The ONE name this instance broadcasts under, for an id spelled any way the grammar allows —
undefined when nothing resolves there.
A ?watch=1 stream needs it to label its events with the same id the fan-out uses, and it
needs it without side effects: opening a watch reads, it does not project. That is why this
is not "reproject and look at the frame".
The carrying declaration of the collection registered at path — undefined for a row
that carries nothing. What the router publishes as OPTIONS carries/index.
The COLLECTION that carries the per-instance row at path — its own path, or undefined
where no registered row declares it. Derived from the declarations, so the stream hub's
carrying rule never becomes a second hand-kept table.
Every registered path whose row declared a confirm gate, path → the gate — the confirms
sheet OPTIONS <base>/ publishes (row grammar, "Confirm: the eighth clause"). Derived from
the declarations, so the published policy and the enforced one are the same object.
Create one item through its entity's POST door and answer the id the store minted.
Every row's FRESH state, with no instance named — the other half of what a booting client needs, beside travels.
travels says what a control may be; this says what it starts at. A client that can read
the first and not the second still has to compile one of the desk's own declarations into
its bundle, which is the whole defect: a value the server enforces and the client guesses,
with nothing on either side able to detect the disagreement.
A row that declares no fresh state is simply absent, and absence reads as "this row has no desk-wide starting point" — never as "it starts empty".
Every instance of one entity, canonically spelled — undefined when nothing is registered
at that path.
An entity that cannot enumerate (ConsoleResource.instances absent) is asked ONCE at
the empty id: a singleton address parses {} and every other codec refuses it, so a
/telemetry/latency is listed without every derived row re-declaring what its address
already says, and a /channel/{kind}/{index}/… contributes nothing rather than a made-up
channel.
Observe every COMMITTED write, whichever door it came through. Returns the unsubscribe.
This is the seam that makes session-dirtiness and undo a property of the ROW rather than of the caller: a host registers one listener at composition time and no write site ever has to remember to schedule an autosave or record an inverse again.
What this instance allows, declared per instance.
Change the one state, WAIT for the write to land, project it, broadcast it, run its ripples — one step.
Asynchronous because a row's answer may not precede its own write: a door whose store
commits within the call settles immediately and this resolves in the same turn, while a door
that suspends is waited on, so the state a caller is handed is the state a reader would find
(Settlement, task #79).
Optionalsource: WriteSourceEvery registered path, for discovery and for the conformance suite.
Read one instance's state — the same state a broadcast carries and a patch mutates.
Declare an entity and get its typed handle back.
Remove one item through its entity's DELETE door, then re-frame what is left.
Nothing is PROJECTED afterwards: the door itself is the actuation (the engine call, the unlink), so a projection here would re-assert state the removal just retired. The declared lifecycle ripples ARE re-projected — that is how an ex-member of a deleted mute group gets its composed mute back.
Re-read, re-project and re-frame one instance WITHOUT writing state — the capability gate is skipped because nothing is written. This is how a composition change (someone else's latch), a queued sink's landing, or a bulk state apply reaches the audio and the surfaces.
One instance as view reads it — the row's own projection over its own fresh read where it
declares one (ConsoleResource.served); undefined where the row declares none (the
caller serves the state it holds) or the instance is not there. The ONE seam both doors read
through: the GET handler at the reader's query, the stream hub per subscriber.
The whole console as a list of reads — what a root ?watch=1 stream opens with, so a client
needs no second replay path to render a populated board.
Every frame is produced by the SAME read a GET on that instance performs, carrying the same
canonical id the fan-out uses, which is why a snapshot cannot drift from the console it
snapshots. An instance that stopped resolving between the enumeration and its read is
skipped: absence is a fact, and a frame with an empty state would be a fabricated one.
A snapshot walks EVERY registered row for EVERY instance it declares, and it is what a client connection runs. So a row that throws — an engine query about a channel it does not hold, a projection over state a restore left half-applied — must never kill the process that is building the snapshot. On the rig, 2026-08-06, one did, and that process was the console itself: the engine died on every WebSocket connection, systemd restarted it, it autoloaded the same session and died again, three times, with no way in for the operator.
A throwing row therefore costs its own frame and nothing else. It is REPORTED, never quietly
dropped — a silently short snapshot is a client mixing against a lie, which is worse than a
visible gap (onFault is how the console says which row failed). Defence in depth: nothing
on a read path should throw in the first place, and this is what holds when one does.
Optionaladmits: (path: string) => boolean
optional path-template filter — a narrower WINDOW on the same console, never a different shape.
OptionalonFault: (called with each row that threw, so the caller can log it and tell the operator. Omitted, the frame is still skipped rather than fatal — a caller with nowhere to report to must not be the reason a desk stops.
Every registered path whose entity declared itself TRANSIENT (run bookkeeping, not board state — see ConsoleResource.transient). Derived from the declarations, so the convergence heartbeat's exclusion set never becomes a second hand-kept list.
Every row's travels, with no instance named — the whole desk's declaration in one answer.
What a booting client binds its controls from. capabilities(id) cannot serve that: it
resolves an address and reads a live station cell, so learning every travel through it means
a request per (row, instance) — thousands, for numbers that do not change. A row that
declares no travel is simply absent here; absence reads as "ask the instance", never as
"unbounded", which is why ConsoleResource.travels withholds a number wherever the
travel belongs to the instance rather than to the row.
Holds every declared entity and serves every request against them. One instance per console; registration happens at composition time and the set never mutates afterwards.