From 3079ca30881cf1c5e39e64ddb2a3032fc2598648 Mon Sep 17 00:00:00 2001 From: Xuepoo Date: Mon, 5 Oct 2026 04:56:12 +0800 Subject: [PATCH] [CTX-0077] docs(links): retarget published-page links away from withheld/excluded targets Closes #107. Published pages linked to withheld/excluded pages (website 404s). Retargeted 6 links to published equivalents; unlinked the rest to plain document names with prose repair. Enumeration over all website-eligible pages reports zero published->unpublished links. --- architecture/README.md | 9 +++--- architecture/plugin-ecosystem-model.md | 12 ++++---- architecture/plugin-ipc-boundary.md | 32 ++++++++++----------- extensibility/README.md | 18 ++++++------ extensibility/faq.md | 2 +- extensibility/history-and-storage-policy.md | 8 +++--- extensibility/package-management.md | 8 +++--- extensibility/plugin-system.md | 4 +-- packaging/plugin-reuse-and-providers.md | 24 ++++++++-------- runtime/plugin-host-runtime-rfc.md | 20 ++++++------- sdk/README.md | 8 +++--- sdk/plugin-api-v1-lua-surface-rfc.md | 32 ++++++++++----------- sdk/reference/env.md | 4 +-- sdk/reference/store.md | 2 +- specifications/plugin-platform-rfc.md | 18 ++++++------ 15 files changed, 100 insertions(+), 101 deletions(-) diff --git a/architecture/README.md b/architecture/README.md index 5438370..fab6558 100644 --- a/architecture/README.md +++ b/architecture/README.md @@ -25,8 +25,9 @@ when real content exists; empty placeholder pages are avoided. All three pages are draft, candidate design input that authorizes no shipped behavior. Accepted boundaries they reconcile against live in the -[runtime](../runtime/README.md), [sdk](../sdk/README.md), and -[packaging](../packaging/README.md) trees and in the accepted +[published runtime contract](../runtime/plugin-host-runtime-rfc.md), +[sdk](../sdk/README.md), and +[packaging](../packaging/plugin-reuse-and-providers.md) pages and in the accepted [Plugin Platform RFC](../specifications/plugin-platform-rfc.md). Shared cross-project governance stays in [bitty-docs](https://github.com/bitty-terminal/bitty-docs) and is linked, never @@ -42,7 +43,7 @@ copied. ## Diagrams -The glossary-driven diagram suite lives in -[diagrams/](diagrams/README.md): the canonical node and edge inventory plus +The glossary-driven diagram suite lives in the corpus-only `diagrams/` +directory (not published on the website): the canonical node and edge inventory plus Mermaid sources and vector exports. Each diagram node carries its own status; diagram content authorizes no shipped behavior. diff --git a/architecture/plugin-ecosystem-model.md b/architecture/plugin-ecosystem-model.md index ba48435..19596b0 100644 --- a/architecture/plugin-ecosystem-model.md +++ b/architecture/plugin-ecosystem-model.md @@ -69,7 +69,7 @@ The layering is semantic, not a nesting of runtimes: `contribution`. - Summarized as **runtime flat, semantics layered**, consistent with the accepted one-VM-per-plugin-identity-and-generation rule in the - [Isolation and Resource RFC](../runtime/isolation-resource-rfc.md) (`IR-D2`). + Isolation and Resource RFC (`IR-D2`). ## Extension points as a first-class concept @@ -112,7 +112,7 @@ Registry versus manifest asymmetry: the author-facing manifest is the declaration source, while the registry is an attestation and index service that only reads and records the dependency edges and compatibility declarations from it, and is not authoritative for them (see the registry boundaries in the -[Package Follow-up RFC](../packaging/package-followup-rfc.md)). +Package Follow-up RFC). ### Candidate contribution shapes (unaccepted) @@ -162,7 +162,7 @@ every Bitter capability and the sandbox would lose its meaning. This extends the accepted deny-by-default capability model in the [Plugin Platform RFC capability model](../specifications/plugin-platform-rfc.md) and the containment rules in the -[Isolation and Resource RFC](../runtime/isolation-resource-rfc.md): grants stay per plugin +Isolation and Resource RFC: grants stay per plugin identity and manifest hash, and a dependency edge is not a grant. ## Extension-platform API versioning @@ -264,7 +264,7 @@ service surface — `process`, `network`, `fs`, `store`, `secrets`, `tasks`, `notifications`, `clipboard`, `commands`, `events`, `services` — each behind the same deny-by-default sandbox described by the [Plugin Platform RFC](../specifications/plugin-platform-rfc.md) and the -[Isolation and Resource RFC](../runtime/isolation-resource-rfc.md). Panel state is split +Isolation and Resource RFC. Panel state is split into distinct axes (lifecycle, focus, visibility, interaction, attention) rather than one enum. For v1 this direction keeps the accepted animation restrictions: only Core-owned chrome animates, plugin shaders and native @@ -353,10 +353,10 @@ treating the whole direction as a generic proposal. | Platform/host versus extension plugin | [Plugin Reuse and Provider Ecology RFC](../packaging/plugin-reuse-and-providers.md) | Extends; provider ecology is close but does not name host plugins | | Extension points and contribution manifest | [UI Extensibility Architecture](ui-extensibility-architecture.md); none for `[contributes]` | Extends; the inventory exists, a formal extension-point model is unaddressed | | Accepted `[dependencies]` manifest | [Plugin Platform RFC](../specifications/plugin-platform-rfc.md) | Aligns; accepted schema already defines the dependency shape | -| Capability non-escalation | [Plugin Platform RFC](../specifications/plugin-platform-rfc.md), [Isolation and Resource RFC](../runtime/isolation-resource-rfc.md) | Aligns; the dependency-edge framing is new | +| Capability non-escalation | [Plugin Platform RFC](../specifications/plugin-platform-rfc.md), Isolation and Resource RFC | Aligns; the dependency-edge framing is new | | Extension-platform API versioning | [Plugin API v1 Lua Surface RFC](../sdk/plugin-api-v1-lua-surface-rfc.md), [Plugin Platform RFC](../specifications/plugin-platform-rfc.md) | Extends; host API versioning is candidate | | Plugin graph | [Plugin system](../extensibility/plugin-system.md) | Extends the dependency and service direction | -| Panel as host / Activity stack | [UI Extensibility Architecture](ui-extensibility-architecture.md) (P2), [Plugin Roadmap](../product/plugin-roadmap.md) | Unaddressed here; the accepted sibling Panel Runtime RFC leaves provider details as its open questions (`RFC-OQ-1`..`RFC-OQ-9`) | +| Panel as host / Activity stack | [UI Extensibility Architecture](ui-extensibility-architecture.md) (P2), Plugin Roadmap | Unaddressed here; the accepted sibling Panel Runtime RFC leaves provider details as its open questions (`RFC-OQ-1`..`RFC-OQ-9`) | | Native UI, widget layer, and application services | [UI Extensibility Architecture](ui-extensibility-architecture.md), [Plugin API v1 Lua Surface RFC](../sdk/plugin-api-v1-lua-surface-rfc.md), [Plugin Platform RFC](../specifications/plugin-platform-rfc.md) | Extends the ownership boundaries, v1 slot UI, and capability families | ## Open points diff --git a/architecture/plugin-ipc-boundary.md b/architecture/plugin-ipc-boundary.md index 6d58e94..633f28b 100644 --- a/architecture/plugin-ipc-boundary.md +++ b/architecture/plugin-ipc-boundary.md @@ -58,7 +58,7 @@ The candidate direction draws the suitability line explicitly: | Out-of-process (IPC) plugin | AI, Git daemon, language tooling, indexer, sync, database, network service, large computation, external application integration | independent lifecycle, may crash, complex dependencies, other languages, network/database use, coarse call granularity | Alignment: the accepted -[Isolation and Resource RFC](../runtime/isolation-resource-rfc.md) already names "a helper +Isolation and Resource RFC already names "a helper process with scoped IPC" as a high-isolation extension direction, and the draft [Plugin Reuse and Provider Ecology RFC](../packaging/plugin-reuse-and-providers.md) Layer 4 defines declared, digest-pinned native helper processes over stdio or a @@ -82,7 +82,7 @@ The dependency-minimization direction matches the "no embed third-party crate bloat" rule and helper-process staging stated in the draft [Plugin Reuse and Provider Ecology RFC](../packaging/plugin-reuse-and-providers.md), and the isolation direction in the accepted -[Isolation and Resource RFC](../runtime/isolation-resource-rfc.md); the daemon split +Isolation and Resource RFC; the daemon split itself remains a proposal. ## Panel and Agent as public protocol surfaces @@ -169,7 +169,7 @@ grammar**: the accepted model uses closed, owner-qualified identifiers with parameters (for example `terminal.semantic-read`, `process.spawn:git`), deny-by-default grants bound to plugin identity and manifest hash, and no wildcards ([Plugin Platform RFC](../specifications/plugin-platform-rfc.md); -[Isolation and Resource RFC](../runtime/isolation-resource-rfc.md)). The boolean +Isolation and Resource RFC). The boolean `[permissions]` table must not be read as schema, and a future plugin process would receive scoped grants, never ambient authority; mapping a capability token to the accepted IPC scopes and plugin grants is an open item (open item @@ -183,7 +183,7 @@ Candidate proposal: an out-of-process plugin that crashes must not take down Bitty; the direction poses restart, disable, and log-surfacing options rather than defining a policy. Alignment: resource isolation and failure semantics for IPC/MCP clients are accepted in the -[Isolation and Resource RFC](../runtime/isolation-resource-rfc.md), but no accepted +Isolation and Resource RFC, but no accepted document defines a plugin-process supervisor, restart policy, or reconnection semantics (candidate, open item 2). @@ -238,7 +238,7 @@ and dependency distinctions live in ### Accepted local baseline versus proposed transport A direct local-function-call shortcut must not be imported literally. -The accepted [Isolation RFC IR-D2](../runtime/isolation-resource-rfc.md#ir-d2-plugin-runtimes) +The accepted Isolation RFC `IR-D2` keeps one VM per plugin identity/generation with no shared globals or module trees; [Host Runtime A.3](../runtime/plugin-host-runtime-rfc.md#a3-bridge-marshalling-contract) requires bounded copied arguments/results, non-reentrant bridge calls, and @@ -289,17 +289,17 @@ owner-pending direction is tracked in ## Affected contracts -| Theme | Existing document | Relationship | -| ---------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------- | -| Lua versus out-of-process plugin suitability | [Isolation and Resource RFC](../runtime/isolation-resource-rfc.md), [Plugin Reuse and Provider Ecology RFC](../packaging/plugin-reuse-and-providers.md) | Aligns with the accepted helper-process direction; broader IPC plugin participants are candidate | -| Core minimization and `bitty-ai` daemon split | [Plugin Reuse and Provider Ecology RFC](../packaging/plugin-reuse-and-providers.md) | Aligns with the draft no-embed rule and Layer 4 staging; the daemon split is candidate | -| Panel/Agent protocol surface | [Plugin Ecosystem Model](plugin-ecosystem-model.md) Panel and activity section, sibling Panel Runtime RFC | Extends; Panel ownership and provider surface stay with the sibling contract | -| Plugin-to-plugin event bus | [Plugin Platform RFC](../specifications/plugin-platform-rfc.md) | Extends the accepted event pipeline to cross-process subscribers; candidate | -| Unified capability model and method vocabulary | [Plugin Platform RFC](../specifications/plugin-platform-rfc.md), [Plugin API v1 Lua Surface RFC](../sdk/plugin-api-v1-lua-surface-rfc.md) | Aligns on one registry for CLI/palette/IPC/Agent reuse; the external binding and names are candidate | -| Capability tokens and `[permissions]` sketch | [Plugin Platform RFC](../specifications/plugin-platform-rfc.md), [Isolation and Resource RFC](../runtime/isolation-resource-rfc.md) | Diverges from the accepted capability grammar; must be reconciled, not added in parallel | -| Crash isolation and supervision | [Isolation and Resource RFC](../runtime/isolation-resource-rfc.md), [IPC and Agent RFC](https://github.com/bitty-terminal/bitty-ai-docs/blob/main/specifications/ipc-agent-rfc.md) | Aligns on untrusted-client boundaries; supervisor semantics are unaddressed | -| Control CLI and multi-instance addressing | [IPC and Agent RFC](https://github.com/bitty-terminal/bitty-ai-docs/blob/main/specifications/ipc-agent-rfc.md) | Aligns with accepted instance selection; `bittyctl` verbs and `bitty://` addressing are candidate | -| Three-layer extension framing | [Plugin Ecosystem Model](plugin-ecosystem-model.md) Platform-versus-extension section | Consistent with "runtime flat, semantics layered"; combined framing is candidate | +| Theme | Existing document | Relationship | +| ---------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------ | ---------------------------------------------------------------------------------------------------- | +| Lua versus out-of-process plugin suitability | Isolation and Resource RFC, [Plugin Reuse and Provider Ecology RFC](../packaging/plugin-reuse-and-providers.md) | Aligns with the accepted helper-process direction; broader IPC plugin participants are candidate | +| Core minimization and `bitty-ai` daemon split | [Plugin Reuse and Provider Ecology RFC](../packaging/plugin-reuse-and-providers.md) | Aligns with the draft no-embed rule and Layer 4 staging; the daemon split is candidate | +| Panel/Agent protocol surface | [Plugin Ecosystem Model](plugin-ecosystem-model.md) Panel and activity section, sibling Panel Runtime RFC | Extends; Panel ownership and provider surface stay with the sibling contract | +| Plugin-to-plugin event bus | [Plugin Platform RFC](../specifications/plugin-platform-rfc.md) | Extends the accepted event pipeline to cross-process subscribers; candidate | +| Unified capability model and method vocabulary | [Plugin Platform RFC](../specifications/plugin-platform-rfc.md), [Plugin API v1 Lua Surface RFC](../sdk/plugin-api-v1-lua-surface-rfc.md) | Aligns on one registry for CLI/palette/IPC/Agent reuse; the external binding and names are candidate | +| Capability tokens and `[permissions]` sketch | [Plugin Platform RFC](../specifications/plugin-platform-rfc.md), Isolation and Resource RFC | Diverges from the accepted capability grammar; must be reconciled, not added in parallel | +| Crash isolation and supervision | Isolation and Resource RFC, [IPC and Agent RFC](https://github.com/bitty-terminal/bitty-ai-docs/blob/main/specifications/ipc-agent-rfc.md) | Aligns on untrusted-client boundaries; supervisor semantics are unaddressed | +| Control CLI and multi-instance addressing | [IPC and Agent RFC](https://github.com/bitty-terminal/bitty-ai-docs/blob/main/specifications/ipc-agent-rfc.md) | Aligns with accepted instance selection; `bittyctl` verbs and `bitty://` addressing are candidate | +| Three-layer extension framing | [Plugin Ecosystem Model](plugin-ecosystem-model.md) Platform-versus-extension section | Consistent with "runtime flat, semantics layered"; combined framing is candidate | ## Open points diff --git a/extensibility/README.md b/extensibility/README.md index 0018b9b..df20d64 100644 --- a/extensibility/README.md +++ b/extensibility/README.md @@ -14,15 +14,15 @@ sidebar_order: 10 Index of the plugin-ecosystem extensibility contracts. Normative detail lives in the linked pages; this index carries no duplicate normative prose. -| Document | Status | Purpose | -| -------------------------------------------------------------------------------- | -------- | ----------------------------------------------------------------------------------------------------------- | -| [Plugin system](plugin-system.md) | Draft | Plugin boundaries, isolation, composition, capabilities, and lifecycle. | -| [Plugin package management](package-management.md) | Draft | Manifests, sources, updates, rollback, and trust. | -| [Plugin history and storage policy](history-and-storage-policy.md) | Accepted | Plugin-facing history and storage ownership, privacy, retention, capabilities, and page sets. | -| [Lua UI Component Model (Candidate)](lua-ui-component-model-candidate.md) | Draft | Candidate five-level Lua UI component ecosystem, theming, accessibility, and panel services. | -| [Plugin UI Slot Inventory (Candidate)](plugin-ui-slot-inventory-candidate.md) | Draft | Candidate per-slot purpose, multiplicity, bounds, and conflict resolution for the accepted closed slot set. | -| [TUI to Native Migration Path (Candidate)](tui-to-native-migration-candidate.md) | Draft | Candidate L0-L4 migration ladder, per-application-type guidance, and Backend Service Plugin pattern. | -| [Frequently asked questions](faq.md) | Draft | Sandboxing, Fuel budgeting, Layer 2 external tools, Host Fuzzy Service, and lifecycle management. | +| Document | Status | Purpose | +| ------------------------------------------------------------------ | -------- | ----------------------------------------------------------------------------------------------------------- | +| [Plugin system](plugin-system.md) | Draft | Plugin boundaries, isolation, composition, capabilities, and lifecycle. | +| [Plugin package management](package-management.md) | Draft | Manifests, sources, updates, rollback, and trust. | +| [Plugin history and storage policy](history-and-storage-policy.md) | Accepted | Plugin-facing history and storage ownership, privacy, retention, capabilities, and page sets. | +| Lua UI Component Model (Candidate) | Draft | Candidate five-level Lua UI component ecosystem, theming, accessibility, and panel services. | +| Plugin UI Slot Inventory (Candidate) | Draft | Candidate per-slot purpose, multiplicity, bounds, and conflict resolution for the accepted closed slot set. | +| TUI to Native Migration Path (Candidate) | Draft | Candidate L0-L4 migration ladder, per-application-type guidance, and Backend Service Plugin pattern. | +| [Frequently asked questions](faq.md) | Draft | Sandboxing, Fuel budgeting, Layer 2 external tools, Host Fuzzy Service, and lifecycle management. | ## Authority and status diff --git a/extensibility/faq.md b/extensibility/faq.md index d476921..d1b3714 100644 --- a/extensibility/faq.md +++ b/extensibility/faq.md @@ -119,6 +119,6 @@ The host acts as a supervisor for all spawned child processes: - [Plugin system](plugin-system.md) - [Plugin package management](package-management.md) - [Plugin reuse and providers](../packaging/plugin-reuse-and-providers.md) -- [Lua UI component model](lua-ui-component-model-candidate.md) +- [UI extensibility architecture](../architecture/ui-extensibility-architecture.md) - [Terminal platform documentation](https://github.com/bitty-terminal/bitty-terminal-docs) - [AI core documentation](https://github.com/bitty-terminal/bitty-ai-docs) diff --git a/extensibility/history-and-storage-policy.md b/extensibility/history-and-storage-policy.md index 7f44892..5d1dcb7 100644 --- a/extensibility/history-and-storage-policy.md +++ b/extensibility/history-and-storage-policy.md @@ -96,7 +96,7 @@ This policy must be read together with, and must not weaken: - The accepted [Plugin API v1 Lua Surface RFC](../sdk/plugin-api-v1-lua-surface-rfc.md), the [Plugin Platform RFC](../specifications/plugin-platform-rfc.md), the [Plugin Host Runtime RFC](../runtime/plugin-host-runtime-rfc.md), and the - [Isolation and Resource RFC](../runtime/isolation-resource-rfc.md). The + Isolation and Resource RFC. The published `bitty.store` ceilings and the atomic-commit rule stay authoritative. - The Terminal Truth and Panel Runtime invariants in `bitty-terminal-docs`: a @@ -131,7 +131,7 @@ This policy must be read together with, and must not weaken: filter. - **Page set**: the standard per-plugin documentation partition (README, design, schemas, evidence) defined by the - [plugin documentation index](../docs/plugins/README.md). + plugin documentation index. - **Candidate**: a proposal that is not decided; candidate status is not acceptance and is not implementation. @@ -394,9 +394,9 @@ later implementation of the history keeper must prove, at minimum: and capability-increase review reused here. - [History-provider direction](../packaging/plugin-reuse-and-providers.md): the candidate history-provider input this policy specializes for plugins. -- [Plugin documentation index](../docs/plugins/README.md): where the standard +- Plugin documentation index: where the standard page set is registered, and the - [plugin roadmap](../product/plugin-roadmap.md): the candidate history plugin + plugin roadmap: the candidate history plugin entry. - [Panel History (Candidate)](https://github.com/bitty-terminal/bitty-terminal-docs/blob/main/specifications/panel-history-candidate.md) and the [Terminal State RFC](https://github.com/bitty-terminal/bitty-terminal-docs/blob/main/specifications/terminal-state-rfc.md): diff --git a/extensibility/package-management.md b/extensibility/package-management.md index 51be1dd..480f1c4 100644 --- a/extensibility/package-management.md +++ b/extensibility/package-management.md @@ -17,7 +17,7 @@ sidebar_order: 20 > candidate contracts except where the security contract is normative. The > integrity verification chain, staged activation lifecycle and safe rollback > semantics are accepted in -> [Package Lifecycle RFC](../packaging/package-lifecycle-rfc.md) +> Package Lifecycle RFC > (OQ-021, 2026-08-27) as normative for staged activation and rollback; real > signature verification, registry service, and key-directory contracts remain > draft under OQ-022 and OQ-026 through OQ-029. @@ -179,7 +179,7 @@ bitty-docs CTX-0201 / bitty-docs#288, It refines the accepted source model above without changing any accepted contract: the source classes, the seven-stage verification pipeline and provenance separation in the -[Package Follow-up RFC](../packaging/package-followup-rfc.md), and the +Package Follow-up RFC, and the package-manager/host split below stay authoritative. No implementation claim: `bitty-package` today models sources as the `PackageSource` data enum (registry / git / local-path / bundled) with no fetch behavior, and only @@ -206,7 +206,7 @@ local-path install has shipped (CTX-0406 slice above). the registry repository into the XDG cache, search local TOML records, and refresh only on an explicit `registry update`. This mirrors the CarryCtx sync philosophy. It is recorded as a candidate because the accepted - [Package Follow-up RFC](../packaging/package-followup-rfc.md) (OQ-028) + Package Follow-up RFC (OQ-028) specifies an HTTPS index snapshot fetch; reconciling the two mechanisms needs an RFC amendment, and this section does not weaken that contract. - **Later native HTTP.** When Git cannot serve a need, native HTTP runs in @@ -381,7 +381,7 @@ Rules: No component command, install, resolution, or `[components]` validation is implemented in the package manager yet. The plugin-facing request surface is -the [bitty.net candidate](../sdk/net-request-surface-candidate.md). +the `bitty.net` candidate request surface. ## Package manager versus runtime host diff --git a/extensibility/plugin-system.md b/extensibility/plugin-system.md index 31f6ac7..34d4fcb 100644 --- a/extensibility/plugin-system.md +++ b/extensibility/plugin-system.md @@ -360,7 +360,7 @@ stdio coprocess, under the accepted [DIR-030 Native Component Boundary](https://github.com/bitty-terminal/bitty-docs/blob/main/docs/development/native-component-boundary.md). DIR-030 makes the plugin-facing surface a non-blocking request handle plus a response event and defers it as follow-up work; the candidate spelling is the -[bitty.net Lua Request Surface (Candidate)](../sdk/net-request-surface-candidate.md) +bitty.net Lua Request Surface (Candidate) (`bitty.net.request` plus `net.*` result events, not implemented). The synchronous `bitty.http.get` sketch and the `CurlBackend` V1 below predate DIR-030 and are superseded as spelling by that candidate; they remain only @@ -623,7 +623,7 @@ receive ADRs and acceptance evidence. - How does the candidate `bitty.http` spelling map onto the DIR-030 non-blocking request handle and response event served by the `net` component? The spelling is now proposed by the - [bitty.net candidate](../sdk/net-request-surface-candidate.md); whether the + bitty.net candidate; whether the `CurlBackend` V1 survives the component model stays with the bitty-network repository. - Which host remote surfaces are plugin-visible (notification delivery and a diff --git a/packaging/plugin-reuse-and-providers.md b/packaging/plugin-reuse-and-providers.md index 58ad441..2d99fd0 100644 --- a/packaging/plugin-reuse-and-providers.md +++ b/packaging/plugin-reuse-and-providers.md @@ -51,12 +51,12 @@ Out of scope (owned elsewhere): budgets (OQ-011/OQ-012/OQ-013, accepted in [Plugin Platform RFC](../specifications/plugin-platform-rfc.md)); - per-plugin instruction, memory, task, and queue enforcement (OQ-014, accepted - in [Isolation Resource RFC](../runtime/isolation-resource-rfc.md)); + in Isolation Resource RFC); - Lua standard-library subset, rooted `require`, and diagnostics (OQ-009, - accepted in [Lua Runtime RFC](../runtime/lua-runtime-rfc.md); pins OQ-030/OQ-031/OQ-032); + accepted in Lua Runtime RFC; pins OQ-030/OQ-031/OQ-032); - package manifest, lockfile, and activation model (OQ-021/OQ-022, - accepted in [Package Lifecycle RFC](package-lifecycle-rfc.md) and - [Package Follow-up RFC](package-followup-rfc.md)); + accepted in Package Lifecycle RFC and + Package Follow-up RFC); - local IPC wire, auth, and scopes (OQ-018, accepted in [IPC and Agent RFC](https://github.com/bitty-terminal/bitty-ai-docs/blob/main/specifications/ipc-agent-rfc.md)); - headless daemon, detach/reattach, and remote UI trust boundary (OQ-020, @@ -80,13 +80,13 @@ or weaken any accepted contract. interception. - [Plugin system](../extensibility/plugin-system.md): extension levels 1 to 4, register versus claim, qualified naming, service boundary direction. -- [Lua Runtime RFC](../runtime/lua-runtime-rfc.md): isolated VM per plugin, restricted +- Lua Runtime RFC: isolated VM per plugin, restricted standard library, rooted module resolution, source-only loading, one `bitty` host bridge. - [Plugin Platform RFC](../specifications/plugin-platform-rfc.md): manifest `bitty-plugin.toml`, capability grammar, grant per manifest hash, service `get` with version constraint, lazy triggers. -- [Isolation Resource RFC](../runtime/isolation-resource-rfc.md): RC-1..RC-10 ceilings, +- Isolation Resource RFC: RC-1..RC-10 ceilings, FS-1..FS-9 failure semantics, three-level queue PerSubscription 64 / PerPlugin 1024 events/256 KiB / Global 8192 events/2 MiB with `DropOldest` default. @@ -452,7 +452,7 @@ suffices. The accepted baseline already distinguishes rooted, source-only in-package `require` from cross-plugin services: the -[Lua Runtime RFC](../runtime/lua-runtime-rfc.md) and +Lua Runtime RFC and [Plugin Host Runtime RFC A.2/A.3](../runtime/plugin-host-runtime-rfc.md#a2-proposed-bitty-lua-seam-extensions) permit no filesystem imports across packages, path traversal, package-path extension, shared module cache, or direct peer-VM access. Packaging a dependency @@ -524,8 +524,8 @@ crates before the post-1.0 boundary. each helper is a single `id` with per-platform `path` and `sha256` under `helpers.`. Manifest spelling below is a proposed sketch (draft) and remains owned by the package and configuration model - ([Package Lifecycle RFC](package-lifecycle-rfc.md), - [Package Follow-up RFC](package-followup-rfc.md), + (Package Lifecycle RFC, + Package Follow-up RFC, [Configuration Model RFC](https://github.com/bitty-terminal/bitty-terminal-docs/blob/main/specifications/configuration-model-rfc.md)); the TOML sketch is not an accepted schema: @@ -657,7 +657,7 @@ only what it means for this corpus. from the host keystore, invisible in plaintext to both the management UI and agents. This subsection does not restate the secret tiers; the candidate storage shapes live in the - [Secrets and credential handling direction](../product/plugin-roadmap.md#secrets-and-credential-handling-direction-candidate), + Secrets and credential handling direction, and the accepted environment baseline stays in ADR 0006. - Acceptance path: an RFC-level provider-interface contract (versioned capability identifiers, grant shape, registry and routing rules) with @@ -892,8 +892,8 @@ Shipped, unsupported, and candidate claims are labelled per claim. - [Plugin Platform RFC](../specifications/plugin-platform-rfc.md) (OQ-011/OQ-012/OQ-013, accepted 2026-08-27) -- [Lua Runtime RFC](../runtime/lua-runtime-rfc.md) (OQ-009, accepted 2026-08-27) -- [Isolation Resource RFC](../runtime/isolation-resource-rfc.md) (OQ-014, accepted +- Lua Runtime RFC (OQ-009, accepted 2026-08-27) +- Isolation Resource RFC (OQ-014, accepted 2026-08-28) - [Configuration Model RFC](https://github.com/bitty-terminal/bitty-terminal-docs/blob/main/specifications/configuration-model-rfc.md) (OQ-010, accepted 2026-08-27) diff --git a/runtime/plugin-host-runtime-rfc.md b/runtime/plugin-host-runtime-rfc.md index 8e237d8..388c56e 100644 --- a/runtime/plugin-host-runtime-rfc.md +++ b/runtime/plugin-host-runtime-rfc.md @@ -66,7 +66,7 @@ Out of scope, owned elsewhere and only referenced here: pipeline classes, batching, and budgets ([Plugin Platform RFC](../specifications/plugin-platform-rfc.md), accepted). - Restricted standard library, rooted module resolution rules, diagnostics - classes ([Lua Runtime RFC](lua-runtime-rfc.md), accepted), the `mlua` versus + classes (Lua Runtime RFC, accepted), the `mlua` versus `piccolo` split and pins ([ADR 0005](https://github.com/bitty-terminal/bitty-docs/blob/main/docs/decisions/adrs/ADR-0005-lua-pins-and-stdlib.md); plugin-VM successor direction is Phodopus per @@ -75,9 +75,9 @@ Out of scope, owned elsewhere and only referenced here: reads ([ADR 0006](https://github.com/bitty-terminal/bitty-docs/blob/main/docs/decisions/adrs/ADR-0006-os-env-policy.md)), and the Config VM async boundary ([ADR 0007](https://github.com/bitty-terminal/bitty-docs/blob/main/docs/decisions/adrs/ADR-0007-async-gc.md)). - Resource ceilings and their numbers - ([Isolation Resource RFC](isolation-resource-rfc.md), accepted; `RC-1`..`RC-11`). + (Isolation Resource RFC, accepted; `RC-1`..`RC-11`). - Package integrity, signature, lock, and rollback semantics - ([Package Lifecycle RFC](../packaging/package-lifecycle-rfc.md), accepted). + (Package Lifecycle RFC, accepted). This RFC selects concrete mechanisms for controls the accepted sources already require. It moves no requirement between owners, relaxes no P0 gate, and @@ -87,7 +87,7 @@ fixes the four proposed defaults, and changing one requires an RFC revision. ## Provenance and problem statement -The accepted [Lua Runtime RFC](lua-runtime-rfc.md) fixes the single host bridge +The accepted Lua Runtime RFC fixes the single host bridge in every VM as a versioned `bitty` module whose function surface is owned by the respective API RFCs, and fixes rooted source-only module resolution. The accepted [Plugin API v1 Lua Surface RFC](../sdk/plugin-api-v1-lua-surface-rfc.md) @@ -105,7 +105,7 @@ semantics but leaves the runtime mechanism to the `bitty` repository. The resource-budget thresholds and enforcement" as a pending decision. For source staging, the accepted -[Package Lifecycle RFC](../packaging/package-lifecycle-rfc.md) describes a staged +Package Lifecycle RFC describes a staged activation transaction whose `wake` phase loads plugins in fresh VMs, but delegates the stored tree location to the draft [Package management](../extensibility/package-management.md) candidate layout. @@ -138,7 +138,7 @@ drafting revision. - [Plugin system](../extensibility/plugin-system.md): extension levels 1-4, register-versus-claim, and the governing boundary that plugins alter presentation but never Terminal Truth. -- [Isolation Resource RFC](isolation-resource-rfc.md): `IR-D2` one VM per +- Isolation Resource RFC: `IR-D2` one VM per plugin identity and generation, `RC-1` instruction and wall budget, `RC-2` memory ceiling, `RC-4` tasks and timers, `RC-5` queue budgets, and `RC-11` plugin store quota. @@ -189,7 +189,7 @@ by exposing Lua's `package`/`package.path`. The resolver caches per VM; the reload rule clears the cache on generation disposal. `os`, `io`, `debug` (except `debug.traceback`), `package.loadlib`, and bytecode loading remain absent or deny-stubbed exactly as the accepted -[Lua Runtime RFC](lua-runtime-rfc.md) requires. The seam exposes no filesystem +Lua Runtime RFC requires. The seam exposes no filesystem or network function to Lua: reading the plugin's own module tree is a host-mediated resolution step, not plugin-visible filesystem authority, and `fs.*` remains a separate capability path with no v1 Lua entry point. @@ -559,11 +559,11 @@ The project initiator (user) ratified the following through v1 surface, `init.lua` entry point, store quota, snapshot schema. - [ADR 0009](https://github.com/bitty-terminal/bitty-docs/blob/main/docs/decisions/adrs/ADR-0009-plugin-api-v1-lua-surface.md) - accepted Lua surface resolutions and authority split. -- [Lua Runtime RFC](lua-runtime-rfc.md) - accepted sandbox, module resolution, +- Lua Runtime RFC - accepted sandbox, module resolution, diagnostics, host bridge ownership. -- [Isolation Resource RFC](isolation-resource-rfc.md) - `IR-D2`, `RC-1`, +- Isolation Resource RFC - `IR-D2`, `RC-1`, `RC-2`, `RC-4`, `RC-5`, `RC-11`. -- [Package Lifecycle RFC](../packaging/package-lifecycle-rfc.md) - staged activation, +- Package Lifecycle RFC - staged activation, local-path development semantics, rollback. - [Package management](../extensibility/package-management.md) - source model and candidate store layout. diff --git a/sdk/README.md b/sdk/README.md index 2e3a57e..c377b20 100644 --- a/sdk/README.md +++ b/sdk/README.md @@ -31,7 +31,7 @@ linked, never copied. ## Contract -| Document | Status | Purpose | -| ----------------------------------------------------------------------------- | -------- | ----------------------------------------------------------------------------- | -| [Plugin API v1 Lua Surface RFC](plugin-api-v1-lua-surface-rfc.md) | Accepted | Lua module functions, payloads, and the L1/L2 split. | -| [bitty.net Lua Request Surface (Candidate)](net-request-surface-candidate.md) | Draft | Candidate non-blocking `bitty.net` requests over the DIR-030 `net` component. | +| Document | Status | Purpose | +| ----------------------------------------------------------------- | -------- | ----------------------------------------------------------------------------- | +| [Plugin API v1 Lua Surface RFC](plugin-api-v1-lua-surface-rfc.md) | Accepted | Lua module functions, payloads, and the L1/L2 split. | +| bitty.net Lua Request Surface (Candidate) | Draft | Candidate non-blocking `bitty.net` requests over the DIR-030 `net` component. | diff --git a/sdk/plugin-api-v1-lua-surface-rfc.md b/sdk/plugin-api-v1-lua-surface-rfc.md index f143101..ea0928a 100644 --- a/sdk/plugin-api-v1-lua-surface-rfc.md +++ b/sdk/plugin-api-v1-lua-surface-rfc.md @@ -51,7 +51,7 @@ not invent identifiers. [Core boundaries](https://github.com/bitty-terminal/bitt and the [Plugin Platform RFC](../specifications/plugin-platform-rfc.md) record the same three-way split. The accepted statements below remain in force: -1. [Lua Runtime RFC](../runtime/lua-runtime-rfc.md) fixes the single host bridge in every +1. Lua Runtime RFC fixes the single host bridge in every VM as a versioned `bitty` module whose "function surface is owned by the respective API RFCs"; [ADR 0006](https://github.com/bitty-terminal/bitty-docs/blob/main/docs/decisions/adrs/ADR-0006-os-env-policy.md) already fixes `bitty.env.get` and `bitty.env.has` under that module. @@ -70,12 +70,12 @@ Out of scope; owned elsewhere and only referenced here: pipeline classes, batching, budgets, and drop policy ([Plugin Platform RFC](../specifications/plugin-platform-rfc.md), accepted). - VM construction, restricted standard library, rooted module resolution, - diagnostics classes ([Lua Runtime RFC](../runtime/lua-runtime-rfc.md), accepted), pins and + diagnostics classes (Lua Runtime RFC, accepted), pins and allowlist ([ADR 0005](https://github.com/bitty-terminal/bitty-docs/blob/main/docs/decisions/adrs/ADR-0005-lua-pins-and-stdlib.md)), environment reads ([ADR 0006](https://github.com/bitty-terminal/bitty-docs/blob/main/docs/decisions/adrs/ADR-0006-os-env-policy.md)), async boundary and tasks/timers ([ADR 0007](https://github.com/bitty-terminal/bitty-docs/blob/main/docs/decisions/adrs/ADR-0007-async-gc.md)). - Resource ceilings and enforcement numbers - ([Isolation Resource RFC](../runtime/isolation-resource-rfc.md), accepted). + (Isolation Resource RFC, accepted). - Scene content contract ([Rich Presentation RFC](https://github.com/bitty-terminal/bitty-terminal-docs/blob/main/specifications/rich-presentation-rfc.md), accepted). - Panel identity, lifecycle, and providers @@ -110,13 +110,13 @@ concept. Options were compared against the accepted sources and the Rust `bitty-plugin-host` evidence (`crates/bitty-plugin-host/src/{event,registry,host,capability,manifest}.rs`), which is the only exact, machine-checkable representation today. -| Option | Disposition | Rationale | -| ------------------------------------------------------------- | --------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| Module root `bitty`, namespaced functions | **Adopted** | Accepted by [Lua Runtime RFC](../runtime/lua-runtime-rfc.md) ("the single host bridge in every VM is a versioned `bitty` module") and already used by accepted `bitty.env.get`/`bitty.env.has` in [ADR 0006](https://github.com/bitty-terminal/bitty-docs/blob/main/docs/decisions/adrs/ADR-0006-os-env-policy.md). The Plugin Platform RFC namespace rules give each namespace an accepted contract. | -| Module root `bitty.api.*` | Rejected | Adds an unaccepted nesting level with no contract behind it; conflicts with the accepted `bitty.env.*` shape; would force one concept to have two spellings. Only source is a finding recommendation that itself cites no accepted spelling. | -| Flat `bitty.register_command`/`on_event`/`get_terminal_state` | Rejected | Accepted material uses namespaced shapes (`bitty.commands.register`, `bitty.events.subscribe`, `bitty.terminal.snapshot`); flat verbs consume the global module namespace, collide with future accepted additions (`bitty.env`), and lose the per-namespace capability mapping. | -| `register_panel` for a panel provider | Rejected for v1 | Panel identity and lifecycle are not accepted: [Workspace Compositor](https://github.com/bitty-terminal/bitty-terminal-docs/blob/main/specifications/workspace-compositor.md) explicitly introduces no `PanelId`, and the [Panel pre-study](https://github.com/bitty-terminal/bitty-terminal-docs/blob/main/specifications/panel-runtime-pre-study.md) leaves the provider contract and `panel.*` mapping open. Panel providers are post-v1.0 per the [plugin roadmap](../product/plugin-roadmap.md#post-v10-panel-ecosystem-candidates) pending that RFC. | -| Colon-style methods `bitty.services:get(...)` | Rejected for v1 | Accepted material uses dot calls with explicit option tables; colon methods imply Lua object/self semantics that the host-owned value-return contract does not require. Provider ecology remains Draft post-1.0. | +| Option | Disposition | Rationale | +| ------------------------------------------------------------- | --------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| Module root `bitty`, namespaced functions | **Adopted** | Accepted by Lua Runtime RFC ("the single host bridge in every VM is a versioned `bitty` module") and already used by accepted `bitty.env.get`/`bitty.env.has` in [ADR 0006](https://github.com/bitty-terminal/bitty-docs/blob/main/docs/decisions/adrs/ADR-0006-os-env-policy.md). The Plugin Platform RFC namespace rules give each namespace an accepted contract. | +| Module root `bitty.api.*` | Rejected | Adds an unaccepted nesting level with no contract behind it; conflicts with the accepted `bitty.env.*` shape; would force one concept to have two spellings. Only source is a finding recommendation that itself cites no accepted spelling. | +| Flat `bitty.register_command`/`on_event`/`get_terminal_state` | Rejected | Accepted material uses namespaced shapes (`bitty.commands.register`, `bitty.events.subscribe`, `bitty.terminal.snapshot`); flat verbs consume the global module namespace, collide with future accepted additions (`bitty.env`), and lose the per-namespace capability mapping. | +| `register_panel` for a panel provider | Rejected for v1 | Panel identity and lifecycle are not accepted: [Workspace Compositor](https://github.com/bitty-terminal/bitty-terminal-docs/blob/main/specifications/workspace-compositor.md) explicitly introduces no `PanelId`, and the [Panel pre-study](https://github.com/bitty-terminal/bitty-terminal-docs/blob/main/specifications/panel-runtime-pre-study.md) leaves the provider contract and `panel.*` mapping open. Panel providers are post-v1.0 per the plugin roadmap pending that RFC. | +| Colon-style methods `bitty.services:get(...)` | Rejected for v1 | Accepted material uses dot calls with explicit option tables; colon methods imply Lua object/self semantics that the host-owned value-return contract does not require. Provider ecology remains Draft post-1.0. | `register_panel`/`on_event`/`get_terminal_state` reappear in this surface as `bitty.ui.mount`, `bitty.events.subscribe`, and `bitty.terminal.snapshot` @@ -285,7 +285,7 @@ bitty.store.set(key, value) -> boolean - Quota: `STORE_QUOTA_BYTES` default 256 KiB persisted per plugin; overflow fails closed with `E_STORE_QUOTA` (`budget` class), never evicting or partially writing. The numbers are recorded as `RC-11` in the - [Isolation Resource RFC](../runtime/isolation-resource-rfc.md). + Isolation Resource RFC. - Persistence: the store survives suspension, reload, and generation disposal; writes from generation N are committed synchronously before N is disposed, so N+1 reads the same values. Data is deleted only by uninstall @@ -317,7 +317,7 @@ returns `nil`, indistinguishable from an unset variable. The manifest capability spelling and the function names above are two different things. The accepted -[Plugin Manifest and Capability Grammar Authority](../specifications/manifest-capability-authority.md) +Plugin Manifest and Capability Grammar Authority section 1 owns the canonical manifest spelling `env.read:`, with `env.read:PREFIX_*` for a prefix wildcard and the bare `env.read:*` allow-all form rejected; the earlier short form `env:` is rejected as well and @@ -599,7 +599,7 @@ and are not satisfied by this documentation change alone: [ADR index](https://github.com/bitty-terminal/bitty-docs/blob/main/docs/decisions/adrs/README.md), [ADR 0006](https://github.com/bitty-terminal/bitty-docs/blob/main/docs/decisions/adrs/ADR-0006-os-env-policy.md), [ADR 0007](https://github.com/bitty-terminal/bitty-docs/blob/main/docs/decisions/adrs/ADR-0007-async-gc.md), the - [Isolation Resource RFC](../runtime/isolation-resource-rfc.md), and the CarryCtx task + Isolation Resource RFC, and the CarryCtx task record were updated in the same ratification change; no divergent copy is created. @@ -631,11 +631,11 @@ dispositions are: resolutions for LUA-OQ-1 through LUA-OQ-12, ratified 2026-09-11. - [Plugin Platform RFC](../specifications/plugin-platform-rfc.md) — accepted manifest, capabilities, namespace rules, event pipeline. -- [Plugin Manifest and Capability Grammar Authority](../specifications/manifest-capability-authority.md) +- Plugin Manifest and Capability Grammar Authority — accepted capability grammar; owns the `env.read:` environment capability spelling, the `env.read:PREFIX_*` wildcard, and the rejection of the short `env:` form. -- [Lua Runtime RFC](../runtime/lua-runtime-rfc.md) — accepted `bitty` host bridge, sandbox, +- Lua Runtime RFC — accepted `bitty` host bridge, sandbox, module resolution, diagnostics. - [Core boundaries](https://github.com/bitty-terminal/bitty-terminal-docs/blob/main/architecture/core-boundaries.md) — ownership and authority statement. @@ -643,7 +643,7 @@ dispositions are: register-versus-claim, key-binding precedence. - [Rich Presentation RFC](https://github.com/bitty-terminal/bitty-terminal-docs/blob/main/specifications/rich-presentation-rfc.md) — accepted `SceneNode` and `RichBlock` contracts. -- [Isolation Resource RFC](../runtime/isolation-resource-rfc.md) — RC budgets and queue +- Isolation Resource RFC — RC budgets and queue ceilings. - [Workspace Compositor](https://github.com/bitty-terminal/bitty-terminal-docs/blob/main/specifications/workspace-compositor.md) and [Panel Runtime pre-study](https://github.com/bitty-terminal/bitty-terminal-docs/blob/main/specifications/panel-runtime-pre-study.md) — panel identity and diff --git a/sdk/reference/env.md b/sdk/reference/env.md index 346d2ff..044fcd0 100644 --- a/sdk/reference/env.md +++ b/sdk/reference/env.md @@ -85,7 +85,7 @@ expected gate is one grant per key: the trait docs require an RFC extension-level split lists the surface as gated by `env.read:` (RFC extension table). The canonical manifest spelling is owned by the accepted -[Plugin Manifest and Capability Grammar Authority](../../specifications/manifest-capability-authority.md) +Plugin Manifest and Capability Grammar Authority section 1: `env.read:` for one variable and `env.read:PREFIX_*` for a prefix wildcard, with the bare `env.read:*` allow-all form rejected. `bitty.env` is absent from the VM unless the manifest declares the grant @@ -169,7 +169,7 @@ granted-path claim beyond this denial shape is follow-up work. - [Plugin API v1 Lua Surface RFC](../plugin-api-v1-lua-surface-rfc.md) (Accepted; "Notifications and environment" spellings, `env.read:` gate, LUA-OQ-2 absent-unless-declared carve-out) -- [Plugin Manifest and Capability Grammar Authority](../../specifications/manifest-capability-authority.md) +- Plugin Manifest and Capability Grammar Authority (Accepted; section 1 owns the canonical `env.read:` spelling, the `env.read:PREFIX_*` wildcard, and the rejection of the short `env:` form and the `env.read:*` allow-all wildcard) diff --git a/sdk/reference/store.md b/sdk/reference/store.md index 549056b..013914b 100644 --- a/sdk/reference/store.md +++ b/sdk/reference/store.md @@ -80,7 +80,7 @@ a callback that completes before reaching a slice boundary is not suspended. The RC-11 quota ceilings (256 KiB total, 8 KiB per value, 8 depth, 1024 nodes) remain unchanged. -See [Isolation and Resource Budgets RFC](../../runtime/isolation-resource-rfc.md) +See the Isolation and Resource Budgets RFC RC-1 row and risk R-RC1-STORE-CREDIT for normative policy, mitigation layers, and the rationale. diff --git a/specifications/plugin-platform-rfc.md b/specifications/plugin-platform-rfc.md index e7406ca..bdce832 100644 --- a/specifications/plugin-platform-rfc.md +++ b/specifications/plugin-platform-rfc.md @@ -49,7 +49,7 @@ rules. Out of scope (each remains owned elsewhere): - Lua runtime/binding choice and standard-library subset (OQ-009, accepted in - [Lua Runtime RFC](../runtime/lua-runtime-rfc.md)) and the + Lua Runtime RFC) and the configuration model (OQ-010). This RFC assumes the accepted direction of one isolated Lua VM per plugin and defines only the host side of the boundary. - Per-plugin budget thresholds, instruction/memory/task enforcement mechanisms, @@ -208,8 +208,7 @@ Accepted validation rules: or the inline-table form `{ version = "...", prerelease = }`. The `version` value is validated by the closed resolver constraint grammar, and `prerelease` is optional and defaults to `false`; `prerelease = true` opts - that single edge into prerelease selection per the - [Package Follow-up RFC](../packaging/package-followup-rfc.md#prerelease-policy). No other + that single edge into prerelease selection. No other table key is accepted. See the open reconciliation item below for the chosen shape rationale and implementation status. 9. The optional `[tools.git]` table declares the accepted Layer-2 system-CLI @@ -224,8 +223,7 @@ Accepted validation rules: is accepted. > **Open reconciliation item — manifest dependency prerelease TOML shape.** -> The accepted [Package Follow-up RFC](../packaging/package-followup-rfc.md#prerelease-policy) -> defines a per-edge `prerelease` opt-in but no manifest TOML shape for it, and +> The accepted per-edge `prerelease` opt-in defines no manifest TOML shape for it, and > the string-only example above left the dependency table ambiguous. This note > fixes the shape and records the reconciliation instead of rewriting the > accepted example. @@ -561,7 +559,7 @@ Accepted rules: budgets. 6. Three-level queue budgets (accepted, OQ-014, aligned with `bitty-plugin-host/src/event.rs` and the - [Isolation Resource RFC](../runtime/isolation-resource-rfc.md#proposed-resource-ceilings) + [Plugin Host Runtime RFC](../runtime/plugin-host-runtime-rfc.md#a6-timeouts-and-budgets) RC-5 family): **PerSubscription 64 events** per `(plugin, event-type)` queue (strict FIFO bound in `EventQueue::push`); **PerPlugin 1024 events / 256 KiB** aggregate across all queues of one plugin (enforced at @@ -681,10 +679,10 @@ Acceptance of this RFC on 2026-08-27 applies these same-change updates: moved from pointer to closure per the close rule. - [Decision register](https://github.com/bitty-terminal/bitty-docs/blob/main/docs/decisions/index.md): the candidate queue and accepted artifacts gain this RFC, and DIR-001 records it as the accepting contract. -- [Specifications index](README.md): the Plugin Platform RFC row moves from +- Specifications index: the Plugin Platform RFC row moves from Draft to Accepted. - [Proposed delivery sequence](https://github.com/bitty-terminal/bitty-terminal-docs/blob/main/product/proposed-delivery-sequence.md) and - [Isolation Resource RFC](../runtime/isolation-resource-rfc.md): stale proposed references + Isolation Resource RFC: stale proposed references are swept to the accepted contract. No new repository, crate, or workflow is added by this RFC. @@ -776,8 +774,8 @@ reopen the closed design-level questions. - [Plugin API v1 Lua Surface RFC](../sdk/plugin-api-v1-lua-surface-rfc.md) and [ADR 0009](https://github.com/bitty-terminal/bitty-docs/blob/main/docs/decisions/adrs/ADR-0009-plugin-api-v1-lua-surface.md): accepted v1 host spellings, signatures, and the authority split. -- [Package Follow-up RFC](../packaging/package-followup-rfc.md) and - [Isolation Resource RFC](../runtime/isolation-resource-rfc.md): dependency +- Package Follow-up RFC and + Isolation Resource RFC: dependency prerelease-shape reconciliation and the RC-5 resource-ceiling family. - [Open-question register](https://github.com/bitty-terminal/bitty-docs/blob/main/docs/decisions/open-questions.md) and [Decision register](https://github.com/bitty-terminal/bitty-docs/blob/main/docs/decisions/index.md): acceptance and closure records for