# M0 decisions and assigned follow-up questions

M0 requires every remaining contract question to have an owner and milestone;
later service implementation and business policy are not silently treated as done.
“SDK maintainer” and “host maintainer” are project implementation roles; “product
owner” is the EpicTuner owner. No external publication is authorized by this file.

| Decision | M0 disposition | Owner / next gate |
|---|---|---|
| Targets | Windows x64, Linux x64 and Linux ARM64; macOS later, per user | Host maintainer, native device/UI gates M1–M7; macOS M10 |
| Native boundary | C11 ABI 1.1, compatible 1.0 prefixes; C++20 helpers; no Qt/STL over ABI | SDK maintainer; frozen |
| Worker and transport | One worker per enabled plugin; authenticated local sockets; framed UTF-8 JSON; native peer identity | Host maintainer; frozen, manager integration M1 |
| Lifetime/error/async syntax | Fixed types, size negotiation, handles, owned errors, borrowed values/completions, committed-operation boundary | SDK maintainer; frozen in FOUNDATION.md |
| UI/service version policy | Named `.v1` features and independently versioned tables; break only with opt-in new major; unknown required features fail | SDK maintainer; frozen |
| Concrete UI properties/prefab tables | Implement through the frozen common handle/value/async contracts; do not expose private Qt controllers | UI maintainer; M2 service v1 in UI.md; full prefab library M4 |
| Background tasks | Serialized callbacks; bounded thread-safe posting, cancellation and stop draining required | Host maintainer, M1 |
| Project/tune revisions | Project generations and expected base revision/old values are mandatory; local/RAM/burn outcomes stay distinct | Project generations/read services complete in M3 (READ.md); tune revisions/edits M4 |
| Package naming/metadata/signing bytes | `.etplugin`, complete v1 schemas, Ed25519 over domain-separated JCS manifest, file SHA-256 inventory | Package maintainer; frozen; native verifier/install implemented M5 |
| Native crypto library | OpenSSL Ed25519; Windows preview stages its runtime DLL and upstream license, Linux links system OpenSSL | Package maintainer; M5 implementation, deployment versions remain platform certification work |
| Publisher trust/key revocation | Explicit per-user public-key import, no built-in roots, key-ID rotation through updated packages, local revocation blocks new and cached package starts | Package maintainer; M5 implemented. Production root distribution and remote revocation operations are product-owner M9 work |
| SDK redistribution terms | Product owner requested a prepared release with terms pending; no new redistribution rights granted here | Product owner, before external publication |
| License binding/offline grace | Signed installation-bound responses; perpetual works offline, trial stops at expiry, subscription uses signed lease and 72-hour grace with expiry as a hard stop | Licensing maintainer; M5 implemented. Refund, transfer, activation limits, recovery and server-side revocation are product-owner M9 policy/operations |
| Performance | Five-worker/100 Hz/30-second transport gate, explicit gaps/cancellations and fixed percentile/queue/deadline budgets | Host maintainer; M0 measurement, M3 actual mock polling/recording baseline in PLUGIN-SDK-M3 audit |
| Raspberry Pi acceptance | ARM64 ABI/SDK builds and emulator conformance in M0; physical device worker/UI/rendering separately verified | Host/UI maintainers, M1/M2/M6/M7 |
| ImGui backend | Windows and Linux required; Pi renderer/device requirements explicitly tested | UI maintainer, M6 |
| Embedded rendering | Copied frames baseline; choose GPU sharing only after measurement | UI maintainer, M8 |
| Commerce provider/hosting | External sales first; provider/payout/production keys not needed for SDK contracts | Product owner, M9 |

SDK constants for future capabilities or quotas do not enable those services. New
methods must use the frozen ownership/version rules and add acceptance tests before
their feature is advertised. Physical-device validation cannot be inferred from
cross-compilation or emulation.
