Files
stack/docs/DEVELOPER-GUIDE/architecture
veronica 12d5258e20 docs(W4): apply fred's six contract decisions from PR #1350 comment 23693
A - docs/README.md:149-190 rewritten. It prescribed a competing front-matter schema
    (title/type/audience/status/source_of_truth) adopted by 4 of 128 live documents. Two
    documented conventions in one repo is the defect this pass removes, so the README now
    documents the contract and the 4 files convert in the same commit: `type` dropped
    (kind replaces it), `title`/`audience`/`source_of_truth` kept.
B - source-of-truth leaves the kind enum, which is now 6 values, and returns as an orthogonal
    boolean. kind was carrying two independent facts. docs/requirements/native-kanban-sot.md
    is stamped `kind: spec` + `source_of_truth: true`, which is what it always was.
C - status gains `completed`. Applied to the two executed plans, on artifact evidence rather
    than on their own say-so: --purpose push|merge ships in ci-queue-wait.sh, and every section
    the README plan specifies exists in docs/README.md today.
D - kind follows content, never filename. docs/native-kanban-sot/TASKS.md is `kind: spec`
    because its body says "a build plan, not a task tracker". The name stays wrong; that is a
    rename and it is out of scope here.
E - the contract covers .md only, written into the README as a decision with vision's
    YAML.parse measurement as the reason, so the omission does not read as an oversight.
F - channel-protocol.md guide -> spec. Applied, with a correction the reviewer should see: the
    ruling cites "7 normative MUSTs" and there are ZERO uppercase RFC2119 terms in that file.
    Control: the identical grep returns 25 lines in docs/requirements/native-kanban-sot.md. The
    citation half of the finding does hold and is larger than stated. Consequence recorded in
    the worklist: the file's own banner now contradicts its header.

Verified: 128 live .md under docs/ (127 baseline + this PR's worklist), 107 stamped, 0 invalid
kinds, 17 operator-held + 3 supersede-stamp deferrals + 1 generated = 21 unstamped. 107+21=128.
Control: the verifier reports valid=False when a kind is corrupted to `nonsense`, so the
0-invalid result is a real result. prettier --check clean across docs/.
2026-08-20 19:58:17 -05:00
..

kind, status
kind status
guide active

Architecture

Status: Partially migrated. The lease-broker security-contract pages below are current references; the remaining architecture pages are still being classified.

This chapter is the canonical home for Mosaic Stack's system model, component boundaries, data and control flow, security model, architecture decisions, and RFCs. It explains why the system has its shape; it does not replace PRD.md, TASKS.md, or the API contract.

Promoted pages

  • lease-broker-protocol.md — authenticated Unix-socket protocol, identity binding, framing, persistence, and lease transitions.
  • lease-broker-security.md — identity, ancestry, filesystem, whole-class, observer, and named residual security boundaries.
  • mutator-class-gate.md — default-deny tool authorization, runtime adapters, launch choke point, and parser assurance boundary.
  • compaction-revocation.md — Claude/Pi observer lifecycle, runtime generations, revocation, and the bounded residual stale window.
  • channel-protocol.md — current shared channel DTOs and Discord compatibility baseline, with unimplemented adapter work explicitly marked draft.
  • decisions/mos-runtime-portability-m1.md — current logical identity, connector lease, grant, audit, and fencing decision; connector activation remains held.

These pages are current security-contract references and are consumed by the lease-broker acceptance suites. Their live deployment gaps remain explicitly labeled in the pages; this migration does not change runtime behavior.

Planned pages

Path Purpose Status
system-overview.md Platform boundary and major request, event, and agent-runtime flows. Planned.
component-map.md Apps, packages, plugins, and dependency ownership. Planned.
data-flow.md Data, event, and control-plane movement. Planned.
security-model.md Trust boundaries, authority, authentication, and authorization model. Planned.
decisions/ Approved architecture decision records. Partially migrated.
rfcs/ Proposals and protocol RFCs. Draft egress RFC indexed.

Draft RFCs

Promoted pages must be linked here, from DEVELOPER-GUIDE/README.md, and from SITEMAP.md. Do not create duplicate architecture pages in docs/mosaic-stack/ or the docs root.

Migration backlog — not current architecture

Source-of-truth boundary

Architecture pages explain approved design and current system boundaries. Requirements remain in PRD.md; active work remains in TASKS.md; executable behavior remains authoritative in source and tests. Draft proposals belong in rfcs/ or docs/plans/, with status clearly labeled.