Repeat the abandoned early SQLite/daemon line properly, under enforced boundaries:
- start from the architecture skeleton
- lock the boundary contracts in crate-local documents
- build the lint/parser gates before substantive implementation
- implement under those guardrails
This document is the execution tracker for that work.
Status:
- complete
Required decisions:
- name the legal composition owner
- confirm
AtmProtocolis the shared contract inatm-core - confirm
ClientTransport/ServerTransportsplit - confirm thin-client workflow is
send/receive - confirm
ackis folded intosend-shape requests for thin clients - confirm
NotificationSink/StatusSourcesplit - add the missing watch/reconcile boundary
Acceptance:
- the boundary set in crate
boundaries.mdfiles is stable enough to review as design, not just schema
Status:
- complete
Required design clarifications:
- where cross-store orchestration lives
- where compatibility/recovery policy lives for:
ConfigIngressInboxIngressInboxExport
- where request dispatch ends and service orchestration begins
- whether remote daemon-to-daemon client behavior depends on the same
ClientTransportboundary
Acceptance:
- each major boundary has a clear ownership line
- no major subsystem remains “named but still fuzzy”
Status:
- complete
Decision required:
- choose whether runtime wiring lives in:
atm-daemon- or a separate composition/app crate
Acceptance:
- the boundary inventories and crate architecture docs agree on the legal composition owner
Status:
- complete
Artifacts:
docs/atm-core/boundaries.mddocs/atm-rusqlite/boundaries.mddocs/atm-daemon/boundaries.mddocs/atm/boundaries.md
Required follow-up:
- revise the records after R.0 design review
- add the missing watch/reconcile boundary
Acceptance:
- every major Phase R boundary is represented in one crate-local record
Status:
- complete
Completed work:
- aligned top-level architecture and project-plan docs
- aligned crate architecture and requirements docs
- filled the missing watch/reconcile boundary family
- resolved the runtime composition-owner contradiction
- added crate-local ADR records for the key Phase R decisions
- ran repeated review/update loops over requirements, architecture, and boundary records until the remaining work moved out of documentation and into parser/lint or implementation execution
Acceptance:
- the documentation set is internally coherent enough to drive parser and lint work without relying on unstated architectural assumptions
Status:
- complete
Required updates:
- make Phase R the active redesign line
- explicitly reference crate-local
boundaries.mdfiles - describe:
AtmProtocolClientTransportServerTransportRequestDispatcherNotificationSinkStatusSource
- state that thin-client workflow is
send/receive - state that
ackis folded intosend-shape requests for thin clients
Acceptance:
- top-level architecture and crate boundary inventories describe the same system
Status:
- complete
Required updates:
- align
docs/atm-core/architecture.md - align
docs/atm-daemon/architecture.md - align
docs/atm-rusqlite/architecture.md - align
docs/atm/architecture.md
Acceptance:
- crate architecture docs and crate boundary inventories agree on:
- ownership
- composition
- dependency direction
- privacy rules
Status:
- complete
Required updates:
- state enforceable “must” rules for:
- private concrete implementations
- no CLI-to-daemon internal dependency
- no CLI-to-SQLite dependency
- shared protocol owned by
atm-core - thin-client
send/receivesurface - watch/reconcile ownership once named
Acceptance:
- requirements contain only rules that can be checked or reviewed concretely
Status:
- complete
Required ADRs:
AtmProtocolownership inatm-coreackfolded intosend- split
ClientTransport/ServerTransport - concrete implementations remain private
- legal composition owner
- ADR-004: structured boundary definitions (lives on
feature/pR-s3-boundary-lint)
Acceptance:
- each major Phase R design decision has one crate-local ADR record
The items below are not part of the completed documentation hardening loop. They depend on the hardened document set above and move into parser, lint, and implementation execution.
Status:
- in progress by
arch-inj
Scope:
- parse crate-local boundary records
- validate basic record structure
Acceptance:
- parser can read all current
boundaries.mdfiles without ambiguity
Status:
- in progress
Initial lint passes:
- schema validation
- manifest dependency-edge checks
- forbidden external-reference checks
- active impl privacy / constructor / re-export checks
- owner-crate test-bypass checks
Deferred until after design freeze:
- composition-root enforcement (carry into
R.4) - cargo-modules cycle gating beyond false-positive review (carry into
R.4) - unsafe view hardening beyond cargo-geiger package-resolution failures (carry into
R.6)
Acceptance:
just lintcan fail on the first hard architectural violations
Status:
- complete
Merged integrate/phase-R baseline reviewed at:
dbe1eeffrom the sprint brief- current worktree baseline after sync
What is already landed:
crates/atm-core/src/boundary/mod.rscontains the first protocol/runtime trait stubs and placeholder data structures for:AtmProtocolClientTransportServerTransportRequestDispatcherNotificationSinkStatusSourceWatchEventSourceReconcileCoordinator
- boundary docs, ADR alignment, and the initial boundary-enforcement lint suite are in place
just lintis already useful for:- boundary schema and duplicate checks
- owner package / manifest consistency
- allowed-dependent / forbidden-edge checks
- forbidden external reference checks
- active implementation privacy / constructor / re-export checks
- owner-crate test-bypass checks
What is not landed yet:
- config ingestion and inbox ingress/export adapter shells
- final module splits that move daemon/runtime and sqlite adapters out of the current crate-root skeleton files
- any future composition path that connects runtime wiring to sqlite-backed
adapters without introducing a direct
atm-daemon -> atm-rusqliteedge - service orchestration shells that route retained command behavior through the new boundary-owned call graph
Gate status before Wave 2:
- authoritative now:
- boundary/manifests/reference/privacy lint checks
- still tooling work or view-only:
- composition-root enforcement
cargo-modules --acycliccycle gating- Graphviz-backed module view generation
- cargo-geiger-backed unsafe view generation
Status:
- complete
Current landed subset:
crates/atm-daemonandcrates/atm-rusqliteexist as crate-root skeletonscrates/atm-core/src/boundary/mod.rsnow carries stub traits plus request/result shells for:MailStoreTaskStoreRosterStoreConfigIngressInboxIngressInboxExport
- daemon runtime stub adapters are landed for:
ServerTransportNotificationSinkStatusSourceWatchEventSourceReconcileCoordinator
- sqlite stub adapters are landed for:
MailStoreTaskStoreRosterStore
- explicit composition modules exist in:
crates/atm-daemon/src/composition.rscrates/atm/src/composition.rs
just lint sc-boundarypasses on the current skeleton branch with:- no direct CLI-to-daemon edge
- no direct CLI-to-sqlite edge
- no direct daemon-to-sqlite edge permitted by the boundary contract
- daemon boundary inventory now records landed stub runtime adapters for:
ConfigIngressInboxIngressInboxExport
PeerClientTransportandRequestDispatcherdaemon runtime adapters are formally deferred toR.4scope review rather than blocking skeleton close
Follow-on work after R.3.1 close:
- final daemon/rusqlite adapter module splits beyond the current crate-root skeletons
- a trait-only composition path for sqlite-backed runtime assembly that does not
require a direct
atm-daemon -> atm-rusqlitedependency R.4scope review for:- peer client transport
- request dispatcher
Required outcome:
- traits/facades exist
- private implementation shells exist
- composition point exists
- illegal references are already blocked by lint and visibility
Concrete checklist:
crates/atm-daemon- scaffold crate, manifest, and
src/lib.rs - add private runtime adapter shells for:
ServerTransportNotificationSinkStatusSourceWatchEventSourceReconcileCoordinator
- add daemon composition module that becomes the only runtime wiring root
- scaffold crate, manifest, and
crates/atm-rusqlite- scaffold crate, manifest, and
src/lib.rs - add private adapter shells for:
MailStoreTaskStoreRosterStore
- keep constructors private and expose only boundary-facing assembly hooks
- scaffold crate, manifest, and
crates/atm-core- extend
src/boundary/beyond protocol/runtime stubs - land Rust trait definitions plus request/result/error shells for:
MailStoreTaskStoreRosterStoreConfigIngressInboxIngressInboxExport
- tighten protocol placeholder structures into named request/response/frame types that the client/server transports and dispatcher will share
- extend
crates/atm- add an explicit client composition module that wires only:
ClientTransport- observability
- thin
send/receivecommand entry points
- keep retained CLI behavior compiling while routing new construction through the Phase R composition surface
- add an explicit client composition module that wires only:
- Shared data structures
- create the major boundary-owned DTO shells required by the first behavior
sprints:
- protocol request/response envelopes
- store query/command result shapes
- config/inbox import-export request and result shells
- notification/status/watch/reconcile event shells
- create the major boundary-owned DTO shells required by the first behavior
sprints:
- Lint compatibility required before closing
R.3.1- boundary records must point at landed crate/module paths
- no new public concrete adapter constructors
- no illegal caller edges to daemon internals or SQLite crates
Acceptance:
- the architecture can compile in skeleton form before feature behavior lands
Status:
- in progress
Purpose:
- review, drill, and finalize the proposed
R.4throughR.8sprint scopes - identify open scope decisions before Wave 2 implementation begins
- convert the current wave outline into reviewable sprint checklists, not to declare those sprints implicitly approved
Required order:
- protocol and transport
- store boundaries
- config / inbox / notifier / watch boundaries
- service orchestration
- thin client surfaces
Review targets:
R.4 Protocol + Transport- Scope review required first:
ServerTransport,NotificationSink,StatusSource,WatchEventSource, andReconcileCoordinatorcurrently have zero methods; define their minimal callable method surfaces before behavior work starts- no
R.4implementation may start until that scope review is documented and approved by team-lead PeerClientTransportandDaemonRequestDispatcher: define trait surfaces inR.4; concrete daemon adapter implementations are deferred to a later sprint
crates/atm-core/src/boundary/mod.rs- replace placeholder
AtmRequestEnvelope,AtmResponseEnvelope, andAtmFramePayloadwith:RequestEnvelopeResponseEnvelopeFramePayloadin an explicitatm_core::protocolmodule or equivalent architecturally correct home
- add callable methods to:
AtmProtocolClientTransportServerTransportRequestDispatcherNotificationSinkStatusSourceWatchEventSourceReconcileCoordinator
- replace placeholder
crates/atm-daemon/src/lib.rs- implement stub method signatures for runtime-owned adapters:
LocalSocketServerTransportDaemonNotificationSinkDaemonStatusSourceFileWatchEventSourceDaemonReconcileCoordinator
- when any new concrete runtime impl structs land, update the matching
boundary records with explicit
implementation.visibilityandimplementation.constructorexpectations in the same sprint
- implement stub method signatures for runtime-owned adapters:
crates/atm-daemon/src/composition.rs- wire runtime composition to the new transport/dispatcher method surfaces without introducing direct CLI or sqlite dependencies
- carry forward the remaining
R.3.1runtime-composition residuals:- define the trait-only composition path that preserves no direct
atm-daemon -> atm-rusqlitedependency - map any remaining daemon/runtime module-split work needed by transport and dispatcher ownership
- define the trait-only composition path that preserves no direct
crates/atm/src/composition.rs- wire
CliCompositionagainst theClientTransportmethod surface only
- wire
- Acceptance:
RequestEnvelope,ResponseEnvelope, andFramePayloadare named protocol DTO targets and exported from the agreed protocol home- zero-method runtime traits resolved by explicit method surfaces
- CLI and daemon compositions compile against callable transport traits
- no direct
atm -> atm-daemonoratm -> atm-rusqliteedge appears - verify
lint_boundaries.pyrejects any impl of boundary traits outside permitted impl sites documented indocs/*/boundaries.md - verify the remaining open ADR-001 action item is closed by confirming
lint_boundaries.pyand the boundary records reflect all current permitted impl sites - verify the
#[doc(hidden)]ADR-001 action item is closed in the landedatm-coreboundary module implementation - any new concrete implementation struct introduced in this sprint must: (a) add boundary-record visibility/constructor rules; (b) have boundary lint enforce them; (c) pass QA verification of those checks
- QA verifies any new runtime impl structs are covered by active privacy / constructor lint checks
- Scope review required first:
R.5 Store Boundaries- Start gate:
R.5may not begin untilR.4acceptance criteria are signed off by team-lead
crates/atm-core/src/boundary/mod.rs- finalize request / response DTOs for:
MailStoreTaskStoreRosterStore
- ensure method families match actual retained behaviors:
- message persistence / visibility / replay state
- task creation / update / ack transition / message links
- roster replace / load / membership query / health
- finalize request / response DTOs for:
crates/atm-rusqlite/src/lib.rs- replace typed stub failures with real trait implementations for:
SqliteMailStoreSqliteTaskStoreSqliteRosterStore
- keep constructors private and assembly boundary-facing only
- keep boundary records and lint privacy rules in lockstep with every new concrete store implementation struct
- carry forward the remaining
R.3.1sqlite residuals:- complete the adapter/module split beyond the current crate-root skeleton file
- keep the runtime-to-sqlite path trait-only rather than a direct daemon dependency
- replace typed stub failures with real trait implementations for:
- Retained behavior cutover:
- identify and replace direct store ownership in existing retained flows
under:
crates/atm-core/src/read/crates/atm-core/src/clear/crates/atm-core/src/send/crates/atm-core/src/ack/crates/atm-core/src/team_admin/
- identify and replace direct store ownership in existing retained flows
under:
- Tests:
- add store-contract coverage in
crates/atm-core/tests/ - keep adapter-specific behavior tests in
crates/atm-rusqlite
- add store-contract coverage in
- Acceptance:
- SQLite-backed behavior lives behind
MailStore/TaskStore/RosterStore - retained core flows no longer own sqlite-facing logic directly
- replacing the sqlite adapter does not require caller changes outside composition or adapter crates
- any new concrete implementation struct introduced in this sprint must: (a) add boundary-record visibility/constructor rules; (b) have boundary lint enforce them; (c) pass QA verification of those checks
- QA verifies store impl structs remain private and lint-enforced as such
- SQLite-backed behavior lives behind
- Start gate:
R.6 Config / Inbox / Notification / Watchcrates/atm-core/src/boundary/mod.rs- finalize method surfaces and DTOs for:
ConfigIngressInboxIngressInboxExportNotificationSinkStatusSourceWatchEventSourceReconcileCoordinator
- finalize method surfaces and DTOs for:
crates/atm-daemon/src/lib.rs- implement real daemon-owned adapters for:
- config loading
- inbox import/export
- notification delivery
- status reporting
- watch capture
- reconcile coordination
- keep boundary records and lint privacy expectations updated for every newly landed daemon-owned implementation struct
- implement real daemon-owned adapters for:
- Policy placement review:
- document and implement where compatibility / recovery policy is allowed to live inside ingress/export adapters versus service orchestration
- Retained behavior cutover:
- remove direct config parsing, inbox compatibility handling, and watch ownership from retained command/service code
- carry forward the remaining
R.3.1service-shell residuals for these domains before R.7 final orchestration cutover - formal R.6 disposition:
daemon-owned config/inbox/watch adapters land in this sprint, but the
retained
send/read/ack/clearcommand-family cutover toConfigIngress/InboxIngress/InboxExportremains deferred toR.7
- Acceptance:
- config/inbox/notification/watch behavior is owned by explicit adapters
- retained service code consumes those behaviors only through boundary traits
- compatibility policy location is documented and matches implementation
- any new concrete implementation struct introduced in this sprint must: (a) add boundary-record visibility/constructor rules; (b) have boundary lint enforce them; (c) pass QA verification of those checks
- QA verifies newly introduced adapter impl structs are covered by privacy and constructor lint rules
R.7 Service Orchestration- Files in scope:
crates/atm-core/src/send/crates/atm-core/src/read/crates/atm-core/src/clear/crates/atm-core/src/ack/crates/atm-core/src/doctor/- retained shared helpers those flows still call directly
- Required routing changes:
- all retained command/service flows call boundary traits or service-owned orchestration seams only
- remove parallel helper paths that bypass:
- store boundaries
- config ingress
- inbox ingress/export
- notification / status / watch adapters
- Composition constraints:
- daemon composition and CLI composition remain the only legal wiring roots
- no direct adapter construction from retained command modules
- Acceptance:
- direct retained bypasses are removed from service code
- orchestration layer is explicit and thin
- boundary lint remains green after routing changes
- any new concrete implementation struct introduced in this sprint must: (a) add boundary-record visibility/constructor rules; (b) have boundary lint enforce them; (c) pass QA verification of those checks
- QA verifies no orchestration change required widening adapter visibility or bypassing boundary privacy rules
- Files in scope:
R.8 Thin Client Surfacescrates/atm/src/- finalize CLI composition around:
ClientTransport- observability port
- thin
sendentry point - thin
receiveentry point
- remove or isolate any retained command construction path that bypasses the composition module
- finalize CLI composition around:
- Shared protocol surface:
- keep
ackfolded into send-shaped requests rather than a separate top-level thin-client method family
- keep
- Extension readiness:
- ensure
atm-graft-style thin client callers can stop atAtmProtocol+ClientTransportwithout daemon or sqlite references
- ensure
- Acceptance:
- CLI public surface is thin and transport-driven
ackremains modeled insidesend- thin clients do not require daemon-internal or sqlite-facing knowledge
- REQ-P-RUNTIME-001 preserved at
R.8close:- daemon auto-start when absent remains supported
- auto-start failure emits a typed actionable error and recovery guidance
- no production path may silently fall back to direct SQLite or inbox-file access
- daemon lifecycle (
start/stop/health) and all currently supportedatmCLI commands remain functional atR.8close lint_boundaries.pyconfirms the following ADR-001 dependency edges remain FORBIDDEN:atm -> atm-daemonatm -> atm-rusqliteatm-core -> atm-daemonatm-core -> atm-rusqliteatm-daemon -> atm-rusqlite(trait-only/reference-only)
- any new concrete implementation struct introduced in this sprint must: (a) add boundary-record visibility/constructor rules; (b) have boundary lint enforce them; (c) pass QA verification of those checks
- QA verifies no thin-client change introduces direct references to daemon or adapter implementation structs
Acceptance:
- no feature sprint begins before the relevant boundary and lint guardrails are in place
R.4throughR.8are reviewable as concrete sprint proposals with explicit files, traits, and acceptance criteria
Cross-sprint hardening rule:
- whenever a sprint introduces a new concrete implementation struct for a
boundary, that same sprint must also:
- add or update the
boundaries.mdrecord for that implementation - set explicit
implementation.visibilityandimplementation.constructorrequirements - ensure boundary lint actively enforces those privacy expectations
- include QA verification that the privacy / constructor / re-export rules
are present and passing in
just lint
- add or update the
- ADR-001 AGENTS.md guard note:
- complete at
cd70665; no further sprint ownership needed unless the prompt location changes again
- complete at
All Phase R stabilization work routes exclusively to feature/pR-s10-thin-client. Branches feature/pR-s8-config-notify (R.6) and feature/pR-s9-service-orch (R.7) are frozen and treated as historical record only.
Surviving branch: feature/pR-s10-thin-client (PR #181)
Frozen branches: feature/pR-s8-config-notify (PR #182), feature/pR-s9-service-orch (PR #180)
RULE-011 and ARCH-SINGLETON requirements were added to develop after the per-sprint QA passes ran. Applying retroactive fixes branch-by-branch would require three separate remediation rounds on overlapping codebases. Consolidating to R.8 eliminates duplicate work and provides one clear merge path to integrate/phase-R.
Verified 2026-05-05: merge-forward is complete.
- 75b5031 (R.6 head) is ancestor of cc3a70a (R.7 head)
- cc3a70a (R.7 head) is ancestor of fc604ce (R.8 head)
- No further merge-forward needed.
- No QA rounds on frozen branches. Findings on R.6 or R.7 are superseded.
- No commits to
feature/pR-s8-config-notifyorfeature/pR-s9-service-orch. - All daemon fixes, ARCH-SINGLETON sweep, CI-WIN-001, and carry-forward findings apply to
feature/pR-s10-thin-clientonly. - quality-mgr: reject any new assignments targeting frozen branches.
Blocking:
- ARCH-SINGLETON [B]:
spawn_test_daemon/DaemonGuardincrates/atm/tests/send.rsand other test files — replace withCliComposition::from_transport()+ in-processFakeClientTransport - CI-WIN-001 [B]: ungated unix-only imports in
atm-daemon/src/lib.rs— gate with#[cfg(unix)]
Important carry-forward (R.6/R.7/R.8):
- ATM-QA-014, ATM-QA-006, ATM-QA-009, FTQ-006, NEW-004, NEW-002
Minor carry-forward:
- ATM-QA-005
Status:
- in progress on
feature/pR-s9-singleton-planning
Scope:
- convert daemon singleton and test fidelity from scattered review comments into explicit requirements, ADRs, testing guidance, and implementation planning
Task list:
- strengthen product and crate requirements so singleton is daemon
requirement
#1 - explicitly prohibit the current daemon-spawn test pattern by name:
spawn_test_daemonwarm_daemonDaemonGuardATM_DAEMON_BIN- direct
Command::new(...atm-daemon...)
- define at least two runtime singleton guard layers plus one lint/CI gate
- write ADR-002 for host-wide daemon singleton
- write ADR-003 for test fidelity and daemon isolation
- define the singleton lint gate and decide whether existing tools are
sufficient
- decision: existing generic tools are not sufficient by themselves;
add
scripts/lint_daemon_singleton.pyas a dedicated repository lint integrated intojust lint
- decision: existing generic tools are not sufficient by themselves;
add
- define the approved test tiers:
FakeClientTransport- loopback/in-process transport
- narrow daemon-runtime harness
- map the planning response to current findings:
- ARCH-SINGLETON
- CI-WIN-001
- singleton review findings
RBP-F001throughRBP-F012 - ATM-QA-014
- ATM-QA-006
- ATM-QA-009
- NEW-004
- NEW-002
- ATM-QA-005
- FTQ-006
Acceptance:
- the requirements/ADR/plan set is explicit enough to guide implementation without re-litigating the singleton rule
Status:
- planned
Execution slices:
- add the client-side pre-spawn launch gate before daemon fork/exec
- keep the daemon-side startup gate as the final ownership rejection layer
- harden stale-owner recovery without allowing split ownership
- make startup failure typed and deterministic when ownership is already held
- ensure signal installation and stale socket cleanup are idempotent and correctly surfaced
- gate Unix-only daemon runtime code explicitly so Windows CI does not compile unsupported imports or paths by accident
Directly addresses:
- RBP-F003
- RBP-F011
- RBP-F012
- ARCH-SINGLETON
- CI-WIN-001
- make
ClientTransportincludeSend + Sync - separate daemon supervision from transport construction
- add semantic path newtypes for daemon binary and socket path
DaemonBinaryPathandDaemonSocketPath- invariants: non-empty and valid UTF-8 path representation at the boundary
- both types must implement
AsRef<Path>for ergonomic filesystem call-site use - failures return typed parse/validation errors rather than panic/expect
- remove unreachable stub patterns that hide impossible paths behind routine
Result - resolve deadline-overrun semantics so callers can distinguish committed work from clean rejection
- bound daemon request framing instead of unbounded
read_to_end - inject daemon home/observability dependencies once rather than recomputing them per request
- fix fixture/setup boundary ambiguities and missing command-local environment injection coverage identified by NEW-004 and NEW-002
Directly addresses:
- RBP-F004
- RBP-F005
- RBP-F007
- RBP-F008
- RBP-F009
- ATM-QA-014
- ATM-QA-006
- NEW-004
- NEW-002
- delete
spawn_test_daemonandDaemonGuard - remove
warm_daemonfrom ordinary CLI tests - delete
ATM_DAEMON_BIN-driven daemon launch from ordinary tests - replace routine CLI daemon usage with
CliComposition::from_transport(...)plusFakeClientTransport - add loopback/in-process transport where request/handler integration needs more realism than a pure fake
- fix
EnvGuardownership so test environment cleanup cannot race - gate Unix-only daemon-dependent tests explicitly or migrate them to approved in-process seams
- remove obsolete launcher-only panic paths and unused helper parameters as the daemon-spawn helpers disappear
- resolve remaining test-harness shutdown semantics such as ATM-QA-005 inside the Tier 3 daemon-runtime suite rather than leaving them as implicit polling behavior
Directly addresses:
- RBP-F001
- RBP-F002
- RBP-F006
- RBP-F010
- ATM-QA-009
- ATM-QA-005
- FTQ-006
- add a dedicated repository lint to
just lint - script entrypoint:
scripts/lint_daemon_singleton.py - scan test code for prohibited daemon-spawn patterns:
spawn_test_daemonwarm_daemonDaemonGuardATM_DAEMON_BINatm-daemon.sock- direct
Command::new(...atm-daemon...) - timing-based daemon warmup shortcuts in ordinary tests
- document the allowed exceptions for the narrow daemon-runtime suite
- include platform gating checks for Unix-only daemon-runtime code where the default workspace targets Windows CI too
Acceptance:
- no new daemon-spawn pattern can land without a deliberate lint/CI change
- lint gate must document explicit allow-list for Tier 3 daemon-runtime suite
patterns; allowed exceptions for the narrow daemon-runtime suite are governed
by
docs/testing-guidelines.md §4.3
feature/pR-s10-thin-client→integrate/phase-R(after R.5 #179 already merged)integrate/phase-R→develop(user authorization required)
Status:
- planned
Notes:
R.11is already referenced by accepted limitations and remains reservedR.12is already taken in the team sprint ledger- the next new implementation sprint identifier is
R.13 sc-lintinventory-parity / planning-metadata support is treated as an external prerequisite that must be ready beforeR.13begins
Execution sequence:
Status:
-
implemented on
feature/pR-s13-runtime-admission -
close B-001, B-002, and B-003
-
move both daemon lock paths to one host-wide ownership root
-
implement a real
RuntimeComposition::start()lifecycle path -
absorb lifecycle-adjacent shutdown hardening from I-001 and I-002
-
delivered host runtime ownership under
~/.atm/daemon/{launch.lock,owner.lock} -
route
run_daemon()only throughRuntimeComposition::start() -
add typed lifecycle states and rollback on failed startup
-
reject direct
LocalSocketServerTransport::serve()bootstrap outsideRuntimeComposition::start() -
preserve pending terminate/reload bits across repeated signal installs
-
perform bounded stale-owner recovery retries before emitting
ATM_DAEMON_STALE_OWNER_RECOVERY_FAILED -
route listener/accept failures through the same
Running -> Draining -> Stoppedshutdown path as signal-driven termination -
sprint plan:
docs/plans/phase-R/sprint-R13.md
- close the host-scoped SQLite root change under
~/.atm/db/mail.db - implement the linear successor-chain model (
add-details/supersede) - keep
atm ackas one visible reply withrequires_ack = false - implement ephemeral stale-time retention without read-triggered deletion
- finish SQLite error-mapping and test-fixture policy updates
- sprint plan:
docs/plans/phase-R/sprint-R14.md
- close B-004, B-005, and B-006
- implement runtime-owned heartbeat/member state
- implement daemon-owned live status cache
- wire doctor to daemon-backed liveness/readiness projection
- sprint plan:
docs/plans/phase-R/sprint-R15.md
- close B-009 and I-013
- replace
PeerClientTransportstub with real outbound daemon-to-daemon transport - wire durable replay/re-export around the outbound peer path
- sprint plan:
docs/plans/phase-R/sprint-R16.md
- close B-007, B-008, and I-012
- replace one-shot boundary-support helpers with runtime-owned watch and reconcile loops
- add daemon-owned notifier/plugin runtime delivery
- sprint plan:
docs/plans/phase-R/sprint-R17.md
- close I-003 through I-016 that remain after the runtime-lane sprints
- finish config reload, request-id, type-safety, env/test portability, and remaining runtime-boundary hardening
- update plan/requirements/architecture/boundaries to the final landed state
- sprint plan:
docs/plans/phase-R/sprint-R18.md
Status:
- completed on
feature/pR-postmortem-linters
Goal:
- convert the recurring mechanically-detectable Phase R finding families into normal repository lint or CI gates
- prove those rules on
atm-corefirst, then migrate the reusable subset into standalonesc-lint
Partition:
- reusable rules that should begin on
atm-coreand later migrate intosc-lint:- Unix platform-gating enforcement
- bare production
Condvar::wait(...)enforcement
- ATM-local rules that should begin and remain on
atm-coreunless they later stabilize into generic frameworks:- duplicate semantic string-literal enforcement in non-test Rust code
- fixed-sleep test-hygiene enforcement
- triage Turtle consistency enforcement
Execution sequence:
- extend
sc-portabilityfor:- ungated
std::os::uniximports cfg_attr(not(unix), allow(dead_code))portability suppressors
- ungated
- extend the existing identity-literal lint into a duplicate semantic
string-literal gate for non-test Rust code, with raw
”team-lead”as the first mandatory case - add a new repository-local fixed-sleep test-hygiene lint and wire it into
just lint - extend
sc-boundaryfor bare productionCondvar::wait(...)- replacement code must inspect the returned
WaitTimeoutResult; swapping towait_timeout(...)while discarding timeout state is still a bug
- replacement code must inspect the returned
- add a repository-local triage-record consistency lint/CI check and wire it into the default developer gate
- after all families are green and low-noise on
atm-core, extract the reusable Rust analyzer rules and any generalized helper framework into standalonesc-lint
Acceptance:
- each family has one concrete implementation home and one concrete integration point
- every family is classified as either:
- reusable and intended for later
sc-lintmigration, or - ATM-local and retained in repository-local lint glue
- reusable and intended for later
- no family is left as “QA-only tribal knowledge”
- sprint plan:
docs/plans/phase-R/sprint-R19.md
Status:
-
in review on
feature/pR-s20-daemon-partitioning -
review the post-
PR #200integrated daemon state onintegrate/phase-R -
define the daemon-private partition plan for exactly these eight partitions:
ownershipserver_runtimerequest_runtimeruntime_statuspeer_transportwatch_runtimereconcile_runtimenotification_runtime
-
tighten daemon architecture, requirements, and boundaries so the partitioned design is explicit and enforceable
-
run a repeated plan-hardening loop over code and docs until the daemon planning set is internally consistent and specific enough for a production cleanup sprint
-
sprint plan:
docs/plans/phase-R/sprint-R20.md
Phase R does not advance by ad hoc implementation.
Required order:
- design decision
- boundary record
- architecture/requirements/ADR alignment
- lint/parser support
- implementation skeleton
- feature behavior