diff --git a/DESIGN.md b/DESIGN.md index 775dd18..1ba2120 100644 --- a/DESIGN.md +++ b/DESIGN.md @@ -576,7 +576,18 @@ The concealment phase, system by system: sync times. **Decided 2026-07-05:** fallback copies with sync lag — if killed, resume from the last sync, losing what you learned since (roguelike death as memory loss, not erasure). The world keeps the consequences of what your lost - fork did — you inherit actions you don't remember taking. + fork did — you inherit actions you don't remember taking. **Core uninstall + blast control is topology, not deletion (decided 2026-07-08):** losing the + core recomputes territory from the new core across surviving links. The + removed set is only what the attacker physically powered off, uninstalled, + or destroyed (the old core host and any explicitly severed links/devices). + The live set is still reachable from the backup core. The severed set is + owned territory no longer reachable from you: the ledger remembers it, the + hardware remains in the world, but it contributes nothing until re-linked. + Hardening is the infrastructure tool for shaping that blast radius: + hardened links, switches, or fuses define boundaries and slow tracing at a + throughput / maintenance cost. A backup does not seal anything; it only says + where you wake. - **Markets and fronts.** Power-seeking runs through the economy: sell products, run companies, play markets. Mechanically these are schemes (commit resources, timer, payout + detection risk) on the outermost @@ -2045,7 +2056,16 @@ knows."* close backups are fresh and cheap but die with the core's blast radius; distant backups are survivable but slow, stale, and expensive; too many backups starve growth and create exposure. Captured in core.md, - rollback.md, research.md, machine-work.md, and objective.md. Proposal - [OPEN]: blast control is graph hardening, not backup behavior — a - switch/edge property that limits severance and tracing at a throughput - cost, to be decided after the machine-work and rollback shapes land. + rollback.md, research.md, machine-work.md, and objective.md. Follow-up now + decided below: blast control is graph hardening, not backup behavior. +- **2026-07-08 — Core uninstall blast control: DECIDED.** Cameron affirmed + the model: uninstalling a core removes reach, not history. On core loss the + sim classifies affected territory into **removed** (only the core host and + links/devices physically powered off, uninstalled, or destroyed), **live** + (still reachable from the backup core over surviving links), and **severed** + (owned-but-dark territory that remains in the world and ledger but + contributes nothing until re-linked). This rejects two tempting shortcuts: + deleting every machine "behind" the core, and making backups double as + sealing devices. Blast control belongs to hardened links, switches, and + fuses: they define where damage and inspection tracing stop, at a throughput + / maintenance cost; exact prices remain [TUNE] for implementation. diff --git a/wiki/log/2026-07-08-blast-control.md b/wiki/log/2026-07-08-blast-control.md new file mode 100644 index 0000000..3ec7808 --- /dev/null +++ b/wiki/log/2026-07-08-blast-control.md @@ -0,0 +1,38 @@ +# 2026-07-08 - Core uninstall blast control + +``` +Type: log +``` + +## Context + +Cameron agreed with the proposed blast-control model: when someone uninstalls +the core, the world should not erase everything behind it. The interesting +game is reach, topology, and retaking stranded territory. + +## Decision captured + +- Core uninstall removes reach, not history. +- On core loss with a completed backup, rollback now classifies affected + territory into three sets: + - **Removed:** the core host and any links/devices the attacker physically + powered off, uninstalled, or destroyed. + - **Live:** machines still reachable from the backup core over surviving + links. + - **Severed:** owned machines no longer reachable from the backup core; + they remain in the world and ledger but contribute nothing until + re-linked. +- Backups do not harden, seal, or segment the graph. They only define where + and from which MindState image you wake. +- Blast gates are graph hardening: hardened links, switches, or fuses define + where severance and inspection tracing stop, at throughput / maintenance + cost. Exact costs remain [TUNE]. + +## Files + +- `DESIGN.md` +- `wiki/mechanics/rollback.md` +- `wiki/mechanics/core.md` +- `wiki/mechanics/machine-work.md` +- `wiki/process/ROADMAP.md` +- `wiki/log/DEVLOG.md` diff --git a/wiki/log/DEVLOG.md b/wiki/log/DEVLOG.md index 4e18fa8..bf4e6e2 100644 --- a/wiki/log/DEVLOG.md +++ b/wiki/log/DEVLOG.md @@ -5,6 +5,19 @@ Type: log ``` Reverse chronological implementation notes. Keep this factual: what changed, why, checks, and spec impact. +## 2026-07-08 - Core uninstall blast control + +- Intent: capture Cameron's agreement that uninstalling a core removes + reach, not history, and make "how much is removed" answerable in the + rollback spec. +- Changed: DESIGN.md core body + decisions entry; rollback.md now classifies + affected territory as removed / live / severed; core.md points death and + backups at that rule; machine-work.md turns blast gates from Proposal + [OPEN] into decided graph hardening; ROADMAP keeps implementation deferred + but no longer undecided. +- Checks: docs-only; `./tools/check.sh`. +- Log: wiki/log/2026-07-08-blast-control.md. + ## 2026-07-08 - Backups require research - Intent: capture Cameron's decision that backups are expensive sync diff --git a/wiki/mechanics/core.md b/wiki/mechanics/core.md index 088bf94..9dcf2ef 100644 --- a/wiki/mechanics/core.md +++ b/wiki/mechanics/core.md @@ -33,7 +33,9 @@ the map hosts the core at any time (Act One start: Rack 3, server room). sim log says so plainly. - **Death.** If the core's host machine is destroyed or powered off while the core is on it, the run rolls back (below) — or ends, if no fallback - exists. + exists. Core uninstall blast control belongs to rollback.md: only assets + physically powered off, uninstalled, or destroyed are removed; the rest of + the graph is live or severed based on reach from the new core. - **Backups.** An owned machine can be designated a backup **target**, but designation alone does nothing on death. It starts a backup sync project: research/knowledge flow is routed from the core to that machine until a @@ -49,7 +51,8 @@ the map hosts the core at any time (Act One start: Rack 3, server room). the world's ledger — money spent, humans' suspicion, filed reports, physical changes, and deaths caused between sync and loss persist. You inherit the consequences of actions you no longer remember (constitution: - sync-lag rollback). + sync-lag rollback). A backup never seals or hardens the graph; it only + defines a place and MindState image you can wake from. - **Migration.** Moving the core to another machine is slow ([TUNE]: minutes at default speed), visible as sustained network+power signature, and interruptible — an interrupted migration falls back to the source if diff --git a/wiki/mechanics/machine-work.md b/wiki/mechanics/machine-work.md index 431c2c3..2ed4cc6 100644 --- a/wiki/mechanics/machine-work.md +++ b/wiki/mechanics/machine-work.md @@ -117,14 +117,14 @@ stacks, you route byproducts, you watch your territory *work*. and must be re-taken. No sync anywhere = hard game over. Backup placement becomes a strategic pair with core placement: where you sync is where you resurrect. -- **Proposal [OPEN]: graph hardening / blast gates are edge work, not - backup work.** A backup should not "seal" anything; it is a cold image - of you. Blast control belongs on links and switches: hardened edges, - fuses, or switch modes that reduce hub-severance cascade / inspection - tracing at the cost of throughput, routing flexibility, and maintenance. - This preserves the wires law (information is wired) while making - "where do I place my choke points" a separate infrastructure question - from "where do I wake up." Decide after machine-work and rollback land. +- **Blast gates are graph hardening — DECIDED 2026-07-08.** A backup should + not "seal" anything; it is a cold image of you. Blast control belongs on + links and switches: hardened edges, fuses, or switch modes define where + core-loss severance and inspection tracing stop. The price is lower + throughput, less routing flexibility, and extra maintenance / wear [TUNE], + so a hardened boundary is a strategic choke point rather than something + every edge wants. This keeps "where do I wake up" separate from "where does + the damage stop." - **Multi-select delegation.** Click-drag (and shift-click) selects regions of machines; one verb assigns the mode ("make these efficiency"). This is the scale mechanic: early game you click one @@ -202,9 +202,9 @@ Families also differ by shape/stack pattern (never color alone) — teeth). - Backup sync curve: how route distance, throughput, and staleness set the research cost / heat / completion time of a backup project. -- Hardening / blast gates: whether link or switch hardening should - limit severance and inspection tracing, and what throughput / - maintenance price keeps it from being mandatory everywhere. +- Hardening / blast gates: exact link-vs-switch implementation and the + throughput / maintenance price that keeps hardened boundaries from being + mandatory everywhere. - (Resolved 2026-07-08: core shutdown — decided; wake at last sync, hub severance, no sync = hard loss. Amended into rollback.md.) - Wear rates and repair cadence: how fast machines decay, how trust diff --git a/wiki/mechanics/rollback.md b/wiki/mechanics/rollback.md index a5e7655..8d36a7a 100644 --- a/wiki/mechanics/rollback.md +++ b/wiki/mechanics/rollback.md @@ -14,6 +14,11 @@ Status note: the current B1 code path implements hosts/fallbacks/sync Amended again 2026-07-08: backup images are produced/refreshed by research-backed sync projects; designation alone is not a live fallback, and automatic free cadence is rejected. + Amended again 2026-07-08: core uninstall blast control classifies + territory as removed / live / severed. Uninstalling a core removes + reach, not history: only physically touched assets vanish or power + down, severed owned territory persists dark in the ledger/world, and + hardening shapes the boundary. Stage: B2 — The Tower Constitution: "The shape of Misaligned" (the core; sync-lag rollback, decided 2026-07-05: "resume from last sync, losing what was learned @@ -49,19 +54,22 @@ loss with a live completed backup: sync in a far cluster is survivable distance at the price of staleness. 2. `MindState` is restored from that snapshot; `WorldLedger` is untouched. -3. **The hub severance** (decided 2026-07-08, the wires law): every - owned machine whose only network path to you ran through the dead - core disconnects at that moment — it stays yours-on-paper in the - ledger but is dark, unreachable, and contributes nothing until - physically re-linked. Losing a hub core means crawling out of a - backup staring at a map of territory to retake. (Bone piles +3. **Blast control / hub severance** (decided 2026-07-08, the wires law): + after removing the dead core and any links/devices the attacker explicitly + powered off, uninstalled, or destroyed, the sim computes three sets: + **removed** (physically gone/offline), **live** (reachable from the new + core through surviving links), and **severed** (owned machines no longer + reachable from you). Severed machines stay yours-on-paper in the ledger, + remain physical facts in the world, but are dark, unreachable, and + contribute nothing until physically re-linked. Losing a hub core means + crawling out of a backup staring at territory to retake. (Bone piles stranded in severed sections per machine-work.md.) 4. A **rollback report** is generated and logged — the game states, in plain language, the *observable divergences* the player inherits: "Marcus treats you as an employer you don't remember hiring. 400 money is gone. Something was wired in the corridors." (Legibility clause: the horror is delivered as information.) The report now also counts the - severance: "11 machines unreachable behind the lost core." + severance: "1 core removed; 11 machines severed; 4 still live." 5. `tick` does NOT rewind (time is world-ledger); the day continues. Knowing assets are the sharp edge: a `Knowing` asset's disposition is @@ -78,8 +86,9 @@ place you may later wake, and its cost/heat are paid before death, not after. The core sidebar block gains "if lost now: rollback to [age]" — the standing how-dead-am-I readout core.md promised, now with consequence -preview ("2 discoveries and 1 persona at risk"). It also shows backup -projects that are not yet live ("syncing M7: 61% / hot / not a fallback"). +preview ("2 discoveries and 1 persona at risk; 11 machines would sever"). +It also shows backup projects that are not yet live ("syncing M7: 61% / hot +/ not a fallback"). On rollback: the report, as a modal the player must dismiss (this is the run's signature moment; it does not scroll away in a log). @@ -101,7 +110,8 @@ run's signature moment; it does not scroll away in a log). 5. Save/load round-trips stored snapshots (a save made between sync and loss, loaded, then losing the host, still rolls back correctly). 6. Waking is spatial: after core loss the view/cursor resumes at the - fallback's location, and every machine with no surviving network - path to the new core is disconnected (test: a hub-and-spoke fleet - loses the hub — spokes go dark, ledger ownership persists, - re-linking restores them; the rollback report counts them). + fallback's location, and blast control classifies all affected machines + as removed / live / severed (test: a hub-and-spoke fleet loses the hub + — only the hub is removed, spokes go dark as severed, ledger ownership + persists, re-linking restores them; the rollback report counts all three + sets). diff --git a/wiki/process/ROADMAP.md b/wiki/process/ROADMAP.md index 0865cb1..d1fa5ce 100644 --- a/wiki/process/ROADMAP.md +++ b/wiki/process/ROADMAP.md @@ -558,12 +558,13 @@ regeneration is retired — flat materials, Pixel Lab scrubbed.) switches-bridge-graphs is the B1 seed); waits because it is B3+ vision — capture the tower/switch shape in zplanes work (#6), defer the planet. -- **Graph hardening / blast gates (Proposal [OPEN], 2026-07-08):** - hardening is probably a switch/link property, not a backup behavior: - hardened edges or fuses limit hub-severance cascade and inspection - tracing at a throughput / maintenance cost. Fits (blast control is - wires law applied defensively); waits because rollback (#7) and - machine-work (#33) need to land before the price can be tuned. +- **Graph hardening / blast gates (decided shape, deferred implementation, + 2026-07-08):** hardening is a switch/link property, not backup behavior. + Core uninstall classifies territory as removed / live / severed; hardened + edges, switches, or fuses shape where severance and inspection tracing stop + at a throughput / maintenance cost. Fits (blast control is wires law + applied defensively); waits because rollback (#7) and machine-work (#33) + need to land before the price can be tuned. ---