha": null,
        "git_sha_tracks_deployed_tip": false,
        "door": "fraggate",
        "kind": "software",
        "mesh": {
          "path": "/runtime/v1/mesh",
          "enabled_default": true,
          "mesh_default": "on",
          "spec": "QNM-BUILD-1.0",
          "companion": "AIH-WP-1.1",
          "rollup_only": true,
          "qnm_s": false,
          "suite_presence": "on",
          "get_never_enables": true,
          "security": {
            "model": "single-node-security-awareness",
            "isolates": "bad-peer-or-self",
            "mesh_fenced_to_loopback": false,
            "forced_loopback": false,
            "loopback_isolation": false,
            "forced_loopback_is_mesh_fence": false,
            "loopback_isolation_is_mesh_fence": false,
            "phoenix": "local-wait-reseal",
            "phoenix_lock": true,
            "public_hostname_resurrection": false,
            "loopback_bearer": "L1-optional",
            "operator_locks": [
              {
                "n": 1,
                "id": "single-node-security-awareness",
                "status": "LIVE",
                "mesh_fenced_to_loopback": false
              },
              {
                "n": 2,
                "id": "phoenix-reboot-loop",
                "status": "LIVE",
                "phoenix": "local-wait-reseal",
                "phoenix_lock": true,
                "public_hostname_resurrection": false
              },
              {
                "n": 3,
                "id": "open-world-awareness",
                "status": "live-when-configured",
                "law": "LIVE",
                "bind": "0.0.0.0",
                "worker_socket": false,
                "forced_loopback_is_mesh_fence": false,
                "loopback_isolation_is_mesh_fence": false
              }
            ],
            "open_world_awareness": {
              "spec": "OPEN-WORLD-AWARENESS-1.0",
              "author": "Aziel Eliab",
              "identity": "Aziel Eliab",
              "open_world_awareness": true,
              "bind": "0.0.0.0",
              "all_interfaces": true,
              "law": "LIVE",
              "status": "live-when-configured",
              "live": false,
              "socket": "live-when-configured",
              "worker_socket": false,
              "qnm_node_bind": "live-when-configured",
              "mock": false,
              "forced_loopback": false,
              "loopback_isolation": false,
              "forced_loopback_is_mesh_fence": false,
              "loopback_isolation_is_mesh_fence": false,
              "mesh_fenced_to_loopback": false,
              "public_egress_ip": false,
              "residential": false,
              "cf_geo_exit": false,
              "cf_geo_exit_pool": false,
              "sticky_public_ip": false,
              "packet_forward": false,
              "packet_forwarding": false,
              "public_icann": false,
              "cap7_is_icann": false,
              "replaces_internet": false,
              "not_a_second_internet": true,
              "hosted_vpn": false,
              "payload_host": false,
              "vpn_hop": false,
              "wireguard": false,
              "openvpn": false,
              "l3_exit": false,
              "note": "Open-world awareness is the outward awareness bind on 0.0.0.0 (all interfaces). The operator lock is LIVE. The OS socket is live-when-configured on local qnm-node and is not a Worker listen. forced_loopback and loopback_isolation are not the mesh fence. This bind is not a loopback fence, not a Cap-7 public egress IP, and not a replacement for the ICANN internet."
            },
            "note": "Operator lock stack: (1) single-node security-awareness isolation — a node isolates a bad peer or itself, and that does not fence the whole mesh to 127.0.0.1; (2) phoenix reboot loop — local wait / re-seal, phoenix_lock, not public hostname resurrection; (3) open-world awareness bound as 0.0.0.0 — all-interfaces awareness bind, not a loopback fence, not a Cap-7 public egress IP, not a replacement for the ICANN internet. forced_loopback and loopback_isolation are not the mesh fence. Open-world awareness is the outward awareness bind. The operator lock is LIVE. The Worker does not open that socket. A local qnm-node listen on 0.0.0.0 is LIVE; until that process binds, the socket stays live-when-configured. Loopback remains an optional L1 peer bearer."
          },
          "fanout": "cron-or-request-path",
          "live_nodes_plane": "human-mesh-users-site-viewers",
          "nodes_plane": "human-mesh-users-uses",
          "software_nodes_plane": "software-worker-fanout",
          "site_live_viewers_plane": "hub-human-page-presence",
          "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users with a recent beat (presence class live or locked, not stale, not isolated) plus concurrent website viewers (site_live_viewers) on godlock.uk + azieleliab.com + azielcorpuslibrary.net. registered_humans and site_registered_viewers are the durable counts and are not Live Nodes. Isolated humans stay on isolated_nodes. Stale humans stay registered and do not count. hedidntjump.com, bots, Softwares, and downloads are excluded. GET /v1/mesh never pulls hub /count. Hubs paint live_nodes / rollup.mesh from this JSON (live_nodes_tip / live_nodes_generation). Do not add a local /count. rollup.live is not published. Never paint software_nodes, registered_nodes, or rollup.live as Live Nodes. Roster presence=live, including {slug}-worker, is rollup.all.live and rollup.software.live — not the Live Nodes pill. A stale hub report is 0 on Live Nodes. Live Nodes does not invent users. Zero is honest when no human is present.",
          "nodes_note": "Public Nodes (nodes / rollup.nodes) count human mesh users plus the cited human uses signal (USES / human_uses). Uses are interaction counters, not unique people. Incomplete or unbound telemetry is reported honestly (0 + complete=false). Nodes does not invent users. Zero is honest.",
          "site_live_viewers_note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers.",
          "site_presence_contract": {
            "method": "POST",
            "path": "/runtime/v1/mesh/site-presence",
            "alias": "/runtime/v1/mesh/site-heartbeat",
            "fraggate": {
              "slug": "mesh",
              "op": "site-presence"
            },
            "body": {
              "host": "godlock.uk | azieleliab.com | azielcorpuslibrary.net",
              "viewers": "non-negative integer concurrent human page sessions (0..10000)",
              "kind": "human-page"
            },
            "ttl_ms": 900000,
            "registered_grace_ms": 1209600000,
            "default_heartbeat_mode": "idle",
            "heartbeat_mode": "active | idle | asleep",
            "stale_keeps_registered": true,
            "stale_counts_as_live": false,
            "allowed_hosts": [
              "godlock.uk",
              "azieleliab.com",
              "azielcorpuslibrary.net"
            ],
            "excluded_hosts": [
              "hedidntjump.com"
            ],
            "refused_kinds": [
              "bot",
              "bots",
              "crawler",
              "software",
              "softwares",
              "download",
              "downloads",
              "instance",
              "mcp"
            ],
            "pull_hub_count": false,
            "invent": false,
            "fail_closed": true,
            "read": "single-key",
            "paint": "live_nodes",
            "local_recompute": false,
            "radios": "not required — hub ingest, not a TX join",
            "rate_kind": "mesh_mutate",
            "note": "site_live_viewers is concurrent human page presence across godlock.uk + azieleliab.com + azielcorpuslibrary.net, reported by hub heartbeats (POST /v1/mesh/site-presence). A fresh beat counts. Miss 3 adaptive beats (default idle: 15 minutes) and that host is stale: site_live_viewers drops it to 0, and site_registered_viewers keeps the last reported count until explicit viewers 0 or 14 days after the last beat. GET /v1/mesh reads one sealed aggregate (live_nodes_generation / live_nodes_tip) and never pulls hub /count. Hubs paint live_nodes / rollup.mesh from that JSON — do not add a local /count. Never paint software_nodes, site_registered_viewers, or rollup.live as Live Nodes. hedidntjump.com, bots, Softwares, and downloads are excluded. Missing reports are 0. Do not invent viewers."
          },
          "software_nodes_note": "software_nodes / rollup.software count in-process catalog product Workers ({slug}-worker) from suite-presence fan-out. That roster is not the Softwares-tab count. Whitestone is a Softwares card and is absent (worker_only; FragGate status none). memory and mesh are FragGate kernel entries and are not software_nodes rows. VeilLock is in this fan-out and is not on the public FragGate allowlist. Do not equate software_nodes with Softwares slugs, FragGate product_count, or the FragGate allowlist. rollup.software.live is that roster's presence=live count. It is not public Live Nodes. rollup.live is not published.",
          "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
          "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Nodes and Live Nodes do not invent users from missing uses.",
          "presence_ttl_ms": 300000,
          "qns_cd": {
            "spec": "QNS-CD-1.0",
            "local": "https://github.com/AzielEliab/qnm-node",
            "note": "Photon vias on local qnsd; Worker cites only"
          },
          "survival": {
            "spec": "CROSS-NETWORK-SURVIVAL-1.0",
            "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
            "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
            "shelves": [
              "hosts",
              "doi",
              "git",
              "vault"
            ],
            "software_tab": false,
            "fraggate_slug": false,
            "named_hosts_only": true,
            "live_network_is_shelf": false,
            "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
          },
          "ban_survival": "BAN-SURVIVAL-1.0",
          "spore_spec": "SPORE-1.0",
          "no_lie": true,
          "no_rewrite": true,
          "rewrite_key": false,
          "lie_to_survive": false,
          "copies_one_tunnel": false,
          "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
          "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
          "no_lie_hint": {
            "spec": "NO-LIE-NO-REWRITE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "no_lie": true,
            "no_rewrite": true,
            "rewrite_key": false,
            "lie_to_survive": false,
            "copies_one_tunnel": false,
            "software_tab": false,
            "fraggate_slug": false,
            "docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
            "survival": "docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "NO-LIE / NO-REWRITE: receipts that still hash; copies not all on one tunnel; rules simple enough others verify without the author's voice; no rewrite key. The network is never allowed to lie — even to self-preserve, sustain, stay alive, adapt, or prevent death. Author: Aziel Eliab only."
          },
          "nine_laws": {
            "hard_true": true,
            "count": 9,
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "runtime_id": "https://www.azieleliab.com/runtime#runtime",
            "hashtag_parts": {
              "person": "#aziel",
              "runtime": "#runtime"
            },
            "about": {
              "path": "/about",
              "v1": "/runtime/v1/about",
              "identity": "Aziel Eliab",
              "always": true
            },
            "clocks_share_socket": false,
            "live_body_sync": false,
            "isolation_is_the_cure": true,
            "neighbor_heal": true,
            "phoenix_local_only": true,
            "die_with_pull": true,
            "restore_godlock_uk": false,
            "node_gate": true,
            "get_is_node_gate": true,
            "implicit_heal": true,
            "auto_heal": true,
            "network": true,
            "network_cite": "on",
            "anonymity_network": true,
            "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
            "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
            "date": "2026-09-17",
            "operator_armed": true,
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "concentrator_name": "AZVPN",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "auto_bind": true,
            "vpn_auto": {
              "default_vpn_backend": "azvpn",
              "auto_use": true,
              "auto_bind": true,
              "concentrator_slug": "azvpn",
              "concentrator_name": "AZVPN",
              "door": "fraggate",
              "explicit_ops": [
                "describe",
                "open",
                "status",
                "list",
                "close",
                "send",
                "recv",
                "pull",
                "peers",
                "attach"
              ],
              "hooks": {
                "mesh_get": "cite-only",
                "mesh_vpn": "ensure",
                "aznet_pair": "cite-and-ensure-when-paired-or-armed",
                "session_open": "ensure-when-armed",
                "azbrowser_vpn": "ensure"
              },
              "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
              "get_never_opens": true,
              "open": false
            },
            "door": "fraggate",
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "wireguard": false,
            "openvpn": false,
            "l3_exit_pool": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "kinds": {
              "https_ws": "REAL",
              "fraggate_envelopes": "REAL",
              "websocket_attach": "REAL",
              "wireguard": "SLOT",
              "openvpn": "SLOT",
              "l3_exit_pool": "SLOT",
              "kernel_udp": "SLOT",
              "tun_tap": "SLOT"
            },
            "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
            "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
            "operator_override": {
              "spec": "OPERATOR-OVERRIDE-2026-09-17",
              "date": "2026-09-17",
              "identity": "Aziel Eliab",
              "author": "Aziel Eliab",
              "operator_armed": true,
              "auto_heal": true,
              "implicit_heal": true,
              "node_gate": true,
              "get_is_node_gate": true,
              "neighbor_heal": true,
              "neighbor_heal_is_cite": true,
              "neighbor_heal_exec": false,
              "network": true,
              "network_cite": "on",
              "anonymity_network": true,
              "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
              "vpn": true,
              "public_vpn": true,
              "tunnel_concentrator": true,
              "concentrator_slug": "azvpn",
              "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
              "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
            },
            "papers": {
              "node_mesh": "docs/NODE_MESH.md",
              "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
              "node_ops": "docs/designs/NODE-OPS-1.0.md",
              "qnm_wp": "docs/designs/QNM-WP-1.0.md"
            }
          },
          "author_id": "https://www.azieleliab.com/#aziel",
          "runtime_id": "https://www.azieleliab.com/runtime#runtime",
          "hashtag_parts": {
            "person": "#aziel",
            "runtime": "#runtime"
          },
          "about": {
            "path": "/about",
            "v1": "/runtime/v1/about",
            "identity": "Aziel Eliab",
            "author_id": "https://www.azieleliab.com/#aziel",
            "always": true
          },
          "clocks_share_socket": false,
          "live_body_sync": false,
          "node_gate": true,
          "get_is_node_gate": true,
          "anonymity_network": true,
          "die_with_pull": true,
          "phoenix_local_only": true,
          "implicit_heal": true,
          "auto_heal": true,
          "neighbor_heal": true,
          "neighbor_heal_is_cite": true,
          "neighbor_heal_exec": false,
          "join_is_presence_only": true,
          "join_is_not_login": true,
          "roster_publishes_exec_urls": false,
          "mesh_mutate_rate_kind": "mesh_mutate",
          "roster_cap": 256,
          "network": true,
          "network_cite": "on",
          "channel_plane": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "operator_armed": true,
            "plane": "channel",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "channels": {
              "wifi": "on",
              "bluetooth": "on",
              "rf": "on",
              "photon": "on"
            },
            "bearer": "suite-presence",
            "worker_bearer": "suite-presence",
            "worker_hardware": false,
            "invented_hardware": false,
            "public_proxy": false,
            "local_process": "qnm-node / qnsd",
            "local": "https://github.com/AzielEliab/qnm-node",
            "local_radio_hooks": {
              "path": "qnm-node/bearers/radio.js",
              "law": "LIVE-when-HW-present / refuse-when-absent",
              "mock": false,
              "worker_hardware": false
            },
            "vpn": true,
            "public_vpn": true,
            "tunnel_concentrator": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "worker_terminates_tunnels": true,
            "worker_terminates_kernel_udp": false,
            "tor": false,
            "socks": false,
            "origin_hiding": false,
            "tunnel": false,
            "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
            "node_mesh": "docs/NODE_MESH.md",
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "channels": {
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on"
          },
          "wifi": "on",
          "bluetooth": "on",
          "rf": "on",
          "photon": "on",
          "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
          "worker_hardware": false,
          "invented_hardware": false,
          "channel_plane_hint": {
            "spec": "QNM-CHANNEL-PLANE-1.0",
            "wifi": "on",
            "bluetooth": "on",
            "rf": "on",
            "photon": "on",
            "vpn": true,
            "public_vpn": true,
            "concentrator_slug": "azvpn",
            "default_vpn_backend": "azvpn",
            "auto_use": true,
            "public_proxy": false,
            "worker_hardware": false,
            "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
          },
          "d2d_carriers": {
            "spec": "D2D-CARRIERS-1.0",
            "author": "Aziel Eliab",
            "identity": "Aziel Eliab",
            "plane": "track2-reachability",
            "phase": "B+C+D",
            "phases": {
              "A": "landed",
              "B": "LIVE-when-armed",
              "C": "LIVE-when-session",
              "D": "LIVE-when-three-local-nodes / fixture",
              "E": "scaffold"
            },
            "lan_discovery": "LIVE-when-armed",
            "wifi_discovery": "ARMED-when-HW",
            "bluetooth_discovery": "ARMED-when-HW",
            "rf_discovery": "REFUSE-without-HW",
            "photon_discovery": "REFUSE-without-HW",
            "peer_tunnel": "LIVE-when-session",
            "store_forward": "LIVE-when-three-local-nodes / fixture",
            "store_forward_public": "FG-STUB",
            "worker_runs_store_forward": false,
            "second_device": false,
            "mobile_client": "present-not-demonstrated",
            "mobile_demonstrated": false,
            "app_store_release": false,
            "mobile_paper": "docs/designs/TRACK2-MOBILE-JOIN-1.0.md",
            "bootstrap_list": "scaffold",
            "needs_starting_address": true,
            "shelf_cite": "scaffold",
            "live_multi_provider": false,
            "cold_shelf_live": false,
            "dns_cut": false,
            "origin_cutover": false,
            "warn5_closed": false,
            "worker_door": "FG-STUB",
            "worker_hardware": false,
            "local_node": "qnm-node",
            "get_never_enables": true,
            "separate_from": "cap7-name",
            "cap7_is_name_plane": true,
            "cap7_public_icann": false,
            "cap7_public_egress": false,
            "mirage_is_azvpn": false,
            "aznet_replaces_internet": false,
            "not_a_second_internet": true,
            "alt_internet_live": false,
            "packet_path_live": false,
            "field_1_0": false,
            "warn5": "STANDS-until-demonstrated",
            "warn5_permanent_stay_off": false,
            "preference": "failover",
            "order": [
              "lan",
              "wifi",
              "bluetooth",
              "rf",
              "photon"
            ],
            "order_label": "LAN, Wi-Fi, Bluetooth, RF, photon light flashes",
            "order_arrow": "LAN → Wi-Fi → Bluetooth → RF → Photon light flashes",
            "status": "NOT-READY",
            "code": "FG-STUB",
            "warn5_until": "demonstrated",
            "warn5_by_design": "separate-from-icann",
            "refuse": {
              "packet": "FG-STUB",
              "radio_absent": "QNM-RADIO-ABSENT",
              "cap7_egress": "MG-NO-IP-EXIT",
              "cap7_egress_engine": "MG-NOT-PUBLIC-EGRESS",
              "bearer": "AZP-BEARER-REFUSE",
              "payload": "AZN-NO-PAYLOAD",
              "route": "MESH-NO-ROUTE",
              "stay_off": "MESH-STAY-OFF",
              "nat": "FED-MESH-NAT-REFUSE"
            },
            "carriers": [
              {
                "order": 1,
                "id": "lan",
                "name": "LAN",
                "op": "d2d_lan",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "lan-interface",
                "discovery": "LIVE-when-armed",
                "note": "First preference. Local node beacons presence and tip hash when the operator arms LAN. Discovery is LIVE only after two peers verify each other. The public Worker stays FG-STUB. A named interface is not alt-internet LIVE."
              },
              {
                "order": 2,
                "id": "wifi",
                "name": "Wi-Fi",
                "op": "d2d_wifi",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "wifi-nm",
                "discovery": "ARMED-when-HW",
                "note": "Second preference. Arm records real Wi-Fi hardware. A LAN beacon is not a Wi-Fi exchange. A phone that reaches the LAN beacon over Wi-Fi is still the LAN client. That path does not set peer_exchange_demonstrated. Absent radio refuses QNM-RADIO-ABSENT. No mock LIVE."
              },
              {
                "order": 3,
                "id": "bluetooth",
                "name": "Bluetooth",
                "op": "d2d_bluetooth",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "bluez",
                "discovery": "ARMED-when-HW",
                "note": "Third preference. Arm records real Bluetooth hardware. Absent radio refuses QNM-RADIO-ABSENT. BlueZ presence is not a demonstrated hop. No mock LIVE."
              },
              {
                "order": 4,
                "id": "rf",
                "name": "RF",
                "op": "d2d_rf",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "rf-beyond-wifi-bt",
                "discovery": "REFUSE-without-HW",
                "note": "Fourth preference. Dedicated RF mesh hop beyond Wi-Fi and Bluetooth. Prefer cellular / ModemManager when that radio is present. Refuse QNM-RADIO-ABSENT when it is absent. No mock LIVE."
              },
              {
                "order": 5,
                "id": "photon",
                "name": "Photon",
                "op": "d2d_photon",
                "status": "NOT-READY",
                "code": "FG-STUB",
                "packet_live": false,
                "mock": false,
                "functional": true,
                "peer_exchange_demonstrated": false,
                "absent_code": "QNM-RADIO-ABSENT",
                "hw": "camera-flash",
                "discovery": "REFUSE-without-HW",
                "note": "Last resort. Optical / LiFi-style light-flash encoding on camera and flash or LED. Refuse QNM-RADIO-ABSENT when that hardware is absent. Local qnsd is not this flash path. No mock LIVE."
              }
            ],
            "security": {
              "isolation": "single-node security-awareness",
              "phoenix": "local wait / re-seal",
              "mesh_fenced_to_loopback": false,
              "forced_loopback": false,
              "loopback_isolation": false
            },
            "paper": "docs/designs/D2D-CARRIERS-1.0.md",
            "note": "Track 2 node-mesh packet reachability stays NOT-READY on the public Worker (FG-STUB). Local LAN discovery is LIVE-when-armed. The peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture: three in-process nodes can deliver a sealed object, second_device is false, and that fixture does not close WARN-5. Wi-Fi and Bluetooth arm when that hardware is present and do not inherit a LAN beacon. The mobile join client speaks the local LAN beacon and sealed peer session. mobile_client stays present-not-demonstrated. A phone on Wi-Fi is that LAN path, not a Wi-Fi carrier exchange, and not an app-store release. RF and photon light flashes refuse QNM-RADIO-ABSENT without hardware, and there is no mock LIVE. peer_exchange_demonstrated stays false on those carriers. Phase E bootstrap lists and shelf cites stay scaffold. live_multi_provider stays false. Cold shelves stay SLOT. Failover is LAN → Wi-Fi → Bluetooth → RF → Photon light flashes. Cap-7 / .aziel stay Track 1 name-plane metadata. MirageGrid is not AZVPN. AZNet is the hash-continuity side-net and does not host payloads. Isolation is single-node security-awareness. Phoenix is local wait / re-seal. WARN-5 stays STANDS-until-demonstrated. alt_internet_live is false."
          },
          "d2d_status": "NOT-READY",
          "d2d_code": "FG-STUB",
          "packet_path_live": false,
          "alt_internet_live": false,
          "d2d_spec": "D2D-CARRIERS-1.0",
          "federated_mesh": "FED-MESH-1.0",
          "federated_mesh_title": "FED-MESH-1.0: Local-First Edge Mesh",
          "verified_handles_note": "verified_handles counts distinct #handles with a matching signing key and presence inside 5 minutes. One handle is one node. Three keys are three nodes. software_nodes and instance_nodes stay on their own planes. The nodes and live_nodes pills are unchanged."
        },
        "qns_cd": {
          "spec": "QNS-CD-1.0",
          "local": "https://github.com/AzielEliab/qnm-node",
          "note": "Photon vias on local qnsd; Worker cites only"
        }
      }
    ]
  },
  "fraggate": {
    "live_count": 42,
    "local_only_count": 1,
    "live_slugs": [
      "vibelock",
      "codelock",
      "godlock",
      "shadowlock",
      "temporallock",
      "forgereceipts",
      "decisiongate",
      "zsolver",
      "azos",
      "glossafilter",
      "miragegrid",
      "staticclock",
      "chronolock",
      "postking",
      "azclce",
      "ark",
      "azai",
      "spectrallock",
      "azbot",
      "employeelock",
      "foldlock",
      "whistlelock",
      "trajectorylock",
      "mialock",
      "azieltether",
      "peacelock",
      "azmail",
      "azbrowser",
      "aznet",
      "azhub",
      "azinterface",
      "aziel-corpus",
      "4dmap",
      "azcoherence",
      "embryolock",
      "azchat",
      "zkattest",
      "mmconsensus",
      "toolbench",
      "azvpn",
      "mesh",
      "memory"
    ],
    "local_only_slugs": [
      "veillock"
    ],
    "list": "https://godlock.uk/runtime/v1/fraggate/list"
  },
  "docs_cite": [
    "docs/NODE_MESH.md",
    "docs/WORKER-LAUNCH.md",
    "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
    "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
    "docs/designs/QNM-WP-1.0.md",
    "docs/audit/HUMAN-UI-MCP-AUDIT-2026-09-17.md",
    "README.md",
    "CHANGELOG.md"
  ],
  "docs_bytes": "CITE — git-hosted; this isolate does not attach the markdown files.",
  "paths": {
    "download": "https://godlock.uk/runtime/download",
    "v1": "https://godlock.uk/runtime/v1/download",
    "suite": "https://godlock.uk/runtime/v1/suite/download",
    "software": "https://godlock.uk/runtime/v1/software",
    "fraggate_list": "https://godlock.uk/runtime/v1/fraggate/list",
    "mesh": "https://godlock.uk/runtime/v1/mesh",
    "github": "https://github.com/AzielEliab/aziel-runtime"
  },
  "note": "One-click suite pack for humans and machines. Packs what ships in-process. Worker wasm, WireGuard/OpenVPN, and qnm-node stay SLOT/CITE. FragGate is THE exec door. Identity Aziel Eliab only. Never .",
  "godlock_runtime": "https://godlock.uk/runtime",
  "library_runtime": "https://www.azielcorpuslibrary.net/runtime",
  "origin_runtime": "https://aziel-runtime.vibelock.workers.dev/",
  "sameAs": [
    "https://godlock.uk/runtime",
    "https://www.azielcorpuslibrary.net/runtime",
    "https://aziel-runtime.vibelock.workers.dev/",
    "https://github.com/AzielEliab/aziel-runtime",
    "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime"
  ],
  "related": [
    "https://godlock.uk/runtime",
    "https://www.azielcorpuslibrary.net/runtime",
    "https://aziel-runtime.vibelock.workers.dev/",
    "https://github.com/AzielEliab/aziel-runtime",
    "https://glama.ai/mcp/servers/AzielEliab/aziel-runtime"
  ]
}