* OpenErrand 0.1: an errand on a website with no API, with the human steps kept human
docs/openerrand.md mints OpenErrand: one JSON file per errand (register an
account, download a transcript) naming the site, the inputs with a
sensitivity class and ordered sources (document, vault, prompt, generate,
derive, candidate, literal), field rules matched by id then label, page and
wait steps, five human gates a runner never performs (declare,
identity-proofing, code, mail, captcha), outcomes, the never-retried shared
secret, vault and download outputs, hand-off cards that may name only public
inputs, the publisher index at /.well-known/openerrand.json, and thirteen
runner rules. The worked example is the MyFTB business registration that
cli-tools `ftb` performs (profullstack/cli-tools#125), with no personal data.
- @logicsrc/schemas: openerrand + openerrand-index schemas and fixtures
- @logicsrc/validators: semantic checks (references, templates, no personal
or secret input on a card) and tests that validate the spec's own examples
- logicsrc-web: registry entry (process family), /openerrand landing page,
the example and the index served as static files, contract tests
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
* OpenErrand: hand-off cards stay on the surface that owns the data
Anthony's ruling: tax and finance data never touches a social or promotion
tool, and nothing is sent to a CPA or preparer.
- Hand-off cards are delivered only on the surface that owns the errand's
data (for a tax or finance errand, the principal's finance app through its
CLI, PWA, MCP server or API, such as CoinPay, or the runner's terminal),
never a social, promotion or third-party posting service, and never to
anyone but the principal. A card for an errand with personal or secret
inputs does not leave that surface. Runner rule 9 says the same.
- The run record and the sample run name the card by an opaque id
(pin-letter/7f3k2q) instead of a mynaposter.com URL; the myna mention is gone.
- `principal: represented` no longer cites a preparer with a power of attorney.
- The FTB card's last step no longer suggests sending the PIN to someone else.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
* OpenErrand: user-agent rule, captcha solver policy, reference runner note
Anthony's answers on #227 ("go with your recommendations"):
- Rule 11: a runner may run headless with a normal desktop browser user agent
(dropping HeadlessChrome) and nothing more: no fingerprint spoofing beyond
the UA string, no stealth plugins, no solving or evading a bot challenge.
A challenge the browser completes itself is a wait step; any other is a
captcha gate.
- Captcha solvers: new site.sector and captcha step `solver`
(forbidden by default | allowed). Never allowed on government, tax,
financial, healthcare or identity-provider sites, nor on any errand with a
declare or identity-proofing step or a secret input; elsewhere only when the
file says so, with every use logged. The validator rejects `allowed` in the
forbidden set or without a stated sector; six new tests. The FTB example
states sector "tax".
- Reference runner: @logicsrc/openerrand / `logicsrc errand run`, marked in
progress; ftb stays the runner the example was taken from.
- Name stays OpenErrand; family stays Agents and process.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
* OpenInstall 0.1: one idempotent bin/install.sh that puts an app into service
A repository carries bin/install.sh and, when the defaults are not right,
bin/install.conf. Run on a box from a checkout it installs the runtime and a
local Postgres or Redis, builds, writes a systemd unit and an nginx site with
TLS, restarts and health-checks the app. Phases setup, build, activate and
status; exit 0, 1 or 3; never overwrites a file without its marker line;
secrets only in STATE_DIR/app.env. sh1pt's deploy-ssh install.sh is the
reference script and `sh1pt ship --target deploy-ssh` the reference deployer.
Registered in the process family, with a landing page at /openinstall and a
contract test holding the page's tables to the spec.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* docs(openinstall): describe DATABASE_URL without a credentials-shaped URL
ThreatCrush flagged the placeholder postgres URL in the worked example.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
There is no shortage of places to look up an AI model and nowhere to look
up what it costs you, from the provider that will bill you, in a form a
program can read. Every provider publishes prices as a marketing page and
every comparison site scrapes those pages. The best of them, models.dev,
is a community database: 8,179 provider offerings across 223 providers,
maintained by volunteers reading pricing pages. Good work, and still a
third party writing down what a company charges.
OpenModel is that table served by its author at
/.well-known/openmodel.json: price per million tokens in, out and cached,
context and output limits, modalities, and what each model can do.
The unit is the offering, a provider and a model together, because the
same model reaches a buyer from many providers at many prices and the
price is the question they came with.
Two rules decide what a row means, and both come from measuring the real
data. A published zero is a fact: of those 8,179 offerings, 638 cost
nothing and 424 published no price at all, so a reader that collapses the
two invents a free model or hides one. And absent is unstated, never
false, because a false travels further than a blank and comes back quoted
as a fact.
Origin is the proof, as with every catalog spec here: a file naming a
provider's web and served by somebody else is a stranger's claim about
that company's prices.
The first reader is the models collection at nichedb.dev/c/models, which
reads descriptors beside the models.dev catalogue in the same vocabulary
so one feed catches both.
Registered in the one registry, with docs/openmodel.md and a docs-only
entry (no landing page yet), and added to the spec-discovery contract so
the family page, docs index, llms feeds and sitemap are proven to carry
it.
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
OpenObject is a bucket you can mount: keyed objects as ipfile swarms placed
on OpenDisk disks under pay2seed at a stated redundancy (three replicas on
three operators in two countries by default), an ipdb index as the bucket's
clock, a repair loop, an HTTP API, an S3 mapping and a mount whose
consistency is close-to-open by seq. d1sks.com is the reference store.
OpenSlice is a container whose compute is rented from one market and whose
disk is mounted from another: a host descriptor at
/.well-known/openslice.json, one signed slice file (image by digest,
OpenCPU/OpenMemory/OpenGPU units, OpenObject mounts, OpenCreds env, ports,
placement, lifetime), and a reservation that is a paid2seed lease applied to
compute with presence proofs per epoch. slic3s.com is the reference
marketplace; c0mpute hosts take the slice role.
Both are registered under OpenServer in the catalogs family with landing
pages, rows in the OpenSwarm family table, and the spec-discovery contract.
llms.txt now cites the specification URL for child specs too, which every
block under OpenServer had been missing.
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
A new LogicSRC spec in the catalogs family. One heading, an identity block
(Kind, Web, Repo, Operator, License, Extends, Updated), one line, then eleven
layers: Languages, Runtimes, Interfaces (one ### per way in: web, api, cli,
tui, mcp, desktop, mobile, worker, extension, bot), Data, Services, Modules,
Tooling, Hosting, Auth, Conventions, Not. An item is one bullet: name,
version, an optional status word (trial, hold, leaving) and a role. Extends
inherits a parent file, sections replace, Conventions and Not accumulate.
Rule 8 is the reading rule for agents: use what is listed, prefer listed
over new, ask before adding a layer or a service, never add a Not, keep the
file true. Discovery at OpenStack.md in the repo, /.well-known/openstack.md,
rel=openstack, or a platform path. JSON is derived and never the source.
logicsrc.com serves its own at /.well-known/openstack.md: the route extracts
the worked example from docs/openstack.md, and a contract test holds the two
together and checks the file follows its own rules. rel=openstack in <head>
and in the Link header beside openprofile.
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
PR 177 shipped a second OpenFleet under the same slug: a published listing of OpenAgent profiles and ipfile swarms with CoinPay rental offers. Anthony ruled that OpenFleet means the human-controlled fleet and the record of who spawned whom, so the rental contract is renamed OpenRental (slug openrental, catalogs family, group noun listing): docs/openrental.md, logicsrc-openrental.schema.json with type logicsrc.openrental and scope kind listing, fixtures/openrental, createOpenRental and OpenRental* types in the SDK, the openrental validator kind. Minor bumps because an export moved: @logicsrc/schemas 0.2.0, @logicsrc/validators 0.2.0, @logicsrc/sdk 0.2.0. The discovery contract test now covers openfleet, openrental and openwall, one per family, and accepts a landing-page link in llms.txt.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01RZV4zJ2pDZLNN3kE5jFCmV