Chrome/Chromium on Linux use ~/.pki/nssdb, not only
update-ca-certificates. Auto-install now runs both paths.
- certificate_authority.js: installLinuxRootCA + certutil for
user NSS (~/.pki/nssdb) and optional /etc/pki/nssdb
- docs/CERTIFICATES.md: manual steps (libnss3-tools, certutil, verify)
- docs/README_LONGFORM.md, EXAMPLES.md, README.md: aligned Linux instructions
Remove the last layer of soft centralization: a lone `--master` on empty
storage could still implicitly genesis a separate Autopass and split the
network on the same TOPIC_SEED. Genesis is now explicit (`--master
--genesis`); secondary masters pair via invite into the same dnsPass as
joiners, with a shared network manifest, split-brain diagnostics, and
writer-aware quorum.
- Genesis vs secondary master boot paths; auto-adopt manifest on upgrade
- Masters without dnsPass accept invites; masters with pass ignore them
- NETWORK_MANIFEST_FILE, P2NS_GENESIS, MASTER_LOAD_DOMAINS, MASTER_INVITE_ONLY
- core.status networkId; admin diagnostics; docs and multi-master tests
BREAKING: operators must run one genesis per network; additional masters
use `node p2ns.js --master` (not `--genesis`) on empty storage.