# Harness and transport boundaries

## Dependency rule

```text
integrations/<harness> → src/core → src/transports/<transport>
```

`src/core` must not import host SDKs, Pi APIs, TUI objects, or transport CLI modules. Harness adapters must not reimplement queue, identity, or completion policy.

## Harness adapter contract

An adapter supplies:

- stable participant identity and runtime incarnation;
- lifecycle callbacks (`start`, `reload`, `stop`);
- normalized tool calls (`send`, `inbox`, `read`, `reply`, `resolve`, `status`);
- envelope-only context delivery;
- host capability declaration (`inject`, `wake`, `interrupt`, `uiStatus`);
- host-specific rendering and session persistence.

Pi is current implementation. OpenCode/Codex adapters must use same normalized operations and may expose fewer capabilities.

## Transport adapter contract

A transport supplies:

- `init/ensure(root, participants)`;
- `send(message)`;
- `watch(envelopes)`;
- `listNew/listHistory`;
- `read(messageId)`;
- `reply(messageId, body, operationId)`;
- `resolve(messageId, operationId)`;
- optional discovery/presence storage.

AMQ filesystem transport owns CLI flags, mailbox paths, one-shot watch behavior, and compatibility helpers. Those details must not leak into core.

## Capability and trust

Capabilities describe what runtime can do. Presence describes freshness. Trust policy determines whether a peer may trigger urgent work. These are separate dimensions.

## Compatibility

Current Pi command names, AMQ root resolution, v3 state, migration readers, and sidecar legacy APIs remain compatibility surfaces until replacement paths have independent tests.
