diff --git a/docs/GENERATE.md b/docs/GENERATE.md index de67b171f..c992530ff 100644 --- a/docs/GENERATE.md +++ b/docs/GENERATE.md @@ -71,6 +71,15 @@ crate and the Python shim read that file. โ›” **Neither language holds its own c what usage is recorded against. It is **not** a provider selector. - **`contents`** โ€” non-empty array of parts. A `text` part carries `text`; an `image` part carries `mime_type` and base64 `data`. Unknown part types are refused. + ๐Ÿ”ด **Owner media travels inline, over the pipe, and is never written to a temp file.** The obvious + alternative โ€” hand the child a path โ€” is what the speaker-analysis boundary does for bulk audio, and + it puts an owner's frames at rest outside the journal, outside retention, with a cleanup step that a + killed child never runs. โ›” Inline is the covenant-correct choice and it is not negotiable for + convenience: **content crossing this boundary is in flight or it is nowhere.** + โš  It has a cost, and it lands on the caller: a screen recording's frames are megabytes each, so **a + client must write requests and read responses concurrently.** A client that writes a large request + while the child is blocked writing a response nobody is reading deadlocks both. See ยง the two + framings. - **`attempt_index`, `exclusive_admission`, `transport_retries`** โ€” retry and admission hints. Each is meaningful to one lane and ignored by the others. โš  These are deliberately named for what they *do* rather than for the lane that honours them; a lane name in a field name is the provider leak