# REMOTE-FRICTION — milestone #304 grill

State: operator-confirmed and GREENLIT on 2026-09-11; execution tracked by milestone #304.
Authority: operator answers on 2026-09-11. Requests: BigscreenVR/spt-bs-releases#304.

## Settled decisions

1. **Node-root docs:** redirect `/<node>/` to `/<node>/docs/`; retire the browser registry index. `spt serve list` remains the exposure audit. This supersedes ADR-0056's original node-root index decision; that ADR must be amended before implementation.
2. **Bootstrap firewall admission:** automatically reconcile admission for the actual bootstrap TCP port and executable. Match installation's network scope, not the earlier proposed LAN/tailnet-only scope: all profiles, without a remote-address restriction. Docs remain loopback-only and tailnet policy is untouched. Request Windows UAC when elevation is needed; use an equivalent Linux mechanism where available. **Q5:** if admission cannot be added, still start bootstrap if its normal startup gates succeed; explain that firewall admission is unverified and the user may rerun bootstrap to retry adding the rule. Never equate rule failure with proven network inaccessibility. Owned-rule teardown details remain to settle. ADR-0059 needs the corresponding admission amendment.
3. **Refresh-freeze release coupling:** supersede #49's old mandatory joint-release coupling to #42. #49 and #267 remain in #304; #42 stays outside unless a demonstrated dependency requires reconsideration. Similar symptoms do not establish a shared cause with #302.
4. **Stale-view visibility:** do not force viewer replacement or detach. **Q6–Q7:** use `ATTACH_CLIENT_STALE` for controlling clients and read-only viewers, delta-only. A release-maintained policy shipped with core carries minimum recommended client version, applicable platform/attach role and concrete degraded-function reason. Raise the minimum only for a demonstrated client defect or required capability, not every release. Unknown versions remain unknown and do not trigger this warning. Recommend reopen when a sufficient client is installed on its node; otherwise recommend update then reopen. Broker skew is not client skew.
5. **File-helper trigger:** #300 uses USER_INPUT, not MSG_OUT or raw terminal-keystroke parsing. Preserve authenticated origin, receiving-endpoint audience, 24-hour lifetime and live-reference serving.
6. **Owned-rule cleanup (Q8, settles Q2's remaining teardown question):** explicit bootstrap stop removes only its owned TCP rule; stale owned rules are reconciled after abnormal termination. Preserve installation's UDP rule and unrelated rules. If required cleanup elevation is declined, stop the listener anyway and report the residual rule with a cleanup command. Listener shutdown never depends on successful rule deletion.

All eight product-design questions are answered. The operator confirmed the shared understanding and greenlit REMOTE-FRICTION on 2026-09-11.

## Terminology clarification

The existing domain model distinguishes a transient attach client (`spt rc`) from the broker that owns the PTY and authoritative render state. Reopening the client does not restart the endpoint or update broker code. Any stale-image guidance must name which process is stale and avoid prescribing a daemon restart for client-only skew.

## Intake

Verified members: #297, #299, #300, #301, #302, #251, #282, #288, #230, #49, #267.

Read-only infra sweep accounted for IR-1–97, including headingless IR-31. Final rider composition is pending. Existing implementations, adoption gaps, incident diagnosis and operator capacity choices remain separate obligations.

Implementation and release orchestration are authorized under the confirmed scope. Build capacity, fixture isolation, independent golden verification and release gates remain mandatory.
