Design stage: there is no released app yet. This site separates what exists in the repository from what is planned. See status

Catalog section · ARCH

Runtime isolation and fault containment

26 planned items in Compartmentalization: Core/Logistics Isolation, Contracts & Independent Delivery.

Isolated process for Logistics

ARCH-0042 Planned Lite and Pro Core

Logistics runs as a separate OS process from core, communicating only through the contract

Depends on: ARCH-0001

Sandbox permissions for Logistics process

ARCH-0043 Planned Lite and Pro Standard

Least privilege: only its own data folder, network sockets it needs and sensors it uses

Depends on: ARCH-0001

Own working directory and data folder

ARCH-0044 Planned Lite and Pro Core

Separate folders for DB, logs, cache and backups

Depends on: ARCH-0001

Crash containment

ARCH-0045 Planned Lite and Pro Core

A Logistics crash is caught at the process boundary; core continues unchanged

Depends on: ARCH-0001, ARCH-0042

Core crash containment from Logistics side

ARCH-0046 Planned Lite and Pro Standard

Logistics keeps running in read-mostly mode if core is down and queues outbound events

Depends on: ARCH-0001

Watchdog supervisor

ARCH-0047 Planned Lite and Pro Core

Small supervisor restarts a crashed or hung compartment with backoff

Depends on: ARCH-0001, ARCH-0042

Heartbeat between compartments

ARCH-0048 Planned Lite and Pro Core

Periodic liveness signal over the contract channel

Depends on: ARCH-0001

Restart backoff and crash-loop breaker

ARCH-0049 Planned Lite and Pro Core

Stop restarting after repeated crashes and show a clear status

Depends on: ARCH-0001

Resource limits (memory, CPU, disk)

ARCH-0050 Planned Lite and Pro Standard

Limits so Logistics cannot starve core

Depends on: ARCH-0001

Disk quota for Logistics data

ARCH-0051 Planned Lite and Pro Standard

Prevent board data from filling the disk used by core

Depends on: ARCH-0001

Outbound event queue (outbox) per side

ARCH-0052 Planned Lite and Pro Core

Durable queue holds events while the other side is down

Depends on: ARCH-0001

Inbound event dedupe

ARCH-0053 Planned Lite and Pro Core

Idempotent processing of replayed events

Depends on: ARCH-0001

Timeouts and circuit breaker on contract calls

ARCH-0054 Planned Lite and Pro Core

Calls fail fast and circuit opens after repeated failures

Depends on: ARCH-0001

Graceful degradation: Logistics missing

ARCH-0055 Planned Lite and Pro Core

Core hides overlay features and keeps all POS functions

Depends on: ARCH-0001

Graceful degradation: core missing or outdated

ARCH-0056 Planned Lite and Pro Core

Logistics runs standalone with its own identity and offline features; integration features are disabled with clear messages

Depends on: ARCH-0001

Graceful degradation: contract mismatch

ARCH-0057 Planned Lite and Pro Core

Fall back to the highest common contract version or disable integration only

Depends on: ARCH-0001

Read-only safe mode

ARCH-0058 Planned Lite and Pro Standard

Compartment can open data read-only when migration or integrity checks fail

Depends on: ARCH-0001

Integrity check on start (per compartment)

ARCH-0059 Planned Lite and Pro Core

SQLite integrity_check and schema version check each start

Depends on: ARCH-0001

Panic-free error handling policy

ARCH-0060 Planned Lite and Pro Core

No unhandled exceptions cross the boundary; errors become contract errors

Depends on: ARCH-0001

Memory-safe implementation requirement

ARCH-0061 Planned Lite and Pro Standard

Logistics core logic in a memory-safe language consistent with the stack recommendation

Depends on: ARCH-0001

Separate crash reports stored locally

ARCH-0062 Planned Lite and Pro Core

Local crash dumps per compartment, never uploaded

Depends on: ARCH-0001

Compartment status panel

ARCH-0063 Planned Lite and Pro Core

UI shows state, version, last heartbeat and last error of each compartment

Depends on: ARCH-0001

Restart compartment from UI

ARCH-0064 Planned Lite and Pro Standard

User can restart Logistics without restarting core

Depends on: ARCH-0001

Window isolation (UI)

ARCH-0065 Planned Lite and Pro Core

Logistics window renders from its own process or isolated view; a UI crash does not close core windows

Depends on: ARCH-0001

Single login with scoped session

ARCH-0066 Planned Lite and Pro Standard

Core issues a scoped session token; Logistics cannot read core secrets

Depends on: ARCH-0001

Key separation (separate rating key)

ARCH-0067 Planned Lite and Pro Core

Logistics keys are separate from core fiscal keys and certificates

Depends on: ARCH-0001