Ten Layers, One Direction: Down.
M31A is implemented as a single, high-assurance Rust crate organized into a strict L0 to L9 hierarchy. Lower layers are strictly forbidden from importing or depending on higher layers.
Strict Downward Dependency
Presentation (L9) and mission orchestration (L8) depend on execution and policy (L1-L7), never the reverse. The UI is a pure projection of SQLite state.
Two Hard Trust Boundaries
Layer 3 bounds external model provider SSE streams; Layer 1 enforces the 11-stage policy gate before any side effect reaches the OS.
Single Crate Kernel
Zero Node.js, Python, or GPU dependencies for runtime execution. Single standalone binary built with Rust 1.85+ (Edition 2024).
The 10-Layer Hierarchy (L0–L9)
Select any layer to inspect its subsystem purpose, source modules, and boundary rules.
Security & Policy Gate
Governance & Access Control
11-stage policy gate, NetworkDestinationPolicy (SSRF defense), fail-closed worktree isolation, approval coordinator.
Hybrid Storage & Checkpoints
M31A stores state across four dedicated local channels inside the .m31a/ workspace directory:
Compact Relational State
WAL mode, strict foreign keys, atomic transactions for mission, task, and policy grant records.
Append-Only NDJSON
Streaming execution logs with automated 5-tier secret scrubbing before serialization.
Immutable Blob Storage
Content-addressed storage indexed by SHA-256 digests for diffs, test logs, and patches.
Atomic Staging Buffer
Two-phase commit buffers ensuring no partial writes compromise crash recovery.