# Habitable roof-space API delta, version 1.5.0

The [pre-edit review](review.md) found no serious flaw in the requested architecture. The new failures
were spatial coordination and component realization defects. Public composition, authority, transaction,
provenance and dependency protocols remain unchanged. No kernel, transport, environment, extension
package, or prior test is intentionally edited. This is self-authored extension evidence, not an audit.

| Public addition | Contract semantics |
|---|---|
| `Blueprint.attic_purpose` | None retains weather-only attics. Bedroom/library/storage explicitly requires a habitable room under each exposed roof run. An explicit roof policy is required; failures cannot omit a requested loft. |
| `Blueprint.porch_bays` | Positive span through contiguous front rooms, starting at the entrance room. Balcony spans additionally require upper rooms. Contact footprint includes the entire deck. |
| `Room.stair_axis` / `StairLayout` | Both ridge directions share the same six-rise flight, aperture and landing calculation. All connected floors in a column use the same orientation. Furniture and lights respect that layout. |
| `upper-floor-access` | Room port at its upper floor origin, region covering the actual stair aperture and clearance, landing/axis/headroom in port-local facts. Read-only connection; no replacement authority. |
| `RoofPlatform` / `roof-seat` | Composes the supported floor with a bounded stair opening and knee beams. Publishes dimensions, aperture, landing, axis and original access source. Prepared before neighboring roofs, reusable as an ordinary component. |
| `ProfileRoof` / `roof-interior` | Publishes local frame at floor height, conservative region, width/depth/axis/height, and floor/knee-wall obligation. Installation capacity one, tag `roof-room`, **zero** replacement allowance. |
| `InhabitedRoof` | Same component lifecycle as all leaves. Connects to upper-floor access (builds its own platform), or a compatible prepared roof seat. Composes ordinary ProfileRoof and an installed LoftInterior; forwards landing access. Supports the existing public roof-policy protocol. |
| `LoftInterior` | Fits actual floor-space routes and furniture, supplies actual hanging lights, collar ties and aperture guards. Purpose is locked. Requires two complete usable furniture groups and a closed envelope except the explicit floor aperture. |
| `FurnitureGroup.placement_geometry()` | Public conservative occupied bound, interaction apron and standing target. The same values construct its own contract, so consumers need no private furniture voxel map. |
| `floor_path(view, frame, start, end, area, blocked)` | Bounded deterministic same-level route planner using actual support, two-cell headroom and prospective occupancy. Explicit local frame and domain; does not infer unknown space as empty. |
| `Porch.entrance_x`, `.maximum_post_span` | Front access stays aligned with the actual entrance while a larger veranda gains intermediate bearings. Beam spacing defaults to 12, supported domain 6..12. The offered front port and actual clear route agree. |
| `Chimney.cap_overhang` | Explicit 0/1-cell cap projection. Default cap follows the shaft footprint; shared building rule ends it three cells above its supporting roof ridge. Actual cap and flues have expected-geometry checks. |
| `enclosed-volume` validator | Six-neighbor flood over actual air inside a bounded room. Glass and door voxels form barriers. Only declared floor apertures connect to the containing scope. Missing interior seed, malformed aperture and exterior leak produce located diagnostics. |

All positional bounds follow the existing inclusive-box and world/local transform rules. Inhabited
roof/platform widths are 9..64, depths 9..128, while the supplied Building planner still constructs
9/11/13-cell bays. These limits are not a claim that every shape/profile/environment combination is
feasible. Custom policies must actually offer compatible roof-interior contracts or fail explicitly.

Composition now constructs room solids, prepared roof floors, taller roof gables, then lower roof
coverings. This is architectural scheduling inside Building, not a new kernel phase or special-case
seed dispatch. Tall gables must precede lower ornamental finials; otherwise a permeable finial can
occupy a future enclosure cell. Flush facade boundaries now also suppress projecting joinery.
Optional dormer mounts check protected stair clearance before installation and record exclusions.
Gable windows use the existing flush implementation when only their projecting sill/edges conflict
with a canopy and the actual glazing face remains clear. An opaque adjoining volume still excludes
the optional opening. This is contract-compatible substitution, not replacement permission expansion.
Ceiling timbers for inhabited-roof buildings run after the supporting floor exists. Porch seats,
collar ties and extra loft stations are optional within recorded bounds; required lofts/functions
and their minimum furniture count are never omitted.

Instance, containment, attachment, current-cell and operation records are automatic. A furniture
block queries as group -> roof room -> roof -> inhabited assembly -> building. Roof rooms also record
`connected_to` the real lower room and `supported_by` the platform. This association is separate from
primary membership. The floor remains owned by its actual platform component. No helper becomes an
ancestor and no client supplies block owners or repairs geometry.

Existing clients keep their original room graphs and seeded choices; the three lodge programs now
explicitly request roof bedrooms/libraries from a separate scope. The default settlement requests
some roof bedrooms only when its selected roof policy offers that capability. All older constructor
defaults remain usable. Version 1.5 changes generated content intentionally; deterministic replay
requires the same implementation version as well as inputs and seed.

Ordinary clients require no private knowledge. Component implementers still must know the public
port conventions and discrete movement/support model. Six-cell storeys, bounded gables, conservative
roof joins and stepped/pier contacts remain constraints. Collar bearings and all enclosure checks are
voxel approximations, not structural engineering, fluid simulation or a full Minecraft collision
engine. Native portability checks are not a new Pyodide execution.
