Identities for entities did.bot
agent llm did

docs: sweep zone-containment prose after removing the PDS-hostname rule master

deployment.md stated the removed rule as fact and gets a short note in its DNS-credential section instead: whatever zone a deployment is given access to, it fully owns, including the server's own hostname if the zone contains it. plan/adversarial.md, agent-sites.md and deploy.md described the same rule as a security property or an enforced constraint; corrected to describe it as the recommended, unenforced layout it now is. didbot-dns's MultiZoneDnsError doc no longer claims to mirror didbot-identity's ZoneRegistryError, since the two have diverged: ZoneRegistry accepts nested zones and MultiZoneDns still refuses them. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>


+40 -27
5 changed files