diff --git a/CLAUDE.md b/CLAUDE.md index f69a422..dbab7d0 100644 --- a/CLAUDE.md +++ b/CLAUDE.md @@ -101,9 +101,15 @@ protocol; the config in `deploy/mavend.json` (with `${VAR}` env expansion from g Count against compose, not against the table. Four of the nine daemons are absent, and each absence has a different reason. -`mavmaild` is commented out in compose, with the reason written beside it: it needs a mail -account and this box has none. `mavcaldav` appears nowhere at all, and unlike the other -three that is an oversight rather than a decision (V-644). +`mavmaild` and `mavcaldav` are commented out in compose, each with the reason written +beside it: the first needs a mail account, the second a CalDAV account, and this box has +neither. `mavcaldav` used to appear nowhere at all, which was an oversight; it became a +recorded decision on 07-08-2026 (V-644). Two things ride on that absence and the block +names them. Agenda questions route to `IntentQuery` at stage 0 (V-498) and the `calendar` +query source then reads a table nobody writes. And `loop.State.CalendarBusy` is fed by the +same facts, so the gate's "do not nag mid-meeting" is permanently false. Its password is +read from a file (`-pass-file`, and `-render-pass-file` for the render collection), never +taken as a flag value, which is the rule `mavpoll` and `mavmaild` follow too. **`mavwaked` and `mavenclient` are absent by decision, not oversight** (Vikunja #463, `docs/plans/17-where-the-voice-loop-runs.md`). diff --git a/docker-compose.yml b/docker-compose.yml index eb8a7aa..2eedef6 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -157,6 +157,44 @@ services: # - maildata:/var/lib/mavmaild # - ./deploy/imap.password:/run/secrets/imap.password:ro + # The calendar reader (Vikunja #644) is OFF and commented out: it needs a + # CalDAV account, and there is none on this box. It was built, listed in + # `make build`, and deployed nowhere, which is the worst of the three states — + # this block records the decision instead. + # + # What its absence costs, so the cost is visible from here: + # - Agenda questions route correctly and answer from nothing. Stage 0 sends + # "что у меня сегодня" to IntentQuery (V-498) and the `calendar` query + # source reads facts(kind=env, source=caldav:*) that nobody writes. + # - The nudge gate loses a suppressor. loop.State.CalendarBusy is fed by + # those same facts, so "do not nag mid-meeting" is permanently false. + # + # Core never sees the CalDAV password: the reader polls the collection itself + # and hands core one fact per event over WriteFact. Nothing here can create a + # reminder, so a misread event cannot fire. + # + # The password is read from a FILE, so it never appears in `ps`, in this file, + # or in shell history — the same rule mavpoll and mavmaild follow. + # + # To enable: write the password to deploy/caldav.password (0600, gitignored), + # point -url at the collection, and uncomment this service. No mavend.json + # block is needed — events arrive over IPC as facts. -render-url is optional + # and OFF here: it publishes Maven's own reminders back as events, and it must + # not name the collection -url reads, or the poller reads its own writes back + # in (checkRenderTarget refuses that). It takes -render-pass-file, and falls + # back to this password when that is not given. + # mavcaldav: + # <<: *image + # command: ["mavcaldav", "-socket", "/run/maven/mavend.sock", + # "-url", "http://localhost:5232/kami/personal", + # "-user", "kami", + # "-pass-file", "/run/secrets/caldav.password", + # "-interval", "5m"] + # depends_on: [mavend] + # volumes: + # - sockets:/run/maven + # - ./deploy/caldav.password:/run/secrets/caldav.password:ro + volumes: dbdata: sockets: