sola.cell:R1.1
When asked for health, cell shall report availability without owner data.
Implementation
- Missing annotation link
Test
- Missing annotation link
Each statement comes from its component contract. Links name the annotated methods. Missing links stay visible.
When asked for health, cell shall report availability without owner data.
When an owner requests the manifest, cell shall identify itself as a zero cell with no business modules.
When a visitor requests the homepage without credentials, documentation shall serve the generated homepage.
When a visitor requests a published document without credentials, documentation shall serve its content and declared media type.
If a requested path escapes the publication root or names an unpublished file, documentation shall return not found.
When a visitor requests the manifest, documentation shall identify its build and distinguish annotation links from test and proof evidence.
When an iteration is accepted, history shall expose an event identifying its actor and request.
When an owner requests history, history shall exclude other owners' events.
Unless an unexpired grant is supplied, identity shall refuse owner data access; neither factor credential shall act as a grant.
When the configured owner key is presented, identity shall issue a short-lived challenge and a private redemption secret.
While an unexpired challenge is pending, identity shall refuse another pending challenge for that owner.
Only after the configured factor approves a challenge shall identity exchange its private redemption secret for one grant.
If approval is denied, identity shall refuse redemption.
If the challenge expires, identity shall refuse proof and redemption.
If the proof names another owner, was already used, or targets a decided challenge, identity shall reject it.
When redemptions race, identity shall issue at most one grant.
Identity shall persist only grant/redemption hashes, expire grants, and revoke a grant on logout.
When a nonblank prompt is submitted, iteration shall durably queue it with an identifier and creation time.
If the prompt or execution options are invalid, then iteration shall reject the request before creating a record.
Unless execution is requested, iteration shall leave the request queued without invoking a runner.
If source changes or archives are supplied, then iteration shall refuse them before creating a record.
When a submission repeats an idempotency key and payload, iteration shall return the original request; a changed payload shall conflict.
When an owner lists iterations, iteration shall return only that owner's requests.
If no runner is configured, then iteration shall refuse execution without consuming the queued request.
When execution succeeds, iteration shall record completion without claiming deployment.
If execution fails or exceeds its time limit, then iteration shall record `failed` or `timed-out` respectively.
If the request is unknown, belongs to another owner or has already started, then iteration shall refuse execution.
Where flight recording is enabled, iteration shall record the run's identifier, duration and outcome without the prompt or credentials.
When cancellation is accepted, iteration shall stop its process group and retain cancellation despite a racing completion.
After a process restart, iteration shall stop identified orphan runners, mark running requests interrupted, and preserve queued execution intent without replaying interrupted work.
Only after the configured verifier returns a matching receipt and patch hash shall iteration report completion and expose that patch to its owner.