Skip to content

Define editor ownership, dependency, and safe-filesystem architecture #2

Description

@zoeyrose

Outcome

Separate lossless documents/transactions, authoring application state, rendering, validation, and external playtest orchestration so the editor cannot corrupt source or duplicate parsers.

Scope and invariants

  • content-toolkit owns syntax/document/schema/catalog/compiler/transaction primitives; editor adapts and presents them.
  • renderer owns logical scenes/GPU/resources/offscreen paths; editor owns document-to-scene adaptation, selection state, and authoring tools.
  • Editor owns project discovery, tabs, history, inspectors, diagnostics presentation, autosave/recovery, and explicit user commands.
  • Client/session/protocol/gameplay authority are forbidden dependencies. Playtest invokes versioned root-wrapper commands with isolated state.
  • Define source roots, generated/runtime paths, symlink/canonical path handling, permissions, file watching, external changes, and write allowlists.
  • All multi-file writes use toolkit transactions; no panel/parser writes files directly.

Acceptance criteria

  • Architecture tests reject client/protocol/legacy imports and direct parser/writer duplication.
  • A threat model covers path traversal, symlink escape, overwrite, external edits, untrusted project files, automation, and crash recovery.
  • Headless fakes test UI/application state without SDL/GPU/filesystem where possible.
  • Dependency/version policy permits renderer/toolkit local overrides only through wrapper profiles, not source manifest edits.
  • Every mutable path has an owner, transaction/recovery policy, and explicit user visibility.

Dependencies and parallelization

Gates full editor implementation. Toolkit document and renderer scene APIs can develop concurrently with adapters.

Licensing

Editor code/tests are MIT. Verified original past work by an approved MIT provenance grantor may be copied, migrated, or translated under the audited file/component grant; other legacy implementation remains behavior/specification input only. Authored content/assets retain exact licenses.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Fields

    Priority

    None yet

    Projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions