Uh oh!
There was an error while loading. Please reload this page.
Retire the plugin manifest's three dead top-level containers: capabilities, configuration, extensions (ADR-0049) - #13287
Conversation
…ners (capabilities, configuration, extensions) ADR-0049 enforce-or-remove. Zero reads of each container itself measured across objectstack, objectui and cloud with positive controls; the census settles all eight keys beneath them at once. configuration.properties.secret promised encryption/masking that nothing implemented — the false-compliance shape. retiredKey() tombstones (ManifestSchema is not .strict(), so a plain deletion would silently strip), RETIRED_KEYS_BY_MAJOR[18] entries, one D3 semantic entry, ledger rows to the tombstone disposition, minor changeset per the launch-window convention, docs corrections, and the two in-repo authors cleaned. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01KX8wnyjStaZcuMyAMNsy3N
📓 Docs Drift CheckThis PR changes 3 package(s): 26 hand-written doc(s) name something this change touched — list omitted above 15 rows. Re-derive on the tree named below: ⛔ 3 release-owned page(s) also affected — read-only, see AGENTS.md Documentation Guardrails. What this run could not see
Coarse fallback — 128 page(s) merely mention a changed package (the pre-#9192 predicate, kept for the deliberately-wide backstop): Which tree this was computed onThis run read A worktree cut from an older # while this PR is open — GitHub drops the merge commit once it closes
git fetch origin 40378a2770084d0e366919f52446f2c0a59e33b8 && git checkout 40378a2770084d0e366919f52446f2c0a59e33b8
# afterwards, rebuild it from the two parents, which stay fetchable
git fetch origin 74049254d47bd0edd2a2fcd732dcc01c91504f10 9eda0f52ccd8b04ca59ef57affb72de4db2c9b68 && git checkout -B drift-repro 74049254d47bd0edd2a2fcd732dcc01c91504f10 && git merge --no-ff 9eda0f52ccd8b04ca59ef57affb72de4db2c9b68
node scripts/docs-audit/affected-docs.mjs --json 74049254d47bd0edd2a2fcd732dcc01c91504f10
|
Uh oh!
There was an error while loading. Please reload this page.
Fixes#11332
ADR-0049 enforce-or-remove retirement of the plugin manifest's three dead top-level containers —
capabilities,configuration,extensions— executed through the pre-registered triage disposition (2026-08-23, on the card) after the cloud leg came back clean (#12400 remains the evidence record: cloud main at commit 15f55df, all three containers CLEAN, controls positive). Family precedents mirrored, not reinvented: PR #12001 (nine contributes members) and themanifest.loadingretirement.Premise re-verification (dispatch-time, all three trees)
configurationat manifest.zod.ts line 305,capabilitiesat 489,extensionsat 496). Container-level probe over non-test, non-dist code:.configurationand.extensionsreturn ZERO hits; all 40.capabilitieshits classify to other surfaces (hook/actionbody.capabilities, client discovery capabilities, driver loader contracts, the ADR-0066 stack-levelcapabilitiescollection, datasource-retirement machinery). Zero manifest-container reads.manifest.(id|name|namespace|version)reads findable (19 in PackagesPage.tsx alone).runtime,integrity,capabilities/configuration/extensions, structuredpermissions) — unblocks #11330 #11331 #11332 #11333 #12400 measurement): zero container reads (body.capabilitiesthere is the sandbox capability-token surface;app.configurationis Cloudflare rollout config); positive controls — 26 manifest field reads,sys_package_versionwriters present.configuration+capabilitiesblocks) are writers, not readers; both are cleaned in this PR, mirroring the hono-server precedent comment left by the contributes retirement.Route: tombstone, not deletion — condition re-verified
ManifestSchemais a plain z.object (line 132); the only.strict()in the file belongs toPluginPermissionsSchema(line 44). A plain deletion would silently strip the keys, so each getsretiredKey()with a prescription following the five house conventions (fully-qualified key, removal record with the ADR id, why-inert clause, imperative fix; NO migrate-meta sentence because no conversion covers this surface — the contributes/loading precedent; no tracker ids in customer-facing prose per the standing check-doc-authoring rules).configuration's prescription records the false promise honestly:properties.*.secretpromised "value is encrypted/masked (e.g. API Keys)" while nothing encrypted, masked or even parsed the flag — the false-compliance shape ADR-0049 exists for.Registration (ADR-0087)
RETIRED_KEYS_BY_MAJOR[18]:kernel/Manifest:capabilities,kernel/Manifest:configuration,kernel/Manifest:extensions— one entry file each underentries/retired-keys/, folded bygen:migration-registry.plugin-manifest-dead-containers-retired, mirroring the record shape ofplugin-manifest-contributes-dead-members-retired.PLURAL_TO_SINGULARstill has nopackages/pluginsentry (itscapabilitiesentry is the unrelated ADR-0066 stack collection), so a package manifest is not a stack collection member and a conversion would be a transform with no seam that ever runs — thekernel/Manifest:loadingreasoning holds verbatim.PluginCapabilityManifestSchemastays exported:plugin-registry.zod.tsline 205 still declares it, so this is a carrier-key tombstone with NO def removal (nothing lands inRETIRED_DEFS_BY_MAJOR; the orphan-schema clause does not apply).Launch-window reconciliation (the #13186 precedent)
The changeset is
minorwith the adr-0087 registration marker: v17.0.0 was cut before this landed, so the accept-set narrowing ships on the 17.x line under the lockstep launch-window convention, while the prescriptions register under protocol major 18 whereos migrate metausers will look.check-changeset-no-major(which refuses amajorand is authoritative for the convention) passes on this diff.Liveness ledger
The three rows move to the tombstone disposition (dead + RETIRED note, row STAYS because
retiredKey()keeps the key in the walked shape — theloadingprecedent, per the ledger README's asymmetry note). The per-child rows (capabilities.{implements,provides,requires,extensionPoints,extensions},configuration.{title,properties}) leave the ledger with the drilled shape; their provenance is folded into the container notes. Counts regenerated viagen:liveness-counts(manifest: dead 21 to 16, total 914 to 909 — arithmetic checks: 7 child rows out, 2 container rows in).Author-facing surfaces
content/docs/references/**(three rows now render the REMOVED prescriptions),authorable-surface/kernel.json(three rows gain the RETIRED mark — key-level tombstone signature: no def rows move, matching the ratchet-visibility table), strictness-ledger counts, spec-changes/upgrade-guide gates green (major-18 content projects at the 18 cut, same as the family precedents).content/docs/protocol/kernel/plugin-spec.mdxtaught all three containers in its "what ManifestSchema actually declares" callout and pointed config defaults AT thesecretflag; both corrected (the callout now lists the four retired tombstones, includingloading, whose listing as an ordinary optional field was stale from the same sentence). Noskills/**page teaches any of the three (measured: zero hits for the container spellings andextensionPoints); no ADR edits — so no landing-posture fork.examples/app-showcasecapabilities:at config line 266 is the ADR-0066 stack-level collection insidedefineStack— a different, live surface, untouched.Verification
dependencies,navigationContributions) still parse.capabilitiestombstone to a plain declaration turned EXACTLY thecapabilitiesrejection pin red (1 failed / 40 passed); mutation proven on disk by anchor grep (marker count 1, tombstone count 0), restoration proven by emptygit diff HEADafterward. In-package leg (spec tests import src directly), so no dist rebuild was part of this leg.extensionson anObjectStackManifestproduced TS2322 (input typed never) via@objectstack/spec/kernel; probe removed. First probe attempt failed with TS2305 for an unrelated reason — that reading was discarded as not-measured and led to finding The two in-repo manifest authoring sites (driver-memory / plugin-hono-server objectstack.config.ts) sit outside every tsc program and import ObjectStackManifest from an entry that does not export it #13284 below.node scripts/pm/dispatch-gates.mjs(no hand-fed paths; derivation stderr names this repo at commit 9eda0f5) — all locally-owed members run green at 9eda0f5: nul-bytes, changeset-no-major, adr-0087-registration, empty-changeset, doc-authoring, docs-single-h1, doc-frontmatter, doc-anchors, doc-route-spelling, docs-section-name, affected-docs, drift-comment, quick-reference-counts, driver-memory-census, test-source-alias, spec-parsed-alias, and in packages/spec: liveness, empty-state, authorable-surface, docs, strictness-ledger, variant-docs, spec-changes, upgrade-guide, skill-examples (after building client-react — its dist is that gate's read prerequisite), pluscheck:generatedfully reconciled. CI owns the full farm.Landing posture
Clause-② YES (the accept set narrows: three previously-accepted containers become loud rejections). This PR parks at DRAFT with
needs:contract-reviewattached at creation; the review chain owns enqueue. Not ready, not queued, not armed.Out of scope, filed separately with evidence: #13284 (the two in-repo manifest authoring sites sit outside every tsc program and import
ObjectStackManifestfrom an entry that does not export it — the tombstone's tsc channel is blind exactly there; found by this PR's reverse verification) and #13285 (plugin-registry.zod.tshas zero consumers outside packages/spec and is now the sole surface publishingPluginCapabilityManifestSchema— census requested;findinglabel). #13284 and #13285 remain open; nothing in this PR addresses them.Generated by Claude Code
Generated by Claude Code