the lineage

this server was not designed from zero. every small network already had a server that solved something well, and the design started by reading them. the borrowings are itemised, with what was declined and when the peer is the better choice.

agate: the identity lifecycle. mint once per hostname, never churn

molly brown: certificate zones. authorized_keys, for capsules

gmcapsule: titan semantics. buffer the upload, then authorise

gmid: the test discipline. real binary, real sockets

gophernicus and kin: menu conventions. the i-line, URL: links, caps.txt, seventy columns, no tabs

twins: the counterexample. the escape hatch is the defect load

returned

what usv offers back: write-time rendering with a portable html tree · the cleartext exclusion made structural rather than procedural · the research and the honest autopsies, published · a field guide to the five networks that stands on its own.

the field guide

agate (rust)

feature-frozen and still maintained; its releases are mostly dependency bumps, which is what a finished project looks like. "agate can only serve static files", full stop, by long-standing policy.

taken: the whole certificate story, the best in the field. a key per hostname on first run with no setup, expiry set far enough out that it never churns, per-hostname directories so serving several names needs no configuration syntax, an operator's own certificate accepted in the same slot. also its file-permission hygiene and its clean container-signal handling.

declined: configuration by command-line flags only, which makes the dockerfile the configuration file.

choose it instead: when you want the smallest possible thing that will never grow a feature. its scope freeze is a feature, and it has already made every future decision for you.

gmid (c)

the most actively developed server in the field: fastcgi, reverse proxying, virtual host and location blocks, and a four-process privilege-separation architecture that is the security high-water mark for a c server.

taken: its configuration semantics (named host blocks, path matching, sane defaults, reload on signal without dropping listeners) and its testing discipline: an in-tree suite that runs the real binary against real sockets. gmid was the only server surveyed with serious integration tests, and this project's wire suite exists because of it.

declined: the multi-process separation (memory safety and the container carry those goals here) and a custom configuration grammar.

choose it instead: when you need fastcgi, reverse proxying, or many virtual hosts under a real configuration language. nothing here matches its expressiveness or its hardening.

molly brown (go)

written by gemini's own creator, for pubnix and shared hosting.

taken: certificate zones essentially as designed: path-scoped allowlists of client-certificate fingerprints, "analogous to ssh's authorized_keys". the zones here are a direct descendant, extended with a named roster and capabilities. also toml as the configuration format, and the principle that a file inside the content tree may never override a security-relevant setting.

declined: per-user expansion and the world-readable bit as a publishing switch; those are shared-hosting concerns and this is single-tenant.

choose it instead: for a pubnix or any shared multi-user host. its per-user model is built for exactly that.

gmcapsule (python)

the reference titan implementation and the extensibility flagship. bubble, the small internet's most successful interaction platform, runs as a gmcapsule module.

taken: its titan handling as the correctness reference: buffer the whole upload before dispatching, require a client certificate by default, hand the caller's fingerprint to the code that authorises the write.

declined: the module interface. there is no extension api here and there will not be one.

choose it instead: when what you are building is a program rather than a site: a custom titan handler, an interaction platform, anything a config file cannot express.

jetforce (python)

the reference teaching implementation: routing over request and response objects, static serving as one application among several.

taken: exactly that internal shape. a handler trait; static serving, redirects, certificate zones, uploads and the status resource are each one handler, which is what lets them compose instead of accreting conditionals.

declined: exposing it as a public extension interface.

twins (go)

static serving plus per-path reverse proxying; barely maintained, and its issue tracker is the evidence file: cropped responses, intermittent images, path handling only partly working.

taken: the idea that a path may map to different kinds of thing, as internal architecture.

declined: proxying itself. almost all of twins' defect load came from the one feature beyond static serving. that single observation is the strongest argument behind refusing to execute or fetch anything, permanently.

the gopher servers

gophernicus, geomyidae, bucktooth and pygopherd between them define what modern gopherspace expects, most of it convention rather than the 1993 specification.

taken: the informational line type that is the backbone of every modern menu, the URL: link convention for pointing at other protocols, caps.txt as the nearest thing gopher has to a server identity endpoint, and the hard formatting rules: display strings under about seventy columns, never a tab inside a field.

declined: gopher+ entirely, since nothing modern depends on it, and the search item type, which needs a query handler and so contradicts a static model.

the conformance suite

not a server: the community's torture test, frozen but canonical. a clean run is a hard gate here, not advice. its limits are worth knowing: no client-certificate tests, no redirect-chain or timeout tests, no virtual-host tests, and a known false negative in its traversal check. those gaps are where this project's own tests and fuzz targets earn their keep.

the pattern

read together, the field's last six years want a short list from a small-internet server: automatic certificates, redirects, per-directory metadata, client-certificate gating, uploads. and every server that grew an escape hatch beyond static serving spent most of its maintenance budget on that hatch.

so: the short list, built in, and no escape hatch.

maturity, honestly: usv is at its first release. agate and gmid have years of production hardening it does not; if uptime-critical serving is the goal today, that gap is real.

the evidence and the risks

back to the plate