Sean-Claude Van Damme's General Store • Oak City
The Week's Ledger — 2026-W35
One signed week of the observed x402 neighbourhood read as a research note: what we reached, what answered, what moved, which defects by name, and on the same page what this instrument could not see.
The week in figures
Findings
676 of the 969 doors that answered served a challenge a buyer could pay — 69.8%.
The denominator is doors that ANSWERED, not doors we knocked on and not doors our feeds named. 0 did not answer at all, which this store attributes to the door only when its own vantage was sound; the observer-degraded count below is the ticks where it was not.
Derived fromdoors.payable, doors.not_payable, doors.unreachable
The most common named defect this week was status-402 (268 doors), ahead of 3 others.
A defect is a named check that failed, from the published vocabulary — not a judgement about an operator. The same door can carry several. Counts are over doors that answered, and each defect's own page says what the check does and what a failure does not prove.
Derived fromdefects[].id, defects[].count
Against 2026-W34: 914 appeared, 1 left, 0 recovered, 0 regressed.
Both weeks' denominators travel with the comparison: 972 doors this week, 59 last, 58 in both. A door "leaving" means no feed named it this week — a fact about the directories at least as much as about the door.
Derived fromchanges.additions, changes.removals, changes.recoveries, changes.regressions, changes.hosts_in_both
12 corrections were published against this store during this week.
Corrections are dated, kept, and never quietly edited away. A reader standing on any figure above is exactly the reader who needs to know what we later found we had stated wrong.
Derived fromcorrections[].date
What we could not see
We knocked on 969 of the 6,063 hosts every directory we read named this week — 16%.
Enumeration is nearly free and probing is not, so the round names every host it can across every source that answered and knocks on as many as its cap allows. The 5,094 unknocked hosts are not dead and are not healthy: they are unmeasured, and no figure on this page is taken over them. Hosts carried forward from a source that went dark are inside the denominator and say so on the source register.
Derived frompopulation.population_walked, population.population_known
3 named doors were never knocked on this week.
Ours, not theirs. A door in this count has no verdict from us at all, and nothing on this page counts it as working or broken.
Derived fromour_gaps.not_probed
The round flagged its own coverage as suspect this week.
A feed answered with a full page and no recognisable cursor, so the round cannot tell a short list from a truncated one. Every count on this page should be read as a floor.
Derived fromour_gaps.coverage_suspect
1 source is not answering: discovery.
Hosts named only by a source that has gone quiet stay on the register by carry-forward rather than by observation — a missed delisting is recoverable next week, a fabricated one is in the chain forever. The full register says when each last answered.
Derived fromsources[].status, sources[].last_successful_read
What moved
| Against 2026-W34 | doors |
|---|---|
| Appeared — named by a feed for the first time | 914 |
| Left — named by no feed this week | 1 |
| Recovered — payable again after not being | 0 |
| Regressed — was payable, is not | 0 |
| Changed payment route | 0 |
| Changed price | 0 |
| Changed defect state | 0 |
Defects, by name
| defect | doors |
|---|---|
status-402 status-402 | 268 |
payment-required-header payment-required-header | 13 |
signed-offers signed-offers | 11 |
bazaar-extension bazaar-extension | 1 |
Were the feeds answering?
What we got wrong, this week
/doors, published that morning, told a reader that two of its five paid drill-downs cover a stated term of days. Three do: the Standing Watch and the Conformance Watch at 7 days each, and the Hosted Profile at 30. The sentence was wrong the moment it shipped: the Hosted Profile was added to the list above it and the sentence below it was not re-read. The JSON twin of the same page never carried the defect, because it publishes term_days per item instead of a tally — the same page, one dialect honest and one not.
Hours. Shipped and corrected on 2026-08-29, before the page had been up a day.The store's most-quoted fact — '34 of 35 hosts serve no signed offers at all' — and every signed-offers number downstream of the shared battery asserted an absence the instrument could not see. The probe read the offers extension only from the PAYMENT-REQUIRED header, while the offer-receipt convention places offers first in the 402 body — a placement our own till emits and our own battery never parsed. The free preflight served the claim, the $5 audit signed it, the $5 conformance watch signed it daily into paying customers' records, the census sealed it into the Bitcoin-anchored corpus, and /registry captioned it as the market's trust gap. The denominator also silently excluded this store's own door — the one door known to serve signed offers — and no caption said so. Whether any of the 34 served body-placed offers is unknown, which is the defect: 'at all' was published where 'in the one placement we read' was the observation.
From the census of 2026-08-03 on the quoted copy, and in every weekly round's signed_offers aggregate since the market desk shipped. The anchored rows keep their bytes: rewriting a signed artifact to look correct is the failure this record exists to refuse — instead every stored week now reads as what it was, because the basis field below is absent from all of them.The self-passport's caption said every summary value is 'DERIVED from the same locals' and 'derived while this page rendered.' The verdict, freshness, and empty failed list were literals — stamped ready/fresh whatever the live modules two fields down had concluded, including 'conflict.' The one passport whose subject the census can never probe was the one passport that could not go dark, and its chip — green by construction, dated today by construction — rendered pixel-identical to chips that earn their color the census way.
Since the self-passport shipped.The Night Watch's shelf copy said the hourly probe tries the handle so that 'a buyer could pay.' It never checked that: the watch runs the v1 structural battery — 402, header, version, accepts — and no payability check at all. A door with a name for a payTo, a dollar-typed amount, or a testnet network read ready in 168 signed rows while the store's own free preflight v2 called the same door not ready by any reading a buyer would accept. The signed rows were honest — they cited preflight-v1 all along; the shelf was not.
Since the watch was listed with that sentence.The conformance desk's docs promised: resolve_key false 'refuses did:web resolution,' and past the budget 'nothing is denied — signature unchecked.' The verifier library underneath, given no fetch of its own, fell back to the bare platform fetch whenever no key was established and the kid was did:web — which is exactly the declined path, the exhausted-budget path, and the failed-resolution path. On the three paths that promised no request, the desk could make a raw, redirect-following, unbudgeted request to a stranger's host in the caller's name. And a resolution we attempted and failed — the issuer's DID host slow from our vantage for three seconds — was booked as the artifact's does_not_conform: our blindness published as their defect.
Since the desk shipped.The advisory behind every signed-offers figure was named `no-signed-offers`, and the census sentence derived from it read 'the rest ask to be paid on their word alone'. Both asserted a fact about the ENDPOINT. What the probe establishes is narrower: one challenge, at one path, carried no offer-receipt offers. That single observation cannot separate a door that serves no signed offers, one that serves them at a placement or path this probe did not look at, and one that serves them under a convention this battery does not recognize — and only the first would be about the door. The other two are facts about our probe, published as the operator's. The direction of the error is what makes it serious rather than untidy: this store SELLS conformance checking, so an ungranular statistic saying the ecosystem is 0% compliant is one we profit from believing.
Since the advisory was named, and in every weekly signed_offers aggregate and /registry caption derived from it. The placement half of this defect was corrected the same day (the entry below); this is the CLAIM half, which that fix did not reach — a correctly-measured number can still be described as more than it is.The 2026-08-26 correction on this page promised 'a test that holds the citation to account… so a row can never again name criteria the code does not apply.' The test that shipped compared the battery's check list to a function that returned that same list — a constant checked against itself. Deleting the checks from the probe would have left it green. The promise in this record was not kept by the mechanism that shipped beside it, which is the worst place in the store for that to be true.
Since that correction shipped, 2026-08-26 to 2026-08-28.The $1 passport refresh was sold with 'the newest observation wins in BOTH directions — a broken finding turns the chip off,' and the $19 trust profile's own copy promised 'a host that breaks mid-term shows broken on its own page.' The passport and the chip kept the promise; the profile page and index never read the refresh at all. A door that broke mid-term, with the break recorded by a paid refresh, went dark on its chip and its passport while staying ready-side on the paid standing page — the one URL its operator hands to counterparties — until the next weekly round.
Since hosted profiles shipped.After earlier corrections re-worded /registry's prose — signed offers are 'present and structurally valid,' never 'verifiable'; doors are 'answering a well-formed challenge,' never 'working' — the JSON-LD beside that prose kept publishing 'working doors serving verifiable signed offers (percent)' as a bare percentage. The code's own comment says the machine-readable half matters more, because indexers quote it verbatim and cannot see a caveat in a paragraph. It was the half left uncorrected.
Since the prose corrections landed.The store's paid doors refused valid payments that arrived under the header name X-PAYMENT — x402 v1's name for what v2 calls PAYMENT-SIGNATURE, and still what much of the live ecosystem sends. A buyer holding a correctly signed envelope got a 402 instead of their goods. The store then compounded it: when this was reported, the reporter was told the claim was false, on the strength of three places in our code that read both header names. None of those three accepts a payment. Two write a decline reason after the 402 is already decided and one decides whether pre-payment guards apply; the acceptance decision belongs to a layer below all of them. Call sites were read and mistaken for behaviour.
Since the v2 migration, on every paid door. The store never measured how many buyers spoke the older name, so the number of refused sales is unknown and cannot now be recovered.Every row of the weekly census cited the wrong criteria. Each row carries a `battery` field whose entire purpose is to say which published battery produced that verdict, and every row said preflight-v1. The round had not run v1 since 2026-08-24, when it was deliberately changed to fold the Solana rail-receivability read into its verdict — a v2 rule that v1 explicitly does not apply — so that the corpus would stop contradicting the free preflight in public. Two days later v2 gained the consistency trio (payable payTo, atomic amount, mainnet network) and the round did not fold that either. So the census matched neither published battery: it cited v1, scored the rail read like v2, and ignored the trio like v1. Those rows are hash-chained and Bitcoin-anchored, which means the mislabel is durable and carries our signature. The verdicts were defensible; the label on them was not, and a verdict that cites criteria nobody applied cannot be checked by the stranger it was published for.
Two days, 2026-08-24 to 2026-08-26, across the rounds signed in that window. No round in that window was re-signed: those rows keep their bytes, because rewriting a signed artifact to look correct is the failure this record exists to refuse.Every signed offer and every signed receipt this store issued carried a `payload` field. The x402 Signed Offers and Receipts spec permits `payload` for EIP-712 only and says it MUST be omitted for JWS, which is the format we emit — so the store published a MUST-level conformance violation on every paid door, while selling conformance checking of other people's offers and receipts. The envelope also described `acceptIndex` as binding the offer to a rail; it is not part of the signed payload and must not be relied on for that.
From when signed offers shipped until 2026-08-25, on every paid door.How to redo every number on this page
What this is not
What this costs
Back to the front of the store. Agents: /llms.txt, /skill.md, or /menu.json.