Skip to content

Installing and managing apps: deployment adoption, the us-apps record, launcher and lifecycle #134

Description

@lannbot

Tracking issue for the "Installing and managing apps" NOTES.md section (recorded 2026-08-26). The direction: install = adopting a deployment — packaging, verification, transparency, and delivery are delegated to polymorph-pkg (deployment manifests signed by a curator key, verified fetch by digest over untrusted mirrors, the trust-compiles rule); polyvisor owns the ceremony, the replicated install record, the launcher/lifecycle UX, and the contact-graph detection layer. The user's one judgment act is the install ceremony (grants + petname/mark); everything downstream is pure mechanism — no "continue anyway?" ever.

Settled directions (see the NOTES section for rationale):

  • The home origin stays app-agnostic beyond the release-carried core set (no operator catalogs; the origin never learns the install set).
  • The core set ships inside the framework's own deployment; split trigger: the first core app needing off-cycle updates or uninstallability.
  • Updates: silent adoption — manifest freshness is revocation; the visor announces, never asks. Curator-root generation changes are announcement-grade.
  • The us-apps record is replicated account state (sibling to User-system partition: device-group state sync (profile, trust records, contacts, devices) #36), including seq/generation rollback floors — devices inherit floors from siblings instead of re-TOFUing after eviction.
  • Uninstall revokes grants and drops bytes; partition data outlives the app (keep / rebind / erase, the last erase-ceremony-grade).
  • Bucket-as-mirror deferred with a guard (the dumb-store contract already satisfies the mirror model; nothing may preclude it).

Open sub-questions:

Parked with triggers: multi-window (own design pass), app-to-app intents (powerbox pickers cover the near term; trigger: a real consumer), background app execution (trigger: an app that genuinely needs liveness — #12 territory), discovery (web-of-trust shaped, never adjacent-equal to installed lists — the picker ruling's discovery clause applies unchanged).

Related: #52 (rescoped: the publishing/transparency half is delegated to polymorph-pkg; polyvisor keeps contact-graph gossip and the visor alarm/response UX), #36 (us-apps as a user-system partition), #7, #21, #45, #2, #1.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions