@@ -19,11 +19,19 @@ R65. The per-command cutover table was retired after completion as required by s
1919enforces the permanent facts-only admission and runtime-proof invariants without naming historical
2020routes or handler functions.
2121
22+ The #2082 extraction completes the physical ownership boundary: all six platform-family
23+ implementations and their family-owned tests live behind private package exports, ` src/platforms `
24+ is retired, and the former R3 folder seam is gone. R13 now owns concrete platform-package import
25+ direction and implementation laziness; the ` retired-platforms-zone ` gate rejects any attempt to
26+ recreate the old root path.
27+
2228## Rules at a glance
2329
24- - Daemon device-execution code depends on platform-neutral contracts. Concrete device mechanics
25- live in private ` @agent-device/platform-* ` packages and are value-imported only by the root
26- composition module.
30+ - Daemon device-execution code depends on platform-neutral contracts. Concrete device mechanics for
31+ the six canonical families live in private ` @agent-device/platform-* ` packages; each family owns
32+ its implementation and family-specific tests, while shared install-source tests are root-owned
33+ under ` src/__tests__/ ` . The root composition module and R13-governed named consumer facades are
34+ the only production static value-import sites.
2735- The platform registry is ** metadata-eager and implementation-lazy** . Cheap family identity,
2836 inventory entrypoints, and static fact declarations may load at composition time; platform
2937 mechanics and process-lived helper managers load only when discovery or the first binding for that
@@ -105,9 +113,11 @@ provider resolver table and wrapper ordering; only the canonical root may load i
105113lazy until a request enters a provider scope. Daemon device-execution modules import the canonical
106114root interface or runtime contracts only.
107115Shared runtime interfaces and neutral data types live in ` @agent-device/contracts ` . In production,
108- only that composition module or its one R13-governed private implementation submodule may import a
109- concrete platform package; reusable types do not leak through type-only platform imports. Platform
110- packages may import contracts, kernel/domain packages,
116+ only that composition module, its one R13-governed private implementation submodule, or the
117+ R13-governed consumer seams under ` src/core/interactors/ ` may statically import concrete platform
118+ package roots; approved runtime hosts use deferred or type-only root imports, and named Apple
119+ facades expose only their governed domain seam. Reusable types do not leak through type-only
120+ platform imports. Platform packages may import contracts, kernel/domain packages,
111121and explicitly injected host capabilities; they may not import daemon requests or responses, mutable
112122session state, command catalogs/grammar, root implementation files, sibling platform packages, or raw
113123process primitives outside the shared host-command port. R13 applies these rules to static, type-only,
@@ -167,22 +177,27 @@ selection, R11/R13 package enumeration, and the composite typecheck project list
167177>
168178> Enforcement: each substrate package's exported subpaths are pinned in
169179> ` package-boundaries.test.ts ` (widening fails the gate), the contracts mechanics gate stays
170- > planted red, and the ` platforms-root-shape ` rule rejects any new shared file or directory
171- > appearing directly under ` src/platforms ` .
180+ > planted red, and the ` retired- platforms-zone ` rule rejects every production, test, or fixture
181+ > file under the former ` src/platforms ` path .
172182
173183The Apple XCUITest runner client is a durable platform-owned implementation facet colocated
174184inside ` packages/platform-apple ` as the ` src/runner/ ` subtree (#2040 ) — Apple mechanics belong to
175- the Apple package. R13 models the facet by enumeration rather than by exception sprawl: the family
176- exports its root façade plus exactly the ` ./runner ` , ` ./runner/client ` , and ` ./runner/test-host `
177- subpaths; the ` ./runner ` façade subpath is the seam through which daemon and root consumers reach
178- runner mechanics directly today; the host-bound ` ./runner/client ` factory has one composition root
179- and ` ./runner/test-host ` one vitest installer; the facet owns its cache files and usbmux sockets
180- (the ambient-host rule exempts exactly that subtree), while raw process primitives stay banned —
181- host authority still enters through one focused injected port (` AppleRunnerHost ` : process
182- execution, diagnostics, retry, probes, locks, foreground Apple tooling, physical-device control)
183- constructed by exactly one composition root. No current issue owns migrating the runner's direct
184- consumers behind the composition gateway; if such a migration retires them, the ` ./runner ` seam
185- narrows with it, but the facet itself is the intended ownership model, not a temporary exception.
185+ the Apple package. R13 models the package by enumeration rather than by exception sprawl: the family
186+ exports its root façade plus fourteen named domain/mechanics facades — ` ./app-lifecycle ` ,
187+ ` ./app-resolution ` , ` ./debug-symbols ` , ` ./doctor ` , ` ./interactions ` , ` ./install-artifact ` , ` ./macos ` ,
188+ ` ./perf ` , ` ./physical-device ` , ` ./runner-owner ` , ` ./runner/operations ` , ` ./simctl ` , ` ./simulator ` , and
189+ ` ./tool-provider ` — as well as exactly the ` ./runner ` , ` ./runner/client ` , and ` ./runner/test-host `
190+ subpaths. The named facades replace root-only access for synchronous domain consumers without a
191+ broad compatibility barrel; R13 pins the exact export set and allowed consumer seams. The
192+ ` ./runner ` façade subpath is the seam through which daemon and root consumers reach runner mechanics
193+ directly today; the host-bound ` ./runner/client ` factory has one composition root and
194+ ` ./runner/test-host ` one vitest installer; the facet owns its cache files and usbmux sockets (the
195+ ambient-host rule exempts exactly that subtree), while raw process primitives stay banned — host
196+ authority still enters through one focused injected port (` AppleRunnerHost ` : process execution,
197+ diagnostics, retry, probes, locks, foreground Apple tooling, physical-device control) constructed by
198+ exactly one composition root. No current issue owns migrating the runner's direct consumers behind
199+ the composition gateway; if such a migration retires them, the ` ./runner ` seam narrows with it, but
200+ the facet itself is the intended ownership model, not a temporary exception.
186201Mechanics-facet declarations are explicit per family: the Apple runner and Android mechanics/host
187202facets are enumerated above, and a new family adds its own named facet only with an owning consumer
188203and evidence.
@@ -770,11 +785,12 @@ belongs to its domain: test-IME restoration is durable device state with marker-
770785helper stops follow the owning platform module's lifecycle policy, and close-time cleanup consumes
771786neutral owner services.
772787
773- R65 is the end-state enforcement: its planted-red AST tests reject every dependency edge — static,
788+ R65 is the daemon-side end-state enforcement: its planted-red AST tests reject every dependency edge — static,
774789dynamic, re-export, and type-only — from production ` src/daemon/** ` modules (test files excluded,
775790matching the layering scanner's scope) to ` src/platforms/** ` and concrete
776- ` @agent-device/platform-* ` packages. The daemon has been removed from the R3 seam, so platform
777- freedom is structurally enforced rather than periodically measured.
791+ ` @agent-device/platform-* ` packages. R13 governs concrete package imports across the whole tree,
792+ while ` retired-platforms-zone ` prevents the old root seam from being recreated; platform freedom is
793+ therefore structurally enforced rather than periodically measured.
778794
779795## Relationship to prior decisions
780796
0 commit comments