Skip to article
Browse chapters

The ADR index

Every boundary decision in bingo, one line each, in the order they were taken.

What an ADR is here

One record per boundary decision: a trait shape, a wire format, a persisted format, a dependency, a crate split, a threshold family. Each is capped at 120 lines and follows one template — Context, Decision, Consequences, Supersedes. Longer material goes to docs/design/ and is linked from the record. Bug fixes are commit bodies, not ADRs.

They live in docs/adr/ in the repository. Thirty-three so far.

Foundations

#titlein one line
0001Crate map and dependency directionFour layers, one direction, five forbidden edges the build asserts.
0002One event stream: frames, journal, reducers, intentsOne Frame type, a per-session ordered journal, two pure reducers, and writes that return nothing.
0003Settings: three JSONC layers, merged per key by the claiming pluginThe kernel owns five keys; every other key belongs to the plugin that claims it, with its own merge rule.
0004Model facts: the catalogue owns the model, the provider owns the endpoint, the server corrects the windowThree owners, no overlap, and one pure resolver that fails closed on what a wrong guess would reject.
0005Session persistence: a JSONL journal per session, a sidecar lock, a derived summaryA session directory is portable, the lock is the only claim, and the summary can always be rebuilt.
0006Context budget: the kernel measures and cuts, the plugin summarises and remembersOne threshold family in the kernel, a compaction accepted only if it shrinks, and a breaker after three failures.

The kernel’s surfaces

#titlein one line
0007The wire: JSON-RPC 2.0 over NDJSON, methods 1:1 with HostApi, events verbatimThe wire is the sdk with an envelope and nothing else; the schema is committed and drift-tested.
0008Commands: parsed and dispatched by the session actor, outcomes as acksNo surface parses a command it does not own; an instant command runs during a turn, anything else queues.
0009Contribution sources: tools and commands that exist only after I/OA source is registered synchronously and answers from what it has now — answering with nothing is never wrong.
0010Sub-sessions: peer delivery, redirect, tree attachmentdeliver is the one door into another session’s queue, and a tree attachment carries every descendant’s frames.
0011Log sessions, plugin state in the journal, the host in handA session without a model records and never runs a turn; plugin state is a journal event, not a file beside one.
0013UI as data: one view vocabulary, three lanes, actionsA plugin describes what to show; the surface decides how, and every node has one text fold.

Credentials, providers and models

#titlein one line
0012OAuth credentials: a library tier, one store, login as an interactionA third tier below plugins for shared code, one 0600 credential file, and a login that is an ordinary question.
0017Named provider instances and paste login for keysinstances under each provider key registers more endpoints by name; environment variables feed the defaults alone.
0026The model catalog reaches the modelThe catalogue’s facts ride the existing entries’ metadata, and one read-only tool hands them to a model.

Plugins and the process boundary

#titlein one line
0015The cross-process plugin bridgeA plugin.json, a process on stdio, and the sdk’s own types as JSON — a bingo-native plugin in any language.
0030Fixed-interface capabilities cross the bridgeProxy structs implementing the sdk’s own traits, zero new traits, and a deadline on every crossing.
0031Wire servicesIn process a service is met by type; across one, by key, method and schema — and only if its owner opened a wire face.
0032Hooks cross the bridgeHookOutcome has no Allow, so an external hook can only tighten what happens, never widen it.
0033The allowance: a host capability, lent for one crossingOne reserved bingo.host service, two doors, and a grant that dies when its crossing ends.

Features that are not the kernel’s

#titlein one line
0014Experience: procedural memory as files, recalled by rankPlaybooks as files under a minted id, ranked by BM25, with the permission card as the propose step.
0016IM channels: one deliverer, adapters that hand over their mechanismA capability is an accessor that returns the mechanism, so it cannot drift from the renderer that draws it.
0018Background commands, and async by defaultA long command detaches to a log file, and only completion or a named condition wakes the session.
0019Schedules: deferred and recurring turnsA small grammar instead of cron, a fire is a turn on the schedule’s own session, and no daemon is pretended.
0020The gateway: a resident bingo, managed like a serviceOne resident host per data directory, a pidfile, a doctor, and a per-user launchd or systemd unit.

Collaboration between sessions

#titlein one line
0021OpenRoom: agents may open roomsAn agent convenes its own children by default, or its siblings with shared — one door, the same seating code.
0022Mentions: what a room post owes@name opens a debt closed by that member’s next post, derived from the journal and chased by one bounded timer.
0023The board: a room’s task listA room is a session, so its task list is the shared board; a claim is stamped at runtime and staleness is rendered, never written.
0024Peer messages: sibling addresses, one deliveryAgent names resolve child-first then sibling, and SendMessage always wakes — the second delivery mode is deleted.
0025The serial roomA post must follow everything its author could have seen; a stale one bounces carrying what it missed.
0027Spawn ≠ wake: the standby memberA briefing can be delivered without demanding an answer to it, so a seated member idles at zero tokens.
0028The holder on the rosterThe session a room hangs under may sit on its roster and hear it, and @parent owes an ordinary debt.
0029The ear on every seatEvery seat has a patience in seconds: zero is a live ear, thirty or more a patient one, and the band between is refused.

Reading them

Start with 0001 and 0002 — every other record assumes them. 0007, 0013 and 0015 are the three boundaries an integrator meets first. The collaboration records, 0021 through 0029, read as one sequence and are best taken in order.

Their live text is in docs/adr/ in the repository, and the plans that carried each one out are in docs/plans/.