DL-329
Self-host stack supervision KEEPS the hand-rolled DL-183/DL-262 pgid mechanism as the SINGLE cross-platform supervision model; per-service Podman Quadlet units are NOT adopted (Linux/systemd-only, so Quadlet structurally fails the ruled all-platforms bar AND the pgid path survives regardless — two models vs one; the imperative cold sequence would need oneshot pre-units + sdnotify re-plumbing; per-service units displace the DL-259-named compass-stack up verb). Whole-stack CRASH RECOVERY ships as a blocking compass-stack up --supervise foreground mode (up-to-Ready, watch children, non-zero exit on child death, teardown on signal) wrapped by the platform-native OS supervisor’s restart policy, plus a one-command compass-stack service install/uninstall that writes + enables the native unit — systemd USER unit (Type=exec, Restart=on-failure, TimeoutStopSec>=90) on Linux, launchd LaunchAgent (RunAtLoad, KeepAlive={SuccessfulExit=false}, ExitTimeOut>=90) on macOS — auto-start at reboot + restart-on-crash; the OS supervisor supplies ONLY restart/backoff/boot-start (DL-183 spawn/teardown unchanged), status truth stays compass-stack status. macOS supervision is RUNTIME-AGNOSTIC (the launchd LaunchAgent supervises the compass-stack host process independent of the podman/apple-container runtime inside it), so it ships now and is NOT gated on the RIG-3238 backend choice (Matt, session directive, 2026-09-05; mirrored on RIG-3239). The --supervise lock lifetime teaches DownDetached’s live-holder guard a mode/state token — a supervise process parked at Ready is a valid down target (signalled, exits zero), a mid-bring-up up is still refused — preserving DL-183 single-owner mutual exclusion (OQ-6 → (b), Matt, RIG-3261). Docker-socket declined at the stack layer (daemon model vs the rootless/no-daemon hard requirement; no per-container keep-id equivalent)
Status: Active (Matt, 2026-09-05)
Record: ../../platform/compass-stack-supervision/design.md#approach