iop/agent-ops/rules/project/domain/platform-common/rules.md

2.2 KiB

domain last_rule_review_commit last_rule_updated_at
platform-common 4695bcbc60 2026-08-02

Platform Common

Responsibility

Platform Common owns stable packages shared by applications: provider execution primitives, configuration, authentication, audit/events, host setup, metadata, observability, policy, stream evidence gating, versioning, and protobuf source/generated Go bindings.

Owned paths

  • packages/go/execution/
  • packages/go/config/
  • packages/go/audit/
  • packages/go/auth/
  • packages/go/events/
  • packages/go/hostsetup/
  • packages/go/metadata/
  • packages/go/observability/
  • packages/go/policy/
  • packages/go/streamgate/
  • packages/go/version/
  • proto/iop/ and proto/gen/iop/
  • configs/

Required patterns

  • Common packages must not import application-internal packages.
  • packages/go/execution remains transport-neutral and defines provider lifecycle, execution events, typed failures, usage, cancellation, registry, optional commands, and tunnels.
  • Configuration uses named provider adapters and provider resource catalogs. Strict loading rejects removed process-control and automation-ownership keys.
  • External API model ids are translated at the Edge boundary; internal execution uses adapter + target.
  • session_id is correlation only and cancellation targets run_id.
  • Stream-gate runtime remains request-local, bounded, transport-neutral, and free of raw payload persistence.
  • Protobuf changes start in proto/iop/*.proto, preserve removed numbers/names as reservations, and regenerate Go and Dart bindings.
  • Tracked configuration and documentation must not contain credentials or private endpoints.

Prohibited ownership

Shared runtime packages must not manage interactive terminals, persistent host programs, working-directory execution context, resumable conversations, arbitrary host commands, or local quota scraping.

Contracts and verification

  • agent-contract/inner/execution-runtime.md
  • agent-contract/inner/edge-config-runtime-refresh.md
  • agent-contract/inner/edge-node-runtime-wire.md
  • Follow the testing domain rule for shared package, config, or protobuf changes.