The monolithic open-questions.md (1310 lines, 47 OQs) was large enough to be unmanageable, with high size variance (OQ-42 at 220 lines next to OQ-06 at 8). Decomposed into one file per OQ under docs/architecture/questions/ (NNN-slug.md, mirroring the ADR convention), with open-questions.md retained as the index: theme-grouped tables plus a cross-theme Deferred/Blocked section that surfaces the 6 deferred OQs with their Blocked-on conditions inline (the safe-exit visibility surface). Per-OQ content moved verbatim; all 62 inbound links stay valid (none used anchors). README's curated OQ summary dropped (now redundant with the index tables). Also seeds tasks/architecture/ with this task plus two follow-ups found during the decompose: OQ-09/10 missing structured Blocked-on fields, and the tasks/architecture/ blocker-task half of the Safe Exit protocol being unenforced.
829 B
829 B
OQ-16: Safe Vault Operations for Call Protocol Exposure
- Origin: operation-registry.md, ADR-008
- Status: resolved
- Door type: One-way
- Priority: high
- Resolution: No vault operations are exposed over the call protocol. The vault is accessed only at the assembly layer (CLI binary at startup). Handlers receive secret material through
OperationContext.capabilities, not by calling vault operations over the wire. Theoperation-registry.mdspec previously showedvault/derive,vault/unlock, andvault/decryptregistered as call protocol operations — that was a contradiction with ADR-008's "capability source" model and has been corrected. See ADR-014. - Cross-references: ADR-008, ADR-014, operation-registry.md