Isolated process for Logistics
ARCH-0042 Planned Lite and Pro CoreLogistics runs as a separate OS process from core, communicating only through the contract
Depends on: ARCH-0001
Catalog section · ARCH
26 planned items in Compartmentalization: Core/Logistics Isolation, Contracts & Independent Delivery.
Logistics runs as a separate OS process from core, communicating only through the contract
Depends on: ARCH-0001
Least privilege: only its own data folder, network sockets it needs and sensors it uses
Depends on: ARCH-0001
Separate folders for DB, logs, cache and backups
Depends on: ARCH-0001
A Logistics crash is caught at the process boundary; core continues unchanged
Logistics keeps running in read-mostly mode if core is down and queues outbound events
Depends on: ARCH-0001
Small supervisor restarts a crashed or hung compartment with backoff
Periodic liveness signal over the contract channel
Depends on: ARCH-0001
Stop restarting after repeated crashes and show a clear status
Depends on: ARCH-0001
Limits so Logistics cannot starve core
Depends on: ARCH-0001
Prevent board data from filling the disk used by core
Depends on: ARCH-0001
Durable queue holds events while the other side is down
Depends on: ARCH-0001
Idempotent processing of replayed events
Depends on: ARCH-0001
Calls fail fast and circuit opens after repeated failures
Depends on: ARCH-0001
Core hides overlay features and keeps all POS functions
Depends on: ARCH-0001
Logistics runs standalone with its own identity and offline features; integration features are disabled with clear messages
Depends on: ARCH-0001
Fall back to the highest common contract version or disable integration only
Depends on: ARCH-0001
Compartment can open data read-only when migration or integrity checks fail
Depends on: ARCH-0001
SQLite integrity_check and schema version check each start
Depends on: ARCH-0001
No unhandled exceptions cross the boundary; errors become contract errors
Depends on: ARCH-0001
Logistics core logic in a memory-safe language consistent with the stack recommendation
Depends on: ARCH-0001
Local crash dumps per compartment, never uploaded
Depends on: ARCH-0001
UI shows state, version, last heartbeat and last error of each compartment
Depends on: ARCH-0001
User can restart Logistics without restarting core
Depends on: ARCH-0001
Logistics window renders from its own process or isolated view; a UI crash does not close core windows
Depends on: ARCH-0001
Core issues a scoped session token; Logistics cannot read core secrets
Depends on: ARCH-0001
Logistics keys are separate from core fiscal keys and certificates
Depends on: ARCH-0001