Architecture
The compositor owns the desktop. Core provides the world runtime and brokers its authority. Everything else connects through explicit contracts.
Keep the render pass predictable
Section titled “Keep the render pass predictable”The plugin reads immutable frame state and draws prepared resources. Capture refresh, cursor changes, focus, workspace transitions and uploads run in a verified safe phase after the outer compositor frame. CPU workers decode assets; they never access compositor objects or GL.
Read the contracts
Section titled “Read the contracts”| Boundary | Decision |
|---|---|
| Repositories and ownership | RFC-0001 |
| Processes, threads and frame graph | RFC-0002 |
| IPC, state, grants and failure | RFC-0003 |
| World content and validation | RFC-0004 |
| Pixels and input | RFC-0005 |
| Interaction and controllers | RFC-0006 |
| Extension hosts and SDK | RFC-0007 |
| Replaceable shells | RFC-0008 |
Honest failure boundaries
Section titled “Honest failure boundaries”A shell crash releases overlay input. An extension crash cannot execute inside the compositor. A daemon crash triggers the plugin’s desktop recovery watchdog. A malformed world fails staging before activation. A plugin bug can still crash Hyprland: keeping that boundary small and testing it against an exact compositor build is essential.
The schema repository owns machine-readable definitions. The world schema, IPC schema, extension schema and screen descriptor are mirrored here for authoring tools; runtime validation uses pinned local copies.