Skip to content

Architecture

The compositor owns the desktop. Core provides the world runtime and brokers its authority. Everything else connects through explicit contracts.

Hyprune process and repository boundariesShell and extension processes connect over public Unix IPC to hypruned. The daemon uses a private bridge to the Hyprland plugin. World packages supply validated scene data. Schemas and SDK define the public boundary.ShellQuickshell or your own UIExtensionsSupervised processesWorldsData, glTF, provenancePublic IPC · JSON-RPCValidatehypruned · coreGrants / packages / IPC / supervisionPrivate bridge · same core buildHyprland + core pluginCapture / trusted input / GPU / authoritative sceneSchema defines the contracts. SDK makes them usable.

The plugin reads immutable frame state and draws prepared resources. Capture refresh, cursor changes, focus, workspace transitions and uploads run in a verified safe phase after the outer compositor frame. CPU workers decode assets; they never access compositor objects or GL.

Frame ownership and deferred workSafe after-frame preparation feeds world rendering, then surfaces, then compositor layers. Only after outer endRender does the next deferred phase begin.Safe preparationCapture / upload / inputWorld passGeometry / lightingSurface passCaptured app pixelsCompositeHyprland / shell layersNext preparation only after outer endRender returns
Boundary Decision
Repositories and ownership RFC-0001
Processes, threads and frame graph RFC-0002
IPC, state, grants and failure RFC-0003
World content and validation RFC-0004
Pixels and input RFC-0005
Interaction and controllers RFC-0006
Extension hosts and SDK RFC-0007
Replaceable shells RFC-0008

A shell crash releases overlay input. An extension crash cannot execute inside the compositor. A daemon crash triggers the plugin’s desktop recovery watchdog. A malformed world fails staging before activation. A plugin bug can still crash Hyprland: keeping that boundary small and testing it against an exact compositor build is essential.

The schema repository owns machine-readable definitions. The world schema, IPC schema, extension schema and screen descriptor are mirrored here for authoring tools; runtime validation uses pinned local copies.