b7091dbd1e95e0c3e18e5da0c2ebaf5ca77b73ea
Adds a consolidated invariant layer (INV-1..INV-5) so that context-isolated implementers (e.g. parallel isolated subagents holding only one subsystem slice) cannot violate global rules they cannot see in their slice. - INV-1: session-DB state columns written only by event projection, with an authoritative table→event map and explicit heartbeat/ui_state exemptions. This is the rule the O2 finding violated; centralizing it prevents recurrence. - INV-2: cross-DB writes use outbox + single writer. - INV-3: side effects only through ToolRegistry → PermissionEngine. - INV-4: one-way import/dependency direction. - INV-5: EventBus is transport, never a source of truth. Each affected subsystem chapter (§5/§7/§8/§9/§11) now opens with an "Applicable invariants (§18.6)" pointer so the constraint travels with the slice. Pure documentation consolidation of already-frozen rules; zero change to contracts, events, schema, or runtime semantics. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Description
AirCoding
Languages
Markdown
100%