docs: finalize v1 design and Windows service model

This commit is contained in:
2026-08-28 11:00:58 +00:00
parent a89253be96
commit 85f4d5d2a0
11 changed files with 833 additions and 241 deletions
+15
View File
@@ -90,6 +90,21 @@ actual lifecycle with a late-after-expiry warning. It renders terminal
`Rejected` with the client's structured validation/platform reason; `Failed`
means the requested code actually launched.
`rvc run --elevated` maps directly to `ExecutionSpec.elevated`; omission is
false. Non-Windows clients reject true as unsupported in v1. Windows chooses
the effective context from that bit and launch-time login state: normal commands
use `active-user` when possible and otherwise `local-service`; elevated commands
with an active user try `active-user-elevated`, `active-system`, then
`local-system`, while logged-out machines use `local-system` directly. These
fallbacks finish before `launch_prepared` and never retry a process.
Detailed `rvc stat CLIENT ISSUE_UUID` output shows requested elevation, every
attempted Windows context, selection/fallback detail, effective context and
process-token SID, and target session ID/owner SID when applicable.
`active-system` is rendered conspicuously as SYSTEM in another user's session,
never as that user. A pre-launch rejection shows the structured final context-
selection error rather than implying requested code ran.
`rvc append` turns a string into `StdinWrite` with `append_newline=true` unless
the caller selects raw mode; `--file` supplies raw bytes; `--attach` streams
local standard input. `CloseStdin` is available separately. All stdin actions