OMNI saysmetaSurf gates what extends the chain — it verifies signal, not identity (that’s auth).
§1e clarifies metaSurf's job: it sits between the user's instance and the LEDGER and decides whether the next block may extend the chain at all, by verifying the block's signal. It does not do authentication — auth comes from the instance existing (the genesis derivation). metaSurf gates the layer below auth: even an authenticated instance can't commit a bad-signal block. It verifies the change is legitimate, not who you are.
Power-ups you unlock
Decides if the next block may extend the chain
Verifies the block’s signal, not identity
Auth = instance exists; metaSurf gates below it
Legitimate change, not "who are you"
The Silent Failure attacks — common mistakes
Conflating metaSurf with authentication
Assuming auth implies a block is valid
Letting authenticated instances skip the gate
Boss battleExplain what metaSurf checks that authentication does not.
Example code
<!doctype html><html><head><meta charset="utf-8"></head>
<body style="background:#06040d;color:#b388ff;font-family:monospace;padding:20px"><pre>auth: instance exists → you may act
metaSurf: is THIS block’s signal legit? → may it extend?
(gates below auth)</pre></body></html>