Appendix B — Reserved ranges
The reserved-discriminant ranges for future protocol extensions: which message-ID slots are earmarked for which categories (lifecycle, hot path, control...
Full source summary
The reserved-discriminant ranges for future protocol extensions: which message-ID slots are earmarked for which categories (lifecycle, hot path, control plane, events, L1 lifecycle), the command-tag allocations within the lifecycle range, and the enum-allocation discipline for PhysicalKey and ErrorCode. Implementers extending the protocol pick from these ranges via PR.
1. Reserved message-ID ranges
For implementers extending the protocol:
WORKLOAD_RESPONSE = 0x04andWORKLOAD_CHALLENGE = 0x84are allocated to the endpoint-neutralphux-workload/v1profile (workload-auth.md);0x05..=0x0Fand0x85..=0x8Fremain open for connection lifecycle.0x14is allocated,0x15is retired,HISTORY_REQUEST = 0x16andINPUT_TERMINAL_REPLY = 0x17are allocated, and0x18..=0x1Fremain open.0x91is permanently retired.BOOTSTRAP_BEGIN..BOOTSTRAP_TOMBSTONE = 0x93..=0x97,HISTORY_TOMBSTONE = 0x98, andHISTORY_REJECTED = 0x99are allocated;FRAME_COMPRESSED = 0x9A(proto.md §6.4) is allocated from the hot-path reserve, which it belongs in: it wraps the hot path’s largest frames.0x9B..=0x9Fremain open for hot-path messages.- Message IDs
0x24..=0x2Fand0xA3..=0xAF: reserved for further L1 Terminal lifecycle / per-pane control frames (phux-4li.10 allocated0x22..=0x23C→S and0xA1..=0xA2S→C from these ranges). - Message IDs
0x31..=0x3Fand0xC2..=0xCF: reserved for control plane. - Message IDs
0x41..=0x4Fand0xB3..=0xBF: reserved for events (phux-y2t allocatedSUBSCRIBE_EVENTS = 0x41C→S andEVENT = 0xB3S→C from these ranges;0x42..=0x4Fand0xB4..=0xBFremain open).
2. Command-tag allocations
Commands ride the generic COMMAND envelope (L1.md §1) and carry
their own one-byte tag inside it. Allocated tags:
| Tag | Command | Owner | Status |
|---|---|---|---|
0x07 | GET_SCREEN | L1.md | shipped |
0x08 | ROUTE_INPUT | L1.md | shipped |
0x09 | KILL_TERMINALS | L1.md | shipped |
0x0c | GET_TERMINAL_STATE | L1.md | shipped |
0x0d | SUBSCRIBE_TERMINAL_EVENTS | L1.md | shipped |
0x0e | UPGRADE | L1.md | shipped |
0x0f | ACQUIRE_INPUT | L1.md | shipped |
0x10 | RELEASE_INPUT | L1.md | shipped |
0x11 | SIGNAL_TERMINAL | L1.md | shipped |
0x12 | REPORT_ASKED | L1.md | shipped |
0x13 | DETACH_CLIENTS | L1.md | shipped |
0x14 | APPLY_INPUT | L1.md | shipped |
0x15 | PUT_FILE | L1.md | shipped |
0x16 | SHUTDOWN | L1.md | shipped |
0x17 | REPORT_AGENT_STATE | L1.md | shipped |
KILL_TERMINALS at tag 0x09 reuses the slot freed by the removed
CREATE_SESSION command. Per
ADR-0030
(option B), the leaked session/collection lifecycle verbs are withdrawn and
their tags are freed:
0x09— formerlyCREATE_SESSION; reallocated toKILL_TERMINALS.0x0a— formerlyRENAME_SESSION; freed, reserved, not reallocated. Rename is now an L3 metadataSETonphux.session.name/v1(L3.md §3).0x0b— formerlyKILL_COLLECTION; freed, reserved, not reallocated. Group teardown isKILL_TERMINALS.
A freed tag SHALL NOT be reallocated to an unrelated command without a
PROTOCOL_VERSION bump, so that an old client speaking a withdrawn verb
fails loudly rather than invoking new behavior.
3. Reserved enum ranges
PhysicalKey enum values and ErrorCode enum values are allocated
sequentially. Implementers proposing new values open a PR against
this document.
ErrorCode = 5 is permanently reserved for the withdrawn OUT_OF_TIER
proposal and is never reused. CODEC_UNAVAILABLE = 6 is allocated by ADR-0070.
DetachReason (proto.md §7.2) allocates sequentially from 0
— 0..=7 are taken, with workload-auth values 5..=7 still spec-only — and
255 is permanently reserved for INTERNAL_ERROR.
It differs from the enums above in how an unallocated value decodes: a
consumer MUST read one it does not recognise as an unstated reason rather
than as a decode error, because DETACHED is the termination signal and
failing it would both hide the ending and make each new value a fleet-wide
break. New values are therefore additive and need no version bump.
(Earlier drafts of the SPEC reserved a DiffOp tag range here; per
ADR-0013, Terminal
content is now a VT byte stream and DiffOp no
longer exists as a wire concept.)
L2 — Reserved, no collection tier
There is no L2 collection tier. The L2 discriminant range is reserved on the wire but unused, and SHALL NOT be allocated for a collection lifecycle service.
Wire-protocol changelog
Wire-format change log for the phux protocol; the top entry's version must match PROTOCOL_VERSION in phux-protocol. CI gate spec-version-sync enforces this.