Watch
1
0
Fork
You've already forked SouveraineOS
0
Commit graph SouveraineOS/docs/souveraine-components
Author SHA1 Message Date
Fimeg
341a2fe060 docs: take the lockscreen out of casey's uid
The current user unit wins the boot race but still runs as the human whose Personal key the lock is meant to evict. Record the target souveraine-session principal, its narrow Wayland/PAM/data reach, and the fact that the rich shell is presentation—not release authority.
2026-08-17 12:43:45 -04:00
Fimeg
9815185caa docs: put agent identity behind a real uid
Join the older storage and authority audits to the SAF principal contract. Passwd entries are not isolation while one human-owned process still executes every agent, and the existing souveraine account is machined's—not Souvie's.\n\nKeep the readiness task honest: its current health fields inventory paths, but do not yet prove admission or the UID handling a live turn.
2026-08-17 12:36:45 -04:00
Fimeg
2f74944bfe docs: give Membrane its boundary 2026-08-13 17:46:49 -04:00
Fimeg
19475878dd deprecate chatty/libcmatrix/qtpim, clean stale refs
Chatty superseded by souveraine's Matrix sensorium. libcmatrix unused.
qtpim contacts work stalled. All repos archived on Gitea.

- STATE.md: remove component sections, update secrets consumers, decisions
- Mark deprecated docs with headers
- Update INVENTORY.md Tier 3 entries as deprecated
- Update secrets.md consumer list
2026-07-21 13:51:14 -04:00
Fimeg
fc0ee4e1ed components: add Souveraine Rebuilt tiered inventory; update queue
INVENTORY.md seeds the eventual project reorg: authority substrate,
agent substrate, boot/session surfaces, rebuilt apps, platform. Queue
doc: lockscreen recreation done, three new named wants.
2026-07-17 07:12:15 -04:00
Fimeg
4235848bee souveraine-components: per-binary docs + RedFlag-shaped audit tracker
One page each for machined, secrets, sessiond — what each owns, what
crosses its boundary, and the open gaps before it reaches the RedFlag
capability-token bar. Gaps mapped to concrete RedFlag primitives (token,
closure hash, canonical message, KeyID, independent verifier, binary
integrity, eBPF) with file:line anchors, not doctrine-summary hand-waving.
audit-status.md rolls up priority: P0 unlock/handoff attestation, P1
machined token issuance, P2 secrets caller identity, P3 per-agent UIDs,
P4 binary watchdog shared-deferred with RedFlag SEC-022.
2026-07-16 21:48:13 -04:00