# Mosaic wake component — VERSION metadata manifest (Gate B). # # EPIC #892, W2 + W3 of the wake/heartbeat canon. # # SCOPE — THIS FILE IS VERSION METADATA ONLY. It declares the wake component's # semantic version and the RANGE of watch-list schema versions it supports. It # does NOT authorize file/path ownership: path-ownership remains the sole domain # of packages/mosaic/framework/framework-manifest.txt (Gate A). Do not read any # ownership meaning into this file. # # Format: KEY=VALUE, one per line. '#' and blank lines ignored. # Component identity + semantic version. # 0.1.0 W2 — store+drain lib + ack-wrapper. # 0.2.0 W3 — cumulative-state digest renderer + non-circular HMAC signer. # 0.3.0 W4 — per-host single-instance delta-gated detector daemon. # 0.4.0 W5 — synthetic-canary FN-oracle + source-parity reconciler. # 0.5.0 W6 — off-host dead-man beacon emitter + pluggable alarm-sink adapter # + beacon-absence alarm (fail-loud on unconfigured/unreachable). component=wake version=0.5.0 # Watch-list schema this component consumes, and the INCLUSIVE range of # schema_version values it supports. A wake-watch-list.json whose schema_version # falls outside [schema_min, schema_max] is rejected by the component (fail-loud), # never silently coerced. schema=wake-watch-list schema_min=1 schema_max=1 # Pieces shipped by this component version (informational): # store.sh A2 — three-cursor durable store + drain lib. (W2) # ack.sh A4 — RECEIVED/CONSUMED ack-wrapper (local-write + ship). (W2) # digest.sh A3 — cumulative-state digest renderer (hard locators, # two-tier trust, injection/secret scrub). (W3) # sign.sh A5 — non-circular HMAC signer (independent wake_id, # load_credentials by-name; fills the hmac placeholder). (W3) # detector.sh A1 — per-host single-instance delta-gated detector daemon # (flock, anchor-scoped hashing, detector-local observed_seq, # fail-loud source semantics; enqueues deltas to store.sh). (W4) # fn-oracle.sh A6 — synthetic-canary FN-oracle: injects a KNOWN delta at the # source boundary, drives the pipeline through the detector's # public poll-once, asserts CONSUMED within the per-class SLO # (off-domain verdict from the terminal store cursor). §4 # requires FN-rate=0; a dropping/disabled detector FAILS. (W5) # reconcile.sh A7 — source-parity reconciler: (i) source-coverage parity # inventory (an omitted source cannot pass the vector # vacuously) + (ii) periodic full reconcile to 0-unaccounted, # enumerating pre-existing/startup state into the store. (W5) # beacon.sh A8 — off-host DEAD-MAN liveness beacon: a monotonic beacon # EMITTER (emit — the primitive the detector run-loop calls # each cycle), the off-host monitor's RECEIVER + beacon-ABSENCE # alarm (record, check), and a pluggable alarm-sink/beacon-sink # ADAPTER INTERFACE. Liveness is SPLIT from work-triggering; # the alarm fires on ABSENCE, routing to a human/other-host # within its SLO (§4/G1). FAIL-CLOSED: an unconfigured OR # unreachable target FAILS LOUD (no silent no-alarm host). # A same-host sibling is REJECTED as non-independent; an # isolated host degrades to a FLAGGED different-supervision-root # beacon; capture-pane is a liveness HINT only. (W6) # Out of scope (later waves): installer (W7 wires + install-validates the beacon # target that beacon.sh's fail-loud primitive is designed for).