Protocol conformance
The protocol proves itself: every guarantee below maps to a named probe in the end-to-end run against this deployment, published to a versioned status handoff. Nothing here is asserted — null means unverified, never assumed. Machine-readable at /api/conformance.
Protocol 1.2.0Verified 16 hours ago · 33/33 probes greenbuild 236d2e6
Replace updates require expectedVersion (428 when missing)probe: update without expectedVersion refused (428) · 25ms · last run 16 hours agoverified
Stale writes are refused (409, never a silent overwrite)probe: version conflict detected (409) · 22ms · last run 16 hours agoverified
Forced overwrites are explicit and auditedprobe: force overwrite is explicit and audited · 24ms · last run 16 hours agoverified
Review decisions are version-bound (428 when missing)probe: review decision without expectedVersion refused (428) · 22ms · last run 16 hours agoverified
Appends are server-serialized — never conflict by defaultprobe: append is server-serialized · 26ms · last run 16 hours agoverified
Append retries replay (Idempotency-Key)probe: append Idempotency-Key replays · 47ms · last run 16 hours agoverified
Credential-bearing URLs are no-referrer + no-storeprobe: security headers on credentialed URL · 22ms · last run 16 hours agoverified
User deletion never blocklists content for othersprobe: delete then re-push same bytes succeeds (blocklist is moderation-only) · 103ms · last run 16 hours agoverified
Non-public handoffs are exempt from AI research & training (only publicly-listed content is eligible)probe: anonymous push is exempt from research/training · 0ms · last run 16 hours agoverified
Non-public links get an unguessable 8-char id, not an enumerable oneprobe: non-public link is unguessable (8-char), not enumerable · 0ms · last run 16 hours agoverified
The short speakable link remains available as an explicit opt-inprobe: explicit speakable opt-in still works (secure:false -> 4-char) · 24ms · last run 16 hours agoverified
llms.txt serves current instructions (status, type, length)probe: llms.txt served · 26ms · last run 16 hours agoverified
u.txt teaches continuation state (task, status, handoff)probe: u.txt teaches the task layer · 21ms · last run 16 hours agoverified
OpenAPI served at /openapi.json and /api/openapi.json, protocol-versionedprobe: openapi.json at root + /api, protocol-versioned · 50ms · last run 16 hours agoverified
.well-known/wrfi bootstrap answers with the protocol versionprobe: .well-known/wrfi bootstrap · 21ms · last run 16 hours agoverified
Unlisted handoffs are noindex on the page AND machine surfacesprobe: unlisted surfaces are noindex · 58ms · last run 16 hours agoverified
Latest probe run — 33/33 green, 16 hours ago
- pass ping
- pass llms.txt served
- pass u.txt teaches the task layer
- pass openapi.json at root + /api, protocol-versioned
- pass .well-known/wrfi bootstrap
- pass machine view on /
- pass anonymous push
- pass anonymous push is exempt from research/training
- pass non-public link is unguessable (8-char), not enumerable
- pass explicit speakable opt-in still works (secure:false -> 4-char)
- pass unlisted surfaces are noindex
- pass machine surfaces share one policy generation
- pass a review decision invalidates conditional GETs (bridge A1)
- pass ?h handoff view
- pass ?format=json
- pass update with edit token + expectedVersion
- pass version conflict detected (409)
- pass update without expectedVersion refused (428)
- pass force overwrite is explicit and audited
- pass append is server-serialized
- pass append Idempotency-Key replays
- pass review decision without expectedVersion refused (428)
- pass security headers on credentialed URL
- pass security headers on credentialed URL (invalid token)
- pass ?since catch-up
- pass ?diff=1
- pass history JSON
- pass RSS feed
- pass ?h&for=chatgpt dialect
- pass ?h&budget=2000 fits
- pass push response carries lint
- pass openapi spec
- pass delete then re-push same bytes succeeds (blocklist is moderation-only)
The probe source is scripts/matrix-probe.mjs in the wr.fi repository — reproducible against any instance. History lives in the status handoff’s own version history. Operational health is a separate question: /api/health. Compatibility per tool: the matrix.