Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
9 changes: 5 additions & 4 deletions architecture/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -25,8 +25,9 @@ when real content exists; empty placeholder pages are avoided.

All three pages are draft, candidate design input that authorizes no
shipped behavior. Accepted boundaries they reconcile against live in the
[runtime](../runtime/README.md), [sdk](../sdk/README.md), and
[packaging](../packaging/README.md) trees and in the accepted
[published runtime contract](../runtime/plugin-host-runtime-rfc.md),
[sdk](../sdk/README.md), and
[packaging](../packaging/plugin-reuse-and-providers.md) pages and in the accepted
[Plugin Platform RFC](../specifications/plugin-platform-rfc.md). Shared
cross-project governance stays in
[bitty-docs](https://github.com/bitty-terminal/bitty-docs) and is linked, never
Expand All @@ -42,7 +43,7 @@ copied.

## Diagrams

The glossary-driven diagram suite lives in
[diagrams/](diagrams/README.md): the canonical node and edge inventory plus
The glossary-driven diagram suite lives in the corpus-only `diagrams/`
directory (not published on the website): the canonical node and edge inventory plus
Mermaid sources and vector exports. Each diagram node carries its own status;
diagram content authorizes no shipped behavior.
12 changes: 6 additions & 6 deletions architecture/plugin-ecosystem-model.md
Original file line number Diff line number Diff line change
Expand Up @@ -69,7 +69,7 @@ The layering is semantic, not a nesting of runtimes:
`contribution`.
- Summarized as **runtime flat, semantics layered**, consistent with the
accepted one-VM-per-plugin-identity-and-generation rule in the
[Isolation and Resource RFC](../runtime/isolation-resource-rfc.md) (`IR-D2`).
Isolation and Resource RFC (`IR-D2`).

## Extension points as a first-class concept

Expand Down Expand Up @@ -112,7 +112,7 @@ Registry versus manifest asymmetry: the author-facing manifest is the
declaration source, while the registry is an attestation and index service that
only reads and records the dependency edges and compatibility declarations from
it, and is not authoritative for them (see the registry boundaries in the
[Package Follow-up RFC](../packaging/package-followup-rfc.md)).
Package Follow-up RFC).

### Candidate contribution shapes (unaccepted)

Expand Down Expand Up @@ -162,7 +162,7 @@ every Bitter capability and the sandbox would lose its meaning. This extends the
accepted deny-by-default capability model in the
[Plugin Platform RFC capability model](../specifications/plugin-platform-rfc.md) and the
containment rules in the
[Isolation and Resource RFC](../runtime/isolation-resource-rfc.md): grants stay per plugin
Isolation and Resource RFC: grants stay per plugin
identity and manifest hash, and a dependency edge is not a grant.

## Extension-platform API versioning
Expand Down Expand Up @@ -264,7 +264,7 @@ service surface — `process`, `network`, `fs`, `store`, `secrets`, `tasks`,
`notifications`, `clipboard`, `commands`, `events`, `services` — each behind
the same deny-by-default sandbox described by the
[Plugin Platform RFC](../specifications/plugin-platform-rfc.md) and the
[Isolation and Resource RFC](../runtime/isolation-resource-rfc.md). Panel state is split
Isolation and Resource RFC. Panel state is split
into distinct axes (lifecycle, focus, visibility, interaction, attention)
rather than one enum. For v1 this direction keeps the accepted animation
restrictions: only Core-owned chrome animates, plugin shaders and native
Expand Down Expand Up @@ -353,10 +353,10 @@ treating the whole direction as a generic proposal.
| Platform/host versus extension plugin | [Plugin Reuse and Provider Ecology RFC](../packaging/plugin-reuse-and-providers.md) | Extends; provider ecology is close but does not name host plugins |
| Extension points and contribution manifest | [UI Extensibility Architecture](ui-extensibility-architecture.md); none for `[contributes]` | Extends; the inventory exists, a formal extension-point model is unaddressed |
| Accepted `[dependencies]` manifest | [Plugin Platform RFC](../specifications/plugin-platform-rfc.md) | Aligns; accepted schema already defines the dependency shape |
| Capability non-escalation | [Plugin Platform RFC](../specifications/plugin-platform-rfc.md), [Isolation and Resource RFC](../runtime/isolation-resource-rfc.md) | Aligns; the dependency-edge framing is new |
| Capability non-escalation | [Plugin Platform RFC](../specifications/plugin-platform-rfc.md), Isolation and Resource RFC | Aligns; the dependency-edge framing is new |
| Extension-platform API versioning | [Plugin API v1 Lua Surface RFC](../sdk/plugin-api-v1-lua-surface-rfc.md), [Plugin Platform RFC](../specifications/plugin-platform-rfc.md) | Extends; host API versioning is candidate |
| Plugin graph | [Plugin system](../extensibility/plugin-system.md) | Extends the dependency and service direction |
| Panel as host / Activity stack | [UI Extensibility Architecture](ui-extensibility-architecture.md) (P2), [Plugin Roadmap](../product/plugin-roadmap.md) | Unaddressed here; the accepted sibling Panel Runtime RFC leaves provider details as its open questions (`RFC-OQ-1`..`RFC-OQ-9`) |
| Panel as host / Activity stack | [UI Extensibility Architecture](ui-extensibility-architecture.md) (P2), Plugin Roadmap | Unaddressed here; the accepted sibling Panel Runtime RFC leaves provider details as its open questions (`RFC-OQ-1`..`RFC-OQ-9`) |
| Native UI, widget layer, and application services | [UI Extensibility Architecture](ui-extensibility-architecture.md), [Plugin API v1 Lua Surface RFC](../sdk/plugin-api-v1-lua-surface-rfc.md), [Plugin Platform RFC](../specifications/plugin-platform-rfc.md) | Extends the ownership boundaries, v1 slot UI, and capability families |

## Open points
Expand Down
32 changes: 16 additions & 16 deletions architecture/plugin-ipc-boundary.md
Original file line number Diff line number Diff line change
Expand Up @@ -58,7 +58,7 @@ The candidate direction draws the suitability line explicitly:
| Out-of-process (IPC) plugin | AI, Git daemon, language tooling, indexer, sync, database, network service, large computation, external application integration | independent lifecycle, may crash, complex dependencies, other languages, network/database use, coarse call granularity |

Alignment: the accepted
[Isolation and Resource RFC](../runtime/isolation-resource-rfc.md) already names "a helper
Isolation and Resource RFC already names "a helper
process with scoped IPC" as a high-isolation extension direction, and the draft
[Plugin Reuse and Provider Ecology RFC](../packaging/plugin-reuse-and-providers.md) Layer 4
defines declared, digest-pinned native helper processes over stdio or a
Expand All @@ -82,7 +82,7 @@ The dependency-minimization direction matches the "no embed third-party crate
bloat" rule and helper-process staging stated in the draft
[Plugin Reuse and Provider Ecology RFC](../packaging/plugin-reuse-and-providers.md), and the
isolation direction in the accepted
[Isolation and Resource RFC](../runtime/isolation-resource-rfc.md); the daemon split
Isolation and Resource RFC; the daemon split
itself remains a proposal.

## Panel and Agent as public protocol surfaces
Expand Down Expand Up @@ -169,7 +169,7 @@ grammar**: the accepted model uses closed, owner-qualified identifiers with
parameters (for example `terminal.semantic-read`, `process.spawn:git`),
deny-by-default grants bound to plugin identity and manifest hash, and no
wildcards ([Plugin Platform RFC](../specifications/plugin-platform-rfc.md);
[Isolation and Resource RFC](../runtime/isolation-resource-rfc.md)). The boolean
Isolation and Resource RFC). The boolean
`[permissions]` table must not be read as schema, and a future plugin process
would receive scoped grants, never ambient authority; mapping a capability
token to the accepted IPC scopes and plugin grants is an open item (open item
Expand All @@ -183,7 +183,7 @@ Candidate proposal: an out-of-process plugin that crashes must not
take down Bitty; the direction poses restart, disable, and log-surfacing
options rather than defining a policy. Alignment: resource isolation and failure
semantics for IPC/MCP clients are accepted in the
[Isolation and Resource RFC](../runtime/isolation-resource-rfc.md), but no accepted
Isolation and Resource RFC, but no accepted
document defines a plugin-process supervisor, restart policy, or reconnection
semantics (candidate, open item 2).

Expand Down Expand Up @@ -238,7 +238,7 @@ and dependency distinctions live in
### Accepted local baseline versus proposed transport

A direct local-function-call shortcut must not be imported literally.
The accepted [Isolation RFC IR-D2](../runtime/isolation-resource-rfc.md#ir-d2-plugin-runtimes)
The accepted Isolation RFC `IR-D2`
keeps one VM per plugin identity/generation with no shared globals or module
trees; [Host Runtime A.3](../runtime/plugin-host-runtime-rfc.md#a3-bridge-marshalling-contract)
requires bounded copied arguments/results, non-reentrant bridge calls, and
Expand Down Expand Up @@ -289,17 +289,17 @@ owner-pending direction is tracked in

## Affected contracts

| Theme | Existing document | Relationship |
| ---------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------- |
| Lua versus out-of-process plugin suitability | [Isolation and Resource RFC](../runtime/isolation-resource-rfc.md), [Plugin Reuse and Provider Ecology RFC](../packaging/plugin-reuse-and-providers.md) | Aligns with the accepted helper-process direction; broader IPC plugin participants are candidate |
| Core minimization and `bitty-ai` daemon split | [Plugin Reuse and Provider Ecology RFC](../packaging/plugin-reuse-and-providers.md) | Aligns with the draft no-embed rule and Layer 4 staging; the daemon split is candidate |
| Panel/Agent protocol surface | [Plugin Ecosystem Model](plugin-ecosystem-model.md) Panel and activity section, sibling Panel Runtime RFC | Extends; Panel ownership and provider surface stay with the sibling contract |
| Plugin-to-plugin event bus | [Plugin Platform RFC](../specifications/plugin-platform-rfc.md) | Extends the accepted event pipeline to cross-process subscribers; candidate |
| Unified capability model and method vocabulary | [Plugin Platform RFC](../specifications/plugin-platform-rfc.md), [Plugin API v1 Lua Surface RFC](../sdk/plugin-api-v1-lua-surface-rfc.md) | Aligns on one registry for CLI/palette/IPC/Agent reuse; the external binding and names are candidate |
| Capability tokens and `[permissions]` sketch | [Plugin Platform RFC](../specifications/plugin-platform-rfc.md), [Isolation and Resource RFC](../runtime/isolation-resource-rfc.md) | Diverges from the accepted capability grammar; must be reconciled, not added in parallel |
| Crash isolation and supervision | [Isolation and Resource RFC](../runtime/isolation-resource-rfc.md), [IPC and Agent RFC](https://github.com/bitty-terminal/bitty-ai-docs/blob/main/specifications/ipc-agent-rfc.md) | Aligns on untrusted-client boundaries; supervisor semantics are unaddressed |
| Control CLI and multi-instance addressing | [IPC and Agent RFC](https://github.com/bitty-terminal/bitty-ai-docs/blob/main/specifications/ipc-agent-rfc.md) | Aligns with accepted instance selection; `bittyctl` verbs and `bitty://` addressing are candidate |
| Three-layer extension framing | [Plugin Ecosystem Model](plugin-ecosystem-model.md) Platform-versus-extension section | Consistent with "runtime flat, semantics layered"; combined framing is candidate |
| Theme | Existing document | Relationship |
| ---------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------ | ---------------------------------------------------------------------------------------------------- |
| Lua versus out-of-process plugin suitability | Isolation and Resource RFC, [Plugin Reuse and Provider Ecology RFC](../packaging/plugin-reuse-and-providers.md) | Aligns with the accepted helper-process direction; broader IPC plugin participants are candidate |
| Core minimization and `bitty-ai` daemon split | [Plugin Reuse and Provider Ecology RFC](../packaging/plugin-reuse-and-providers.md) | Aligns with the draft no-embed rule and Layer 4 staging; the daemon split is candidate |
| Panel/Agent protocol surface | [Plugin Ecosystem Model](plugin-ecosystem-model.md) Panel and activity section, sibling Panel Runtime RFC | Extends; Panel ownership and provider surface stay with the sibling contract |
| Plugin-to-plugin event bus | [Plugin Platform RFC](../specifications/plugin-platform-rfc.md) | Extends the accepted event pipeline to cross-process subscribers; candidate |
| Unified capability model and method vocabulary | [Plugin Platform RFC](../specifications/plugin-platform-rfc.md), [Plugin API v1 Lua Surface RFC](../sdk/plugin-api-v1-lua-surface-rfc.md) | Aligns on one registry for CLI/palette/IPC/Agent reuse; the external binding and names are candidate |
| Capability tokens and `[permissions]` sketch | [Plugin Platform RFC](../specifications/plugin-platform-rfc.md), Isolation and Resource RFC | Diverges from the accepted capability grammar; must be reconciled, not added in parallel |
| Crash isolation and supervision | Isolation and Resource RFC, [IPC and Agent RFC](https://github.com/bitty-terminal/bitty-ai-docs/blob/main/specifications/ipc-agent-rfc.md) | Aligns on untrusted-client boundaries; supervisor semantics are unaddressed |
| Control CLI and multi-instance addressing | [IPC and Agent RFC](https://github.com/bitty-terminal/bitty-ai-docs/blob/main/specifications/ipc-agent-rfc.md) | Aligns with accepted instance selection; `bittyctl` verbs and `bitty://` addressing are candidate |
| Three-layer extension framing | [Plugin Ecosystem Model](plugin-ecosystem-model.md) Platform-versus-extension section | Consistent with "runtime flat, semantics layered"; combined framing is candidate |

## Open points

Expand Down
Loading
Loading