Skip to content

Io Durable Governed Tethers

Io is the AncientOS kernel primitive for durable observation continuity over long-running governed work.

Clockwerk governs time; Io governs continuity.

Clockwerk determines when a pulse occurs. Io determines which durable governed objects remain tethered, relinks them from authoritative state after restart, and invokes only the typed observer registered for that tether type. Io is not an independent scheduler and keeps no private durable watch list.

Contract

  • Tether: the registered durable observation relationship between Io and a governed object.
  • Tether target: the durable governed object identified by its canonical domain ID and lifecycle state.
  • Pulse: one Clockwerk-supplied invocation of a registered typed observer.
  • Break Tether: removal from active observation when authoritative state is terminal or suspended.
  • Relink: reconstruction of active tethers by querying authoritative durable domain state after runtime restart.

Each registration supplies a bounded durable discovery function, exact active, terminal, and suspended states, a cadence coordinated through Clockwerk, one typed observation function, durable target inspection, and required single-flight ownership. Io rejects unknown tether types and exposes bounded status containing only type, target ID, lifecycle state, cadence, counts, and last-pulse disposition.

Authority boundary

Scheduling and observation authority do not imply mutation authority. A tether permits Io to invoke only its registered observer; it grants no capability, approval, execution, or mutation authority. Rubick remains capability/readiness authority, Lich remains approval authority, and Zeus remains evidence authority. The domain service interprets observations and may perform only mutations already authorized by its existing governed lifecycle.

First consumer: episode downloads

The governed episode-download registration discovers only durable download_active proposals and invokes the existing exact EpisodeDownloadLifecycleService.observe(proposal_id) capability. Clockwerk supplies the existing 60-second cadence. Io provides relink, single-flight, and tether disposition; the media domain retains progress interpretation, VPN/containment checks, safety stop, completion detection, exact torrent stop, evidence, and receipts. download_complete is terminal and download_safety_stopped is suspended, so either breaks the active tether.

Io has no qBittorrent adapter and no start, resume, stop, delete, acquisition, filesystem, seeding, or Plex capability. See Governed TV Episode Acquisition Lifecycle.