Engine Internals

Engine Internals An architecture diagram generated by Archify. CLI + Web Controls · CLI + web page · Architecture component CLI + Web Controls CLI + web page ControlHttpServer · TLS 1.3, loopback only · Main thread (Node 24) · CSRF + Origin ControlHttpServer TLS 1.3, loopback only CSRF + Origin ControlService · 4 static commands · Main thread (Node 24) ControlService 4 static commands CodingWorkflowRunner · one step at a time · Main thread (Node 24) · 100 ms tick CodingWorkflowRunner one step at a time 100 ms tick BoundedStorageExecutor · main-thread proxy · Main thread (Node 24) · 128 pending max BoundedStorageExecutor main-thread proxy 128 pending max DynamicControlService · 11 governed decisions · Main thread (Node 24) DynamicControlService 11 governed decisions Identity Adapter · host supplied · Main thread (Node 24) · trust boundary Identity Adapter host supplied trust boundary LocalCodingWorker · spawn argv, no shell · Main thread (Node 24) · native helper on win32 LocalCodingWorker spawn argv, no shell native helper on win32 Storage Worker Thread · 11 repo connections · Storage worker thread Storage Worker Thread 11 repo connections Clock Trust Gate · assertClockDispatch · Storage worker thread · high-water time Clock Trust Gate assertClockDispatch high-water time engine.sqlite · WAL, FULL, IMMEDIATE · Storage worker thread engine.sqlite WAL, FULL, IMMEDIATE Telemetry Queue · bounded, leased rows · Storage worker thread Telemetry Queue bounded, leased rows HTTPS session /engine/v1/* /engine/dynamic/v1/requests authenticate + authorize human command {id, op, args} execute stage command postMessage, bounded dispatch gate one transaction per command audit trigger Main thread (Node 24) Storage worker thread Legend Frontend Backend Database Security Message bus

Trust Boundaries

  • • The host identity adapter alone establishes a verified HUMAN session; tokens or fixtures never do
  • • Cookie sessions need a constant-time CSRF header and an exact Origin on every non-GET

One Storage Thread

  • • All repositories share one SQLite file opened with WAL, synchronous FULL and pragma read-back
  • • Dynamic controls keep their own main-thread connection for challenge rows

Execution Evidence

  • • Timeouts, signals or a null exit code classify as UNKNOWN, never as failure
  • • Windows routes commands through a signed native helper with a nonce-bound completion marker