diff --git a/logos-developer-guide.md b/logos-developer-guide.md index 6283e10..d12db13 100644 --- a/logos-developer-guide.md +++ b/logos-developer-guide.md @@ -308,7 +308,7 @@ The full set of available fields: | `uses` | No (`ui_qml` only) | `[]` | Intents this module may request, as an **array of objects**: `[{"intent": "wallet.sign", "cardinality": "single"}]`. Mandatory to request one — an undeclared request fails `not_declared`. `cardinality` is optional; only `single` is accepted today (`all` is reserved). ⚠ A bare string array is silently ignored — see §8.5. | | `interface_dependencies` | No | `[]` | Header *interfaces* this module binds at runtime, decoupled from any concrete module. Each entry is `{ name, file, impl_class?, input? }`; its canonical contract is bundled in `assets/lidl/`. See [Dependency interfaces](#dependency-interfaces) and the [tutorial](tutorial-interface-dependencies.md). | | `dependency_overrides` | No | `{}` | Per-dependency LIDL-contract source overrides, keyed by dependency name → `{ file, input?, impl_class? }`. Forces where a dependency's interface is read from; normally auto-resolved from the dep's `lidl` output. See [§9.2 Module Dependencies](#92-module-dependencies). | -| `host_services` | No | `[]` | Privileged host capabilities granted into the module's own image. Closed set: `token_registry`, `token_delivery` — both trust-root, and both granted only to `capability_module`, and only to the copy in the runtime's bundled directories, because a build-time allowlist a module could extend from its own metadata would not be an allowlist. An ungranted module asking for one gets `LP_ERR_UNSUPPORTED` at runtime, however loudly its metadata asked. | +| `host_services` | No | `[]` | Privileged host capabilities granted into the module's own image. Closed set: `token_delivery`, the trust root, granted only to `capability_module`, and only to the copy in the runtime's bundled directories, because a build-time allowlist a module could extend from its own metadata would not be an allowlist. `token_registry` is retired: still accepted, it grants nothing. An ungranted module asking for `token_delivery` gets `LP_ERR_UNSUPPORTED` at runtime, however loudly its metadata asked. | | `platforms` | No | `[]` | Platform-keyed overlays merged into this metadata before anything else reads it. See [§9.4 Platform-keyed metadata](#94-platform-keyed-metadata). | | `include` | No | `[]` | Runtime files to stage beside the plugin that nothing links against — in practice, **`dlopen`'d libraries**. Nothing else can stage these: a library reached only through `dlopen` has no import-table or `DT_NEEDED` entry for the build to follow. Names are looked up in this module's `nix.packages.runtime` and resolved external libraries, under both `lib/` and `bin/`. A name that matches nothing is **normal** — the list is a deliberate cross-platform superset (`.so`, `.dylib` and `.dll` side by side), so at most one spelling can match. | | `nix.packages.build` | No | `[]` | Nix packages for build time | @@ -1182,10 +1182,9 @@ forwards them under the name of the token the client presented. Your module sees an operator: `Operator{name: "auto"}` for the local boot token, or the name given to `logosctl token issue --name`. Forwarded calls to `capability_module` and `core_service` are refused (`unauthorized`), so the CLI can't mint module tokens. -The package modules are called as `core_service`. This is how the shipped -`logosctl` runs, because its bundled `capability_module` runs in the daemon's -process and issues every credential. A daemon started without it forwards as the -runtime, and your module sees `Host`. +The package modules are called as `core_service`. The daemon's bundled +`capability_module` runs in its process and issues every credential; a daemon +without it does not start. #### Running modules in the daemon's process