@@ -17,7 +17,7 @@
## Frontends
- smith-web: SSE skeleton first (std-only possible), websocket when live input and multi-viewer arrive — websocket forces the async runtime decision. Sequence: formalize smith-rpc as first smith-ui consumer, then smith-web.
-- smith daemon: detached smith speaking one frontend protocol (smith-ui intents + control) over pluggable transports (websocket, p2p stream, stdio). Topologies: n clients + 1 daemon (hub), 1 client + n daemons (roaming), n + n (fleet with session-home ownership routing — single-writer law preserved, merge dissolved into ownership). New design surface only: connection auth, per-connection permissions, event sequence/resume, per-connection backpressure. Trigger: first remote frontend (smith-web).
+- smith daemon: detached smith speaking one frontend protocol (smith-ui intents + control) over pluggable transports (websocket, p2p stream, stdio). Topologies: n clients + 1 daemon (hub), 1 client + n daemons (roaming), n + n (fleet with session-home ownership routing — single-writer law preserved, merge dissolved into ownership). New design surface only: connection auth, per-connection permissions, event sequence/resume, per-connection backpressure. Security posture: loopback-only default bind; off-loopback requires a single pairing token (one bearer secret per daemon, no user management in core ever); richer auth is plugin territory; unauthenticated remote control is RCE by design. Trigger: first remote frontend (smith-web).
- Fleet / remote effects: p2p multiplexing of machines, tools, plugin instances across smith peers. Layer: beside the effect layer, not smith-ui. Sync scope: sessions + plugins; filesystem and environment stay plugin territory. Blockers when design starts: multi-writer session merge, effect host attribution, peer trust tier, credentialed-host routing rule — first two need zero preparation, additive fields ride the compatibility laws. Frontends attach to one peer; remote attach arrives with the web/daemon frontend. Candidate transport: iroh (node keys, encrypted tunnels, self-hostable relays). Trigger: multi-machine usage hurts.
- smith-mcp: MCP is a UI for agents and humans; smith-as-MCP-server consumes smith-ui so plugin features translate naturally into MCP (progress notifications, resources, tools). Frontend, not adapter mode. Trigger: external-harness integration wanted.
- ACP (Agent Client Protocol): editor-facing agent protocol; technical shape and smith layer unclear to us both — likely a frontend sibling of smith-rpc and smith-mcp, but unverified. Deferred. Trigger: editor integration wanted.