RFC: NetScript Single Deployment — process-managed apps, single & multi runtime (#820)#822
RFC: NetScript Single Deployment — process-managed apps, single & multi runtime (#820)#822rickylabs wants to merge 8 commits into
Conversation
…+ 9-cycle adversarial eval trail
Seed/RFC harness run rfc-single-deployment--orchestrator (Fable 5 high generator,
Sol-max adversarial PLAN-EVAL in 9 separate Codex sessions). Contents:
- research.md: eis-chat#150 POC forensics @ aeaf2df (via public GitHub API),
gap analysis G1-G8, origin/main re-baseline, deployment-debt reconciliation
- plan.md rev 10: the RFC design — PM-first Tier-4 split, deploy-core installer
with journaled operation state machines, one snapshot-update mechanism incl.
Windows apply + crash-recoverable boot composition, two-mode composition
contract, 22-draft dependency-ordered board, owner forks OF-A..OF-K
- plan-eval-cycle{1..9}.md: full verdict trail (final: 6/8 plan-gate boxes PASS
incl. Decisions-locked); escalation.md; closure.md; corpus/ evidence
- Rev 10 folds cycle-9's residual: public/internal classification for the PM-5
RuntimeCommandSpec additions (public), PM-15 renderer knobs (internal,
re-decided at PM-20), SD-1 host-side surface (internal; public = #451/SD-6)
No board mutations were made by this run (evaluator-audited every cycle); the
#820 RFC comment stays gated on a PASS from the owner-launched cycle-10 eval
(recipe in context-pack.md). Refs #820.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016wV13zTE9bz2Yf1iR762qZ
|
@openhands-agent model=openrouter/minimax/minimax-m3 output=pr-comment iterations=100 use harness SKILL
Act as a cheap-and-quick documentation accuracy evaluator. Do not edit source, documentation,
Keep the iteration budget small. Prefer one to three decisive manual checks over broad exploration, |
OpenHands Agent — Agent failedOPENHANDS_VERDICT: NONE Model: OpenHands Agent SummaryThe agent run failed before producing a summary. This is a workflow failure, not a task verdict. Diagnostics
See the uploaded Actions artifact for bootstrap.log and agent.log when present. Run: https://github.com/rickylabs/netscript/actions/runs/29595954682 |
#822) in the rfc-820 run artifacts Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016wV13zTE9bz2Yf1iR762qZ
|
@openhands-agent model=openrouter/minimax/minimax-m3 output=pr-comment iterations=100 use harness SKILL
Act as a cheap-and-quick documentation accuracy evaluator. Do not edit source, documentation,
Keep the iteration budget small. Prefer one to three decisive manual checks over broad exploration, |
OpenHands Agent — Agent failedOPENHANDS_VERDICT: NONE Model: OpenHands Agent SummaryThe agent run failed before producing a summary. This is a workflow failure, not a task verdict. Diagnostics
See the uploaded Actions artifact for bootstrap.log and agent.log when present. Run: https://github.com/rickylabs/netscript/actions/runs/29595996526 |
… record) + trail The reader-facing enterprise RFC synthesized from plan.md rev 10: foundations, shipping plan, acme-notes e2e flows with mermaid diagrams, security model, board impact, owner forks OF-A..K. Refs #820. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016wV13zTE9bz2Yf1iR762qZ
|
@openhands-agent model=openrouter/minimax/minimax-m3 output=pr-comment iterations=100 use harness SKILL
Act as a cheap-and-quick documentation accuracy evaluator. Do not edit source, documentation,
Keep the iteration budget small. Prefer one to three decisive manual checks over broad exploration, |
OpenHands Agent — Agent failedOPENHANDS_VERDICT: NONE Model: OpenHands Agent SummaryThe agent run failed before producing a summary. This is a workflow failure, not a task verdict. Diagnostics
See the uploaded Actions artifact for bootstrap.log and agent.log when present. Run: https://github.com/rickylabs/netscript/actions/runs/29598237598 |
), RFC rev 11 - FILING-LOG.md + filing-log.json: milestone beta.14, epic:unified-runtime label (+labels.yml parity), 17 new issues, 14 adjustments, #349 closed - rfc.md rev 11: unified epic #823 separated from desktop; installer = .NET Aspire ATS integration #825 (OF-D resolved); ratified shipping order PM -> unified -> desktop-graph; live-numbered board state + decision log - plan.md authority banner (GitHub + rfc.md win on sequencing); worklog Turn 2; drift entry 8; context-pack final state. Refs #820 #823 #830. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016wV13zTE9bz2Yf1iR762qZ
|
@openhands-agent model=openrouter/minimax/minimax-m3 output=pr-comment iterations=100 use harness SKILL
Act as a cheap-and-quick documentation accuracy evaluator. Do not edit source, documentation,
Keep the iteration budget small. Prefer one to three decisive manual checks over broad exploration, |
OpenHands Agent — Agent failedOPENHANDS_VERDICT: NONE Model: OpenHands Agent SummaryThe agent run failed before producing a summary. This is a workflow failure, not a task verdict. Diagnostics
See the uploaded Actions artifact for bootstrap.log and agent.log when present. Run: https://github.com/rickylabs/netscript/actions/runs/29612042812 |
…er-confirmed) in run trail Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016wV13zTE9bz2Yf1iR762qZ
|
@openhands-agent model=openrouter/minimax/minimax-m3 output=pr-comment iterations=100 use harness SKILL
Act as a cheap-and-quick documentation accuracy evaluator. Do not edit source, documentation,
Keep the iteration budget small. Prefer one to three decisive manual checks over broad exploration, |
OpenHands Agent — Agent failedOPENHANDS_VERDICT: NONE Model: OpenHands Agent SummaryThe agent run failed before producing a summary. This is a workflow failure, not a task verdict. Diagnostics
See the uploaded Actions artifact for bootstrap.log and agent.log when present. Run: https://github.com/rickylabs/netscript/actions/runs/29612633339 |
…irst thin-client, tiered updates (RFC rev 12) - epic #840 (beta.11): full frontend as desktop app the NetScript way — SDK auto-update wrapper #841 (Deno.desktop churn isolation, Windows staged+manual posture, upstream apply tracked denoland/deno#35269), type-safe bindings #842 (oRPC MessagePort over bind-channel shim), fresh-ui desktop components #843 - #452/#456/#457 re-scoped native-first; #825 -> beta.14 (full-stack tier); F4 tiered update lifecycle; one release-server/manifest lineage - FILING-LOG Option-A section; labels.yml parity epic:desktop-frontend Refs #820 #840 #327. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016wV13zTE9bz2Yf1iR762qZ
|
@openhands-agent model=openrouter/minimax/minimax-m3 output=pr-comment iterations=100 use harness SKILL
Act as a cheap-and-quick documentation accuracy evaluator. Do not edit source, documentation,
Keep the iteration budget small. Prefer one to three decisive manual checks over broad exploration, |
OpenHands Agent — Agent failedOPENHANDS_VERDICT: NONE Model: OpenHands Agent SummaryThe agent run failed before producing a summary. This is a workflow failure, not a task verdict. Diagnostics
See the uploaded Actions artifact for bootstrap.log and agent.log when present. Run: https://github.com/rickylabs/netscript/actions/runs/29614034402 |
…topology) — RFC rev 13 Owner-identified middle tier between server Servy deploys and the beta.14 single-output artifact: desktop window + PM-managed sidecars as Windows services & Scheduled Tasks. PM-19 compile splits by start policy (resident -> Servy; cron -> Scheduled Task). Wraps schtasks now; adopts Deno.cron.persistent (denoland/deno#33965 — verified: scaffold open, backends pending) when upstream lands. Prosumer CLI install v1, no .NET dependency; consumer MSI variant folds into #833/#825 at beta.14. Refs #820 #510 #327 #845. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016wV13zTE9bz2Yf1iR762qZ
|
@openhands-agent model=openrouter/minimax/minimax-m3 output=pr-comment iterations=100 use harness SKILL
Act as a cheap-and-quick documentation accuracy evaluator. Do not edit source, documentation,
Keep the iteration budget small. Prefer one to three decisive manual checks over broad exploration, |
OpenHands Agent — Agent failedOPENHANDS_VERDICT: NONE Model: OpenHands Agent SummaryThe agent run failed before producing a summary. This is a workflow failure, not a task verdict. Diagnostics
See the uploaded Actions artifact for bootstrap.log and agent.log when present. Run: https://github.com/rickylabs/netscript/actions/runs/29614247275 |
…ndoff beta-11 orchestrator kickoff (charter = milestone 13 / RFC #820 outcomes), launched in tmux beta11-orch (Fable 5 low, bypassPermissions, session id 86d308d5-...) with Remote Control enabled. RFC run closure.md records the handoff. Refs #820 #840. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016wV13zTE9bz2Yf1iR762qZ
|
@openhands-agent model=openrouter/minimax/minimax-m3 output=pr-comment iterations=100 use harness SKILL
Act as a cheap-and-quick documentation accuracy evaluator. Do not edit source, documentation,
Keep the iteration budget small. Prefer one to three decisive manual checks over broad exploration, |
OpenHands Agent — Agent failedOPENHANDS_VERDICT: NONE Model: OpenHands Agent SummaryThe agent run failed before producing a summary. This is a workflow failure, not a task verdict. Diagnostics
See the uploaded Actions artifact for bootstrap.log and agent.log when present. Run: https://github.com/rickylabs/netscript/actions/runs/29615415901 |
rfc.md presents the ratified direction, laws, public API design, wave plan, 29-child placeholder board, migration/supersession map, and owner forks OF-1..OF-8 in the #822 RFC format. Drift D-6 records the owner's in-turn stop-line lift for the draft PR (board filing still withheld). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EWs7xBg7oNqCCkxipVM5HR
RFC — NetScript Single Deployment: process-managed apps, single & multi runtime
plan.md(this PR)Abstract
Today a NetScript application is a development-time orchestration: Aspire runs the graph, and nothing owns what happens on an end user's machine. This RFC makes "one artifact, one install, one update" a first-class NetScript capability:
The same contract covers two composition modes: single-runtime (all services composed into one process) and singleton-graph (a native window supervising an adjacent process graph — databases with exclusive locks, external tools, isolated workers). Both modes share one packaging pipeline, one manifest family, one update mechanism, and one first-run story; they diverge only where physics demands it.
Single-runtime as a product is bigger than any single deployment target: it is the Unified epic (#823) — Nitro v3 as the runtime-agnostic single deploy output with cloud presets and its adapter surface (database, cache, KV, tasks, WebSocket), positioning NetScript as a Next.js/Nuxt-class contender while teams scale by splitting resources into "macro services" across deploy targets. This RFC owns the foundations (supervision, packaging, installation, update) and the desktop targets; the Unified epic owns the single-runtime product and starts with its own seed run (#824).
1. Motivation
The eis-chat prototype (eis-chat#150) proved the end state is real: a Deno Desktop window directly supervising Garnet plus six compiled NetScript services, shipped as a single folder, working offline, with full Aspire telemetry — no Docker, no .NET runtime, no installed Aspire on the user's machine.
It also proved exactly what must NOT be script glue, because the prototype breaks precisely where the framework is absent:
.cmdlauncherDeno.autoUpdate()patches only the window binary — and cannot apply on WindowsEvery row above becomes a framework foundation below.
2. Goals and non-goals
Goals (v1):
Non-goals (v1, explicitly deferred): macOS installers/notarization; fleet management (MDM/GPO/MSIX/app stores); staged-rollout rings; per-user instance brokering on shared machines; serverless/edge packaging.
3. The two composition modes
The rule: applications default to single-runtime and earn the graph — the framework treats the graph as the same app with K > 0 artifacts, not a different product. The enforcement point is a typed manifest family plus a cross-mode conformance suite (#837) that runs one reference app in both modes and asserts the shared behavior (discovery, data layout, provisioning, update, telemetry identity).
4. Architecture — five foundations
F1 · Process supervision (the Process Manager engine — epic #510)
The supervision layer the POC lacked, built as a library (never a god-daemon):
nextDelay(state, policy, clock)— exponential backoff, restart budgets, skip-exit-codes.http,tcp,process-lingering(the three the POC actually needed), grace windows.SIGKILL) closes it and the child self-terminates via a core runtime helper. Processes that can't cooperate (Garnet-class raw executables) are spawned through a tiny guardian wrapper that holds the pipe and kills its child-tree on EOF. OS backstops: Windows Job Objects (kill-on-job-close); Linux renderedKillMode=control-groupfor per-machine units.F2 · Packaging pipeline (from the app model, never a hand map)
One pipeline turns the app you already have into the artifact set:
PackagingModel— resources, endpoints, dependency edges, env/discovery topology — from the same model that already generates the Aspire dev helpers. Zero hand-maintained service maps.(PackagingModel, deploy.targets.<member>.package config) → InstallGraphManifestadds what the graph can't know: scope, identity, signing, provisioning, migration/snapshot policy.deno compiled sidecars (plugins ship compile-ready./servicesentrypoints), staged tools, launchers — with OTEL enablement baked at compile time (a hard-won POC lesson: runtime-only env yields an empty dashboard).netscript deploy <target> buildverb, and a named TS-AppHostpipeline.addStep(...)soaspire publishproduces installers as part of its step graph.F3 · Installation layer (inside the deploy stack, not beside it)
Desktop targets are ordinary
DeployTargetPortadapters in the existing registry (install→up,uninstall→down) plus a narrowMaintenancePortforrepair/recover— no parallel command tree, no new port axis.OsServicePortunder a dedicated low-privilege account; every user's window is a client).staged → claiming → provisioning → registering → starting → confirmed, with reverse-replay compensation from any failure), repair (journal-reconciling, idempotent), uninstall (retains data by default), and purge (a separate four-state, roll-forward-only operation whose journal lives outside the install root, so an explicit purge survives even the installer's own deletion).%ProgramData%\NetScript\//var/lib/netscript/): installs reserve fixed ports transactionally and refuse with actionable diagnostics on conflict — two NetScript apps coexist or fail loudly, never silently.deno desktop's pure-Rust MSI packages only the window bundle (per-machine, no sidecars) and its docs punt to WiX/NSIS/Inno for more. SoNetScript.Aspire.Packagingships as a C# Aspire hosting-integration NuGet annotated with ATS[AspireExport]: the Aspire CLI generates a typed TypeScript SDK from it (JSON-RPC into the C# code at runtime), and the TS AppHost consumes it as decorators/publish-pipeline steps — the exact mechanism Aspire documents for multi-language integrations. WiX-class MSI authoring and thesigntoolhook live behind it; deb/rpm stays native-side. Build machines need the .NET SDK (already true in the POC); end users need nothing.F4 · Update lifecycle (tiered — ratified Option A, 2026-07-17)
Two apply mechanisms, one release-server/manifest lineage, each used where it's honest:
Window-only artifacts (the thin-client tier, beta.11 — epic epic: Desktop Frontend — the full frontend as a native desktop app, the NetScript way #840): native
Deno.autoUpdate()— bsdiff deltas, Ed25519-signedlatest.json, staged swap, self-healing rollback — wrapped by a typed SDK mechanism (feat(sdk): robust programmatic auto-update — typed wrapper over Deno.autoUpdate + release client #841) that pins keys, wires per-arch URLs, reports rollbacks to telemetry, and isolates upstream API churn (theDeno.desktopnamespace move, feat(desktop): move desktop runtime APIs under Deno.desktop namespace denoland/deno#35939). Windows caveat, stated honestly: upstream apply is still unsupported (patches stage but never swap — tracked in deno desktop: follow-ups (test coverage, CJS analyzer heuristic, platform gaps) denoland/deno#35269), so v1 ships staged-detection + a manual-update UX; if upstream lands apply, the tier converges for free.Combined artifacts (window + sidecars, beta.14): the native mechanism patches one file and cannot cover N artifacts, so NetScript updates the whole release atomically:
Immutable releases:
releases/<version>/+ acurrentlink; a stable installer-managed bootstrap resolves the release journal-first (by direct path), so recovery works even whencurrentis missing after a crash — Windows' junction-swap non-atomicity becomes harmless.A durable journal (append-only, checksummed, fsynced) drives every transition; recovery from any crash boundary — including a cold reboot mid-switch — is a deterministic table lookup, executed unattended by an installer-registered recovery unit before any workload starts.
Three-phase ownership (no self-starting deadlocks): boot recovery does pointer-level reconciliation only → the OS starts the graph → one confirm watcher observes sustained health (default 60 s, zero crash-restarts) and either commits or initiates rollback.
Data safety: pre-migration snapshots into a transaction area; irreversible migrations declare a rollback barrier — crossing one and failing lands in an explicit
maintenancestate with a documentedrecoverpath, never silent data loss.Supply-chain posture: Ed25519-signed manifests against a key pinned at install time; a monotonic sequence high-water blocks replay/downgrade even across an authorized recovery; release/bootstrap version compatibility is enforced before staging.
The release server ships in the thin-client tier serving the native manifest format; the combined-artifact release manifest is a designed superset (same crypto) — one lineage, no fork.
F5 · Runtime surface (discovery, health, auth, window bindings)
Type-safe window bindings (feat(sdk/fresh): type-safe desktop bindings — oRPC MessagePort adapter over the bind channel #842): Deno Desktop's webview↔runtime bindings have no built-in type bridge (the docs prescribe a hand-maintained
bindings.d.ts). NetScript replaces that with contract-first RPC: a port shim adapts the bind channel into a MessagePort pair, and oRPC's Message Port adapter runs the same typed contracts NetScript services already use across the window boundary — end-to-end types, browser/Aspire no-op parity. Desktop UI itself becomes NetScript components (feat(fresh-ui): desktop UI components — tray, menus, dialogs, notifications, window chrome #843: tray, menus, dialogs, notifications, window chrome — fresh-ui, desktop-gated).Discovery without port collisions: per-user graphs allocate sidecar ports dynamically; browser code compiles against port-free same-origin paths (
/_svc/<name>) proxied by the window — N users on one machine can't collide, and the build-timeimport.meta.envconstraint is respected. Per-machine tenants use manifest-fixed, registry-reserved ports.End-user health awareness (the POC's "silently broken" fix): a small SDK widget subscribes to the control plane — "search is restarting (2/3)…" instead of dead features.
Auth: the window's proxy requires a per-launch token (another local user can't ride it); per-machine control-plane access mints per-user read tokens over an OS-authenticated channel; mutations require the admin/updater identity.
5. Sequencing and how it ships (owner-ratified 2026-07-17)
The what-ships-first decision. Three candidates were weighed: desktop multi-process without the PM, the Unified single-runtime epic, and the PM foundation. Resolution:
@netscriptadapters, composition contract, epic decomposition) proceeds in parallel with PM implementation on a separate lane.Deno.autoUpdatewiring (#456), thin-client e2e incl. macOS/Linux apply+rollback proof and the Windows manual path (#457), generator app-type + packaging hook (#452), SDK auto-update mechanism (#841), type-safe bindings via oRPC MessagePort (#842), fresh-ui desktop components (#843); health-aggregation fix (#826); Unified seed run (#824)./servicesentrypoints (#829); PM console packaged window-only (#543)schtasks, adoptsDeno.cron.persistentdenoland/deno#33965 when its backends land**)** — prosumer CLI install, no .NET dependency; the consumer MSI variant folds into beta.14NetScript.Aspire.Packaging#825 (the .NET/ATS integration — load-bearing once the full stack ships as one output), graph update transaction (#834), first-run provisioning (#835), health widget (#836), cross-mode conformance suite (#837), full-fault e2e (#838)Every slice carries adversarially-derived fault gates (crash-mid-junction, torn journal, power-loss replay, barrier crashes, non-cooperative-process hard-kill, unattended reboot, two-app port conflict, replay/downgrade, cross-user proxy denial).
6. End-to-end flows
Example app: acme-notes — a Fresh window UI, a
notesservice owning a tursodb database (exclusive lock ⇒ singleton-graph mode), backgroundworkers, and Garnet as the shared queue backend.6.1 Developer ships a release
flowchart LR subgraph Dev["Developer machine / CI"] A["NetScript app model<br/>(services, plugins, apps)"] -->|generator emits| B["PackagingModel<br/>(typed graph snapshot)"] C["deploy.targets.desktop.package<br/>(scope, identity, signing, migrations)"] --> D B --> D["Manifest compiler<br/>(pure function)"] D --> E["InstallGraphManifest"] E --> F["Build: window bundle +<br/>compiled sidecars + tools<br/>(OTEL baked at compile)"] F --> G["Installer second pass<br/>MSI / deb / rpm"] F --> H["Release manifest<br/>Ed25519-signed, sequenced"] end G --> I[("Distribution")] H --> J[("Release server<br/>per-arch, per-channel")]Triggered by
netscript deploy desktop buildor the registeredaspire publishpipeline step — same code path.6.2 End user installs and runs (per-user mode)
6.3 An update arrives — atomic, health-confirmed, reversible
sequenceDiagram participant RS as Release server participant A as Update authority<br/>(shim / updater unit) participant J as Journal participant OS as OS / graph participant W as Confirm watcher RS-->>A: signed manifest (sequence > high-water?) A->>J: staged (artifacts hash-verified into releases/v2) A->>OS: stop graph (reverse order, budgets) A->>J: migrating — snapshot targets, run steps,<br/>barrier journaled BEFORE irreversible step A->>J: switching — intended target journaled,<br/>repoint current (crash here? journal replays it) A->>OS: start graph on v2 OS->>W: hand-off (journaled) alt healthy for grace window W->>J: confirmed — prune v0, drop snapshots else unhealthy, no barrier crossed W->>A: roll back — restore snapshots,<br/>repoint v1, restart, journal rolled-back else unhealthy, barrier crossed W->>J: maintenance — explicit state,<br/>operator "recover" path, nothing silent end6.4 The journal that makes it crash-safe
stateDiagram-v2 [*] --> staged staged --> stopping stopping --> migrating migrating --> switching : no barrier /<br/>barrier journaled switching --> starting starting --> confirmed : sustained health starting --> rolling_back : failed, no barrier rolling_back --> rolled_back rolling_back --> maintenance : previous release<br/>also fails migrating --> maintenance : failed past barrier confirmed --> [*] rolled_back --> [*] note right of switching Power loss anywhere: the bootstrap replays the journal on next start - unattended, even with "current" missing end note7. Security model (summary)
Install-time-pinned Ed25519 trust root (re-pin only via installer/operator, never a downloaded manifest) · signed manifests + per-artifact hashes · monotonic sequence high-water (no replay/downgrade, survives authorized recovery) · elevation only inside the installer · updater/workload/user privilege separation enforced by ACLs and negatively tested · per-launch proxy tokens · OS-authenticated read-token minting for per-machine status.
8. Board state — FILED 2026-07-17 (owner-ratified and owner-authorized; Option-A pass included)
Full mapping in
FILING-LOG.md(this PR). Option-A pass: Desktop Frontend epic #840 (beta.11) with #841 (SDK auto-update wrapper), #842 (type-safe bindings via oRPC MessagePort), #843 (fresh-ui desktop components); #452/#456/#457 re-scoped native-first under it; #825 → beta.14; labelepic:desktop-frontend. Hybrid-tier pass: #844 (PM-C Task Scheduler adapter, beta.13, Part of #510) + #845 (Windows hybrid deployment tier, beta.13, Part of #327). Base pass: milestone0.0.1-beta.14created; labelepic:unified-runtimecreated (+labels.ymlparity in this PR). New: Unified epic #823 + seed #824 · packaging integration #825 · health fix #826 · PM-A #827 · PM-B #828 · plugin entrypoints #829 · Desktop-graph epic #830 with #831–#838 + #839 (stable). Adjusted: #456/#457 re-titled + re-scoped as the single-artifact substrate; #452 re-scoped (+ public./typesjsr gate); #451/#453/#454/#455 re-homed to #823 (Backlog/Triage pending the seed); PM-1/PM-5/PM-15 amended (#512/#516/#526); #543 Windows-caveat superseded; #458 → stable; #349 closed as superseded; #510 and #327 epic bodies updated with the ratified order.9. Decision log (all ratified 2026-07-17)
| OF-L | Thin-client update mechanism (Option A, ratified 2026-07-17 late) | Native-first: window-only tier uses
Deno.autoUpdatevia the SDK wrapper #841 (Windows = staged-detection + manual UX until upstream apply lands, denoland/deno#35269); the snapshot transaction stays the combined-artifact mechanism (beta.14); one release-server/manifest lineage; #825 → beta.14. Freed capacity funds the Desktop Frontend wave #840 (#841/#842/#843) || OF-M | Windows middle tier (owner-identified, ratified 2026-07-17 late) | Hybrid deployment #845 (beta.13): window app + sidecars as Windows services & Scheduled Tasks — PM-19 compile splits by start policy (resident → Servy service; cron → Scheduled Task via #844, wrapping
schtasksnow and adoptingDeno.cron.persistentwhen upstream backends land); prosumer CLI install v1; consumer MSI variant joins #833/#825 at beta.14 |Remaining open decisions now live where they belong: the Unified epic's are produced by its seed run (#824); the desktop-graph slices carry theirs as implementation-time acceptance (#830 tree).
Provenance. Supersedes #821 (opened from a stale branch by mistake). This PR lands the full engineering record:
plan.mdrev 10 (the normative spec behind §4/§6/§7; where its beta.11 "single-runtime lane" framing conflicts with the ratified §5 order, GitHub and this document win),research.md(eis-chat#150 forensics + gap analysis), a 9-cycle adversarial review trail (plan-eval-cycle1..9.md, GPT-5.6 Sol·max, separate sessions — final: 6/8 plan-gate boxes PASS), andFILING-LOG.md(the 2026-07-17 owner-authorized board filing this document's §8 reflects). Refs #820 — no closing keyword. 🤖 Generated with Claude Code · https://claude.ai/code/session_016wV13zTE9bz2Yf1iR762qZ