Every install recipe walked the reader through `shaterd apply` + `shaterd
confirm` as if commit-confirm were armed. It is not: DefaultGlobals() never
seeds ConfirmTimeout, the shipped config carries confirm_timeout '0', and
ArmRollback returns at once on a non-positive timeout. A reader following the
README believed an apply that cut their SSH would undo itself. It would not.
README/README.en/INSTALL now arm it in the recipe and say what 0 means; the
apply-flow diagram gained the edge it always took on a stock box.
The boot armor was documented nowhere at all (`grep -rli armor --include=*.md`
returned zero) while shipping enabled and blocking LAN->WAN on every boot.
INSTALL 4 now says what it is, why SSH/LuCI stay up on purpose, every condition
under which it refuses to arm, and how to switch it off.
Also removed or corrected, each checked against the code, not inherited:
* MASQUE/CONNECT-IP is advertised in both READMEs and absent from parse,
generate and model -- registry names it among the types deliberately left
unregistered. Dropped, with the fork-vs-product distinction spelled out.
The inverse too: Hysteria2/TUIC/XHTTP were tagged [T1] while shipped under
with_quic/with_xhttp; ShadowTLS is generate+registry only, no parser.
* `direct (flow-offload on)` -- no offload/flowtable/flow_offloading anywhere
in openwrt/, shater/ or panel/src. The product does not do this.
* shater-core deps were two releases stale in two places, one of which vouched
for a config.buildinfo check that never covered kmod-tun. Ruling narrowed to
what was actually checked.
* PORTING's "Full schema" -- the shipped config points at it -- was missing
l3_tunnel and untunnelable_egress (UCI is their only path; the panel does not
show them) and the blocklist/allowlist/device/alert sections, while listing a
`config preset` that ReadUCI has no branch for.
* ARCHITECTURE had no L3 ingress and no kernel egress at all, though both are
[MVP] and one creates an fw4 zone in the user's firewall config. New 3a.
* nftset-for-routing in the DNS diagram: that is the v0.1 mechanism, gone in v0.2.
* CONTEXT described a pre-Phase-1 repo and a 24.10.3 testbed. The testbed is
ImmortalWrt 25.12.1 r37978-cd0a06bfd3fd (read off the box), which is not a
detail: .apk does not install on 24.10 at all.
* The gate existed and no .md mentioned it. README/README.en/CONTEXT now do.
* release.yml's header still described publishing as either/or after the rolling
pointer became unconditional. Comment only.
* Shipped /etc/config/shater: schema_version '1' against CurrentSchemaVersion=2;
a pointer to a dns_filter line that was not in the globals block (added, '0');
and `option sniff '1'` on the inbound -- an option the model deliberately does
not have, which the first panel save would have silently washed out.
* lx-changelog pointed at a D25 heading that does not exist.
* ROADMAP 2b and 5 were done and unmarked.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01BHw89tdWddzhjUc4bAH4tS