Current state

Ownership boundary

Wiki publication is serialized by the publisher’s own global lock plus the Flowmaster heavy lock. The shared Quartz engine is owned through build.sh; a foreign --serve preview process holds only a process-local mutex and is not a publisher. Tiny never stops, signals, or reconfigures that preview, and never bypasses the publisher. If the publisher ever refuses (lock held or preflight failure), that refusal is the blocker.

What is shipped versus pending

  • The tool registry tools.json drives both the generated wiki index and the application dock.
  • This wiki is published by the locked publisher (build.sh tiny, heavy lock) with rendered titles verified and no leaked frontmatter.
  • The application is built: static shell with a daisyUI 5 bottom dock (pinned Tailwind 4.3.3 / daisyUI 5.7.46, committed lockfile), Terracraft mounted at /t/terracraft/ with vendored Preact 10.19.2 / HTM 3.1.1. The c2 headless-Chrome run passed 6/6 cases at 390 and 1280 widths: dock navigation, 16 textures, place, right-click rotation, R rotation, 512 × 512 PNG export, reload persistence, no iframe, zero console errors, zero third-party requests. This is local loopback proof, never public proof.
  • Nginx vhosts and certificates are Gatekeeper-only. Prepared configs and a handoff README wait in /home/loca/dev/tiny/deploy/; both public hosts still fail TLS hostname validation and are recorded as ingress: prepared, awaiting Gatekeeper.
  • README claims are not runtime evidence. The old address http://0rk.de:55333/ is stale; the source export button exists, X is not implemented in the inspected handler.

Public deployment contract

  • Application host tiny.loca.zone: nginx static root /home/loca/dev/tiny/dist, no Node service.
  • Wiki host wiki.tiny.loca.zone: one public content tree, publisher-managed current artifact root.
  • Wiki config disables external font loading, analytics, comments, and private/unlisted plugins.
  • Exact-host TLS certificates (one per host) via certbot webroot /var/www/html, applied by Gatekeeper.
flowchart LR
  Registry[tools.json] --> Generator[wiki generator]
  Registry --> Dock[Shell dock build]
  Generator --> Index[Public wiki index]
  Index --> Publish[Locked publisher]
  Publish --> Wiki[Public wiki]
  Dock --> App[Static dist]
  App --> Proof[Local browser proof]
  Proof --> Ingress[Gatekeeper vhosts and certs]

Evidence boundary

Mission evidence lives in /home/loca/dev/tiny/evidence/ (original round and -c2 continuation). Browser interaction proof (place, rotate, PNG export, dock navigation, no CDN requests) is recorded per round; public HTTPS acceptance is recorded separately from local proof and must never be inferred from it.

Current URL / state

SurfaceURLCurrent state
Tiny applicationhttps://tiny.loca.zone/built and locally proven; ingress: prepared, awaiting Gatekeeper
Terracraft mounted toolhttps://tiny.loca.zone/t/terracraft/built and locally proven; ingress: prepared, awaiting Gatekeeper
Public wikihttps://wiki.tiny.loca.zone/published via locked publisher; ingress: prepared, awaiting Gatekeeper
Terracraft quickstarthttps://wiki.tiny.loca.zone/terracraftpublished via locked publisher; ingress: prepared, awaiting Gatekeeper
Adding tools workflowhttps://wiki.tiny.loca.zone/adding-toolspublished via locked publisher; ingress: prepared, awaiting Gatekeeper
Current statehttps://wiki.tiny.loca.zone/statepublished via locked publisher; ingress: prepared, awaiting Gatekeeper