Principles
The same few rules recur across the applications on this site. They are not a house style; each one is written into the code that ships.
A promise the architecture can break is only a sentence.
Every example below is held by a test, a code boundary or a statement in the project's own documentation, read from the repository rather than from the marketing. Where the practice still falls short of the principle, the last section says so.
A claim is a structure, not a sentence
"Read only" is not true because the README says it. A promise about what software will never do belongs in a test that fails the build the moment the promise is broken.
- PlainSight walks the syntax tree of every module. Three named modules may write a file; a fourth that tries fails the build.
- Stellody makes the methods that write music tags unreachable from every module that reads one, so the player cannot damage the library it plays.
- SymDiary fails the build on any import of a network package; a second test holds the page to a content policy that forbids connections from the other side.
- Postal Gambit forbids every network library across the app and its setup program, bar one named module granted one import for the update check.
Outbound traffic fits on a page
If an application calls itself local-first, everything it sends off the machine should be listable: each host, each purpose, ideally each field.
- EarthNow builds its HTTP client with five named hosts and refuses every other, redirects included. The README lists all five.
- Stellody lets four modules reach the network. Tests pin every address asked and every field sent; another checks that nothing sent names the listener or the machine.
- TimeRibbon lets one package import a network package. Its one request is the update check.
- Postal Gambit makes exactly one outbound call, disclosed in full; your own mail client carries the games.
- PigeonPost lets seven packages open a connection: your own mail and calendar servers, Microsoft sign-in, the images you choose to load and the update check. A test fails any other that tries; another forbids the interface from making a request of its own.
- ClearBudget and Fulcrum each open one connection themselves, the update check. A test fails any module of the application or its setup program that imports networking code beside it.
- Meridian names six ways out and pins each to one home: the feed fetcher, the update check, the one component that asks Wikipedia for suggestions and the one that draws YouTube's player.
Leaving is always possible
Standard formats, local files and data that stays with its provider. Nothing here should be harder to leave than it was to start.
- PigeonPost leaves your mail on your provider's server. Calendars and contacts travel as ICS, vCard and CSV, each format with a round-trip test.
- SymDiary exports and imports its record; a test reads back every export format version the app has ever written.
- ClearBudget backs up everything to one file. A broken backup is refused and changes nothing.
- Fulcrum exports a plan as JSON that imports again; it can also export one as a single HTML page.
Failure is visible; partial success is reported as partial
Software that hides a failure moves the cost to the moment you discover it. Saying what did not happen is part of the job.
- AudioDeck reports a profile switch as partial when some devices could not be set, in the window and from the command line.
- ScreenState reports what a restore could not do, naming any application it could not read.
- EarthNow keeps the other days drawn when one day's data fails to arrive; a status panel gives the reason for each failure.
- PigeonPost reports a partly refused move as an error, with the count the server accepted rather than the count it asked for.
- Stellody reports an unanswered lookup as unanswered. A scan summary never reads as more complete than the scan was.
- Meridian ends every import with a report: what was added, what you already had and each feed it could not add, with the reason.
Automation removes work, not agency
The software does the counting and proposes; a person decides. Nothing destructive happens behind a default.
- PigeonPost counts what a mail rule would move before it moves anything. Importing rules shows a plan that writes nothing.
- ScreenState saves nothing until you confirm. Apply never closes one of your windows, whatever the settings say.
- Stellody describes a damaged tag and never repairs one. The repair is yours, in a tagger you chose.
- NarrateX defaults its remove-book confirmation to cancel; declining removes nothing.
Same input, same answer
A number someone will act on should come out the same the second time. Randomness is seeded, time is injected and the output is pinned.
- Fulcrum forbids its model layer from importing randomness or the clock; a structural test fails if it does. Same model, same score.
- LatencyLab runs a hundred seeded simulations twice and requires them to match; a golden snapshot pins the exact output.
- MMSP publishes its specification only when the conformance suite passes. The 300-second poll floor is a test; Meridian raises any shorter interval to it.
Say what it does not do
The most useful line in a README is often the one a reader would otherwise have assumed.
- ClearBudget, PigeonPost, SymDiary and Stellody each state plainly that their local data is not encrypted at rest.
- Postal Gambit has no in-app sending and says it never will.
- EarthNow, ScreenState, TimeRibbon and SymDiary each carry a section headed "What it does not do".
Where the practice is behind the principle
Measured against the repositories as they stand, one gap remains. The coverage gates run on the build machine; only the MMSP specification runs its suite in continuous integration.