Add a contextual File.Delete component for contained file removal #567

Description

@taras

Story

As a workflow author, I want to remove one file through ordinary Executable Markdown, so a retained Workspace proposal can delete obsolete content without receiving a filesystem handle or command-execution authority.

Authoring contract

<File.Delete path="obsolete.md" />

File.Delete is an ordinary contextual component with one required non-empty string prop, path. It is self-closing, accepts no content, renders nothing, and returns no caller-visible value. as therefore has nothing useful to bind.

The path resolves relative to contextual Env.cwd, exactly where the element is written. The operation removes one non-directory entry:

  • a regular file is removed;
  • a final symlink is removed as a link without following or changing its target;
  • a missing entry succeeds as an idempotent no-op; and
  • a directory is refused, even when empty.

There is no recursive form, force prop, glob, multiple-path prop, trash, restore handle, or implicit directory cleanup.

Containment and authority

Reject an empty path, an absolute path, and a lexical .. escape before mutation. Resolve existing parent ancestors and refuse a parent symlink that would place the named entry outside Env.cwd. Removing a final symlink changes only the contained directory entry and therefore does not grant access to its target.

The component makes no host filesystem call directly. It extends the contextual Files API with the semantic operation required to remove one file entry. The ordinary host Files provider implements the same contract for xmd run; the workflow Files provider performs it against the selected run-owned Workspace through the existing transaction boundary.

Generated source receives no deletion authority merely because the component exists or is registered. #369 owns generated-XMD admission. After its initial Dir plus paired File:write slice is delivered, this issue also owns adding the exact pinned File.Delete identity to the standard Deno workflow host's write table and the focused admission evidence. A host without that pinned identity continues to refuse generated deletion.

Durability and failure

Under xmd workflow, one successful invocation is one ordinary Workspace-local durable effect and one Workspace transaction. Its Workspace mutation and journal completion commit atomically under #365. Completed replay restores completion without deleting again; partial replay reaches the operation against the retained Workspace frontier.

An ordinary missing entry is successful, not a failure. An invalid path, directory target, containment refusal, provider refusal, or filesystem failure changes nothing and follows the ordinary component failure contract. The operation publishes no synthetic mutation receipt; its durable effect record is the authoritative account.

Acceptance

  • <File.Delete path="file.txt" /> removes one contained regular file and renders nothing.
  • Removing an already-missing file succeeds, changes nothing, and renders nothing.
  • Removing a final symlink removes the link and leaves its target unchanged, including when the target is outside Env.cwd.
  • An empty path, absolute path, lexical escape, escaping parent symlink, or directory target is refused without changing the Workspace.
  • Paired content is refused before any mutation.
  • The ordinary host and workflow Files providers implement the same semantic operation without the component selecting a runtime.
  • A workflow mutation and its durable completion commit atomically; completed replay performs no second removal.
  • The standard generated-XMD write policy admits deletion only by this component's exact pinned identity and only when the host supplied it. Same-name repository components, registrations, middleware replacement, and another loaded package copy do not satisfy that identity.
  • A generated fragment mixing admitted deletion with any unadmitted syntax performs no generated effect because Evaluate Agent-generated XMD through a constrained allowlist #369 preflights the whole fragment.
  • Core, runtime-provider, workflow transaction/replay, and generated-admission regressions cover the observable contract.
  • The executable-MDX and workflow-Workspace specifications describe the component, containment, durability, and generated-admission boundary.

Dependencies and delivery order

Out of scope

  • Directory removal, recursive removal, globs, or several paths in one invocation.
  • Returning a path, boolean, receipt, removed contents, or restoration handle.
  • Host paths outside contextual Env.cwd.
  • Direct Agent filesystem or command access.
  • Granting generated source admission; only Evaluate Agent-generated XMD through a constrained allowlist #369's host-owned policy can admit the pinned identity.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions

      , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all \u003cpre\u003e\u003ccode\u003e blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks"); } } catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); } })(); (function(){ try { var __m = "github.com"; var __re = new RegExp('^' + "github\\.com" + '
      Skip to content

      Add a contextual File.Delete component for contained file removal #567

      Description

      @taras

      Story

      As a workflow author, I want to remove one file through ordinary Executable Markdown, so a retained Workspace proposal can delete obsolete content without receiving a filesystem handle or command-execution authority.

      Authoring contract

      <File.Delete path="obsolete.md" />

      File.Delete is an ordinary contextual component with one required non-empty string prop, path. It is self-closing, accepts no content, renders nothing, and returns no caller-visible value. as therefore has nothing useful to bind.

      The path resolves relative to contextual Env.cwd, exactly where the element is written. The operation removes one non-directory entry:

      • a regular file is removed;
      • a final symlink is removed as a link without following or changing its target;
      • a missing entry succeeds as an idempotent no-op; and
      • a directory is refused, even when empty.

      There is no recursive form, force prop, glob, multiple-path prop, trash, restore handle, or implicit directory cleanup.

      Containment and authority

      Reject an empty path, an absolute path, and a lexical .. escape before mutation. Resolve existing parent ancestors and refuse a parent symlink that would place the named entry outside Env.cwd. Removing a final symlink changes only the contained directory entry and therefore does not grant access to its target.

      The component makes no host filesystem call directly. It extends the contextual Files API with the semantic operation required to remove one file entry. The ordinary host Files provider implements the same contract for xmd run; the workflow Files provider performs it against the selected run-owned Workspace through the existing transaction boundary.

      Generated source receives no deletion authority merely because the component exists or is registered. #369 owns generated-XMD admission. After its initial Dir plus paired File:write slice is delivered, this issue also owns adding the exact pinned File.Delete identity to the standard Deno workflow host's write table and the focused admission evidence. A host without that pinned identity continues to refuse generated deletion.

      Durability and failure

      Under xmd workflow, one successful invocation is one ordinary Workspace-local durable effect and one Workspace transaction. Its Workspace mutation and journal completion commit atomically under #365. Completed replay restores completion without deleting again; partial replay reaches the operation against the retained Workspace frontier.

      An ordinary missing entry is successful, not a failure. An invalid path, directory target, containment refusal, provider refusal, or filesystem failure changes nothing and follows the ordinary component failure contract. The operation publishes no synthetic mutation receipt; its durable effect record is the authoritative account.

      Acceptance

      • <File.Delete path="file.txt" /> removes one contained regular file and renders nothing.
      • Removing an already-missing file succeeds, changes nothing, and renders nothing.
      • Removing a final symlink removes the link and leaves its target unchanged, including when the target is outside Env.cwd.
      • An empty path, absolute path, lexical escape, escaping parent symlink, or directory target is refused without changing the Workspace.
      • Paired content is refused before any mutation.
      • The ordinary host and workflow Files providers implement the same semantic operation without the component selecting a runtime.
      • A workflow mutation and its durable completion commit atomically; completed replay performs no second removal.
      • The standard generated-XMD write policy admits deletion only by this component's exact pinned identity and only when the host supplied it. Same-name repository components, registrations, middleware replacement, and another loaded package copy do not satisfy that identity.
      • A generated fragment mixing admitted deletion with any unadmitted syntax performs no generated effect because Evaluate Agent-generated XMD through a constrained allowlist #369 preflights the whole fragment.
      • Core, runtime-provider, workflow transaction/replay, and generated-admission regressions cover the observable contract.
      • The executable-MDX and workflow-Workspace specifications describe the component, containment, durability, and generated-admission boundary.

      Dependencies and delivery order

      Out of scope

      • Directory removal, recursive removal, globs, or several paths in one invocation.
      • Returning a path, boolean, receipt, removed contents, or restoration handle.
      • Host paths outside contextual Env.cwd.
      • Direct Agent filesystem or command access.
      • Granting generated source admission; only Evaluate Agent-generated XMD through a constrained allowlist #369's host-owned policy can admit the pinned identity.

      Activity

      Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

      Metadata

      Metadata

      Assignees

      No one assigned

        Labels

        No labels
        No labels

        Projects

        No projects

          Relationships

          None yet

          Development

          No branches or pull requests

          Issue actions

          , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
          Skip to content

          Add a contextual File.Delete component for contained file removal #567

          Description

          @taras

          Story

          As a workflow author, I want to remove one file through ordinary Executable Markdown, so a retained Workspace proposal can delete obsolete content without receiving a filesystem handle or command-execution authority.

          Authoring contract

          <File.Delete path="obsolete.md" />

          File.Delete is an ordinary contextual component with one required non-empty string prop, path. It is self-closing, accepts no content, renders nothing, and returns no caller-visible value. as therefore has nothing useful to bind.

          The path resolves relative to contextual Env.cwd, exactly where the element is written. The operation removes one non-directory entry:

          • a regular file is removed;
          • a final symlink is removed as a link without following or changing its target;
          • a missing entry succeeds as an idempotent no-op; and
          • a directory is refused, even when empty.

          There is no recursive form, force prop, glob, multiple-path prop, trash, restore handle, or implicit directory cleanup.

          Containment and authority

          Reject an empty path, an absolute path, and a lexical .. escape before mutation. Resolve existing parent ancestors and refuse a parent symlink that would place the named entry outside Env.cwd. Removing a final symlink changes only the contained directory entry and therefore does not grant access to its target.

          The component makes no host filesystem call directly. It extends the contextual Files API with the semantic operation required to remove one file entry. The ordinary host Files provider implements the same contract for xmd run; the workflow Files provider performs it against the selected run-owned Workspace through the existing transaction boundary.

          Generated source receives no deletion authority merely because the component exists or is registered. #369 owns generated-XMD admission. After its initial Dir plus paired File:write slice is delivered, this issue also owns adding the exact pinned File.Delete identity to the standard Deno workflow host's write table and the focused admission evidence. A host without that pinned identity continues to refuse generated deletion.

          Durability and failure

          Under xmd workflow, one successful invocation is one ordinary Workspace-local durable effect and one Workspace transaction. Its Workspace mutation and journal completion commit atomically under #365. Completed replay restores completion without deleting again; partial replay reaches the operation against the retained Workspace frontier.

          An ordinary missing entry is successful, not a failure. An invalid path, directory target, containment refusal, provider refusal, or filesystem failure changes nothing and follows the ordinary component failure contract. The operation publishes no synthetic mutation receipt; its durable effect record is the authoritative account.

          Acceptance

          • <File.Delete path="file.txt" /> removes one contained regular file and renders nothing.
          • Removing an already-missing file succeeds, changes nothing, and renders nothing.
          • Removing a final symlink removes the link and leaves its target unchanged, including when the target is outside Env.cwd.
          • An empty path, absolute path, lexical escape, escaping parent symlink, or directory target is refused without changing the Workspace.
          • Paired content is refused before any mutation.
          • The ordinary host and workflow Files providers implement the same semantic operation without the component selecting a runtime.
          • A workflow mutation and its durable completion commit atomically; completed replay performs no second removal.
          • The standard generated-XMD write policy admits deletion only by this component's exact pinned identity and only when the host supplied it. Same-name repository components, registrations, middleware replacement, and another loaded package copy do not satisfy that identity.
          • A generated fragment mixing admitted deletion with any unadmitted syntax performs no generated effect because Evaluate Agent-generated XMD through a constrained allowlist #369 preflights the whole fragment.
          • Core, runtime-provider, workflow transaction/replay, and generated-admission regressions cover the observable contract.
          • The executable-MDX and workflow-Workspace specifications describe the component, containment, durability, and generated-admission boundary.

          Dependencies and delivery order

          Out of scope

          • Directory removal, recursive removal, globs, or several paths in one invocation.
          • Returning a path, boolean, receipt, removed contents, or restoration handle.
          • Host paths outside contextual Env.cwd.
          • Direct Agent filesystem or command access.
          • Granting generated source admission; only Evaluate Agent-generated XMD through a constrained allowlist #369's host-owned policy can admit the pinned identity.

          Activity

          Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

          Metadata

          Metadata

          Assignees

          No one assigned

            Labels

            No labels
            No labels

            Projects

            No projects

              Relationships

              None yet

              Development

              No branches or pull requests

              Issue actions

              , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length \u003e 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
              Skip to content

              Add a contextual File.Delete component for contained file removal #567

              Description

              @taras

              Story

              As a workflow author, I want to remove one file through ordinary Executable Markdown, so a retained Workspace proposal can delete obsolete content without receiving a filesystem handle or command-execution authority.

              Authoring contract

              <File.Delete path="obsolete.md" />

              File.Delete is an ordinary contextual component with one required non-empty string prop, path. It is self-closing, accepts no content, renders nothing, and returns no caller-visible value. as therefore has nothing useful to bind.

              The path resolves relative to contextual Env.cwd, exactly where the element is written. The operation removes one non-directory entry:

              • a regular file is removed;
              • a final symlink is removed as a link without following or changing its target;
              • a missing entry succeeds as an idempotent no-op; and
              • a directory is refused, even when empty.

              There is no recursive form, force prop, glob, multiple-path prop, trash, restore handle, or implicit directory cleanup.

              Containment and authority

              Reject an empty path, an absolute path, and a lexical .. escape before mutation. Resolve existing parent ancestors and refuse a parent symlink that would place the named entry outside Env.cwd. Removing a final symlink changes only the contained directory entry and therefore does not grant access to its target.

              The component makes no host filesystem call directly. It extends the contextual Files API with the semantic operation required to remove one file entry. The ordinary host Files provider implements the same contract for xmd run; the workflow Files provider performs it against the selected run-owned Workspace through the existing transaction boundary.

              Generated source receives no deletion authority merely because the component exists or is registered. #369 owns generated-XMD admission. After its initial Dir plus paired File:write slice is delivered, this issue also owns adding the exact pinned File.Delete identity to the standard Deno workflow host's write table and the focused admission evidence. A host without that pinned identity continues to refuse generated deletion.

              Durability and failure

              Under xmd workflow, one successful invocation is one ordinary Workspace-local durable effect and one Workspace transaction. Its Workspace mutation and journal completion commit atomically under #365. Completed replay restores completion without deleting again; partial replay reaches the operation against the retained Workspace frontier.

              An ordinary missing entry is successful, not a failure. An invalid path, directory target, containment refusal, provider refusal, or filesystem failure changes nothing and follows the ordinary component failure contract. The operation publishes no synthetic mutation receipt; its durable effect record is the authoritative account.

              Acceptance

              • <File.Delete path="file.txt" /> removes one contained regular file and renders nothing.
              • Removing an already-missing file succeeds, changes nothing, and renders nothing.
              • Removing a final symlink removes the link and leaves its target unchanged, including when the target is outside Env.cwd.
              • An empty path, absolute path, lexical escape, escaping parent symlink, or directory target is refused without changing the Workspace.
              • Paired content is refused before any mutation.
              • The ordinary host and workflow Files providers implement the same semantic operation without the component selecting a runtime.
              • A workflow mutation and its durable completion commit atomically; completed replay performs no second removal.
              • The standard generated-XMD write policy admits deletion only by this component's exact pinned identity and only when the host supplied it. Same-name repository components, registrations, middleware replacement, and another loaded package copy do not satisfy that identity.
              • A generated fragment mixing admitted deletion with any unadmitted syntax performs no generated effect because Evaluate Agent-generated XMD through a constrained allowlist #369 preflights the whole fragment.
              • Core, runtime-provider, workflow transaction/replay, and generated-admission regressions cover the observable contract.
              • The executable-MDX and workflow-Workspace specifications describe the component, containment, durability, and generated-admission boundary.

              Dependencies and delivery order

              Out of scope

              • Directory removal, recursive removal, globs, or several paths in one invocation.
              • Returning a path, boolean, receipt, removed contents, or restoration handle.
              • Host paths outside contextual Env.cwd.
              • Direct Agent filesystem or command access.
              • Granting generated source admission; only Evaluate Agent-generated XMD through a constrained allowlist #369's host-owned policy can admit the pinned identity.

              Activity

              Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

              Metadata

              Metadata

              Assignees

              No one assigned

                Labels

                No labels
                No labels

                Projects

                No projects

                  Relationships

                  None yet

                  Development

                  No branches or pull requests

                  Issue actions

                  , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
                  Skip to content

                  Add a contextual File.Delete component for contained file removal #567

                  Description

                  @taras

                  Story

                  As a workflow author, I want to remove one file through ordinary Executable Markdown, so a retained Workspace proposal can delete obsolete content without receiving a filesystem handle or command-execution authority.

                  Authoring contract

                  <File.Delete path="obsolete.md" />

                  File.Delete is an ordinary contextual component with one required non-empty string prop, path. It is self-closing, accepts no content, renders nothing, and returns no caller-visible value. as therefore has nothing useful to bind.

                  The path resolves relative to contextual Env.cwd, exactly where the element is written. The operation removes one non-directory entry:

                  • a regular file is removed;
                  • a final symlink is removed as a link without following or changing its target;
                  • a missing entry succeeds as an idempotent no-op; and
                  • a directory is refused, even when empty.

                  There is no recursive form, force prop, glob, multiple-path prop, trash, restore handle, or implicit directory cleanup.

                  Containment and authority

                  Reject an empty path, an absolute path, and a lexical .. escape before mutation. Resolve existing parent ancestors and refuse a parent symlink that would place the named entry outside Env.cwd. Removing a final symlink changes only the contained directory entry and therefore does not grant access to its target.

                  The component makes no host filesystem call directly. It extends the contextual Files API with the semantic operation required to remove one file entry. The ordinary host Files provider implements the same contract for xmd run; the workflow Files provider performs it against the selected run-owned Workspace through the existing transaction boundary.

                  Generated source receives no deletion authority merely because the component exists or is registered. #369 owns generated-XMD admission. After its initial Dir plus paired File:write slice is delivered, this issue also owns adding the exact pinned File.Delete identity to the standard Deno workflow host's write table and the focused admission evidence. A host without that pinned identity continues to refuse generated deletion.

                  Durability and failure

                  Under xmd workflow, one successful invocation is one ordinary Workspace-local durable effect and one Workspace transaction. Its Workspace mutation and journal completion commit atomically under #365. Completed replay restores completion without deleting again; partial replay reaches the operation against the retained Workspace frontier.

                  An ordinary missing entry is successful, not a failure. An invalid path, directory target, containment refusal, provider refusal, or filesystem failure changes nothing and follows the ordinary component failure contract. The operation publishes no synthetic mutation receipt; its durable effect record is the authoritative account.

                  Acceptance

                  • <File.Delete path="file.txt" /> removes one contained regular file and renders nothing.
                  • Removing an already-missing file succeeds, changes nothing, and renders nothing.
                  • Removing a final symlink removes the link and leaves its target unchanged, including when the target is outside Env.cwd.
                  • An empty path, absolute path, lexical escape, escaping parent symlink, or directory target is refused without changing the Workspace.
                  • Paired content is refused before any mutation.
                  • The ordinary host and workflow Files providers implement the same semantic operation without the component selecting a runtime.
                  • A workflow mutation and its durable completion commit atomically; completed replay performs no second removal.
                  • The standard generated-XMD write policy admits deletion only by this component's exact pinned identity and only when the host supplied it. Same-name repository components, registrations, middleware replacement, and another loaded package copy do not satisfy that identity.
                  • A generated fragment mixing admitted deletion with any unadmitted syntax performs no generated effect because Evaluate Agent-generated XMD through a constrained allowlist #369 preflights the whole fragment.
                  • Core, runtime-provider, workflow transaction/replay, and generated-admission regressions cover the observable contract.
                  • The executable-MDX and workflow-Workspace specifications describe the component, containment, durability, and generated-admission boundary.

                  Dependencies and delivery order

                  Out of scope

                  • Directory removal, recursive removal, globs, or several paths in one invocation.
                  • Returning a path, boolean, receipt, removed contents, or restoration handle.
                  • Host paths outside contextual Env.cwd.
                  • Direct Agent filesystem or command access.
                  • Granting generated source admission; only Evaluate Agent-generated XMD through a constrained allowlist #369's host-owned policy can admit the pinned identity.

                  Activity

                  Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

                  Metadata

                  Metadata

                  Assignees

                  No one assigned

                    Labels

                    No labels
                    No labels

                    Projects

                    No projects

                      Relationships

                      None yet

                      Development

                      No branches or pull requests

                      Issue actions

                      , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
                      Skip to content

                      Add a contextual File.Delete component for contained file removal #567

                      Description

                      @taras

                      Story

                      As a workflow author, I want to remove one file through ordinary Executable Markdown, so a retained Workspace proposal can delete obsolete content without receiving a filesystem handle or command-execution authority.

                      Authoring contract

                      <File.Delete path="obsolete.md" />

                      File.Delete is an ordinary contextual component with one required non-empty string prop, path. It is self-closing, accepts no content, renders nothing, and returns no caller-visible value. as therefore has nothing useful to bind.

                      The path resolves relative to contextual Env.cwd, exactly where the element is written. The operation removes one non-directory entry:

                      • a regular file is removed;
                      • a final symlink is removed as a link without following or changing its target;
                      • a missing entry succeeds as an idempotent no-op; and
                      • a directory is refused, even when empty.

                      There is no recursive form, force prop, glob, multiple-path prop, trash, restore handle, or implicit directory cleanup.

                      Containment and authority

                      Reject an empty path, an absolute path, and a lexical .. escape before mutation. Resolve existing parent ancestors and refuse a parent symlink that would place the named entry outside Env.cwd. Removing a final symlink changes only the contained directory entry and therefore does not grant access to its target.

                      The component makes no host filesystem call directly. It extends the contextual Files API with the semantic operation required to remove one file entry. The ordinary host Files provider implements the same contract for xmd run; the workflow Files provider performs it against the selected run-owned Workspace through the existing transaction boundary.

                      Generated source receives no deletion authority merely because the component exists or is registered. #369 owns generated-XMD admission. After its initial Dir plus paired File:write slice is delivered, this issue also owns adding the exact pinned File.Delete identity to the standard Deno workflow host's write table and the focused admission evidence. A host without that pinned identity continues to refuse generated deletion.

                      Durability and failure

                      Under xmd workflow, one successful invocation is one ordinary Workspace-local durable effect and one Workspace transaction. Its Workspace mutation and journal completion commit atomically under #365. Completed replay restores completion without deleting again; partial replay reaches the operation against the retained Workspace frontier.

                      An ordinary missing entry is successful, not a failure. An invalid path, directory target, containment refusal, provider refusal, or filesystem failure changes nothing and follows the ordinary component failure contract. The operation publishes no synthetic mutation receipt; its durable effect record is the authoritative account.

                      Acceptance

                      • <File.Delete path="file.txt" /> removes one contained regular file and renders nothing.
                      • Removing an already-missing file succeeds, changes nothing, and renders nothing.
                      • Removing a final symlink removes the link and leaves its target unchanged, including when the target is outside Env.cwd.
                      • An empty path, absolute path, lexical escape, escaping parent symlink, or directory target is refused without changing the Workspace.
                      • Paired content is refused before any mutation.
                      • The ordinary host and workflow Files providers implement the same semantic operation without the component selecting a runtime.
                      • A workflow mutation and its durable completion commit atomically; completed replay performs no second removal.
                      • The standard generated-XMD write policy admits deletion only by this component's exact pinned identity and only when the host supplied it. Same-name repository components, registrations, middleware replacement, and another loaded package copy do not satisfy that identity.
                      • A generated fragment mixing admitted deletion with any unadmitted syntax performs no generated effect because Evaluate Agent-generated XMD through a constrained allowlist #369 preflights the whole fragment.
                      • Core, runtime-provider, workflow transaction/replay, and generated-admission regressions cover the observable contract.
                      • The executable-MDX and workflow-Workspace specifications describe the component, containment, durability, and generated-admission boundary.

                      Dependencies and delivery order

                      Out of scope

                      • Directory removal, recursive removal, globs, or several paths in one invocation.
                      • Returning a path, boolean, receipt, removed contents, or restoration handle.
                      • Host paths outside contextual Env.cwd.
                      • Direct Agent filesystem or command access.
                      • Granting generated source admission; only Evaluate Agent-generated XMD through a constrained allowlist #369's host-owned policy can admit the pinned identity.

                      Activity

                      Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

                      Metadata

                      Metadata

                      Assignees

                      No one assigned

                        Labels

                        No labels
                        No labels

                        Projects

                        No projects

                          Relationships

                          None yet

                          Development

                          No branches or pull requests

                          Issue actions

                          , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
                          Skip to content

                          Add a contextual File.Delete component for contained file removal #567

                          Description

                          @taras

                          Story

                          As a workflow author, I want to remove one file through ordinary Executable Markdown, so a retained Workspace proposal can delete obsolete content without receiving a filesystem handle or command-execution authority.

                          Authoring contract

                          <File.Delete path="obsolete.md" />

                          File.Delete is an ordinary contextual component with one required non-empty string prop, path. It is self-closing, accepts no content, renders nothing, and returns no caller-visible value. as therefore has nothing useful to bind.

                          The path resolves relative to contextual Env.cwd, exactly where the element is written. The operation removes one non-directory entry:

                          • a regular file is removed;
                          • a final symlink is removed as a link without following or changing its target;
                          • a missing entry succeeds as an idempotent no-op; and
                          • a directory is refused, even when empty.

                          There is no recursive form, force prop, glob, multiple-path prop, trash, restore handle, or implicit directory cleanup.

                          Containment and authority

                          Reject an empty path, an absolute path, and a lexical .. escape before mutation. Resolve existing parent ancestors and refuse a parent symlink that would place the named entry outside Env.cwd. Removing a final symlink changes only the contained directory entry and therefore does not grant access to its target.

                          The component makes no host filesystem call directly. It extends the contextual Files API with the semantic operation required to remove one file entry. The ordinary host Files provider implements the same contract for xmd run; the workflow Files provider performs it against the selected run-owned Workspace through the existing transaction boundary.

                          Generated source receives no deletion authority merely because the component exists or is registered. #369 owns generated-XMD admission. After its initial Dir plus paired File:write slice is delivered, this issue also owns adding the exact pinned File.Delete identity to the standard Deno workflow host's write table and the focused admission evidence. A host without that pinned identity continues to refuse generated deletion.

                          Durability and failure

                          Under xmd workflow, one successful invocation is one ordinary Workspace-local durable effect and one Workspace transaction. Its Workspace mutation and journal completion commit atomically under #365. Completed replay restores completion without deleting again; partial replay reaches the operation against the retained Workspace frontier.

                          An ordinary missing entry is successful, not a failure. An invalid path, directory target, containment refusal, provider refusal, or filesystem failure changes nothing and follows the ordinary component failure contract. The operation publishes no synthetic mutation receipt; its durable effect record is the authoritative account.

                          Acceptance

                          • <File.Delete path="file.txt" /> removes one contained regular file and renders nothing.
                          • Removing an already-missing file succeeds, changes nothing, and renders nothing.
                          • Removing a final symlink removes the link and leaves its target unchanged, including when the target is outside Env.cwd.
                          • An empty path, absolute path, lexical escape, escaping parent symlink, or directory target is refused without changing the Workspace.
                          • Paired content is refused before any mutation.
                          • The ordinary host and workflow Files providers implement the same semantic operation without the component selecting a runtime.
                          • A workflow mutation and its durable completion commit atomically; completed replay performs no second removal.
                          • The standard generated-XMD write policy admits deletion only by this component's exact pinned identity and only when the host supplied it. Same-name repository components, registrations, middleware replacement, and another loaded package copy do not satisfy that identity.
                          • A generated fragment mixing admitted deletion with any unadmitted syntax performs no generated effect because Evaluate Agent-generated XMD through a constrained allowlist #369 preflights the whole fragment.
                          • Core, runtime-provider, workflow transaction/replay, and generated-admission regressions cover the observable contract.
                          • The executable-MDX and workflow-Workspace specifications describe the component, containment, durability, and generated-admission boundary.

                          Dependencies and delivery order

                          Out of scope

                          • Directory removal, recursive removal, globs, or several paths in one invocation.
                          • Returning a path, boolean, receipt, removed contents, or restoration handle.
                          • Host paths outside contextual Env.cwd.
                          • Direct Agent filesystem or command access.
                          • Granting generated source admission; only Evaluate Agent-generated XMD through a constrained allowlist #369's host-owned policy can admit the pinned identity.

                          Activity

                          Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

                          Metadata

                          Metadata

                          Assignees

                          No one assigned

                            Labels

                            No labels
                            No labels

                            Projects

                            No projects

                              Relationships

                              None yet

                              Development

                              No branches or pull requests

                              Issue actions

                              , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
                              Skip to content

                              Add a contextual File.Delete component for contained file removal #567

                              Description

                              @taras

                              Story

                              As a workflow author, I want to remove one file through ordinary Executable Markdown, so a retained Workspace proposal can delete obsolete content without receiving a filesystem handle or command-execution authority.

                              Authoring contract

                              <File.Delete path="obsolete.md" />

                              File.Delete is an ordinary contextual component with one required non-empty string prop, path. It is self-closing, accepts no content, renders nothing, and returns no caller-visible value. as therefore has nothing useful to bind.

                              The path resolves relative to contextual Env.cwd, exactly where the element is written. The operation removes one non-directory entry:

                              • a regular file is removed;
                              • a final symlink is removed as a link without following or changing its target;
                              • a missing entry succeeds as an idempotent no-op; and
                              • a directory is refused, even when empty.

                              There is no recursive form, force prop, glob, multiple-path prop, trash, restore handle, or implicit directory cleanup.

                              Containment and authority

                              Reject an empty path, an absolute path, and a lexical .. escape before mutation. Resolve existing parent ancestors and refuse a parent symlink that would place the named entry outside Env.cwd. Removing a final symlink changes only the contained directory entry and therefore does not grant access to its target.

                              The component makes no host filesystem call directly. It extends the contextual Files API with the semantic operation required to remove one file entry. The ordinary host Files provider implements the same contract for xmd run; the workflow Files provider performs it against the selected run-owned Workspace through the existing transaction boundary.

                              Generated source receives no deletion authority merely because the component exists or is registered. #369 owns generated-XMD admission. After its initial Dir plus paired File:write slice is delivered, this issue also owns adding the exact pinned File.Delete identity to the standard Deno workflow host's write table and the focused admission evidence. A host without that pinned identity continues to refuse generated deletion.

                              Durability and failure

                              Under xmd workflow, one successful invocation is one ordinary Workspace-local durable effect and one Workspace transaction. Its Workspace mutation and journal completion commit atomically under #365. Completed replay restores completion without deleting again; partial replay reaches the operation against the retained Workspace frontier.

                              An ordinary missing entry is successful, not a failure. An invalid path, directory target, containment refusal, provider refusal, or filesystem failure changes nothing and follows the ordinary component failure contract. The operation publishes no synthetic mutation receipt; its durable effect record is the authoritative account.

                              Acceptance

                              • <File.Delete path="file.txt" /> removes one contained regular file and renders nothing.
                              • Removing an already-missing file succeeds, changes nothing, and renders nothing.
                              • Removing a final symlink removes the link and leaves its target unchanged, including when the target is outside Env.cwd.
                              • An empty path, absolute path, lexical escape, escaping parent symlink, or directory target is refused without changing the Workspace.
                              • Paired content is refused before any mutation.
                              • The ordinary host and workflow Files providers implement the same semantic operation without the component selecting a runtime.
                              • A workflow mutation and its durable completion commit atomically; completed replay performs no second removal.
                              • The standard generated-XMD write policy admits deletion only by this component's exact pinned identity and only when the host supplied it. Same-name repository components, registrations, middleware replacement, and another loaded package copy do not satisfy that identity.
                              • A generated fragment mixing admitted deletion with any unadmitted syntax performs no generated effect because Evaluate Agent-generated XMD through a constrained allowlist #369 preflights the whole fragment.
                              • Core, runtime-provider, workflow transaction/replay, and generated-admission regressions cover the observable contract.
                              • The executable-MDX and workflow-Workspace specifications describe the component, containment, durability, and generated-admission boundary.

                              Dependencies and delivery order

                              Out of scope

                              • Directory removal, recursive removal, globs, or several paths in one invocation.
                              • Returning a path, boolean, receipt, removed contents, or restoration handle.
                              • Host paths outside contextual Env.cwd.
                              • Direct Agent filesystem or command access.
                              • Granting generated source admission; only Evaluate Agent-generated XMD through a constrained allowlist #369's host-owned policy can admit the pinned identity.

                              Activity

                              Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

                              Metadata

                              Metadata

                              Assignees

                              No one assigned

                                Labels

                                No labels
                                No labels

                                Projects

                                No projects

                                  Relationships

                                  None yet

                                  Development

                                  No branches or pull requests

                                  Issue actions