Skip to content

feat(desktop): supervisor host — embedded PM engine (per-user) / client mode (per-machine) [SD-1] #832

Description

@rickylabs

Part of #830.

Per-user: the window embeds the PM engine and supervises sidecars. Per-machine: OS units supervise; the window is a client. Same-origin /_svc proxy with per-launch token + dynamic ports (multi-login safe); OS-authenticated read-token broker; adoption via PM-A #827; containment = universal pipe-EOF (entrypoint harness + guardian wrapper for raw executables, both over PM-B #828) + the core Job-Object primitive. Entire host-side surface INTERNAL (public consumption = #451 + SD-6).

Depends on: PM-1..14, #827, #828, #831.

  • gate: hard-kill containment incl. a deliberately non-cooperative raw executable, both platforms
  • gate: proxy auth positive + cross-user negative; embedding tests w/ failure injection + fake clock; non-export lint

Design source: PR #822 (rfc.md + plan.md rev 10, 9-cycle adversarial trail) in .llm/runs/rfc-single-deployment--orchestrator/. (plan.md §A.3/§B.3a/§C.3b)

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions