diff --git a/SPEC.md b/SPEC.md index 60b9189..9e2def8 100644 --- a/SPEC.md +++ b/SPEC.md @@ -472,9 +472,13 @@ misread as gaps: - **`DP-*` and `VR-*` trace to no system requirement.** Deployment and parameter studies are single-repo concerns serving `PR-004` and `PR-002` directly. This is correct. -- **`PR-005` (leak nothing) has no software row at all.** It is satisfied - *structurally* — `SR-004` (server holds no binary) and `GR-005` (gallery never - leaves the instance) — rather than by any component doing something. It cannot - be verified by pointing at code, and it dies the moment either prohibition is - relaxed. A goal preserved only by prohibitions needs watching precisely because - nothing traces to it. +- **`PR-005` (leak nothing) will look thinly covered, and that is the true + picture.** It had no software row anywhere; jRay is the component that + actually performs egress, so four rows now carry it — `JR-038` (exchange + off by default, Done), `JR-034` (contribution strips `movie` and + `jellyfin_id`, posts only to contribute-enabled servers) and `JR-039` + (batch `exists` capped at 100, sweeps paced), both High and T1, and + `JR-040` (the config page states the per-server exposure, T4). Three are + untagged because they are unbuilt, not because the chain is broken. The + structural guarantees — `SR-004` and `GR-005` — still hold the goal from + the other side, and it still dies the moment either prohibition is relaxed.