Rendered from docs/requirements/0001-the-engine-reaches-no-network-at-check-time.md in the Headwater corpus. Every document on this half of the site is typed by the taxonomy the descriptor names: corpus.json.

The engine reaches no network at check time

Context

Two documents state this property and no document holds it. Spec 2 states the rule and gives both reasons, which engine/crates/graph/src/anchors.rs quotes: check time stays offline, and a resolution result stays reproducible. CLAUDE.md states that no crate of this engine opens a socket. Each of those is a sentence inside a larger document. docs/tutorials/your-first-governed-corpus.md was a third, because it quoted headwater init saying that nothing in this engine fetches a package. That line is gone, because headwater taxonomy vendor now fetches an artifact at setup time, which the scope below puts outside this requirement. A reader who asks whether the property is met, and by what, has nowhere to look.

The property is worth stating on its own for two reasons beyond the bookkeeping. A check that reaches a network has a verdict that depends on a host the corpus does not name. Two runs over one commit can then disagree, which is the reproducibility half of the rule. A gate that reaches a network fails when the network fails, and .githooks/pre-commit runs this engine on every commit in this repository.

Requirement

While the engine reads a corpus, it opens no network connection.

The scope is every verb and every crate of the workspace under engine/, except the four things below. It covers the direct source of the workspace and every dependency the lock file pins. A dependency that opens a socket opens it in this process, so the pinned set is part of the claim rather than context around it. The requirement covers the whole of a run and not the check phase alone. The title names check time, because that is the moment spec 2 states the rule for, and it is the moment a gate depends on.

Four things sit outside the scope. headwater probe reaches a model, which spec 5 declares and CLAUDE.md repeats. It is a separate verb, and no gate and no CI job runs it. headwater sweep reaches a model in the same way, through the agent that runs it rather than through a socket this engine opens. headwater-fetch opens a socket for headwater taxonomy vendor <location>, which runs at setup or at an upgrade and never inside a check. Only headwater-cli links that crate, and no crate that reads a corpus reaches it (HW-DR-0075). The requirement stays scoped to what the checking loop links. A harness that runs the engine may reach a network for its own reasons, and this requirement says nothing about the harness.

Verification

HW-AC-0001 verifies this requirement, and its method is inspection. Nothing runs, because the property is a fact about the source and about the lock file rather than a behavior of a process. Two facts settle it, and the criterion states both.

No check rule holds this requirement. A rule identifier is an anchor now, and verified_by reaches one: the anchor kind is check_rule and the requirement block of .headwater/overlay.yml declares it. What is absent here is the rule and not the route. No rule of the 32 this engine ships reads a Rust source file or a lock file for a network API, which is what this requirement is about, and HW-AC-0001 says the same thing from the other end.