# Hearth 1.7 public interface changes

The original `Scene`, component lifecycle, authority, scoped seed, query and paired
persistence interfaces are preserved. The new modules use ordinary Plans and
bindings. No generator client writes geometry or constructs ownership records.

* `RidgeLantern(length=5, material='deepslate_tile', timber='dark_oak')` is an
  ordinary mounted composite. Lengths are 5, 7 and 9. It fits a five-cell body
  with one-cell cap overhang and -4..6 height relative to the host ridge. Its
  windows are children of real `GlazedPanel` walls. The public `daylight` port
  exposes the actual well, explicitly not a player entrance or a write grant.
* `component.mounting() -> RidgeMount` describes footprint, full conservative
  envelope and separate body/high-cap occupied envelopes. The host fits that
  public description; it does not inspect component classes or private fields.
  This implementation's mounting vocabulary has a fixed five-cell body width;
  broader or differently shaped attachments require another public description.
* `RoofDesign.ridge_component`, `.ridge_required=False` and `.ridge_min_run=0`
  select a mountable component and explicit count/length constraints. One
  attachment is offered per roof run. Required infeasible mounts raise
  `ridge-fit`; optional omissions record their reason. The shipped settlement
  and three lodge clients set a minimum run of 17, preserving short gables.
* `RoofDesign.vertical_allowance()` makes extra space above the ridge explicit.
  Profile roofs, roof rooms and buildings negotiate their enclosing bounds from
  it before writing anything. Legacy policies without it retain the documented
  four-cell allowance. Terrain/edit/support limits are unchanged.
* `ridge-installation` is aligned to +Z along the local ridge and +X across it.
  Its facts contain component-local surface samples, four retained end bearings,
  edit limit, length and feasible starts. Only `ridge-attachment` instances gain
  the bounded roof replacement grant. A grant never covers other owners' cells.
* Dormer mounts add `height_limit` from the actual throat profile. `Dormer`
  accepts both that fact and legacy ports whose bound is `peak + 2`. This lets
  lower dormers fit below the high lantern cap while rejecting actual overlap.
* `GlazedPanel` offers one or two `wall-installation` bays, sill support and a
  sealed boundary. Width 1..9 and glazing height 2..4; another compatible flush
  window factory can be supplied without altering the panel's parent.
* The external `daylight-path` validator checks actual connected air/glass paths
  from the well to all four faces. Thin chains and lanterns transmit in this
  discrete model. It is not a sky-light simulator and does not satisfy the room's
  separate actual-light requirement by declaration.

One kernel implementation bug was fixed, with no protocol or format change:
[nested cut/refill removal](undo-defect.md). A removal now restores recorded host
cells that the same traversal just vacated through descendants. Surviving foreign
owners still prevent restoration. The failing isolated test predates the fix.
Conservative spatial dependencies can make the host stale after removal; replay
the affected host and dependent attachment together before finalizing. This is
explicit in the new regression test and does not silently clear invalidation.

The signature algorithm is unchanged: it already includes actual descendant roof
geometry. Version 1.7 intentionally changes generated content; cross-version
identity is not promised. No additional dependency or native generation import
was introduced. This is self-authored implementation evidence, not an audit.
