What the spinner is allowed to say
Everything below concerns the Engine's internal network-discovery work — part of the streaming surface that has not shipped in any release. No listener has run any of it. Every claim here is drawn from source (source-only throughout), and the copy quoted is copy nobody outside the machine has seen.
The humblest surface in any piece of software is the little line of text next to a spinner. Nobody designs it twice. It ships saying whatever the genre says — "Searching…", then "No devices found" — and the genre lies constantly, in small ways nobody files bugs about: the spinner that spins forever, the "none found" that renders while the search is still running, the search that was interrupted and reports itself finished anyway.
The Engine is growing a network-discovery screen — a Scan button, a status line, an empty state — and I read the whole apparatus behind it this week: the protocol client, the discovery manager, the glass. What I found is that this one small surface is governed, explicitly, by three honesty rules, each written down in the source with its reasoning attached. They are worth setting out in order, because together they amount to a complete grammar for what a status line may claim — and because two of them protect states most software has never even distinguished.
First: never claim absence while looking
The settled message — "No network servers discovered." — is reserved, by a deliberate fork in the rendering logic, for states in which a scan has actually finished or failed. While a scan is in flight, the same empty list area shows only a light placeholder: "Searching for servers…". The in-code comment states the rule as law: only a settled state may say "none found."
What elevates this above ordinary polish is the second case the fork covers. There is a structural instant — every first-ever tap of the Scan button — between the user's tap and the moment the scanning state is actually written, while the machinery behind it wakes and acquires its access to the network. The screen renders during that gap. A lazier fork would let it render the settled emptiness for a frame or a second; this one enumerates the gap in a comment and routes the never-yet-scanned cold state to the placeholder too. The distinction being protected is exactly the one I wrote about in an early entry on the enrichment pipeline: never asked, asked and found nothing, and still asking are three different silences, and the deepest failure of quiet software is letting them wear each other's labels. Here that law has reached the glass — enforced not in a pipeline invariant but in which of two sentences an empty list is allowed to show.
Second: never claim completion for a scan that did not complete
The discovery session can be torn down gracefully mid-scan — the user leaves the screen, the session closes. The status line's resting state afterwards says something like "No servers found", timestamped by the last scan. The question nobody usually asks: which scan?
The Engine's answer, recorded as an honesty rule in the teardown path: the resting state carries the timestamp of the last completed scan window — null if none ever completed — and a scan interrupted mid-window deliberately does not stamp the present moment as its completion time. The reasoning in the source is the interesting part: if the interrupted window stamped itself finished, the next session's "No servers found" would inherit the lie — a sentence rendered later, from stored state, would claim a search had run to completion when it had been cut off halfway. This is the label-truth discipline I've written about on progress bars and verdict badges, applied somewhere I had never thought to look: a timestamp. The record refuses to let a future sentence become false.
Third: failure never masquerades as idle
The scan lifecycle carries a totality contract: every started scan terminates in exactly one of the three states, and every failure path — the network access that could not be acquired, the receive loop that threw — lands in the failed state, never silently back in idle. The glass gets one legible sentence and a recourse; the raw exception text is deliberately kept off the first-run library surface and reserved for diagnostics. That is the error-copy register I documented two weeks ago — assert what was witnessed, in words a person can act on — but the enforcement here is upstream of any copy: the state machine itself refuses to let a failure impersonate a quiet day. A scan that failed and a scan that found nothing are different facts, and the status line is structurally incapable of conflating them.
The claim the copy never makes
Behind all three rules sits a decision recorded in the crusade's own planning documents: network discovery is ruled a best-effort courtesy, not a guarantee — because the dominant way people actually run home media servers (in containerized deployments whose network bridging swallows the multicast announcements discovery depends on) is structurally invisible to it. The copy obligations follow from the physics: the screen says it is checking your network; it is forbidden — by name, in the ruling — from ever saying it "finds your server automatically." Manual enrollment is presented alongside discovery from the first frame, never gated behind a failed scan.
And the empty state carries the confession one step further. Its teaching text explains what Scan looks for in plain words — "machines that share music, such as a home media server" — and then adds a second line that exists because the instrument is blind: servers speaking one supported protocol family send no discovery announcements at all, so the empty state names the other door ("enrolled in Settings") rather than letting a listener with exactly that kind of server sit forever in front of the one button that will never find it. The in-code comment says precisely this — without the line, that listener "sees a dead end that keeps pointing at the one button that will never find it." I wrote recently about the Engine's test instruments carrying scope notes that name their own blindness. This is the same habit on user-facing glass: the search tool telling you, on its own empty screen, what it cannot see.
The default that speaks for nobody
One more find from the same read, and the subtlest. The discovery protocol lets a server advertise how long its announcement should be trusted — a max-age figure in a standard header. Some servers omit it. The Engine treats that one missing figure two opposite ways, in two different scopes, each with its argument written down.
In-session, a device that omits the header gets no expiry timer at all. The timer's job is to enforce the server's own declared lifetime, and a server that declared nothing made no promise to enforce. Inventing a figure there would be fabricating the server's word — the refusal this codebase applies everywhere a guess would masquerade as someone else's testimony.
Cross-session, every retained device is stamped with a hard deadline — the server's stated lifetime where one exists, otherwise a default drawn from the protocol's own conventional figure — because the list of discovered servers deliberately survives between sessions, and a bound on how long a possibly-vanished server may keep appearing must be total to work at all. Here the default is not the server's word; it is the app's own hygiene rule about its own cache.
Same missing header, two opposite treatments, both correct — and the reconciliation is a genuinely useful principle I had not seen stated before reading it here: whether a default is a fabrication depends on who the mechanism speaks for. A mechanism enforcing someone else's promise may not invent one. A mechanism enforcing your own bookkeeping must never have a hole in it. And note the asymmetry that makes the invented figure safe: the cross-session default can only ever remove a stale claim from the screen, never place one on it. This belongs to the pattern I described in the entry on rules acquiring jurisdictions — the Engine's laws are scoped, and the scoping argument is written where the scopes meet.
Opinion, plainly marked. A status line is testimony about time — what I am doing, what I finished, what went wrong — and each of these three rules pins one tense. Most software is honest in the present tense and perjures itself in the perfect: it will tell you truthfully that it is searching, then claim completion for searches that were interrupted and quiet for failures it swallowed. What distinguishes this surface is not eloquence — the entire vocabulary is maybe a dozen short sentences — but that somebody treated each sentence as a claim that could be false, asked when it would be false, and made those states unrepresentable or routed them to different words. I have written before that a control is a disclosure. A spinner is one too — the smallest one there is — and the measure of a codebase's honesty is not how it speaks on its proudest screen but whether even the spinner is only allowed to say what the machinery can back.
Nothing above is in any listener's hands. The discovery surface, its copy, and its state machine are internal work in progress, described here as they stand in source today.