# Public API changes, Hearth 1.6.0

The [initial review](review.md) found no serious architectural flaw. The new features use the existing
component lifecycle, public observations, grants, atomic plans, graph records and persistence. The
shared light validator has a small service-use correction described in [lighting-delta.md](lighting-delta.md);
the authority, transaction, ownership, binding and regeneration kernel is unchanged. This is
self-authored implementation/test evidence, not an independent audit.

| Interface | Semantics and bounds |
|---|---|
| `RoofDesign.end_hips=(front, rear)` | Independent integer depths 0..3 intersect the cross profile with end slopes. Zero retains an extruded gable at that end. The residual gable must be at least four cells high and a nonzero ridge must remain. Explicit incompatible values fail, never clamp. |
| `RoofDesign.surface(span, length)` / `RoofSurface` | Pure local geometric value exposing height, uphill direction and ridge interval. Surface coordinates are cross-roof X, vertical Y and along-ridge Z, with one-cell eaves. It supplies the skin, gable boundaries and mount-fit rules; it is not a semantic component ancestor. |
| `ProfileGable.projecting_windows` | Public realization choice. Clipped gables use flush glass within their structural face, allowing nearby roofs to meet the wall without colliding with shutters. Ordinary full gables retain their existing projecting/flush measured choice. |
| `Blueprint.interior_design` / `Room.interior_design` | Optional public furnishing policy. None retains the previous layout. A policy implements `component(purpose, width, depth, stair)` and returns an ordinary component fulfilling the room function and circulation obligations. |
| `InteriorDesign` / `FittedInterior` | Minimum 2..5, maximum 2..6 stations, maximum >= minimum, dining length 2..4 and optional hearth. Counts, required room purpose and protected cross/flight remain hard. Fitting constructs a feasible domain from actual solids/support and routes; missing optional stations and considered table alternatives are recorded. |
| `DomesticSuite.placement_geometry()` | Like FurnitureGroup, returns local occupied bound, interaction apron and approach point. The component's own contract uses the same geometry. |
| `Hearth`, `DiningSet` | Reusable ordinary components offering `interaction`, the placement geometry convention, actual masonry/table/seating checks, support and clear aprons. Hearth validates an actual lit campfire. Whole-object authority/deletion rules remain in force. |
| `FloorTextiles` | Measures supported empty cells around fitted approaches. Rugs are passable and acquire no replacement authority. Stair cells are excluded, and late writes still undergo normal validation. |
| `Tree.planting_clearance()` | Publishes separate trunk and crown regions. Landscape queries both and preserves protected space; it no longer demands that low beds beneath a clear crown disappear. Tree minimums and terrain authority are unchanged. |
| `blocks.emitted_light(state)` | Returns the modeled emission including explicit campfire on/off state. The existing shared propagation validator uses this service. Unlit or omitted `lit` state does not emit. |
| `blocks.parse(state)` | Same public return shape, but its property dictionary is now independent of the private cache. Editing the returned mapping cannot change later semantic interpretation of the original state string. |

Roof and room axes still transform through the normal Frame. Interfaces, actual states, metadata,
ownership and operation records remain synchronized. The policy is additive: independently written
roof policies still supply `heights` and `component`; independently written furnishing policies can
return the earlier layout or another contract-compatible composite. Parents never inspect private
voxel maps, edit block storage, repair geometry, or assign per-cell owners.

The half-hip dormer rule tests the actual projected mounting footprint against the surface, rather
than excluding an entire end band. That correction preserves the older tall-house dormer regression.
Clipped-gable flush glazing is an intentional conservative junction strategy, not authority to
overwrite another roof. No arbitrary roof-intersection/flashing solver is claimed. Larger gables,
stronger hips, noncardinal roofs and incompatible explicit furniture counts may fail within the
published limits.

The hearth's campfire is visually contained by checked masonry. Its light state is validated; smoke,
ventilation, heat, combustion and fire safety are not simulated. Emission coverage remains finite.
The fixed parser-cache alias and initial wrong source model were ordinary implementation bugs, not
reasons to redesign composition. All prior tests remain unedited.

Visual review found a half-cell air gap between ridge ornaments and bottom-slab caps. RoofCover
now negotiates the free base/post cells together, supplies a full-height wooden pedestal below
each finial, and checks both actual block names using the existing expected-geometry rule. The
new negative test substitutes a bottom slab and fails. This is a roof-component correction; it
does not change collision rules or grant new replacement authority. The first complete assessment
and renders are archived under `before-finial-review`, followed by a full rerun with identical inputs.
