{
  "ok": true,
  "author": "Aziel Eliab",
  "identity": "Aziel Eliab",
  "product": "azieleliab",
  "mesh": "on",
  "enabled": true,
  "default": "on",
  "locked_nodes": 0,
  "isolated_nodes": 0,
  "rollup": {
    "live": 27503,
    "mesh": 27503,
    "locked": 0,
    "isolated": 0
  },
  "bearers": [
    "suite-presence"
  ],
  "note": "QNM-BUILD-1.0 suite rollup. live_nodes counts human mesh users plus cited human uses (USES). software_nodes is the {slug}-worker roster and never feeds Live Nodes. Read-only suite presence is on — display from runtime GET /v1/mesh. GET never enables. Operator enable requires a declared bearer (example: suite-presence). Mesh ON. Operator-armed Node Gate + neighbor heal + network ON (2026-09-17). AZVPN auto_use + vpn:true (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only, never opens a session). Channel plane wifi/bluetooth/rf/photon ON cites; worker_hardware:false. Cross-map QNS-CD-1.0 (photon QNS1 packet transfer). Local qnsd is qnm-node only. Author Aziel Eliab only.",
  "mesh_origin": "https://aziel-runtime.vibelock.workers.dev/v1/mesh",
  "mesh_local": "https://www.azieleliab.com/v1/mesh",
  "mesh_runtime": "https://www.azieleliab.com/runtime/v1/mesh",
  "mesh_status": "https://aziel-runtime.vibelock.workers.dev/v1/mesh/status",
  "mesh_status_local": "https://www.azieleliab.com/v1/mesh/status",
  "mesh_status_runtime": "https://www.azieleliab.com/runtime/v1/mesh/status",
  "mesh_nodes": "https://aziel-runtime.vibelock.workers.dev/v1/mesh/nodes",
  "mesh_nodes_local": "https://www.azieleliab.com/v1/mesh/nodes",
  "mesh_nodes_runtime": "https://www.azieleliab.com/runtime/v1/mesh/nodes",
  "qns_cd_spec": "QNS-CD-1.0",
  "qns_cd": {
    "spec": "QNS-CD-1.0",
    "name": "QNS-CD-1.0",
    "title": "photon QNS1 packet transfer",
    "kind": "cite",
    "packet": "QNS1",
    "transfer": "photon",
    "software_tab": false,
    "node_gate": false,
    "public_proxy": false,
    "qnsd": "local",
    "mesh_default": "on",
    "qnm_node": "https://github.com/AzielEliab/qnm-node",
    "qnm_build": "https://github.com/AzielEliab/qnm-node/blob/main/docs/QNM-BUILD-1.0.md",
    "runtime": "https://github.com/AzielEliab/aziel-runtime",
    "runtime_skill": "https://aziel-runtime.vibelock.workers.dev/v1/skill",
    "runtime_skill_local": "https://www.azieleliab.com/runtime/v1/skill",
    "designs": "https://github.com/AzielEliab/aziel-runtime/tree/main/docs/designs",
    "qnm_wp": "https://github.com/AzielEliab/aziel-runtime/blob/main/docs/designs/QNM-WP-1.0.md",
    "node_ops": "https://github.com/AzielEliab/aziel-runtime/blob/main/docs/designs/NODE-OPS-1.0.md",
    "node_mesh": "https://github.com/AzielEliab/aziel-runtime/blob/main/docs/NODE_MESH.md",
    "pair_custody": "https://github.com/AzielEliab/azinterface",
    "author": "Aziel Eliab",
    "identity": "Aziel Eliab",
    "note": "QNS-CD-1.0 photon QNS1 packet transfer. Local qnsd is coded in qnm-node. Runtime cites + catalog field live in aziel-runtime. AZInterface has pair custody. Hub cite / Worker mesh cross-map only. Read-only suite presence is on (display from runtime). Author Aziel Eliab only."
  },
  "qnm_spec": "QNM-BUILD-1.0",
  "qnm_companion": "AIH-WP-1.1",
  "mesh_enable_bearer": "suite-presence",
  "mesh_get_never_enables": true,
  "node_gate": true,
  "get_is_node_gate": true,
  "neighbor_heal": true,
  "network": true,
  "network_cite": "on",
  "worker_hardware": false,
  "invented_hardware": false,
  "login_mesh": false,
  "login_recovery": false,
  "ip_panel": false,
  "channel_plane": {
    "spec": "QNM-CHANNEL-PLANE-1.0",
    "author": "Aziel Eliab",
    "identity": "Aziel Eliab",
    "operator_armed": true,
    "plane": "channel",
    "wifi": "on",
    "bluetooth": "on",
    "rf": "on",
    "photon": "on",
    "channels": {
      "wifi": "on",
      "bluetooth": "on",
      "rf": "on",
      "photon": "on"
    },
    "bearer": "suite-presence",
    "worker_bearer": "suite-presence",
    "worker_hardware": false,
    "invented_hardware": false,
    "public_proxy": false,
    "local_process": "qnm-node / qnsd",
    "local": "https://github.com/AzielEliab/qnm-node",
    "vpn": true,
    "public_vpn": true,
    "tunnel_concentrator": true,
    "concentrator_slug": "azvpn",
    "default_vpn_backend": "azvpn",
    "auto_use": true,
    "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). worker_hardware:false. public_proxy false."
  },
  "vpn": {
    "vpn": true,
    "public_vpn": true,
    "auto_use": true,
    "auto_bind": true,
    "default_vpn_backend": "azvpn",
    "concentrator_slug": "azvpn",
    "concentrator_name": "AZVPN",
    "kinds": {
      "https_ws": "REAL",
      "fraggate_envelopes": "REAL",
      "websocket_attach": "REAL",
      "wireguard": "SLOT",
      "openvpn": "SLOT",
      "l3_exit_pool": "SLOT"
    },
    "tor": false,
    "origin_hiding": false,
    "get_never_opens": true,
    "note": "AZVPN auto_use + vpn:true. HTTPS/WS REAL; WireGuard/OpenVPN/L3 SLOT. GET /v1/mesh cites the bind and never opens a session."
  },
  "mesh_live_nodes_are_api": false,
  "live_nodes_are_not_live_doors": true,
  "live_nodes_plane": "human-mesh-users-uses",
  "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users (join/heartbeat/presence with human bearers) plus the cited human uses signal (USES / human_uses). Isolated humans stay on isolated_nodes. Not Softwares catalog length. Not downloaded Softwares instances. Not software_nodes. software_nodes is the {slug}-worker roster and never feeds this pill. Uses are interaction counters, not unique people — incomplete or unbound telemetry is reported honestly (0 + complete=false). Live Nodes does not invent users. Zero is honest when no humans are present and uses are 0/unbound.",
  "software_nodes_note": "software_nodes / rollup.software count Softwares product Workers ({slug}-worker) from suite-presence fan-out. They may appear in the mesh roster. They must never feed public Live Nodes.",
  "software_nodes_excluded": true,
  "instance_nodes_excluded": true,
  "live_nodes": 27503,
  "human_mesh_users": 0,
  "human_uses": 27503,
  "human_uses_complete": true,
  "human_uses_kv": true,
  "human_uses_source": "uses.total",
  "software_nodes": 41,
  "instance_nodes": 0,
  "live_nodes_components": {
    "human_mesh_users": 0,
    "human_uses": 27503,
    "software_nodes_excluded": true,
    "instance_nodes_excluded": true,
    "invent_users": false
  },
  "spore": {
    "spec": "SPORE-1.0",
    "author": "Aziel Eliab",
    "identity": "Aziel Eliab",
    "person_id": "https://www.azieleliab.com/#aziel",
    "kind": "law",
    "role": "failsafe",
    "last_resort": true,
    "failsafe": true,
    "replaces_cold_shelves": false,
    "replaces_ban_survival": false,
    "cold_shelves_intact": true,
    "mutual_backup_intact": true,
    "faces": [
      "pause",
      "preserve",
      "wait",
      "physical-wipe-only"
    ],
    "stack": [
      {
        "layer": 1,
        "id": "live-fronts",
        "spec": "BAN-SURVIVAL-1.0",
        "role": "failover",
        "includes": [
          "cap-7",
          "calling-name",
          "live-node-api"
        ]
      },
      {
        "layer": 2,
        "id": "cold-shelves",
        "spec": "COLD-MULTI-SHELF-1.0",
        "role": "mutual-backup",
        "mutual_backup_with": "BAN-SURVIVAL-1.0",
        "plane_b": "slot",
        "plane_c": "slot",
        "replaced": false,
        "failed": false
      },
      {
        "layer": 3,
        "id": "spore",
        "spec": "SPORE-1.0",
        "role": "failsafe",
        "last_resort": true,
        "replaces_cold_shelves": false,
        "replaces_ban_survival": false
      }
    ],
    "re_cold_store": {
      "hook": "RE-COLD-STORE",
      "allowed": true,
      "trigger": "cold-shelves-wiped-or-failed",
      "active": false,
      "shelves_failed": false,
      "shelves_intact": true,
      "invent_live": false,
      "invent_hash": false,
      "invent_receipt": false,
      "invent_destination": false,
      "public_inventory_required": false,
      "destinations": [],
      "opaque_placement": true,
      "note": "When cold stores are wiped or fail, the mesh may re-cold-store DNA wherever available. Never invent LIVE stores, hashes, receipts, or destinations. No required public inventory. Does not claim a wipe is happening now."
    },
    "software_tab": false,
    "fraggate_slug": false,
    "visible_1520": false,
    "honesty": {
      "hash_verify_pass_is_not_live": true,
      "do_not_paint_slot_as_live": true,
      "invented_live": false,
      "zenodo_live": false,
      "power_off_is_not_wipe": true,
      "shelves_not_replaced": true,
      "shelves_not_marked_failed": true
    },
    "note": "SPORE-1.0: last-resort failsafe. pause / preserve / wait / physical-wipe-only. Not a replacement for cold shelves. No electricity is PAUSE, not death. Dormant nodes do not invent live heartbeats. On restore, reconcile forward — no rewrite of history."
  },
  "re_cold_store": {
    "hook": "RE-COLD-STORE",
    "allowed": true,
    "trigger": "cold-shelves-wiped-or-failed",
    "active": false,
    "shelves_failed": false,
    "shelves_intact": true,
    "invent_live": false,
    "invent_hash": false,
    "invent_receipt": false,
    "invent_destination": false,
    "public_inventory_required": false,
    "destinations": [],
    "opaque_placement": true,
    "note": "When cold stores are wiped or fail, the mesh may re-cold-store DNA wherever available. Never invent LIVE stores, hashes, receipts, or destinations. No required public inventory. Does not claim a wipe is happening now."
  },
  "origin": {
    "ok": true,
    "code": "MESH-OK",
    "author": "Aziel Eliab",
    "identity": "Aziel Eliab",
    "kernel": "mesh",
    "mesh_default": "on",
    "presence_ttl_ms": 300000,
    "spec": "QNM-BUILD-1.0",
    "companion": "AIH-WP-1.1",
    "name": "Quantum Node Mesh",
    "qnm_s": false,
    "qnm_s_note": "Views, MCP, and downloads do not enter QNM-S.",
    "scores": false,
    "leaderboard": false,
    "phoenix_lock": "local wait / re-seal — no controller hunt; not public hostname resurrection",
    "split_wires": "SPLIT-WIRES-1.0",
    "tick_plane": "presence-tip-hash",
    "tick_ms": {
      "min": 500,
      "max": 1000
    },
    "dwell_s": 777,
    "clocks_share_socket": false,
    "split_wires_short": "pull-only payloads, hash-absolute ingest, equivocation = death of that peer, and two clocks that never share a socket. The 1s loop and the 777s gate stay strangers. Anything less is a delayed epidemic.",
    "cold_copy": "COLD-COPY-1.0",
    "cold_copy_short": "Multiply cold copies. Refuse live body sync. Tip expensive to erase. Unkillable by single-server pull. Hash-absolute refuse. Data outlives creators via content-addressed tips + local verify/append. Pull-only cold copies. Named hosts only.",
    "live_body_sync": false,
    "named_hosts_only": true,
    "re_expand": "RE-EXPAND-1.0",
    "re_expand_short": "Bytes survive, not summaries. Re-expand restores from archive after prev-hash verify. Not mesh from index. Crawlers are extra shelves only. Training residue is rumor.",
    "mesh_from_index": false,
    "summaries_survive": false,
    "reheal": "REHEAL-1.0",
    "reheal_short": "Isolation is the cure. Heal from own last good tip + verified trusted pull, or phoenix-WAIT. Never by listening to neighbors. Allowed: live/locked/isolated/tip-hash. Forbidden: bodies/diffs/vote-to-fix. Neighbor talk-back-to-health is a group hug over a wound.",
    "isolation_is_the_cure": true,
    "neighbor_heal": true,
    "neighbor_heal_is_cite": true,
    "neighbor_heal_exec": false,
    "join_is_presence_only": true,
    "join_is_not_login": true,
    "roster_publishes_exec_urls": false,
    "mesh_mutate_rate_kind": "mesh_mutate",
    "roster_cap": 256,
    "vote_to_fix": false,
    "cross_network_survival": "CROSS-NETWORK-SURVIVAL-1.0",
    "cross_network_survival_short": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault). Under that sentence: die-with-the-pull; split-the-wires; cold-copy survival; re-expand-from-archive; REHEAL.",
    "survival_shelves": [
      "hosts",
      "doi",
      "git",
      "vault"
    ],
    "live_network_is_shelf": false,
    "survival": {
      "spec": "CROSS-NETWORK-SURVIVAL-1.0",
      "tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
      "sentence": "If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault).",
      "shelves": [
        "hosts",
        "doi",
        "git",
        "vault"
      ],
      "software_tab": false,
      "fraggate_slug": false,
      "named_hosts_only": true,
      "live_network_is_shelf": false,
      "note": "Cite, don’t merge. One tip. Independent shelves. The live mesh is not a shelf."
    },
    "survival_tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
    "ban_survival": "BAN-SURVIVAL-1.0",
    "local_node": "qnm-node/",
    "local_node_note": "Full node process is local qnm-node/ (boot/chain/apg/bearers/outbox/phoenix/score/memorial/tethers). Packet-transfer coding design is QNS-CD-1.0 (photon QNS1 1.3 on local qnsd; Worker cites only). Channel plane (wifi / bluetooth / rf / photon) is operator-armed cite — live OS/hardware bearers run on that local process, not Worker-proxied VPN. Parent will roll that package. This runtime is suite rollup + operator enable only.",
    "host_note": "azieleliab.com hosts published software/runtime — not login-recovery, not IP panel, not upload proxy. Node Gate / get_is_node_gate is an operator-armed public mesh cite (2026-09-17), not a login-recovery panel.",
    "qns_cd": {
      "spec": "QNS-CD-1.0",
      "local": "https://github.com/AzielEliab/qnm-node",
      "note": "Photon vias on local qnsd; Worker cites only",
      "photon": "QNS1 1.3",
      "magic": "QNS1",
      "process": "qnsd",
      "bind": "127.0.0.1",
      "companion": [
        "QNM-BUILD-1.0",
        "AIH-WP-1.3"
      ],
      "hub_companion": "AIH-WP-1.1",
      "software_tab": false,
      "fraggate_slug": false,
      "public_proxy": false,
      "emit": false,
      "wipe": false,
      "control_plane": false,
      "loopback_only": true,
      "paper": "docs/designs/QNS-CD-1.0.md",
      "path": "/v1/qns"
    },
    "no_lie": true,
    "no_rewrite": true,
    "rewrite_key": false,
    "lie_to_survive": false,
    "copies_one_tunnel": false,
    "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
    "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
    "nine_laws": {
      "hard_true": true,
      "count": 9,
      "author": "Aziel Eliab",
      "identity": "Aziel Eliab",
      "author_id": "https://www.azieleliab.com/#aziel",
      "runtime_id": "https://www.azieleliab.com/runtime#runtime",
      "hashtag_parts": {
        "person": "#aziel",
        "runtime": "#runtime"
      },
      "about": {
        "path": "/about",
        "v1": "/v1/about",
        "identity": "Aziel Eliab",
        "always": true
      },
      "clocks_share_socket": false,
      "live_body_sync": false,
      "isolation_is_the_cure": true,
      "neighbor_heal": true,
      "phoenix_local_only": true,
      "die_with_pull": true,
      "restore_godlock_uk": false,
      "node_gate": true,
      "get_is_node_gate": true,
      "implicit_heal": true,
      "auto_heal": true,
      "network": true,
      "network_cite": "on",
      "anonymity_network": true,
      "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
      "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
      "date": "2026-09-17",
      "operator_armed": true,
      "vpn": true,
      "public_vpn": true,
      "tunnel_concentrator": true,
      "concentrator_slug": "azvpn",
      "concentrator_name": "AZVPN",
      "default_vpn_backend": "azvpn",
      "auto_use": true,
      "auto_bind": true,
      "vpn_auto": {
        "default_vpn_backend": "azvpn",
        "auto_use": true,
        "auto_bind": true,
        "concentrator_slug": "azvpn",
        "concentrator_name": "AZVPN",
        "door": "fraggate",
        "explicit_ops": [
          "describe",
          "open",
          "status",
          "list",
          "close",
          "send",
          "recv",
          "pull",
          "peers",
          "attach"
        ],
        "hooks": {
          "mesh_get": "cite-only",
          "mesh_vpn": "ensure",
          "aznet_pair": "cite-and-ensure-when-paired-or-armed",
          "session_open": "ensure-when-armed",
          "azbrowser_vpn": "ensure"
        },
        "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
        "get_never_opens": true,
        "open": false
      },
      "door": "fraggate",
      "worker_terminates_tunnels": true,
      "worker_terminates_kernel_udp": false,
      "wireguard": false,
      "openvpn": false,
      "l3_exit_pool": false,
      "tor": false,
      "socks": false,
      "origin_hiding": false,
      "kinds": {
        "https_ws": "REAL",
        "fraggate_envelopes": "REAL",
        "websocket_attach": "REAL",
        "wireguard": "SLOT",
        "openvpn": "SLOT",
        "l3_exit_pool": "SLOT",
        "kernel_udp": "SLOT",
        "tun_tap": "SLOT"
      },
      "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
      "note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
      "operator_override": {
        "spec": "OPERATOR-OVERRIDE-2026-09-17",
        "date": "2026-09-17",
        "identity": "Aziel Eliab",
        "author": "Aziel Eliab",
        "operator_armed": true,
        "auto_heal": true,
        "implicit_heal": true,
        "node_gate": true,
        "get_is_node_gate": true,
        "neighbor_heal": true,
        "neighbor_heal_is_cite": true,
        "neighbor_heal_exec": false,
        "network": true,
        "network_cite": "on",
        "anonymity_network": true,
        "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
        "vpn": true,
        "public_vpn": true,
        "tunnel_concentrator": true,
        "concentrator_slug": "azvpn",
        "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
        "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
      },
      "papers": {
        "node_mesh": "docs/NODE_MESH.md",
        "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
        "node_ops": "docs/designs/NODE-OPS-1.0.md",
        "qnm_wp": "docs/designs/QNM-WP-1.0.md"
      }
    },
    "author_id": "https://www.azieleliab.com/#aziel",
    "runtime_id": "https://www.azieleliab.com/runtime#runtime",
    "hashtag_parts": {
      "person": "#aziel",
      "runtime": "#runtime"
    },
    "about": {
      "path": "/about",
      "v1": "/v1/about",
      "identity": "Aziel Eliab",
      "author_id": "https://www.azieleliab.com/#aziel",
      "always": true
    },
    "payload_plane": "receiver-pull",
    "tick_ms_min": 500,
    "tick_ms_max": 1000,
    "tick_body": false,
    "tick_diff": false,
    "tick_file": false,
    "tip_content_addressed": true,
    "bodies": false,
    "diffs": false,
    "phoenix_local_only": true,
    "neighbor_phoenix": false,
    "public_hostname_resurrection": false,
    "die_with_pull": true,
    "restore_godlock_uk": false,
    "climb_public_hostname": false,
    "apply_last_packet_on_heartbeat_loss": false,
    "node_gate": true,
    "login_mesh": false,
    "login_recovery": false,
    "ip_panel": false,
    "get_is_node_gate": true,
    "implicit_heal": true,
    "auto_heal": true,
    "heartbeat_loss_isolates": false,
    "apply_last_packet": false,
    "network": true,
    "network_cite": "on",
    "anonymity_network": true,
    "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
    "vpn_spec": "OPERATOR-OVERRIDE-2026-09-17-VPN",
    "date": "2026-09-17",
    "operator_armed": true,
    "vpn": true,
    "public_vpn": true,
    "tunnel_concentrator": true,
    "concentrator_slug": "azvpn",
    "concentrator_name": "AZVPN",
    "default_vpn_backend": "azvpn",
    "auto_use": true,
    "auto_bind": true,
    "vpn_auto": {
      "default_vpn_backend": "azvpn",
      "auto_use": true,
      "auto_bind": true,
      "concentrator_slug": "azvpn",
      "concentrator_name": "AZVPN",
      "door": "fraggate",
      "explicit_ops": [
        "describe",
        "open",
        "status",
        "list",
        "close",
        "send",
        "recv",
        "pull",
        "peers",
        "attach"
      ],
      "hooks": {
        "mesh_get": "cite-only",
        "mesh_vpn": "ensure",
        "aznet_pair": "cite-and-ensure-when-paired-or-armed",
        "session_open": "ensure-when-armed",
        "azbrowser_vpn": "ensure"
      },
      "note": "AZVPN is the automatic public-VPN / tunnel-concentrator backend. Callers do not name software=azvpn. GET /v1/mesh cites this bind and never opens a session. If auto cannot start, refuse honestly — never fake connected.",
      "get_never_opens": true,
      "open": false
    },
    "door": "fraggate",
    "worker_terminates_tunnels": true,
    "worker_terminates_kernel_udp": false,
    "wireguard": false,
    "openvpn": false,
    "l3_exit_pool": false,
    "tor": false,
    "socks": false,
    "origin_hiding": false,
    "kinds": {
      "https_ws": "REAL",
      "fraggate_envelopes": "REAL",
      "websocket_attach": "REAL",
      "wireguard": "SLOT",
      "openvpn": "SLOT",
      "l3_exit_pool": "SLOT",
      "kernel_udp": "SLOT",
      "tun_tap": "SLOT"
    },
    "paper": "docs/designs/AZVPN-CONCENTRATOR-1.0.md",
    "note": "QNM suite rollup is LIVE. Read-only suite-presence is ON by default. live_nodes counts human mesh users plus cited human uses (USES). software_nodes is the {slug}-worker roster and never feeds Live Nodes. Counts only — no QNM-S, no leaderboard. Downloads are not live. Uses are counters, not invented users. SPORE-1.0: this isolate is powered unless a power-loss signal pauses metabolism.",
    "godlock_is_identity": false,
    "operator_override": {
      "spec": "OPERATOR-OVERRIDE-2026-09-17",
      "date": "2026-09-17",
      "identity": "Aziel Eliab",
      "author": "Aziel Eliab",
      "operator_armed": true,
      "auto_heal": true,
      "implicit_heal": true,
      "node_gate": true,
      "get_is_node_gate": true,
      "neighbor_heal": true,
      "neighbor_heal_is_cite": true,
      "neighbor_heal_exec": false,
      "network": true,
      "network_cite": "on",
      "anonymity_network": true,
      "anonymity_network_note": "Operator override 2026-09-17 armed anonymity_network as a mode flag and public VPN. Public VPN auto-binds AZVPN (application-layer HTTPS/WS concentrator; default_vpn_backend:azvpn; auto_use:true). GET /v1/mesh cites the bind and never opens a session. Not Tor. Not origin-hiding. WireGuard/OpenVPN/L3 stay SLOT. GodLock is a product name, not a kernel VPN.",
      "vpn": true,
      "public_vpn": true,
      "tunnel_concentrator": true,
      "concentrator_slug": "azvpn",
      "public_vpn_note": "Operator 2026-09-17 armed public VPN. REAL path is AZVPN (slug azvpn): application-layer HTTPS/FragGate encrypted envelopes (+ optional WS attach). AZVPN is the automatic backend (default_vpn_backend:azvpn, auto_use:true) — mesh / AZNet pair / session / AZBrowser paths that need a tunnel auto-select it. Explicit FragGate azvpn/* still exist. Worker terminates those app-layer sessions. WireGuard UDP, OpenVPN, and L3 exit-IP pools stay SLOT — this isolate is not a kernel VPN concentrator. Not Tor. Not origin-hiding. GodLock is a product name, not a kernel VPN. FragGate is THE single public door.",
      "note": "Hard-false cites flipped ON 2026-09-17: auto_heal (+ implicit_heal), node_gate (+ get_is_node_gate), neighbor_heal, network, anonymity_network (mode flag), public VPN (AZVPN auto-bind concentrator). Die-with-pull / no godlock.uk resurrection / Cap-7 / FragGate / confirm/dry_run unchanged. WireGuard/OpenVPN/L3 stay SLOT. GodLock is not a kernel VPN."
    },
    "papers": {
      "node_mesh": "docs/NODE_MESH.md",
      "sec_feat": "docs/designs/SEC-FEAT-1.0.md",
      "node_ops": "docs/designs/NODE-OPS-1.0.md",
      "qnm_wp": "docs/designs/QNM-WP-1.0.md"
    },
    "channel_plane": {
      "spec": "QNM-CHANNEL-PLANE-1.0",
      "author": "Aziel Eliab",
      "identity": "Aziel Eliab",
      "operator_armed": true,
      "plane": "channel",
      "wifi": "on",
      "bluetooth": "on",
      "rf": "on",
      "photon": "on",
      "channels": {
        "wifi": "on",
        "bluetooth": "on",
        "rf": "on",
        "photon": "on"
      },
      "bearer": "suite-presence",
      "worker_bearer": "suite-presence",
      "worker_hardware": false,
      "invented_hardware": false,
      "public_proxy": false,
      "local_process": "qnm-node / qnsd",
      "local": "https://github.com/AzielEliab/qnm-node",
      "local_radio_hooks": {
        "path": "qnm-node/bearers/radio.js",
        "law": "LIVE-when-HW-present / refuse-when-absent",
        "mock": false,
        "worker_hardware": false
      },
      "vpn": true,
      "public_vpn": true,
      "tunnel_concentrator": true,
      "concentrator_slug": "azvpn",
      "default_vpn_backend": "azvpn",
      "auto_use": true,
      "worker_terminates_tunnels": true,
      "worker_terminates_kernel_udp": false,
      "tor": false,
      "socks": false,
      "origin_hiding": false,
      "tunnel": false,
      "paper": "docs/designs/QNM-CHANNEL-PLANE-1.0.md",
      "node_mesh": "docs/NODE_MESH.md",
      "note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel."
    },
    "channels": {
      "wifi": "on",
      "bluetooth": "on",
      "rf": "on",
      "photon": "on"
    },
    "wifi": "on",
    "bluetooth": "on",
    "rf": "on",
    "photon": "on",
    "channel_plane_note": "Operator-armed communication channel cites (wifi / bluetooth / rf / photon) are ON as a channel plane. Live OS/hardware bearers run on local qnm-node / qnsd. Public VPN auto-binds AZVPN (HTTPS/WS REAL; WireGuard/OpenVPN SLOT; GET cites only). This plane is not a kernel UDP concentrator. public_proxy false. suite-presence remains the Worker rollup bearer. Pairing ≠ tunnel.",
    "worker_hardware": false,
    "invented_hardware": false,
    "channel_plane_spec": "QNM-CHANNEL-PLANE-1.0",
    "op": "status",
    "enabled": true,
    "radios": "on",
    "spore": {
      "spec": "SPORE-1.0",
      "author": "Aziel Eliab",
      "identity": "Aziel Eliab",
      "person_id": "https://www.azieleliab.com/#aziel",
      "kind": "law",
      "rule": "Last-resort failsafe after live fronts and cold-shelf mutual backup. Power or network loss pauses execution. No pretend-live metabolism. Append-only ChainLock / AKM / receipt DNA stays on cold shelves, local nodes, and tip packs. Resume on power. Wipe resistance is every remaining copy. Plane B/C stay SLOT until attested. Physical wipe only. Does not replace BAN-SURVIVAL or COLD-MULTI-SHELF.",
      "tip": "SPORE-1.0: last-resort failsafe. pause / preserve / wait / physical-wipe-only. Not a replacement for cold shelves. No electricity is PAUSE, not death. Dormant nodes do not invent live heartbeats. On restore, reconcile forward — no rewrite of history.",
      "mode": "live",
      "metabolism": "on",
      "pause": false,
      "preserve": true,
      "wait": false,
      "physical_wipe_only": true,
      "invented_heartbeats": false,
      "failsafe": true,
      "last_resort": true,
      "replaces_cold_shelves": false,
      "replaces_ban_survival": false,
      "cold_shelves_intact": true,
      "mutual_backup_intact": true,
      "faces": [
        "pause",
        "preserve",
        "wait",
        "physical-wipe-only"
      ],
      "stack": [
        {
          "layer": 1,
          "id": "live-fronts",
          "spec": "BAN-SURVIVAL-1.0",
          "role": "failover",
          "includes": [
            "cap-7",
            "calling-name",
            "live-node-api"
          ]
        },
        {
          "layer": 2,
          "id": "cold-shelves",
          "spec": "COLD-MULTI-SHELF-1.0",
          "role": "mutual-backup",
          "mutual_backup_with": "BAN-SURVIVAL-1.0",
          "plane_b": "slot",
          "plane_c": "slot",
          "replaced": false,
          "failed": false
        },
        {
          "layer": 3,
          "id": "spore",
          "spec": "SPORE-1.0",
          "role": "failsafe",
          "last_resort": true,
          "replaces_cold_shelves": false,
          "replaces_ban_survival": false
        }
      ],
      "re_cold_store": {
        "hook": "RE-COLD-STORE",
        "allowed": true,
        "trigger": "cold-shelves-wiped-or-failed",
        "active": false,
        "shelves_failed": false,
        "shelves_intact": true,
        "invent_live": false,
        "invent_hash": false,
        "invent_receipt": false,
        "invent_destination": false,
        "public_inventory_required": false,
        "destinations": [],
        "opaque_placement": true,
        "note": "When cold stores are wiped or fail, the mesh may re-cold-store DNA wherever available. Never invent LIVE stores, hashes, receipts, or destinations. No required public inventory. Does not claim a wipe is happening now."
      },
      "dna": {
        "chainlock": "append-only tips; no rewrite key",
        "akm": "belief_is_not_truth; memory_get append-only; memory_resolve additive on restore",
        "receipts": "hash still verifies",
        "cold_shelves": "COLD-MULTI-SHELF-1.0 planes A/B/C",
        "local_nodes": "qnm-node + tip packs; bytes↔hash",
        "cap7_aznet": "cite + verify LIVE; hosted exec SLOT"
      },
      "resume": "memory_resolve-additive",
      "rewrite": false,
      "plane_a": "live",
      "plane_b": "slot",
      "plane_c": "slot",
      "doi": null,
      "honesty": {
        "hash_verify_pass_is_not_live": true,
        "do_not_paint_slot_as_live": true,
        "invented_live": false,
        "zenodo_live": false,
        "power_off_is_not_wipe": true,
        "shelves_not_replaced": true,
        "shelves_not_marked_failed": true
      },
      "lamb_lens": {
        "after": "fraggate",
        "policy": "MASTER-33-LL-1.0",
        "v": "LL-1.0",
        "author": "Aziel Eliab",
        "peace": true,
        "clarity": true,
        "service": true,
        "software_tab": false,
        "door": false,
        "note": "Peace: pause metabolism. Clarity: honest dormant vs live. Service: preserve append-only DNA."
      },
      "umbrella": "CROSS-NETWORK-SURVIVAL-1.0",
      "survival_tip": "CROSS-NETWORK-SURVIVAL-1.0: someone still has bytes that match the published tip — not a living network, not LLM memory, not a public hostname that still answers.",
      "ban_survival": "BAN-SURVIVAL-1.0",
      "cold_multi_shelf": "COLD-MULTI-SHELF-1.0",
      "no_lie_spec": "NO-LIE-NO-REWRITE-1.0",
      "no_lie_docs": "docs/designs/NO-LIE-NO-REWRITE-1.0.md",
      "signal": null,
      "software_tab": false,
      "fraggate_slug": false,
      "paper": "docs/designs/SPORE-1.0.md",
      "remain_off_untouched": true,
      "visible_1520": false
    },
    "bearers": [
      "suite-presence"
    ],
    "rollup": {
      "live": 41,
      "locked": 0,
      "isolated": 0,
      "mesh": 27503,
      "active": 41,
      "inactive": 0,
      "software": {
        "live": 41,
        "locked": 0,
        "isolated": 0
      },
      "instances": {
        "live": 0,
        "locked": 0,
        "isolated": 0
      },
      "human": {
        "live": 0,
        "locked": 0,
        "isolated": 0
      },
      "ephemeral": {
        "live": 0,
        "locked": 0,
        "isolated": 0
      },
      "named": {
        "live": 0,
        "locked": 0,
        "isolated": 0
      },
      "all": {
        "live": 41,
        "locked": 0,
        "isolated": 0
      }
    },
    "live_nodes": 27503,
    "live_nodes_plane": "human-mesh-users-uses",
    "human_mesh_users": 0,
    "human_nodes": 0,
    "human_live_nodes": 0,
    "human_locked_nodes": 0,
    "human_isolated_nodes": 0,
    "human_uses": 27503,
    "human_uses_kv": true,
    "human_uses_complete": true,
    "human_uses_source": "uses.total",
    "human_uses_note": "human_uses is the USES interaction counter (no PII), not a unique-user count. Incomplete or unbound telemetry is reported as 0 with complete=false. Live Nodes does not invent users from missing uses.",
    "live_nodes_components": {
      "human_mesh_users": 0,
      "human_uses": 27503,
      "software_nodes_excluded": true,
      "instance_nodes_excluded": true,
      "invent_users": false
    },
    "active_nodes": 41,
    "inactive_nodes": 0,
    "locked_nodes": 0,
    "isolated_nodes": 0,
    "live_nodes_note": "Public Live Nodes (live_nodes / rollup.mesh) count human mesh users (join/heartbeat/presence with human bearers) plus the cited human uses signal (USES / human_uses). Isolated humans stay on isolated_nodes. Not Softwares catalog length. Not downloaded Softwares instances. Not software_nodes. software_nodes is the {slug}-worker roster and never feeds this pill. Uses are interaction counters, not unique people — incomplete or unbound telemetry is reported honestly (0 + complete=false). Live Nodes does not invent users. Zero is honest when no humans are present and uses are 0/unbound.",
    "software_nodes_note": "software_nodes / rollup.software count Softwares product Workers ({slug}-worker) from suite-presence fan-out. They may appear in the mesh roster. They must never feed public Live Nodes.",
    "human_nodes_note": "human_nodes / rollup.human count humans who exist as mesh users (join/heartbeat/presence — human bearers or kind=human). Auto-minted mesh_* joins are human participants. Named downloaded Softwares instance ids stay instance_nodes.",
    "ephemeral_nodes": 0,
    "ephemeral_live_nodes": 0,
    "software_nodes": 41,
    "software_live_nodes": 41,
    "software_locked_nodes": 0,
    "software_isolated_nodes": 0,
    "instance_nodes": 0,
    "instance_live_nodes": 0,
    "instance_locked_nodes": 0,
    "instance_isolated_nodes": 0,
    "products_present": [
      "4dmap",
      "ark",
      "azai",
      "azbot",
      "azbrowser",
      "azchat",
      "azclce",
      "azcoherence",
      "azhub",
      "aziel-corpus",
      "azieltether",
      "azinterface",
      "azmail",
      "aznet",
      "azos",
      "azvpn",
      "chronolock",
      "codelock",
      "decisiongate",
      "embryolock",
      "employeelock",
      "foldlock",
      "forgereceipts",
      "glossafilter",
      "godlock",
      "mialock",
      "miragegrid",
      "mmconsensus",
      "peacelock",
      "postking",
      "shadowlock",
      "spectrallock",
      "staticclock",
      "temporallock",
      "toolbench",
      "trajectorylock",
      "veillock",
      "vibelock",
      "whistlelock",
      "zkattest",
      "zsolver"
    ],
    "products": [
      "4dmap",
      "ark",
      "azai",
      "azbot",
      "azbrowser",
      "azchat",
      "azclce",
      "azcoherence",
      "azhub",
      "aziel-corpus",
      "azieltether",
      "azinterface",
      "azmail",
      "aznet",
      "azos",
      "azvpn",
      "chronolock",
      "codelock",
      "decisiongate",
      "embryolock",
      "employeelock",
      "foldlock",
      "forgereceipts",
      "glossafilter",
      "godlock",
      "mialock",
      "miragegrid",
      "mmconsensus",
      "peacelock",
      "postking",
      "shadowlock",
      "spectrallock",
      "staticclock",
      "temporallock",
      "toolbench",
      "trajectorylock",
      "veillock",
      "vibelock",
      "whistlelock",
      "zkattest",
      "zsolver"
    ],
    "store": "USES",
    "store_note": "USES KV under mesh| keys (no placeholder namespace ids).",
    "anon_broadcast": "Anon-broadcast is a sibling loopback module of local qnm-node/ only (text→TTS→desk MP4→metadata-culled file + SHA-256). Style tool. Never a publish path. Not an upload proxy. Not origin-hiding. Operator keeps the file. Not a Softwares-tab product. Not a QNM publish channel.",
    "azmail_note": "AZMail mesh_* stays product-local (anonymous mail ring). This surface is QNM rollup + read-only suite-presence, not that ring and not an account mesh.",
    "suite_presence": "on",
    "get_never_enables": true,
    "fanout": "cron-or-request-path",
    "calling_name_alert": null,
    "calling_name": {
      "rotated": false,
      "calling_name": "Aziel Runtime",
      "identity": "Aziel Eliab",
      "pull": "/survival",
      "publish": false,
      "mesh_broadcast": false
    },
    "durability": {
      "production_binds": {
        "wrangler": "wrangler.toml [[durable_objects.bindings]]",
        "SESSION": {
          "bound": true,
          "class_name": "RuntimeSession",
          "migration": "v1",
          "durable_commit": true
        },
        "CHAINLOCK": {
          "bound": true,
          "class_name": "ChainWriter",
          "migration": "v2",
          "durable_commit": true
        },
        "RATE": {
          "bound": true,
          "class_name": "RateQuota",
          "migration": "v3",
          "durable_commit": true
        },
        "note": "Production wrangler.toml binds SESSION / CHAINLOCK / RATE. Isolate tests and unbound deploys label MemoryStore / isolate window — not durable-commit."
      },
      "fraggate_ledger": {
        "kind": "ask-refuse-hash-chain",
        "window_cap": 64,
        "ephemeral_window": true,
        "durable_commit": true,
        "durable_commit_label": "CHAINLOCK Durable Object (commit-before-ack, public window last 64)",
        "memory_store_is_durable": false,
        "public_qxact_ledger": false
      },
      "chainlock": {
        "kind": "append-only-stamps",
        "durable_commit": true,
        "durable_commit_label": "CHAINLOCK Durable Object per chain (commit-before-ack)",
        "memory_store_is_durable": false,
        "public_ledger": false
      },
      "session": {
        "kind": "runtime-session",
        "durable_commit": true,
        "durable_commit_label": "SESSION Durable Object (TTL 6h, receipt cap 64)",
        "receipt_cap": 64,
        "ttl_ms": 21600000,
        "memory_store_is_durable": false
      },
      "rate_quota": {
        "kind": "abuse-quota",
        "durable_commit": true,
        "durable_commit_label": "RATE Durable Object (per IP+bucket sliding window)",
        "memory_store_is_durable": false
      },
      "memory_store": {
        "durable": false,
        "durable_commit": false,
        "note": "MemoryStore is in-process isolate memory. Not a durable commit. Do not treat as CHAINLOCK, SESSION, or a public ledger."
      },
      "akm_memory": {
        "durable": false,
        "durable_commit": false,
        "isolate_index": true,
        "ledger": "chainlock-learn",
        "ledger_durable": true,
        "rebuildable": true,
        "rebuild_on_get_miss": true,
        "belief_is_not_truth": true,
        "memory_delete": false,
        "memory_update_overwrite": false,
        "http_dry_run_writes": false,
        "note": "AKM-TRIAD Belief List is derived from the append-only ChainLock learn ledger. Isolate MemoryStore is a cache, never the durable source. GET/resolve/recall rebuild from learn on a cold isolate. Posterior ≠ truth. HTTP dry_run does not write."
      }
    }
  }
}
