commit 00cf3888b08e490730dc189cd124cc89a39a21f0
parent b4b63c79191d7105e5a12c68602a0e1ab176309c
Author: triesap <tyson@radroots.org>
Date: Thu, 30 Jul 2026 14:43:15 +0000
signing: quarantine superseded package surface
- retain authority and Nostr signer bridges only for audited consumers
- keep both superseded packages private and outside the public inventory
- record downstream cutovers and exact Step 313 removal authority
- enforce package quarantine and prevent public documentation identity
Diffstat:
7 files changed, 110 insertions(+), 4 deletions(-)
diff --git a/crates/authority/Cargo.toml b/crates/authority/Cargo.toml
@@ -9,6 +9,7 @@ license.workspace = true
description = "Authority model for Radroots"
repository.workspace = true
homepage.workspace = true
+readme = "README.md"
[features]
default = ["std"]
diff --git a/crates/authority/README.md b/crates/authority/README.md
@@ -0,0 +1,14 @@
+# `radroots_authority` transition package
+
+`radroots_authority` is a private, non-publishable transition package. New
+code must use `radroots_signing` for actor context, sign requests, sign
+receipts, and signer injection.
+
+The package remains only because the standalone `oss/cli` and
+`oss/studio_app` repositories still consume its source API. Those consumers
+are assigned to the first-party downstream migration phase (Steps 269-293).
+The package must be removed at Step 313 after the Step 294 compatibility
+matrix proves every consumer has completed its cutover.
+
+This package is not an approved public crate, must keep `publish = false`, and
+must not acquire new consumers, features, or behavior while it is retained.
diff --git a/crates/authority/tests/quarantine.rs b/crates/authority/tests/quarantine.rs
@@ -0,0 +1,29 @@
+use std::{fs, path::PathBuf};
+
+fn package_root() -> PathBuf {
+ PathBuf::from(env!("CARGO_MANIFEST_DIR"))
+}
+
+#[test]
+fn transition_package_remains_private_and_has_an_exact_removal_step() {
+ let root = package_root();
+ let manifest = fs::read_to_string(root.join("Cargo.toml")).expect("read package manifest");
+ let readme = fs::read_to_string(root.join("README.md")).expect("read transition record");
+ let release_policy =
+ fs::read_to_string(root.join("../../contracts/releases/publish_policy.toml"))
+ .expect("read release policy");
+
+ assert!(manifest.contains("publish = false"));
+ assert!(manifest.contains("readme = \"README.md\""));
+ assert!(readme.contains("`radroots_signing` for actor context"));
+ assert!(readme.contains("removed at Step 313"));
+ assert!(release_policy.contains("private = [\n \"radroots_authority\""));
+ assert!(
+ !release_policy
+ .split("approved_packages = [")
+ .nth(1)
+ .and_then(|tail| tail.split(']').next())
+ .expect("approved package list")
+ .contains("radroots_authority")
+ );
+}
diff --git a/crates/nostr_signer/Cargo.toml b/crates/nostr_signer/Cargo.toml
@@ -9,7 +9,6 @@ license.workspace = true
description = "Signer state model for Radroots"
repository.workspace = true
homepage.workspace = true
-documentation = "https://docs.rs/radroots_nostr_signer"
readme = "README"
[features]
diff --git a/crates/nostr_signer/README b/crates/nostr_signer/README
@@ -1,8 +1,22 @@
# radroots_nostr_signer
-This is the README for `radroots_nostr_signer`, which provides transport-
-neutral signer stores and NIP-46 handler primitives for the `radroots` core
-libraries.
+`radroots_nostr_signer` is a private, non-publishable transition package. New
+public integrations must use `radroots_signing` for signer injection and
+`radroots_nostr_connect` for NIP-46 protocol types. Myc-private persisted state
+will remain application-owned.
+
+The package remains temporarily because `radroots_net`,
+`radroots_nostr_accounts`, `oss/sdk`, `oss/myc`, and `oss/cli` still consume
+parts of its source API. Their scheduled crate, SDK, and downstream cutovers
+run through Steps 109-294. The package must be removed at Step 313 after the
+Step 294 compatibility matrix proves that every first-party consumer has
+migrated.
+
+This package is not an approved public crate, must keep `publish = false`, and
+must not acquire new consumers, features, or behavior while it is retained.
+
+The retained implementation currently provides transport-neutral signer
+stores and NIP-46 handler primitives for existing consumers.
## Overview
diff --git a/crates/nostr_signer/tests/quarantine.rs b/crates/nostr_signer/tests/quarantine.rs
@@ -0,0 +1,29 @@
+use std::{fs, path::PathBuf};
+
+fn package_root() -> PathBuf {
+ PathBuf::from(env!("CARGO_MANIFEST_DIR"))
+}
+
+#[test]
+fn transition_package_remains_private_and_has_an_exact_removal_step() {
+ let root = package_root();
+ let manifest = fs::read_to_string(root.join("Cargo.toml")).expect("read package manifest");
+ let readme = fs::read_to_string(root.join("README")).expect("read transition record");
+ let release_policy =
+ fs::read_to_string(root.join("../../contracts/releases/publish_policy.toml"))
+ .expect("read release policy");
+
+ assert!(manifest.contains("publish = false"));
+ assert!(!manifest.contains("documentation = \"https://docs.rs/"));
+ assert!(readme.contains("`radroots_signing` for signer injection"));
+ assert!(readme.contains("removed at Step 313"));
+ assert!(release_policy.contains("\"radroots_nostr_signer\","));
+ assert!(
+ !release_policy
+ .split("approved_packages = [")
+ .nth(1)
+ .and_then(|tail| tail.split(']').next())
+ .expect("approved package list")
+ .contains("radroots_nostr_signer")
+ );
+}
diff --git a/docs/implementation/COMPATIBILITY_SHIMS.md b/docs/implementation/COMPATIBILITY_SHIMS.md
@@ -0,0 +1,20 @@
+# Compatibility shim quarantine
+
+Step 109 searched every first-party Rust source and manifest before attempting
+to remove superseded signing packages. Active consumers make immediate
+deletion unsafe, so only private source bridges remain. None is an approved
+public crate identity or a second contract authority.
+
+| Bridge | Final owner | Remaining first-party consumers | Assigned cutover | Exact final removal |
+| --- | --- | --- | --- | --- |
+| `radroots_authority` | `radroots_signing` | `oss/cli`, `oss/studio_app` | downstream Steps 269-293; matrix Step 294 | Step 313 |
+| `radroots_nostr_signer` | `radroots_signing`, `radroots_nostr_connect`, Myc-private state | `radroots_net`, `radroots_nostr_accounts`, `oss/sdk`, `oss/myc`, `oss/cli` | crate Steps 109-143; SDK Step 248; downstream Steps 269-293; matrix Step 294 | Step 313 |
+
+Both package manifests keep `publish = false`. Release policy classifies both
+as private and excludes both from the exact 19-package public inventory. The
+`radroots_nostr_signer` manifest intentionally has no docs.rs URL. No new
+consumer, feature, public contract, or behavior may be added before removal.
+
+The Step 294 matrix must prove all listed consumers have migrated. Step 313
+then removes the packages, their workspace/dependency entries, their source
+names, and every remaining source pin.