Use this skill before deciding where new files belong or how readable and writable content resolves across users and groups.
The Three Layers
L0is firmware. Repo-owned first-party code belongs here.L1is group customware. It is writable only for group managers and admins.L2is user customware. It is writable only for that user and admins.
Group And User Structure
L1/_allis the shared group layer available to everyone.L1/_adminis the admin group layer.L2/<username>/user.yamlstores user metadata such asfull_name.L2/<username>/meta/holds auth state such as password and login session records.L2/<username>/mod/is that user's customware module root.L1/<group>/group.yamlis the canonical group membership and management file.- When
CUSTOMWARE_GIT_HISTORYis enabled, each writableL1/<group>/andL2/<username>/root may have a server-managed local Git history repository. - L2 history ignores
meta/password.jsonandmeta/logins.json; rollback preserves those current auth files and keeps previous heads listable for forward travel when possible, while revert creates a new inverse commit.
Permission Model
- Nobody writes
L0. - Users may read their own
L2/<username>/. - Users may read
L0/<group>/andL1/<group>/for groups they belong to. - Users may write
L1/<group>/only when they manage that group directly or through a managing-group include chain. _adminmembers may write anyL1/andL2/path.
Group Config Fields
group.yaml uses these canonical fields:
included_usersincluded_groupsmanaging_usersmanaging_groups
Resolution Order
Readable module and extension resolution is rank-based:
L0/_all- readable
L0/<group>entries in group order L1/_all- readable
L1/<group>entries in group order L2/<username>
Higher-ranked exact same module-relative paths override lower-ranked ones. Different filenames under the same extension point compose together.
Placement Rules For Repo Work
- Put repo-owned first-party development work in
app/L0/_all/mod/_core/.... - Use
L1andL2only when the user explicitly wants layered customware or user- or group-specific overrides. - Do not treat repo-local
app/L1orapp/L2as durable framework source; they are transient runtime state and are gitignored. - Do not read, write, or depend on
.gitpaths inside writable layer roots; they are reserved for server-managed history.
Mandatory Doc Follow-Up
- If layer order, ownership rules, group semantics, or permission rules change, update the mirrored docs and the
developmentskill subtree in the same session.