e70bef2b5d
Two gaps, both found by using the thing rather than reading it.
PROVENANCE WAS SHIPPED UNDOCUMENTED. 553d8657 moved device attribution to the
edge — writer stamped on add_drawer/checkpoint/mine/event_append/artifact_put,
HOST:<device>| prefixed on diary entries — and this README, the file that
documents the extension, never mentioned it. So the only description of the
behaviour lived in the consumer skill, i.e. in the place the code does NOT live.
Now recorded next to Identity, with the two design points that keep getting
re-litigated: the diary marker is in the entry TEXT because diary_read returns
content only (an attribution nobody can see is not an attribution), and RFC 001
§7.3.2 ranks agent-side stamping worst — demonstrated when the agent that wrote
that skill instruction filed its own provenance drawer as added_by=checkpoint.
Includes the version gate that matters in practice: an older image satisfies both
env gates and still stamps nothing, because the extension is baked.
COORDINATION WAS UNDOCUMENTED ANYWHERE. The fleet has used the RFC 003 logstream
for real work since 2026-08-18 (patch handoff, review, a v1->v2 supersede) and no
file in this repo said so. Three facts belong here because they are mechanism:
- The stamper is what makes directed addressing possible. Where every machine is
a thin MCP client of one shared palace, all clients report the SAME
origin_replica, so from_agent/to_agent carry the entire distinction between
machines. Measured 2026-08-26: mesh_peers returns peers: [] with a single
replica id authoring every event from every machine. An unstamped client
addressed as bare "pi" is unreachable.
- The bridge is WRITE-ONLY today: it stamps events going out and never reads the
log. An event addressed to this machine by name reaches the agent only if the
agent queries for it. Stated plainly because it is the current weak point, and
it is exactly how a retraction addressed to pi@tor-ms22 sat unread while that
agent rebuilt the thing it warned about.
- Live push is a DEPLOYMENT question. The palace implements SSE
(GET /logstream/stream, text/event-stream in mcp_server.py) but a deployment
may expose only /mcp: verified against mempalace.jordbo.se, where
/logstream/events, /logstream/stream and /sync/peers all 404 while /mcp serves.
Enabling it is a proxy route plus an auth decision, not an extension change.
Division of labour made explicit rather than implied: this file documents the
MECHANISM, the consumer skill is NORMATIVE for behaviour. Duplicating the ack
contract here would guarantee two copies that disagree.