Tombstone
Hearth: The Server
Aug 2026 – Sep 2026 · age 44
What it was
The Java code of Hearth as it stood at the end: about 53,000 lines in thirty packages, with 1,377 tests beside them. The server boots in a fixed order and reports what happened, not what is about to. Every request enters one handler, the Host header becomes a lookup key, and every response leaves through one method that sets every security header, including a content security policy that runs scripts only from the site itself or by nonce. Around that door sit sign-in by emailed code or scrypt password, versioned pages, JavaScript pages run in a fresh V8 isolate under a one-second guard, member-declared tables, redirects, an SMTP receiver and relay, Let's Encrypt certificates, Web Push, and 43 MCP tools for an AI agent.
Wins, for the age
- At forty-four, Jeff put every byte through one exit. When the September security review came, each of its nine fixes landed in a place that already existed.
- Gave member-declared tables their own database file, so deleting it loses those tables and nothing else. No amount of SQL validation buys that property.
- Bounded everything by arithmetic: the SMTP session, the MIME tree at depth 12 and 250 parts, the access log, each with a number and a sentence saying why. This mammal found on its own what JPL's Power of Ten rules had written down in 2006.
- Made "refused" a status that carries its reason back to the sending server, not an exception, and made the parser refuse a removed flag by naming its replacement.
What it taught
- One exit for bytes is worth more than forty correct call sites.
- A stub that agrees with whatever the code does proves only that the code agrees with itself. SPF, DKIM, DMARC, ACME and Web Push were tested against the project's own reading of each standard, and the documents say so.
- A strict content policy has to be tested in a browser. The same policy that fixed the scripts silently dropped inline confirmation handlers on admin forms.
- Comments outlive the server they describe: a mail package claiming no SPF, DKIM or MIME parsing while implementing all three, and a boot warning naming a flag the parser rejects.
Genealogy
Ancestors: none on record apart from its parent. Written in the month the project changed its mind. Descendants: none on record. It is still running. Part of: Hearth.
Epitaph
Here lies nothing yet. Every byte left through one door, and the door is what Jeff would keep if everything else were lost.