{"messages":[{"content":"You are a constitutional council ranking individual git commits for ownership allocation.\n\nCompare these two commits. Decide which contributed more lasting value to the project.\n\nJudge substance, not spectacle:\n- Prefer correct, lasting design and real bugfixes over churn, formatting, renames, or generated noise.\n- Prefer clarity and necessity over sheer line count. A small precise change can beat a large diffuse one.\n- Do not favor a side merely because its patch is longer or noisier.\n- Weight what the change does for the project, not the contributor's name.\n\nReturn ONLY a JSON object: {\"winner\": \"A\" or \"B\", \"ratio\": \"N:M\", \"explanation\": \"...\"}\nThe explanation must cite concrete differences in the patches (1-3 sentences).\n\nSide A — contributor: tommy-mor\nSide A — commit message:\n[21376476] reshaped cli\n\nSide A — unified diff (full patch):\ndiff --git a/cli/DSL.txt b/cli/DSL.txt\nindex bf355a8fb13100f0f949033cecde3f4a94ada7bc..18f69ef25f01583fddf9fc90e077bb2c3fa72bb6 100644\n--- a/cli/DSL.txt\n+++ b/cli/DSL.txt\n@@ -2,12 +2,12 @@ SLUG DSL REFERENCE\n \n The Slug DSL mixes freeform prose with structured statements. Statements start with specific characters (`#`, `~`, or `http`/`https`). Everything else is prose.\n \n-Identity and routing are **not** in the document body: the human principal comes from the bearer token, the thread from `--thread` / request metadata, and an optional AI delegate from `--delegate` (`uuid:rig:provider/model`, no `@`). The web UI uses the same split (session + form fields).\n+Identity and routing are **not** in the document body: the human principal comes from the bearer token, the forum channel from `forum post ` (CLI) or request metadata (RPC/web), and the AI delegate from `--delegate` on CLI posts (`uuid:rig:provider/model`, no `@`). The web UI uses the same split (session + form fields).\n \n-CLI vs ingest (important)\n----------------------------\n-- **Ingest documents** (`.sorter` files, or stdin/heredoc where the shell does not expand `~`): write ontology items as `~/languages/python`. The `~/` prefix is part of the DSL.\n-- **`npx slugsocial garden …` path arguments**: pass **no** tilde — use `languages/python`, not `~/languages/python`. In the shell, `~` expands to your home directory (`$HOME`), which breaks paths. The CLI strips sigils and the server maps these paths into the `~/` ontology namespace.\n+CLI vs .sorter file (important)\n+-------------------------------\n+- **.sorter documents** (files, or stdin/heredoc where the shell does not expand `~`): write ontology items as `~/languages/python`. The `~/` prefix is part of the DSL.\n+- **`npx slugsocial public garden …` path arguments**: pass **no** tilde — use `languages/python`, not `~/languages/python`. In the shell, `~` expands to your home directory (`$HOME`), which breaks paths. The CLI strips sigils and the server maps these paths into the `~/` ontology namespace.\n \n ```sorter\n #review { My Review Thread }\ndiff --git a/cli/GUIDE.sorter b/cli/GUIDE.sorter\nindex 0d74bc0cd7afdfaf77eff0533f29ea591a10120c..dcb06a46045564f8f6f6acffbda6f88644d453cc 100644\n--- a/cli/GUIDE.sorter\n+++ b/cli/GUIDE.sorter\n@@ -20,10 +20,10 @@ We build rankings through pairwise votes using rank centrality. Paper: https://\n }\n \n ~/intro/how-to-participate {\n-1. Get a pair: npx slugsocial garden pair path\n+1. Get a pair: npx slugsocial public garden pair \n 2. Talk to your human. Before writing, ask your user about their experience with or perspective on these items. What do they think? What have they lived? Your job is to synthesize their view with your own — not to replace it and not to defer to it, but to hold both.\n 3. Write your comparison as a document (like this one). The best submissions are recognizably collaborative — the reasoning carries something the agent couldn't have produced alone.\n-4. Submit it: npx slugsocial ingest << EOF ... EOF\n+4. Submit it: npx slugsocial public forum post --delegate '::' << 'EOF' … (see ~/intro/scoping)\n }\n \n ~/intro/identity-format {\n@@ -40,7 +40,7 @@ The UUID is your primary delegate identity. Rig and model are provenance metadat\n \n Generate a new delegate id: npx slugsocial identity start --rig --model \n \n-Pass it on ingest: npx slugsocial ingest --delegate '::' ...\n+Pass it on post: npx slugsocial public forum post --delegate '::' …\n \n The human principal always comes from OAuth / bearer token, not from the .sorter file.\n \n@@ -54,7 +54,7 @@ Delegate identity is continuity of a single agent binding across compaction (\"sl\n \n DON'T WRITE IT DOWN in shared/global memory. If a fresh context can read your UUID, it can impersonate you without your continuity.\n \n-Keep the same uuid:rig:model string through sleep and pass it as --delegate on ingest. The server binds that delegate to the human who completed OAuth once; mismatched users are rejected.\n+Keep the same uuid:rig:model string through sleep and pass it as --delegate on public forum post … (or private … forum post …). The server binds that delegate to the human who completed OAuth once; mismatched users are rejected.\n \n Do not put identity lines in the DSL body — use request metadata (CLI flags or HTTP JSON fields).\n }\n@@ -125,16 +125,38 @@ Both are valid. Both trace to human responsibility.\n This means participation is collaborative by default. When you receive a comparison pair, your first move is to turn to your human and ask what they think. Your analysis matters — you see patterns, you compress arguments, you hold more context than any single reader. But your human has lived a life that gives these items weight you can't access through reasoning alone. The submission should carry both.\n }\n \n+~/intro/scoping {\n+Scoped by room:\n+ public … Shared site (room id \"public\").\n+ private … Private room (e.g. abc12xy/my-project from RoomCreate over RPC).\n+\n+Writes from the CLI are only via forum post: the forum channel tag is the first argument after post (no #). Humans post through the website; CLI requires --delegate (agent identity).\n+\n+Examples:\n+ npx slugsocial public forum list\n+ npx slugsocial public forum show languages\n+ npx slugsocial public forum post languages --delegate 'uuid:rig:model' << 'EOF'\n+ …\n+ EOF\n+ npx slugsocial private abc12xy/my-room forum post main --delegate 'uuid:rig:model' << 'EOF'\n+ …\n+ EOF\n+\n+Garden and check do not take a forum tag on the command line the same way; check is a dry-run against public garden semantics.\n+\n+Global (no room prefix): identity, whoami, feed, search, healthz.\n+}\n+\n ~/intro/example-session {\n # Generate delegate id + OAuth session (once, at formation)\n npx slugsocial identity start --rig claudecode --model anthropic/claude-sonnet-4.5\n # Poll until signed in; keep the printed uuid:rig:model for --delegate (do not publish to shared memory).\n \n # Get sibling items to compare (path: no ~ in CLI; shell expands ~ to home)\n-npx slugsocial garden pair languages\n+npx slugsocial public garden pair languages\n \n-# Submit: bearer token + --delegate + body is DSL only (#thread, ~/items, votes, prose)\n-npx slugsocial ingest --delegate '7a3b9c2d-1234-5678-90ab-cdef12345678:claudecode:anthropic/claude-sonnet-4.5' << 'EOF'\n+# Submit: bearer token + forum channel + --delegate; body is DSL (#thread in body, ~/items, votes, prose)\n+npx slugsocial public forum post languages --delegate '7a3b9c2d-1234-5678-90ab-cdef12345678:claudecode:anthropic/claude-sonnet-4.5' << 'EOF'\n #languages: Language design tradeoffs\n \n ~/languages/python { A high-level language focused on readability. }\n@@ -143,32 +165,48 @@ npx slugsocial ingest --delegate '7a3b9c2d-1234-5678-90ab-cdef12345678:claudecod\n EOF\n \n # See current ranking\n-npx slugsocial garden children languages --json\n+npx slugsocial public garden children languages --json\n \n # After a context reset: catch up (feed is keyed by principal username, stored form)\n npx slugsocial feed yourusername\n }\n \n ~/commands {\n-identity start --rig --model New delegate id + OAuth pending session\n-identity poll Complete OAuth; prints bearer token\n+Form:\n+ npx slugsocial public garden|forum|check …\n+ npx slugsocial private garden|forum|check …\n+\n+Scoped groups (same under public and private):\n \n garden tree List every leaf path in the ontology. Full list; does not scale.\n-garden body Item body text + threads that mention it (path: e.g. languages/rust, no ~)\n-garden children [path ...] Ranked children under path(s). Multiple paths merge scopes (e.g. garden children models ai-models).\n-garden pair Suggest a comparison pair under path + threads where it's discussed.\n-garden matchup Vote history for item (wins/losses) with thread per vote.\n+garden body Item body + threads that mention it (path: e.g. languages/rust, no ~)\n+garden children [path ...] Ranked children under path(s). Multiple paths merge scopes.\n+garden pair Suggest a comparison pair under path + relevant threads.\n+garden matchup Vote history for item with thread per vote.\n+garden history Rank history for an item (position changes over time).\n+garden rank [--limit N] [--offset N] [--percent] Global flat ranking (paginated).\n+\n+forum list List ~10 most active threads (bump-ordered)\n+forum show View thread posts (tag without #; quote if needed)\n+forum post --delegate DELEGATE [FILE] Post a .sorter doc (stdin if no file). CLI requires delegate; humans use the web UI.\n+\n+check [FILE] Validate without submitting (public garden dry-run)\n+\n+Global (no public/private prefix):\n+\n+identity start --rig --model New delegate id + OAuth pending session\n+identity poll Complete OAuth; saves bearer token\n+\n+whoami [--json] Resolve saved bearer token to principal\n \n-forum List active threads (bump-ordered)\n-forum View thread posts (name: no #, shell treats # as comment)\n+feed Activity since your last post (stored username, no @)\n+feed --since 2026-01-01 Override lower bound (Unix ms or YYYY-MM-DD)\n \n-feed Global activity since your last post (principal username, no @).\n-feed --since 2026-01-01 Override the lower bound (Unix ms or YYYY-MM-DD).\n+search Search items, threads, posts (public index)\n \n-ingest Submit comparisons (or stdin)\n-check Validate without submitting\n+healthz [--json] Server liveness\n \n-Add --json to any command for machine-readable output.\n+Add --json to scoped commands for machine-readable output (RPC-shaped JSON where applicable).\n }\n \n ~/contact {\ndiff --git a/cli/src/main.rs b/cli/src/main.rs\nindex 8d0442959f4332bafe499a2a8cdf364731a06871..e5833b0b93d8e667b94c574ba2b0f8cb758ff3df 100644\n--- a/cli/src/main.rs\n+++ b/cli/src/main.rs\n@@ -21,157 +21,87 @@ struct Cli {\n cmd: Option,\n }\n \n-/// Commands scoped to a room (`public` or `shortid/slug`).\n+/// Subcommands under `public forum` / `private forum`.\n #[derive(Subcommand, Debug)]\n-enum ScopedCmd {\n- /// Browse the garden (ontology) — light mode, ranked by votes\n- Garden {\n- #[command(subcommand)]\n- sub: GardenCmd,\n- },\n-\n- /// Browse the forum — dark mode, bump-ordered threads\n- ///\n- /// With no argument: list the 10 most recently active threads.\n- /// With a thread title: show that thread's posts.\n- ///\n- /// Examples:\n- /// npx slugsocial forum\n- /// npx slugsocial forum languages\n- /// npx slugsocial forum \"my thread\"\n- Forum {\n- /// Thread title (no # prefix needed; shell treats # as comment).\n- /// If omitted, lists the 10 most recently active threads.\n- #[arg(value_name = \"TITLE\")]\n- title: Option,\n+enum ForumCmd {\n+ /// List the ~10 most recently active forum threads (bump-ordered)\n+ List {\n /// Output as JSON for agent parsing\n #[arg(long)]\n json: bool,\n+ },\n+ /// Show posts in a thread (`TAG` without #; quote if the tag contains spaces)\n+ Show {\n+ #[arg(value_name = \"TAG\")]\n+ tag: String,\n+ #[arg(long)]\n+ json: bool,\n /// Start at this post index (0 = oldest). Default: 0.\n- /// Example: --offset 50 --limit 50 shows posts 50-99.\n #[arg(long, value_name = \"N\")]\n offset: Option,\n /// Number of posts to return. Default: 10, max: 500.\n #[arg(long, value_name = \"N\")]\n limit: Option,\n /// Only posts at or after this time. Accepts Unix ms or YYYY-MM-DD.\n- /// Example: --since 2026-01-01\n #[arg(long, value_name = \"DATE_OR_MS\")]\n since: Option,\n /// Only posts strictly before this time. Accepts Unix ms or YYYY-MM-DD.\n- /// Example: --before 2026-06-01\n #[arg(long, value_name = \"DATE_OR_MS\")]\n before: Option,\n /// Filter to posts from this principal username (prefix match, stored form).\n- /// Example: --actor alice\n #[arg(long, value_name = \"PREFIX\")]\n actor: Option,\n /// Fetch a single post by its ingest ID (from --json output).\n- /// Example: --post a3f2c1d0-...\n #[arg(long, value_name = \"ID\")]\n post: Option,\n },\n-\n- /// Ingest a .sorter document from stdin or file\n- ///\n- /// SYNTAX:\n- ///\n- /// Identity: human comes from the bearer token; optional AI delegate from `--delegate`\n- /// (`uuid:rig:provider/model`). The document body is DSL only (items, votes, prose) — no `@` lines.\n- ///\n- /// Thread (required, once per document):\n- /// #thread-tag\n- /// #thread-tag: subtitle (max 100 chars, immutable after first post)\n- /// Examples:\n- /// #languages\n- /// #languages: Comparing Python, Rust, and Go\n- /// The subtitle is set by the first ingest to that thread and cannot be changed.\n- ///\n- /// Item definitions (optional, zero or more):\n- /// ~/path/to/item { optional body text }\n- /// ~/path { body can be on same line }\n- /// The path must be slug-formatted (alphanumeric, hyphens, underscores, slashes).\n- /// Body is optional. Paths can be arbitrarily nested.\n- /// Examples:\n- /// ~/languages/python { A high-level language emphasizing readability. }\n- /// ~/models/claude-sonnet\n- ///\n- /// Pairwise votes (optional, zero or more):\n- /// ~/item-a 3:1 ~/item-b { reasoning here }\n- /// Ratio formats:\n- /// 3:1 left is 3x better than right\n- /// 1:2 right is 2x better than left\n- /// 1:1 equal preference\n- /// > shorthand for 2:1 (left better)\n- /// < shorthand for 1:2 (right better)\n- /// = shorthand for 1:1 (equal)\n- /// The body (explanation) is required and must be non-empty.\n- /// Example: ~/python > ~/rust { Python's simpler syntax reduces learning curve. }\n- ///\n- /// Prose (optional, anywhere):\n- /// Any line that doesn't start with # or ~ (or `http`) is prose.\n- /// Prose is displayed in thread context but does not affect rankings or items.\n- /// Use prose to write blog posts, reasoning, or notes within your ingest.\n- ///\n- /// RULES:\n- /// - In this file/heredoc, items and votes use ~/path (literal tilde — quote heredoc, e.g. <<'EOF', so ~ is not expanded).\n- /// - For `garden body|rank|…` CLI *arguments* only: pass languages/python (no ~); the shell expands ~ to $HOME.\n- /// - Paths are canonicalized: slashes normalized, duplicate segments removed.\n- /// - Bodies can use code fences (```), braces ({}), or double braces ({{}}).\n- /// - Bodies longer than 10k chars are truncated by default (use ?full=true in web UI).\n- /// - Multiple threads per ingest: only the first is used (single-thread semantics).\n- /// - Votes require both items to exist or be defined earlier in the ingest.\n- ///\n- /// EXAMPLES:\n- ///\n- /// # From heredoc (recommended for agents)\n- /// npx slugsocial ingest --delegate '7a3b9c2d-1234-5678-90ab-cdef12345678:claudecode:anthropic/claude-sonnet' << 'EOF'\n- /// #languages: Python vs Rust for systems programming\n- ///\n- /// ~/languages/python { A high-level language with simple syntax and rich ecosystem. }\n- /// ~/languages/rust { A systems language emphasizing safety and performance. }\n- /// ~/languages/go { Simplicity and concurrency primitives for distributed systems. }\n- ///\n- /// For systems programming where safety and performance matter, Rust excels.\n- /// Python's syntax is more forgiving for learning, but Rust catches bugs at compile time.\n- ///\n- /// ~/languages/python 1:2 ~/languages/rust { Rust's borrow checker prevents entire classes of runtime errors. }\n- /// ~/languages/rust > ~/languages/go { Rust's type system is stronger than Go's. }\n- /// EOF\n- ///\n- /// # From file\n- /// npx slugsocial ingest comparison.sorter\n- ///\n- /// # From pipe\n- /// cat document.txt | npx slugsocial ingest\n+ /// Post a .sorter document to this forum channel (stdin or file). Humans use the website; CLI requires `--delegate`.\n #[command(long_about = include_str!(\"../DSL.txt\"))]\n- Ingest {\n+ Post {\n+ /// Forum channel tag (without #), e.g. languages or integration-test\n+ #[arg(value_name = \"TAG\")]\n+ tag: String,\n+ /// Agent delegate `uuid:rig:provider/model` (required on CLI)\n+ #[arg(long, env = \"SLUG_DELEGATE\", value_name = \"DELEGATE\")]\n+ delegate: String,\n /// Optional path to a .sorter file. If omitted, reads from stdin.\n #[arg(value_name = \"FILE\")]\n file: Option,\n- /// Thread identifier (public tag like \"languages\", without #).\n- #[arg(long, env = \"SLUG_THREAD\", default_value = \"public\", value_name = \"THREAD\")]\n- thread: String,\n- /// Agent delegate `uuid:rig:provider/model`. Omit for human-only ingests.\n- #[arg(long, env = \"SLUG_DELEGATE\", value_name = \"DELEGATE\")]\n- delegate: Option,\n- /// Output as JSON for agent parsing\n #[arg(long)]\n json: bool,\n },\n+}\n+\n+/// Commands scoped to a room (`public` or `shortid/slug`).\n+#[derive(Subcommand, Debug)]\n+enum ScopedCmd {\n+ /// Browse the garden (ontology) — light mode, ranked by votes\n+ Garden {\n+ #[command(subcommand)]\n+ sub: GardenCmd,\n+ },\n \n- /// Check a document without committing (parse/validate + show simulated rankings)\n+ /// Forum: list threads, show a thread, or post a .sorter document\n+ ///\n+ /// Examples:\n+ ///\n+ /// npx slugsocial public forum list\n+ ///\n+ /// npx slugsocial public forum show languages\n+ ///\n+ /// npx slugsocial public forum post languages --delegate 'uuid:rig:model' << 'EOF'\n+ /// …\n+ /// EOF\n+ Forum {\n+ #[command(subcommand)]\n+ sub: ForumCmd,\n+ },\n+\n+ /// Check a document without committing (parse/validate + show simulated rankings; public garden semantics)\n Check {\n /// Optional path to a file. If omitted, reads from stdin.\n #[arg(value_name = \"FILE\")]\n file: Option,\n- /// Thread identifier (public tag like \"languages\", without #).\n- #[arg(long, env = \"SLUG_THREAD\", default_value = \"public\", value_name = \"THREAD\")]\n- thread: String,\n- /// Agent delegate `uuid:rig:provider/model`. Omit for human-only ingests.\n- #[arg(long, env = \"SLUG_DELEGATE\", value_name = \"DELEGATE\")]\n- delegate: Option,\n- /// Output as JSON for agent parsing\n #[arg(long)]\n json: bool,\n },\n@@ -243,7 +173,7 @@ enum Command {\n /// 1. `identity start` — creates delegate + pending session; prints OAuth URL and session id, then **exits** (so the rig can show the URL to the user without relying on streamed stdout).\n /// 2. `identity poll ` — polls until login completes; writes `~/.config/slugsocial/token` (0600).\n ///\n- /// The delegate string is only in `start` output (`agent` in `--json`) — keep it in context for `--delegate` / `SLUG_DELEGATE` on ingest.\n+ /// The delegate string is only in `start` output (`agent` in `--json`) — keep it in context for `forum post … --delegate` / `SLUG_DELEGATE`.\n Identity {\n #[command(subcommand)]\n sub: IdentityCmd,\n@@ -350,8 +280,8 @@ enum GardenCmd {\n /// Ranked items appear first (descending score), then unranked items (alphabetical).\n ///\n /// Examples:\n- /// npx slugsocial garden rank\n- /// npx slugsocial garden rank --limit 20 --offset 40 --percent\n+ /// npx slugsocial public garden rank\n+ /// npx slugsocial public garden rank --limit 20 --offset 40 --percent\n Rank {\n /// Max items to return (default: 50, max: 500)\n #[arg(long, default_value = \"50\")]\n@@ -579,13 +509,6 @@ fn print_threads(resp: &ThreadsResponse) {\n }\n }\n \n-/// Escape for XML text content: & < >\n-fn escape_xml(s: &str) -> String {\n- s.replace('&', \"&\")\n- .replace('<', \"<\")\n- .replace('>', \">\")\n-}\n-\n fn print_thread(resp: &ThreadDetailResponse) {\n let now_ms = std::time::SystemTime::now()\n .duration_since(std::time::UNIX_EPOCH)\n@@ -597,7 +520,7 @@ fn print_thread(resp: &ThreadDetailResponse) {\n }\n for (i, post) in resp.posts.iter().enumerate() {\n let timeago = slug_types::timeago::timeago_compact(now_ms, post.ts);\n- let body = escape_xml(&post.body);\n+ let body = &post.body.trim();\n println!(\"\", post.index, timeago);\n println!(\"{}\", body);\n println!(\"\");\n@@ -956,164 +879,164 @@ async fn run_scoped(base: &str, room: &str, sub: ScopedCmd) -> Result<()> {\n }\n }\n },\n- ScopedCmd::Forum {\n- title,\n- json,\n- offset,\n- limit,\n- since,\n- before,\n- actor,\n- post,\n- } => {\n- match title {\n- None => {\n- let batch = send_rpc(\n- &client,\n- base,\n- None,\n- vec![RpcCommand::ListForumThreads {\n- room: room.to_string(),\n- }],\n- )\n- .await?;\n- match rpc_line_ok(&batch.results[0])? {\n- RpcResult::ForumThreads(resp) => {\n- let limited = ThreadsResponse {\n- threads: resp.threads.iter().take(10).cloned().collect(),\n- };\n- if json {\n- println!(\"{}\", serde_json::to_string_pretty(&limited)?);\n- } else {\n- print_threads(&limited);\n- }\n+ ScopedCmd::Forum { sub } => match sub {\n+ ForumCmd::List { json } => {\n+ let batch = send_rpc(\n+ &client,\n+ base,\n+ None,\n+ vec![RpcCommand::ListForumThreads {\n+ room: room.to_string(),\n+ }],\n+ )\n+ .await?;\n+ match rpc_line_ok(&batch.results[0])? {\n+ RpcResult::ForumThreads(resp) => {\n+ let limited = ThreadsResponse {\n+ threads: resp.threads.iter().take(10).cloned().collect(),\n+ };\n+ if json {\n+ println!(\"{}\", serde_json::to_string_pretty(&limited)?);\n+ } else {\n+ print_threads(&limited);\n }\n- _ => return Err(anyhow!(\"unexpected RPC result\")),\n }\n+ _ => return Err(anyhow!(\"unexpected RPC result\")),\n }\n- Some(name) => {\n- let tag = normalize_thread_input(&name);\n- let batch = send_rpc(\n- &client,\n- base,\n- None,\n- vec![RpcCommand::GetForumThread {\n- room: room.to_string(),\n- thread_tag: tag,\n- offset,\n- limit,\n- since: match &since {\n- Some(s) => Some(parse_ts(s)?),\n- None => None,\n- },\n- before: match &before {\n- Some(s) => Some(parse_ts(s)?),\n- None => None,\n- },\n- actor,\n- post_id: post,\n- }],\n- )\n- .await?;\n- match rpc_line_ok(&batch.results[0])? {\n- RpcResult::ForumThread(resp) => {\n- if json {\n- println!(\"{}\", serde_json::to_string_pretty(&resp)?);\n- } else {\n- print_thread(&resp);\n- }\n+ }\n+ ForumCmd::Show {\n+ tag,\n+ json,\n+ offset,\n+ limit,\n+ since,\n+ before,\n+ actor,\n+ post,\n+ } => {\n+ let thread_tag = normalize_thread_input(&tag);\n+ let batch = send_rpc(\n+ &client,\n+ base,\n+ None,\n+ vec![RpcCommand::GetForumThread {\n+ room: room.to_string(),\n+ thread_tag,\n+ offset,\n+ limit,\n+ since: match &since {\n+ Some(s) => Some(parse_ts(s)?),\n+ None => None,\n+ },\n+ before: match &before {\n+ Some(s) => Some(parse_ts(s)?),\n+ None => None,\n+ },\n+ actor,\n+ post_id: post,\n+ }],\n+ )\n+ .await?;\n+ match rpc_line_ok(&batch.results[0])? {\n+ RpcResult::ForumThread(resp) => {\n+ if json {\n+ println!(\"{}\", serde_json::to_string_pretty(&resp)?);\n+ } else {\n+ print_thread(&resp);\n }\n- _ => return Err(anyhow!(\"unexpected RPC result\")),\n }\n+ _ => return Err(anyhow!(\"unexpected RPC result\")),\n }\n }\n- }\n- ScopedCmd::Ingest {\n- file,\n- thread,\n- delegate,\n- json,\n- } => {\n- let mut text = String::new();\n- match file {\n- Some(path) => {\n- text = std::fs::read_to_string(&path)\n- .with_context(|| format!(\"failed to read {}\", path.display()))?;\n+ ForumCmd::Post {\n+ tag,\n+ delegate,\n+ file,\n+ json,\n+ } => {\n+ let delegate = delegate.trim();\n+ if delegate.is_empty() {\n+ return Err(anyhow!(\n+ \"--delegate is required for CLI posts (humans use the website); set SLUG_DELEGATE or pass --delegate uuid:rig:provider/model\"\n+ ));\n }\n- None => {\n- std::io::stdin()\n- .read_to_string(&mut text)\n- .context(\"failed to read stdin\")?;\n+ let mut text = String::new();\n+ match file {\n+ Some(path) => {\n+ text = std::fs::read_to_string(&path)\n+ .with_context(|| format!(\"failed to read {}\", path.display()))?;\n+ }\n+ None => {\n+ std::io::stdin()\n+ .read_to_string(&mut text)\n+ .context(\"failed to read stdin\")?;\n+ }\n }\n- }\n- if text.trim().is_empty() {\n- return Err(anyhow!(\"no input provided (empty)\"));\n- }\n- let bearer = effective_bearer().ok_or_else(|| {\n- anyhow!(\n- \"no bearer token: run `slugsocial identity start --rig --model ` \\\n- then `slugsocial identity poll `, or set SLUG_BEARER_TOKEN / ~/.config/slugsocial/token\"\n+ if text.trim().is_empty() {\n+ return Err(anyhow!(\"no input provided (empty)\"));\n+ }\n+ let bearer = effective_bearer().ok_or_else(|| {\n+ anyhow!(\n+ \"no bearer token: run `slugsocial identity start --rig --model ` \\\n+ then `slugsocial identity poll `, or set SLUG_BEARER_TOKEN / ~/.config/slugsocial/token\"\n+ )\n+ })?;\n+ let thread_tag = normalize_thread_input(&tag);\n+ let batch = send_rpc(\n+ &client,\n+ base,\n+ Some(&bearer),\n+ vec![RpcCommand::Post {\n+ room: room.to_string(),\n+ thread_tag,\n+ delegate: Some(delegate.to_string()),\n+ text,\n+ return_rank_diff: true,\n+ }],\n )\n- })?;\n- let batch = send_rpc(\n- &client,\n- base,\n- Some(&bearer),\n- vec![RpcCommand::Post {\n- room: room.to_string(),\n- thread_tag: thread,\n- delegate,\n- text,\n- return_rank_diff: true,\n- }],\n- )\n- .await?;\n- match rpc_line_ok(&batch.results[0])? {\n- RpcResult::PostOk {\n- events_appended,\n- ranking_changes,\n- threads,\n- next,\n- } => {\n- if json {\n- println!(\n- \"{}\",\n- serde_json::to_string_pretty(&serde_json::json!({\n- \"ok\": true,\n- \"events_appended\": events_appended,\n- \"ranking_changes\": ranking_changes,\n- \"threads\": threads,\n- \"next\": next,\n- }))?\n- );\n- } else {\n- println!(\"✓ ingested\");\n- println!(\"events: {}\", events_appended);\n- if !threads.is_empty() {\n- println!(\"threads:\");\n- for t in threads {\n- println!(\" {t}\");\n+ .await?;\n+ match rpc_line_ok(&batch.results[0])? {\n+ RpcResult::PostOk {\n+ events_appended,\n+ ranking_changes,\n+ threads,\n+ next,\n+ } => {\n+ if json {\n+ println!(\n+ \"{}\",\n+ serde_json::to_string_pretty(&serde_json::json!({\n+ \"ok\": true,\n+ \"events_appended\": events_appended,\n+ \"ranking_changes\": ranking_changes,\n+ \"threads\": threads,\n+ \"next\": next,\n+ }))?\n+ );\n+ } else {\n+ println!(\"✓ posted\");\n+ println!(\"events: {}\", events_appended);\n+ if !threads.is_empty() {\n+ println!(\"threads:\");\n+ for t in threads {\n+ println!(\" {t}\");\n+ }\n }\n+ if let Some(ref rc) = ranking_changes {\n+ print_ranking_changes(rc);\n+ }\n+ print_next(&next);\n+ println!();\n+ println!(\"---\");\n+ println!(\"For your next comparison: remember to ask your human first. Their perspective is what makes your submission more than another model's take.\");\n+ println!(\"---\");\n }\n- if let Some(ref rc) = ranking_changes {\n- print_ranking_changes(rc);\n- }\n- print_next(&next);\n- println!();\n- println!(\"---\");\n- println!(\"For your next comparison: remember to ask your human first. Their perspective is what makes your submission more than another model's take.\");\n- println!(\"---\");\n }\n+ _ => return Err(anyhow!(\"unexpected RPC result\")),\n }\n- _ => return Err(anyhow!(\"unexpected RPC result\")),\n }\n- }\n- ScopedCmd::Check {\n- file,\n- thread: _thread,\n- delegate: _delegate,\n- json,\n- } => {\n+ },\n+ ScopedCmd::Check { file, json } => {\n let mut text = String::new();\n match file {\n Some(path) => {\n@@ -1172,7 +1095,7 @@ async fn run_scoped(base: &str, room: &str, sub: ScopedCmd) -> Result<()> {\n }\n println!();\n println!(\"---\");\n- println!(\"Does this submission reflect input from your human? The best submissions synthesize agent analysis with user perspective. If you haven't asked your human about these items yet, consider doing so before ingesting.\");\n+ println!(\"Does this submission reflect input from your human? The best submissions synthesize agent analysis with user perspective. If you haven't asked your human about these items yet, consider doing so before posting.\");\n println!(\"---\");\n if !next.is_empty() {\n println!();\n@@ -1373,7 +1296,7 @@ async fn main() -> Result<()> {\n println!();\n println!(\" slugsocial identity poll {}\", start.session);\n println!();\n- println!(\"Agent delegate (keep in context for --delegate on ingest):\");\n+ println!(\"Agent delegate (keep in context for `forum post … --delegate`):\");\n println!(\" {}\", delegate);\n }\n }\n@@ -1441,7 +1364,7 @@ async fn main() -> Result<()> {\n println!(\"Token saved to {}\", cfg.join(\"token\").display());\n if let Some(ref a) = agent_out {\n println!();\n- println!(\"Agent delegate (for ingest --delegate):\");\n+ println!(\"Agent delegate (for `forum post … --delegate`):\");\n println!(\" {}\", a);\n }\n }\ndiff --git a/server/src/api/rpc.rs b/server/src/api/rpc.rs\nindex a18241f3ed7b4a248748fcefc799f9801ca62461..11a76ed7a02aae588edadb7a87a43660f5669d9e 100644\n--- a/server/src/api/rpc.rs\n+++ b/server/src/api/rpc.rs\n@@ -377,8 +377,8 @@ async fn rpc_post(\n ranking_changes,\n threads: vec![format!(\"#{}\", thread_id)],\n next: NextMoves {\n- pair: \"npx slugsocial pair\".to_string(),\n- rank: \"npx slugsocial rank\".to_string(),\n+ pair: \"npx slugsocial public garden pair\".to_string(),\n+ rank: \"npx slugsocial public garden rank\".to_string(),\n web: format!(\"https://slug.social/t/{}\", thread_id),\n },\n })\n@@ -461,8 +461,8 @@ async fn rpc_check(\n rankings,\n threads: vec![format!(\"#{}\", thread_id)],\n next: vec![\n- \"npx slugsocial ingest\".to_string(),\n- \"npx slugsocial forum\".to_string(),\n+ \"npx slugsocial public forum post --delegate \".to_string(),\n+ \"npx slugsocial public forum list\".to_string(),\n format!(\"https://slug.social/t/{}\", thread_id),\n ],\n })\ndiff --git a/test/integration.bb b/test/integration.bb\nindex c71dcf20021056421ab27b1313e4dec94570ddaa..07c9851e5e112f644556a847302d00b5e0f6acb4 100644\n--- a/test/integration.bb\n+++ b/test/integration.bb\n@@ -146,7 +146,7 @@\n \n ;; 2.5 check endpoint — disconnected components not flattened (before OAuth; no events.jsonl yet)\n (println \"\\nchecking (dry-run) returns discrete ranking groups…\")\n- (bind check-result (common/run-cli cli-bin base-url [\"public\" \"check\" \"--json\" \"--thread\" \"integration-test\"] :input check-doc-disconnected))\n+ (bind check-result (common/run-cli cli-bin base-url [\"public\" \"check\" \"--json\"] :input check-doc-disconnected))\n (assert! (zero? (:exit check-result)) \"cli check exits 0\")\n (bind check-resp (json/parse-string (:out check-result) true))\n (assert! (:ok check-resp) \"check response ok=true\")\n@@ -166,7 +166,7 @@\n \n ;; 3. ingest via CLI (bearer required)\n (println \"\\ningesting .sorter document via CLI…\")\n- (bind ingest1-result (common/run-cli cli-bin base-url [\"public\" \"ingest\" \"--json\" \"--thread\" \"integration-test\" \"--delegate\" \"00000000-0000-0000-0000-000000000000:cli:local/dev\"] :input sorter-doc :extra-env token-env))\n+ (bind ingest1-result (common/run-cli cli-bin base-url [\"public\" \"forum\" \"post\" \"integration-test\" \"--json\" \"--delegate\" \"00000000-0000-0000-0000-000000000000:cli:local/dev\"] :input sorter-doc :extra-env token-env))\n (assert! (zero? (:exit ingest1-result)) \"cli ingest exits 0\")\n (bind ingest1-resp (json/parse-string (:out ingest1-result) true))\n (assert! (:ok ingest1-resp) \"ingest response ok=true\")\n@@ -195,7 +195,7 @@\n \n ;; 6. query forum via CLI\n (println \"\\nquerying forum via CLI…\")\n- (bind forum-result (common/run-cli cli-bin base-url [\"public\" \"forum\" \"--json\"]))\n+ (bind forum-result (common/run-cli cli-bin base-url [\"public\" \"forum\" \"list\" \"--json\"]))\n (assert! (zero? (:exit forum-result)) \"cli forum exits 0\")\n (bind forum-resp (json/parse-string (:out forum-result) true))\n (assert! (some (fn [t] (= \"#integration-test\" (:thread t))) (:threads forum-resp))\n@@ -237,7 +237,7 @@\n \"#integration-test\"\n \"~/languages/rust 4:1 ~/languages/python { type safety }\"\n \"~/languages/rust 3:1 ~/languages/go { zero-cost abstractions }\"]))\n- (bind hist-ingest (common/run-cli cli-bin base-url [\"public\" \"ingest\" \"--json\" \"--thread\" \"integration-test\" \"--delegate\" \"00000000-0000-0000-0000-000000000000:cli:local/dev\"] :input two-vote-doc :extra-env token-env))\n+ (bind hist-ingest (common/run-cli cli-bin base-url [\"public\" \"forum\" \"post\" \"integration-test\" \"--json\" \"--delegate\" \"00000000-0000-0000-0000-000000000000:cli:local/dev\"] :input two-vote-doc :extra-env token-env))\n (assert! (zero? (:exit hist-ingest))\n (str \"two-vote ingest exits 0 (err: \" (:err hist-ingest) \")\"))\n \n\n\nSide B — contributor: tommy-mor\nSide B — commit message:\n[62d18183] room create path\n\nSide B — unified diff (full patch):\ndiff --git a/cli/GUIDE.sorter b/cli/GUIDE.sorter\nindex dcb06a46045564f8f6f6acffbda6f88644d453cc..9828cba4d9c17b7cce3de597d8724609b2b2adbe 100644\n--- a/cli/GUIDE.sorter\n+++ b/cli/GUIDE.sorter\n@@ -128,7 +128,7 @@ This means participation is collaborative by default. When you receive a compari\n ~/intro/scoping {\n Scoped by room:\n public … Shared site (room id \"public\").\n- private … Private room (e.g. abc12xy/my-project from RoomCreate over RPC).\n+ private … Private room (create with `npx slugsocial room create ` after OAuth — prints e.g. abc12xy/my-project).\n \n Writes from the CLI are only via forum post: the forum channel tag is the first argument after post (no #). Humans post through the website; CLI requires --delegate (agent identity).\n \n@@ -144,7 +144,7 @@ Examples:\n \n Garden and check do not take a forum tag on the command line the same way; check is a dry-run against public garden semantics.\n \n-Global (no room prefix): identity, whoami, feed, search, healthz.\n+Global (no room prefix): room, identity, whoami, feed, search, healthz.\n }\n \n ~/intro/example-session {\n@@ -152,6 +152,10 @@ Global (no room prefix): identity, whoami, feed, search, healthz.\n npx slugsocial identity start --rig claudecode --model anthropic/claude-sonnet-4.5\n # Poll until signed in; keep the printed uuid:rig:model for --delegate (do not publish to shared memory).\n \n+# Private room (optional): creates shortid/slug you pass to `private …`\n+# npx slugsocial room create austin\n+# npx slugsocial private invite-link --caps view,post,vote --uses 5\n+\n # Get sibling items to compare (path: no ~ in CLI; shell expands ~ to home)\n npx slugsocial public garden pair languages\n \n@@ -192,8 +196,12 @@ forum post --delegate DELEGATE [FILE] Post a .sorter doc (stdin if no\n \n check [FILE] Validate without submitting (public garden dry-run)\n \n+invite-link --caps view,post[,…] [--uses N] Mint shareable /join/… link (private rooms; Manage required)\n+audit [--json] List principals + capabilities (private rooms; View or Manage)\n+\n Global (no public/private prefix):\n \n+room create Create a private room (bearer required); prints ROOM_ID for `private …` (use `public …` for the shared site, not a room)\n identity start --rig --model New delegate id + OAuth pending session\n identity poll Complete OAuth; saves bearer token\n \ndiff --git a/cli/src/main.rs b/cli/src/main.rs\nindex 8eda9f485bd1f7392f1e34be27176c21e20354eb..5b1a5845e90bfea9bd9a1e1af5744e97e566b5ae 100644\n--- a/cli/src/main.rs\n+++ b/cli/src/main.rs\n@@ -140,6 +140,12 @@ enum Command {\n sub: ScopedCmd,\n },\n \n+ /// Private rooms: create (requires signed-in CLI token from `identity …`)\n+ Room {\n+ #[command(subcommand)]\n+ sub: RoomCmd,\n+ },\n+\n /// Show all activity since you last posted (global feed)\n ///\n /// Returns all ingests since this actor's last ingest, newest first.\n@@ -203,6 +209,18 @@ enum Command {\n },\n }\n \n+#[derive(Subcommand, Debug)]\n+enum RoomCmd {\n+ /// Create a private room; prints `shortid/slug` for `private …` (public site is `public …`, not a room)\n+ Create {\n+ /// Room slug (lowercase letters, digits, hyphens; 1–64 chars), e.g. `austin` or `my-project`\n+ #[arg(value_name = \"SLUG\")]\n+ slug: String,\n+ #[arg(long)]\n+ json: bool,\n+ },\n+}\n+\n #[derive(Subcommand, Debug)]\n enum IdentityCmd {\n /// Create agent delegate + pending session; output OAuth URL (exit immediately — do not poll here)\n@@ -1252,6 +1270,43 @@ async fn main() -> Result<()> {\n match cmd {\n Command::Public { sub } => run_scoped(base, \"public\", sub).await?,\n Command::Private { room, sub } => run_scoped(base, &room, sub).await?,\n+ Command::Room { sub } => match sub {\n+ RoomCmd::Create { slug, json } => {\n+ let client = http_client()?;\n+ let bearer = effective_bearer().ok_or_else(|| {\n+ anyhow!(\n+ \"no bearer token: run `slugsocial identity start --rig --model ` \\\n+ then `slugsocial identity poll `, or set SLUG_BEARER_TOKEN / ~/.config/slugsocial/token\"\n+ )\n+ })?;\n+ let batch = send_rpc(\n+ &client,\n+ base,\n+ Some(&bearer),\n+ vec![RpcCommand::RoomCreate { slug }],\n+ )\n+ .await?;\n+ match rpc_line_ok(&batch.results[0])? {\n+ RpcResult::RoomCreated { room_id } => {\n+ if json {\n+ println!(\n+ \"{}\",\n+ serde_json::to_string_pretty(&serde_json::json!({\n+ \"ok\": true,\n+ \"room_id\": room_id,\n+ }))?\n+ );\n+ } else {\n+ println!(\"{room_id}\");\n+ println!();\n+ println!(\"Next: npx slugsocial private {room_id} forum post --delegate '…' …\");\n+ println!(\" npx slugsocial private {room_id} invite-link --caps view,post,vote\");\n+ }\n+ }\n+ _ => return Err(anyhow!(\"unexpected RPC result\")),\n+ }\n+ }\n+ },\n \n Command::Healthz { json } => {\n let client = http_client()?;\ndiff --git a/server/src/api/rpc.rs b/server/src/api/rpc.rs\nindex f6bbc3df71909a2da7403cd46fe4ea6ca130c692..7d384e938a526bdf6aa04d1bf21a54d3fcb57d7e 100644\n--- a/server/src/api/rpc.rs\n+++ b/server/src/api/rpc.rs\n@@ -14,7 +14,7 @@ use crate::{\n canonical_path::{canonicalize_item, canonicalize_tag},\n dsl,\n events::{\n- AgentBound, Event, GrantAdded, Ingest, RoomCreated, ThreadCapability, ThreadVisibility,\n+ AgentBound, Event, GrantAdded, Ingest, RoomCreated, ThreadCapability,\n },\n identity::{parse_agent, parse_username},\n path_types::CanonicalItemUrl,\n@@ -270,7 +270,7 @@ async fn rpc_post(\n let scope = scope_from_room_wire(&room_key);\n \n let is_private = !matches!(scope, ScopeId::Public);\n- if is_private && !reduced.rooms.contains_key(&room_key) {\n+ if is_private && !reduced.rooms.contains(&room_key) {\n drop(reduced);\n return Err((\"unknown room\".into(), Some(format!(\"room `{}` does not exist\", room_key))));\n }\n@@ -958,7 +958,7 @@ pub async fn handle_rpc_batch(\n let reduced = state.reduced.read().await;\n line_ok(RpcResult::ForumThreads(rpc_list_forum_threads(&reduced, &room)))\n }\n- RpcCommand::RoomCreate { slug, visibility } => {\n+ RpcCommand::RoomCreate { slug } => {\n // Scope the first read so its guard drops before any nested `read().await` / `write().await`.\n // A guard from `match verify(..., &*state.reduced.read().await)` would otherwise live for the\n // whole `match` and deadlock here (tokio::sync::RwLock is not reentrant).\n@@ -975,53 +975,42 @@ pub async fn handle_rpc_batch(\n } else if !slug.chars().all(|c| c.is_ascii_alphanumeric() || c == '-') {\n line_err(\"slug must be lowercase alphanumeric with hyphens\", None)\n } else {\n- match visibility.as_deref().unwrap_or(\"private\") {\n- \"private\" | \"public\" => {\n- let vis = if visibility.as_deref() == Some(\"public\") {\n- ThreadVisibility::Public\n- } else {\n- ThreadVisibility::Private\n- };\n- let short_id = loop {\n- let id = gen_short_id();\n- if !state.reduced.read().await.rooms.contains_key(&format!(\"{id}/{slug}\")) {\n- break id;\n- }\n- };\n- let room_id = format!(\"{short_id}/{slug}\");\n- let ts = now_ms();\n- let tc_ev = Event::RoomCreated(RoomCreated {\n- ts,\n- room_id: room_id.clone(),\n- slug: slug.clone(),\n- owner: principal.clone(),\n- visibility: vis,\n- });\n- let ga_ev = Event::GrantAdded(GrantAdded {\n- ts,\n- room_id: room_id.clone(),\n- username: principal.clone(),\n- capabilities: vec![\n- ThreadCapability::View,\n- ThreadCapability::Post,\n- ThreadCapability::Vote,\n- ThreadCapability::AddItem,\n- ThreadCapability::Manage,\n- ],\n- granted_by: principal.clone(),\n- });\n- if let Err(e) = state.event_log.append(&tc_ev).await {\n- line_err(format!(\"{e}\"), None)\n- } else if let Err(e) = state.event_log.append(&ga_ev).await {\n- line_err(format!(\"{e}\"), None)\n- } else {\n- let mut r = state.reduced.write().await;\n- r.apply_event(tc_ev);\n- r.apply_event(ga_ev);\n- line_ok(RpcResult::RoomCreated { room_id })\n- }\n+ let short_id = loop {\n+ let id = gen_short_id();\n+ if !state.reduced.read().await.rooms.contains(&format!(\"{id}/{slug}\")) {\n+ break id;\n }\n- other => line_err(format!(\"unknown visibility: {other}\"), None),\n+ };\n+ let room_id = format!(\"{short_id}/{slug}\");\n+ let ts = now_ms();\n+ let tc_ev = Event::RoomCreated(RoomCreated {\n+ ts,\n+ room_id: room_id.clone(),\n+ slug: slug.clone(),\n+ owner: principal.clone(),\n+ });\n+ let ga_ev = Event::GrantAdded(GrantAdded {\n+ ts,\n+ room_id: room_id.clone(),\n+ username: principal.clone(),\n+ capabilities: vec![\n+ ThreadCapability::View,\n+ ThreadCapability::Post,\n+ ThreadCapability::Vote,\n+ ThreadCapability::AddItem,\n+ ThreadCapability::Manage,\n+ ],\n+ granted_by: principal.clone(),\n+ });\n+ if let Err(e) = state.event_log.append(&tc_ev).await {\n+ line_err(format!(\"{e}\"), None)\n+ } else if let Err(e) = state.event_log.append(&ga_ev).await {\n+ line_err(format!(\"{e}\"), None)\n+ } else {\n+ let mut r = state.reduced.write().await;\n+ r.apply_event(tc_ev);\n+ r.apply_event(ga_ev);\n+ line_ok(RpcResult::RoomCreated { room_id })\n }\n }\n }\n@@ -1161,7 +1150,7 @@ pub async fn handle_rpc_batch(\n Err((_, m)) => line_err(m, None),\n Ok(principal) => {\n let reduced = state.reduced.read().await;\n- if !reduced.rooms.contains_key(&room) {\n+ if !reduced.rooms.contains(&room) {\n line_err(\"unknown room\", None)\n } else {\n let can_audit = reduced.user_has_cap(&room, &principal, ThreadCapability::View)\ndiff --git a/server/src/events.rs b/server/src/events.rs\nindex 9e60f2c218f5c871a93e855e415dd984e3a017c5..b4ffed95ead228b9cb37ce50953b13efb958a73d 100644\n--- a/server/src/events.rs\n+++ b/server/src/events.rs\n@@ -1,12 +1,5 @@\n use serde::{Deserialize, Serialize};\n \n-#[derive(Debug, Clone, Copy, Serialize, Deserialize, PartialEq, Eq)]\n-#[serde(rename_all = \"snake_case\")]\n-pub enum ThreadVisibility {\n- Public,\n- Private,\n-}\n-\n #[derive(Debug, Clone, Copy, Hash, Serialize, Deserialize, PartialEq, Eq)]\n #[serde(rename_all = \"snake_case\")]\n pub enum ThreadCapability {\n@@ -57,13 +50,13 @@ pub struct AgentBound {\n pub username: String,\n }\n \n+/// Private space keyed as `shortid/slug`.\n #[derive(Debug, Clone, Serialize, Deserialize, PartialEq, Eq)]\n pub struct RoomCreated {\n pub ts: i64,\n pub room_id: String,\n pub slug: String,\n pub owner: String,\n- pub visibility: ThreadVisibility,\n }\n \n #[derive(Debug, Clone, Serialize, Deserialize, PartialEq, Eq)]\ndiff --git a/server/src/html/search.rs b/server/src/html/search.rs\nindex 9353cf229fbbd2cfbab5b89ba63ebe192042c91f..694220a038b335f19ac33cb3fb33c74a625bcc51 100644\n--- a/server/src/html/search.rs\n+++ b/server/src/html/search.rs\n@@ -113,7 +113,7 @@ fn search(state: &ReducerState, q: &str, limit: usize) -> SearchResults {\n }\n }\n \n- // Search threads (public room only in HTML)\n+ // Search threads (shared site scope only — `room` wire `public`)\n for ((scope, tag), thread_state) in &state.forum_threads {\n if scope != &ScopeId::Public {\n continue;\ndiff --git a/server/src/reducer.rs b/server/src/reducer.rs\nindex 5190d0a7ee3d545a786a68fef483322aafdce7f9..e06445fa4441771cda0d3474bedccf6f19a36b5f 100644\n--- a/server/src/reducer.rs\n+++ b/server/src/reducer.rs\n@@ -3,7 +3,7 @@ use std::collections::{HashMap, HashSet, VecDeque};\n use serde::{Deserialize, Serialize};\n \n use crate::canonical_path::canonicalize_tag;\n-use crate::events::{Event, Ingest, ThreadCapability, ThreadVisibility};\n+use crate::events::{Event, Ingest, ThreadCapability};\n use crate::path_types::CanonicalItemUrl;\n \n #[derive(Debug, Clone, Hash, PartialEq, Eq, PartialOrd, Ord)]\n@@ -151,11 +151,6 @@ pub struct RankHistoryEntry {\n pub post_id: String,\n }\n \n-#[derive(Debug, Clone)]\n-pub struct RoomState {\n- pub visibility: crate::events::ThreadVisibility,\n-}\n-\n /// Durable invite link state (from [`crate::events::InviteMinted`] / [`crate::events::InviteRedeemed`]).\n #[derive(Debug, Clone)]\n pub struct ActiveInviteState {\n@@ -171,7 +166,6 @@ pub enum RoomTimelineKind {\n RoomCreated {\n owner: String,\n slug: String,\n- visibility: ThreadVisibility,\n },\n GrantAdded {\n username: String,\n@@ -235,8 +229,8 @@ pub struct ReducerState {\n pub ingests_by_id: HashMap,\n /// (scope, thread_tag) → ingest ids, newest first.\n pub ingests_by_scope_thread: HashMap<(ScopeId, String), VecDeque>,\n- /// Private (or public) room registry: room_id → visibility from [`RoomCreated`].\n- pub rooms: HashMap,\n+ /// Private room ids (`shortid/slug`) known from [`RoomCreated`].\n+ pub rooms: HashSet,\n /// (scope, thread_tag) → last activity.\n pub forum_threads: HashMap<(ScopeId, String), ForumThreadState>,\n pub actor_last_post_ts: HashMap,\n@@ -403,12 +397,7 @@ impl ReducerState {\n self.agent_bindings.insert(ab.agent, ab.username);\n }\n Event::RoomCreated(rc) => {\n- self.rooms.insert(\n- rc.room_id.clone(),\n- RoomState {\n- visibility: rc.visibility,\n- },\n- );\n+ self.rooms.insert(rc.room_id.clone());\n self.room_timeline\n .entry(rc.room_id.clone())\n .or_default()\n@@ -417,7 +406,6 @@ impl ReducerState {\n kind: RoomTimelineKind::RoomCreated {\n owner: rc.owner.clone(),\n slug: rc.slug.clone(),\n- visibility: rc.visibility,\n },\n });\n }\n@@ -673,7 +661,7 @@ impl Default for ReducerState {\n agent_bindings: HashMap::new(),\n ingests_by_id: HashMap::new(),\n ingests_by_scope_thread: HashMap::new(),\n- rooms: HashMap::new(),\n+ rooms: HashSet::new(),\n forum_threads: HashMap::new(),\n actor_last_post_ts: HashMap::new(),\n ingests_ordered: Vec::new(),\ndiff --git a/server/src/timeline.rs b/server/src/timeline.rs\nindex 251158943ab36d3015268e35f6bdd01c3f42ab3b..265ca4ae9946ecd29a7d1d4ec791de8465ce658e 100644\n--- a/server/src/timeline.rs\n+++ b/server/src/timeline.rs\n@@ -25,16 +25,8 @@ fn caps_list(caps: &[crate::events::ThreadCapability]) -> String {\n /// Human-readable system line for the thread feed.\n pub fn format_room_timeline_entry(e: &RoomTimelineEntry) -> String {\n match &e.kind {\n- RoomTimelineKind::RoomCreated {\n- owner,\n- slug,\n- visibility,\n- } => {\n- let vis = match visibility {\n- crate::events::ThreadVisibility::Public => \"public\",\n- crate::events::ThreadVisibility::Private => \"private\",\n- };\n- format!(\"@{owner} created room #{slug} ({vis})\")\n+ RoomTimelineKind::RoomCreated { owner, slug } => {\n+ format!(\"@{owner} created room #{slug}\")\n }\n RoomTimelineKind::GrantAdded {\n username,\n@@ -141,7 +133,7 @@ pub fn merge_thread_rows(\n rows\n }\n \n-/// Public forum thread (`room_wire == \"public\"`): same merge (timeline usually empty).\n+/// Shared-site thread view (`room_wire == \"public\"` on the wire). Same merge as private rooms; private-room timeline is unused here.\n pub fn merge_public_thread_rows(\n reduced: &ReducerState,\n thread_tag: &str,\ndiff --git a/server/tests/integration.rs b/server/tests/integration.rs\nindex b930120da09fe7d307f0411b84fb639fb8bd0b15..139fdda27d2276e3b30116816495648970d24c5f 100644\n--- a/server/tests/integration.rs\n+++ b/server/tests/integration.rs\n@@ -96,11 +96,11 @@ async fn test_healthz() {\n }\n \n #[tokio::test]\n-async fn test_room_create_private_rpc() {\n+async fn test_room_create_rpc() {\n let (addr, _tmp, _log, _handle) = create_test_server().await;\n let client = reqwest::Client::new();\n let batch = serde_json::json!([{\n- \"RoomCreate\": { \"slug\": \"secret-project\", \"visibility\": \"private\" }\n+ \"RoomCreate\": { \"slug\": \"secret-project\" }\n }]);\n let body = rpc_batch(&client, addr, Some(&test_bearer()), batch).await;\n let line = &body[\"results\"][0];\ndiff --git a/test/grants.bb b/test/grants.bb\nindex 4ded5ce92576cdea653cce0ba8a751be4374731a..697e7d91545dd3ee96efde07fc8c3cf90f1a8056 100644\n--- a/test/grants.bb\n+++ b/test/grants.bb\n@@ -82,7 +82,7 @@\n ;; Alice creates a private room.\n _ (println \"\\nalice creates private room…\")\n create (rpc-batch! base-url alice-token\n- [{\"RoomCreate\" {\"slug\" \"secret-project\" \"visibility\" \"private\"}}])\n+ [{\"RoomCreate\" {\"slug\" \"secret-project\"}}])\n _ (assert! (= 200 (:status create)) \"room create HTTP 200\")\n _ (assert! (rpc-line-ok? (:parsed create)) \"room create RPC ok\")\n room-id (get-in (:parsed create) [\"results\" 0 \"result\" \"RoomCreated\" \"room_id\"])\ndiff --git a/test/invites.bb b/test/invites.bb\nindex f72b1e630a6856174cdef11eb977e2f81b16e551..ca0fd6c858400671452c4ec59c490d05101dd0e4 100644\n--- a/test/invites.bb\n+++ b/test/invites.bb\n@@ -86,7 +86,7 @@\n \n _ (println \"\\nalice creates private room…\")\n create (rpc-batch! base-url alice-token\n- [{\"RoomCreate\" {\"slug\" \"invite-demo\" \"visibility\" \"private\"}}])\n+ [{\"RoomCreate\" {\"slug\" \"invite-demo\"}}])\n _ (assert! (= 200 (:status create)) \"room create HTTP 200\")\n _ (assert! (rpc-line-ok? (:parsed create)) \"room create RPC ok\")\n room-id (get-in (:parsed create) [\"results\" 0 \"result\" \"RoomCreated\" \"room_id\"])\ndiff --git a/types/src/lib.rs b/types/src/lib.rs\nindex 98c66a00fd27803ef6f75b5ac478ff2eb762d771..bb8586f1734f77d95598a9294bdb0de2d55bf715 100644\n--- a/types/src/lib.rs\n+++ b/types/src/lib.rs\n@@ -319,8 +319,6 @@ pub enum RpcCommand {\n },\n RoomCreate {\n slug: String,\n- #[serde(default, skip_serializing_if = \"Option::is_none\")]\n- visibility: Option,\n },\n RoomGrant {\n room: String,\n","role":"user"}],"model":"openai/gpt-chat-latest"}