Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 5 additions & 5 deletions .mstar/knowledge/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -18,9 +18,9 @@ Engineering reference for the Nexus OSS harness **knowledge** tree.
| Document | Role |
| --- | --- |
| [crate-selection-best-practices.md](crate-selection-best-practices.md) | Rust workspace dependency conventions |
| [schemas-external-consumer-boundary.md](../specs/schemas-external-consumer-boundary.md) | **Moved to specs** (2026-08-17) — wire vs local-only contract types |
| [world-kb-runtime-architecture.md](../specs/world-kb-runtime-architecture.md) | **Moved to specs** (2026-08-17) — World KB implementation SSOT |
| [architecture-patterns/actor-bearer-boundary-composition.md](architecture-patterns/actor-bearer-boundary-composition.md) | Actor bearer boundary composition — stored admission, owner-scoped KE, exact session keys, shared memory pipeline, atomic ToM carrier writes (distilled from the shipped v1.184 Actor vertical; SSOT: [specs/actor-product-model.md](../specs/actor-product-model.md)) |
| [schemas-external-consumer-boundary.md](../specs/architecture/schemas-external-consumer-boundary.md) | **Moved to specs** (2026-08-17) — wire vs local-only contract types |
| [world-kb-runtime-architecture.md](../specs/architecture/world-kb-runtime-architecture.md) | **Moved to specs** (2026-08-17) — World KB implementation SSOT |
| [architecture-patterns/actor-bearer-boundary-composition.md](architecture-patterns/actor-bearer-boundary-composition.md) | Actor bearer boundary composition — stored admission, owner-scoped KE, exact session keys, shared memory pipeline, atomic ToM carrier writes (distilled from the shipped v1.184 Actor vertical; SSOT: [specs/architecture/actor-product-model.md](../specs/architecture/actor-product-model.md)) |
| [architecture-patterns/canvas-surface-implementation-pattern.md](architecture-patterns/canvas-surface-implementation-pattern.md) | Canvas surface implementation pattern — six-layer coupled contract + projection data-completeness + spatial edges + fixture-projection + viewport guard + **layer 11 discoverability** (V1.67–V1.76 distilled; V1.108–V1.111 updates; compound V1.77/V1.109/V1.111) |
| [architecture-patterns/spoke-adapter-conversion-seam.md](architecture-patterns/spoke-adapter-conversion-seam.md) | SPOKE adapter conversion-seam: product domain type ↔ spoke wire type; sole extension point for body schema evolution |
| [architecture-patterns/action-registry-command-palette.md](architecture-patterns/action-registry-command-palette.md) | Action registry + command palette — module store + `useSyncExternalStore`, render-time `available?()`, `useHotkey` conflict-avoidance, WAI-ARIA combobox (V1.111 P0 distilled; compound V1.111) |
Expand Down Expand Up @@ -342,14 +342,14 @@ Engineering reference for the Nexus OSS harness **knowledge** tree.

| Document | Description |
| --- | --- |
| [architecture-patterns/actor-maintenance-lifecycle-capture.md](architecture-patterns/actor-maintenance-lifecycle-capture.md) | Actor maintenance lifecycle + run capture — per-resource revision CAS (expected_revision, named conflict codes), internal lifecycle_epoch as a session fence (re-read under the exclusive fence), per-Character activity fence with busy-refusal (`character_busy`) held across effects, drain-authoritative capture from the `HostFacade::exec` stream, atomic cancel latch + bounded outcome memory, receipt-keyed immutable dedup + FK-backed provenance, bounded digest accumulation with checked arithmetic (distilled from the landed v1.185 Actor maintenance vertical; SSOT: [specs/actor-product-model.md](../specs/actor-product-model.md) §11) |
| [architecture-patterns/actor-maintenance-lifecycle-capture.md](architecture-patterns/actor-maintenance-lifecycle-capture.md) | Actor maintenance lifecycle + run capture — per-resource revision CAS (expected_revision, named conflict codes), internal lifecycle_epoch as a session fence (re-read under the exclusive fence), per-Character activity fence with busy-refusal (`character_busy`) held across effects, drain-authoritative capture from the `HostFacade::exec` stream, atomic cancel latch + bounded outcome memory, receipt-keyed immutable dedup + FK-backed provenance, bounded digest accumulation with checked arithmetic (distilled from the landed v1.185 Actor maintenance vertical; SSOT: [specs/architecture/actor-product-model.md](../specs/architecture/actor-product-model.md) §11) |
| [engineering-conventions/canonical-invalid-input-422.md](engineering-conventions/canonical-invalid-input-422.md) | Canonical `invalid_input` → HTTP 422 convention — errors.rs is the mapping SSOT; the legacy `InvalidInput { field, reason }` variant is the same code but 400 (constructor decides status); JSON-Schema `maxLength` is codepoints while byte caps are runtime-enforced (summary 65,536 bytes); manual raw-query parsing where Axum extractors bypass the error envelope; spec-prose drift reconciliation (§11.1/§11.5/§11.6 three 400→422 alignments — check spec status tables against errors.rs before coding) |

### v1.187 additions

| Document | Description |
| --- | --- |
| [architecture-patterns/design-pair-token-compiler.md](architecture-patterns/design-pair-token-compiler.md) | Design-pair token compiler — one deterministic projection from `DESIGN.md`/`DESIGN.dark.md` to the three checked-in derived artifacts (`tokens.css`, package `theme.css`, generated brand snapshot); path-only projection registry, fail-closed null/empty/parity/duplicate-key/cycle rules, `generate` + byte-compare `check`, and the Studio Vite plugin that transforms the same CSS in memory (memoized compile, DESIGN files registered as watch inputs, full CSS-module invalidation, document-request re-read without a reload loop, no HMR source writes) (v1.187 P0 distilled; compound v1.187; normative contract: [specs/design-studio.md](../specs/design-studio.md) §3.5) |
| [architecture-patterns/design-pair-token-compiler.md](architecture-patterns/design-pair-token-compiler.md) | Design-pair token compiler — one deterministic projection from `DESIGN.md`/`DESIGN.dark.md` to the three checked-in derived artifacts (`tokens.css`, package `theme.css`, generated brand snapshot); path-only projection registry, fail-closed null/empty/parity/duplicate-key/cycle rules, `generate` + byte-compare `check`, and the Studio Vite plugin that transforms the same CSS in memory (memoized compile, DESIGN files registered as watch inputs, full CSS-module invalidation, document-request re-read without a reload loop, no HMR source writes) (v1.187 P0 distilled; compound v1.187; normative contract: [specs/surfaces/design-studio.md](../specs/surfaces/design-studio.md) §3.5) |
| [architecture-patterns/iframe-pair-view-theme-isolation.md](architecture-patterns/iframe-pair-view-theme-isolation.md) | Same-origin iframe pair view with forced frame-local theme — two documents through the same Studio entrypoint plus an allowlisted `studio-embed=light\|dark` parameter; pre-render theme application; forced ThemeProvider bypassing storage/media listeners; a validated ready handshake (`origin` + `contentWindow` + theme/path) tied to the mounted lazy leaf; remount-by-key reset/retry; 640px local-scroll frames, 1024px two-column threshold (v1.187 P2 distilled; compound v1.187; spec §5.3) |
| [architecture-patterns/studio-catalog-mount-then-focus.md](architecture-patterns/studio-catalog-mount-then-focus.md) | Studio catalog + mount-then-focus navigation contract — metadata-only `GalleryEntry` catalog with frozen ids, filterable section index with the full keyboard/no-results/Clear path, and the route→mount→focus protocol: bounded cancellable animation-frame retry that focuses the resolved heading (not the wrapper section) below measured sticky chrome; compare mode updates frame hashes instead of searching the parent document (v1.187 P2 distilled; compound v1.187; spec §5.4) |
| [conventions/bounded-local-scroll-containment.md](conventions/bounded-local-scroll-containment.md) | Bounded local scrolling as the responsive containment pattern — keep `scrollWidth === clientWidth` at 1440/1280/390 and contain wide content in local scroll regions (`min-w-0` on grid/flex containers, `.studio-fixture-boundary`, keep-web table overflow wrappers, stacking rails, wrapping chrome/badges); never hide document overflow or delete/scale content (v1.187 P1+P2 distilled; compound v1.187) |
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
# Governance-Audience Strictness Needs a Runtime Guard

**Source:** v1.199 medium-residual convergence (`R4-audience-oneOf`, plan `2026-09-28-medium-residual-convergence`). SSOT for the audience contract: [holder-governance.md](../../specs/holder-governance.md).
**Source:** v1.199 medium-residual convergence (`R4-audience-oneOf`, plan `2026-09-28-medium-residual-convergence`). SSOT for the audience contract: [holder-governance.md](../../specs/architecture/holder-governance.md).

## Failure shape

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -31,7 +31,7 @@ related_components:

A Character crosses identity, World membership, knowledge, execution, memory, and mental-state storage. Isolation is sound only when every layer derives scope from stored rows and passes an admitted capability forward. Rechecking only the route payload, revision, or provider session id leaves cross-Actor seams.

Normative product semantics live in [Actor Product Model](../../specs/actor-product-model.md). This document captures the reusable implementation pattern validated by the shipped v1.184 Actor vertical ([Actor Product Model §10](../../specs/actor-product-model.md)); the v1.184 iteration package is a local process artifact and is not tracked at HEAD.
Normative product semantics live in [Actor Product Model](../../specs/architecture/actor-product-model.md). This document captures the reusable implementation pattern validated by the shipped v1.184 Actor vertical ([Actor Product Model §10](../../specs/architecture/actor-product-model.md)); the v1.184 iteration package is a local process artifact and is not tracked at HEAD.

## Guidance

Expand Down Expand Up @@ -87,8 +87,8 @@ Apply this pattern when adding an Actor kind, widening World/binding visibility,

Durable spec/source authority for each shipped slice (the v1.184 package files behind these remain historical provenance only):

- Actor identity and binding — [Actor Product Model §2/§4.2](../../specs/actor-product-model.md)
- Actor knowledge ownership and view — [Actor Product Model §5](../../specs/actor-product-model.md)
- Actor execution and session isolation — [Actor Product Model §6](../../specs/actor-product-model.md), [agent-host.md](../../specs/agent-host.md)
- Character SOUL and Memory — [Actor Product Model §4.1](../../specs/actor-product-model.md), [creator-memory-soul-lifecycle.md](../../specs/creator-memory-soul-lifecycle.md)
- Character ToM L1/L2 — [Actor Product Model §4.1](../../specs/actor-product-model.md), [spoke-adapter-architecture.md](../../specs/spoke-adapter-architecture.md)
- Actor identity and binding — [Actor Product Model §2/§4.2](../../specs/architecture/actor-product-model.md)
- Actor knowledge ownership and view — [Actor Product Model §5](../../specs/architecture/actor-product-model.md)
- Actor execution and session isolation — [Actor Product Model §6](../../specs/architecture/actor-product-model.md), [agent-host.md](../../specs/agents/agent-host.md)
- Character SOUL and Memory — [Actor Product Model §4.1](../../specs/architecture/actor-product-model.md), [creator-memory-soul-lifecycle.md](../../specs/creator/creator-memory-soul-lifecycle.md)
- Character ToM L1/L2 — [Actor Product Model §4.1](../../specs/architecture/actor-product-model.md), [spoke-adapter-architecture.md](../../specs/architecture/spoke-adapter-architecture.md)
Original file line number Diff line number Diff line change
Expand Up @@ -32,7 +32,7 @@ related_components:

The v1.185 developer loop added material mutation and reversible freeze to the shipped Actor vertical: identity edit, archive/restore, WorldSheet maintenance, bounded KE content maintenance, and an opted-in run-to-memory capture. Three well-known concurrency mechanisms are individually insufficient here: SQLite row CAS does not cover Host sessions or file effects, a provider session can outlive a DB transaction, and a server-owned stream ends on the Host's schedule, not the request's. The pattern combines **per-resource revision CAS**, an **internal lifecycle epoch**, a **per-Character activity fence**, and a **drain-authoritative capture** with a receipt-keyed immutable dedup.

Normative product semantics: [Actor Product Model §11](../../specs/actor-product-model.md). The sibling composition doc covers the shipped v1.184 admission/bearer boundaries: [actor-bearer-boundary-composition.md](actor-bearer-boundary-composition.md).
Normative product semantics: [Actor Product Model §11](../../specs/architecture/actor-product-model.md). The sibling composition doc covers the shipped v1.184 admission/bearer boundaries: [actor-bearer-boundary-composition.md](actor-bearer-boundary-composition.md).

Rejected option (kept as explicit non-goal): archive cancels all sessions, persists conversation/job history, and reconstructs capture from broadcast or SSE. Cancellation cannot atomically roll back provider or file effects, broadcasts are lossy, and persistent history is out of scope. Busy is refused, never forced.

Expand Down Expand Up @@ -123,4 +123,4 @@ Each mechanism covers what the others cannot. Row CAS protects the SQLite truth;
- Drain, digest, persist — `crates/nexus-daemon-runtime/src/actor_run_capture.rs` (`drain_and_finalize_character_operation`, `try_persist_capture`, `DrainAccumulator`, `build_capture_digest`).
- Receipt dedup, provenance — `crates/nexus-local-db/src/character_pending_review.rs` (`capture_character_run`, `capture_character_run_in_tx`, `receipt_matches_input`), migration `crates/nexus-local-db/migrations/20260906000003_character_run_capture.sql`.
- Stale-session rejection and session admission order — `crates/nexus-daemon-runtime/src/api/handlers/agent_host.rs` (`prepare_prompt`, retired-session paths).
- Published slice — the v1.185 iteration package is a local process artifact (not tracked at HEAD); the durable authorities are [§11](../../specs/actor-product-model.md) plus the sources above.
- Published slice — the v1.185 iteration package is a local process artifact (not tracked at HEAD); the durable authorities are [§11](../../specs/architecture/actor-product-model.md) plus the sources above.
Original file line number Diff line number Diff line change
Expand Up @@ -90,5 +90,5 @@ V1.148 P3 adopted `spoke-connect` (libp2p + noise + yamux + Ed25519 signed-hello
## Examples

- V1.148 P3 `crates/nexus-spoke-adapter/src/manifest.rs` (shared builder), `apps/nexus42/src/commands/connect/{mod,identity,allowlist,interop}.rs` (Connect Host + interop), `crates/nexus-home-layout/src/device_id.rs` (host_id SSOT).
- Spec: `.mstar/specs/spoke-adapter-architecture.md` §10 (Connect Host N-C0 normative surface).
- Spec: `.mstar/specs/architecture/spoke-adapter-architecture.md` §10 (Connect Host N-C0 normative surface).
- The N-C series shipped end-to-end: **N-C1 (V1.153)** — write-op exchange; **N-C2 (V1.154)**; **N-C3 (V1.155)**. Capability-token production (issuance CLI + `config.json` enforcement + PeerScope intersection) shipped in **V1.155 P1**.
Original file line number Diff line number Diff line change
Expand Up @@ -50,6 +50,6 @@ When you discover (or are asked to consume) a shipped Local API handler whose re

## See Also

- [schemas-external-consumer-boundary.md](../../specs/schemas-external-consumer-boundary.md) — wire vs local-only contract types (external consumer side).
- [schemas-external-consumer-boundary.md](../../specs/architecture/schemas-external-consumer-boundary.md) — wire vs local-only contract types (external consumer side).
- [crate-selection-best-practices.md](../crate-selection-best-practices.md) — Rust workspace dependency conventions.
- [`AGENTS.md`](../../../AGENTS.md) — the single-truth-source-for-DTOs invariant (`crates/nexus-daemon-runtime/AGENTS.md`, which restated it, was deleted with the crate in v1.193 P2).
Original file line number Diff line number Diff line change
Expand Up @@ -85,5 +85,5 @@ Use this pattern whenever a local-first service adds an opt-in remote listener.

- Implementation: `crates/nexus-daemon-runtime/src/boot.rs`
- Auth middleware: `crates/nexus-daemon-runtime/src/api/auth_middleware.rs`
- Spec: `.mstar/specs/daemon-runtime.md`
- Surface conventions: `.mstar/specs/daemon-api-surface-conventions.md`
- Spec: `.mstar/specs/archived/daemon-runtime.md`
- Surface conventions: `.mstar/specs/runtime/daemon-api-surface-conventions.md`
Original file line number Diff line number Diff line change
Expand Up @@ -86,7 +86,7 @@ V1.110 optimized the cold-start path. Previously `start_with_budget` ran the ful

V1.96 () hit a P0 blocker: the setup wizard Step 2 hung indefinitely in "Starting daemon…" on a clean `~/.nexus42/` first launch. RCA revealed **three** consumer-side root causes (pre-V1.118, the daemon also crashed within milliseconds when `WorkspaceState::initialize()` found no `active_creator_id`; the wizard just never learned about it). The fixes distill into four durable rules that apply to **any** observer of a process lifecycle event stream, not just the daemon-ready gate.

> **V1.118 supersession (daemon no-Profile boot):** After V1.118 P0 ships, clean home reaches T0 health without `active_creator_id`; the gate opens on `running` and Profile selection is post-gate business flow. Crash-on-no-creator RCA below is **pre-V1.118** only. See [daemon-runtime.md §17](../../specs/daemon-runtime.md) + [desktop-shell.md §13.11](../../specs/desktop-shell.md).
> **V1.118 supersession (daemon no-Profile boot):** After V1.118 P0 ships, clean home reaches T0 health without `active_creator_id`; the gate opens on `running` and Profile selection is post-gate business flow. Crash-on-no-creator RCA below is **pre-V1.118** only. See [daemon-runtime.md §17](../../specs/archived/daemon-runtime.md) + [desktop-shell.md §13.11](../../specs/surfaces/desktop-shell.md).

### Rule 5: probe current state on mount, BEFORE subscribing

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -28,7 +28,7 @@ tags:

Before v1.187, `tooling/design-tokens` shipped a hand-maintained `tokens.css` plus a `check-tokens.mjs` gate that searched strings in handwritten CSS and preset files. That gate could only find literals it was told to search: a DESIGN edit that changed a value without a matching handwritten update either shipped stale CSS or was invisible to the check entirely. The design-language overhaul (full palette, type stack, radius, motion and elevation change in one revision) made the gap unacceptable — every changed token had to flow from the DESIGN pair with no second transcription.

The replacement is a single build-time compiler, `tooling/design-tokens/scripts/project-tokens.mjs`, that owns the entire projection from the repo-root DESIGN pair to every derived artifact. The normative contract is [.mstar/specs/design-studio.md](../../specs/design-studio.md) §3.5.
The replacement is a single build-time compiler, `tooling/design-tokens/scripts/project-tokens.mjs`, that owns the entire projection from the repo-root DESIGN pair to every derived artifact. The normative contract is [.mstar/specs/surfaces/design-studio.md](../../specs/surfaces/design-studio.md) §3.5.

## Guidance

Expand Down
Loading
Loading