lib

Core libraries for Radroots
git clone https://radroots.dev/git/lib.git
Log | Files | Refs | README

commit 621c7a63db8ed59604a5992e635ca0320ef659f8
parent 7c5671ff6fb42f3ef10f488c2474bfd16e1bb0ff
Author: triesap <tyson@radroots.org>
Date:   Tue,  4 Aug 2026 15:17:13 +0000

docs: finalize release v1 migration

Diffstat:
Dcrates/nostr/COMPATIBILITY.md | 20--------------------
Mcrates/nostr/Cargo.toml | 2+-
Mcrates/nostr/tests/package_boundary.rs | 24+++++++-----------------
Mdocs/implementation/PUBLICATION_FREEZE.md | 24+++++++++++-------------
Adocs/migration/release-v1.md | 25+++++++++++++++++++++++++
5 files changed, 44 insertions(+), 51 deletions(-)

diff --git a/crates/nostr/COMPATIBILITY.md b/crates/nostr/COMPATIBILITY.md @@ -1,20 +0,0 @@ -# Superseded surface retirement - -`radroots_nostr` remains `publish = false` while Release V1 migration is in -progress. Step 133 removed its public `error`, `events`, `types`, `util`, -`codec_adapters`, `job_adapter`, `event_adapters`, `event_verify`, and -`draft_signing` paths, the unsupported `codec` feature, and every public -`radroots_nostr_*` item. The durable surface is limited to the seven modules -and single root `Error` export in the Release V1 package charter. - -An all-first-party source search also found separate OSS capsules that still -reference the predecessor `radroots_nostr::prelude` API. Those capsules are -outside the authorized `oss/lib` and `oss/sdk` crate-surface edit boundary and -already require their own upstream cutover; no compatibility path was restored -for them here. No new consumer may adopt any retired path. - -Step 313 is the exact final pre-release audit. It must repeat the all-first-party -search, confirm every separate capsule has migrated or pinned a compatible -upstream library revision, remove this migration record, regenerate the public -API baseline, and pass the package-realistic downstream matrix before Release -V1 approval. diff --git a/crates/nostr/Cargo.toml b/crates/nostr/Cargo.toml @@ -13,7 +13,7 @@ documentation = "https://docs.rs/radroots_nostr" readme = "README.md" keywords = ["radroots", "nostr", "events", "signing"] categories = ["network-programming", "cryptography"] -include = ["src/**", "tests/**", "!tests/generic_builder_boundary.rs", "!tests/package_boundary.rs", "examples/**", "Cargo.toml", "README.md", "COMPATIBILITY.md", "LICENSE-APACHE", "LICENSE-MIT"] +include = ["src/**", "tests/**", "!tests/generic_builder_boundary.rs", "!tests/package_boundary.rs", "examples/**", "Cargo.toml", "README.md", "LICENSE-APACHE", "LICENSE-MIT"] [package.metadata.docs.rs] features = ["std", "events", "blossom", "nip17", "signing"] diff --git a/crates/nostr/tests/package_boundary.rs b/crates/nostr/tests/package_boundary.rs @@ -22,7 +22,6 @@ const README: &str = include_str!("../README.md"); const SIGNING_MODULE: &str = include_str!("../src/signing.rs"); const TAG_MODULE: &str = include_str!("../src/tag.rs"); const TYPES_MODULE: &str = include_str!("../src/types.rs"); -const COMPATIBILITY: &str = include_str!("../COMPATIBILITY.md"); const PUBLIC_API: &str = include_str!("../../../docs/api/radroots_nostr.txt"); const IDENTITY_MANIFEST: &str = include_str!("../../identity/Cargo.toml"); const IDENTITY_KEY_MODULE: &str = include_str!("../../identity/src/key.rs"); @@ -551,22 +550,13 @@ fn superseded_surface_retirement_is_explicit_and_release_bounded() { ); } } - for required in [ - "publish = [\"crates-io\"]", - "outside the authorized `oss/lib` and `oss/sdk` crate-surface edit boundary", - "no compatibility path was restored", - "Step 313 is the exact final pre-release audit", - ] { - let authority = if required == "publish = [\"crates-io\"]" { - MANIFEST - } else { - COMPATIBILITY - }; - assert!( - authority.contains(required), - "retirement contract is missing `{required}`" - ); - } + assert!(MANIFEST.contains("publish = [\"crates-io\"]")); + assert!( + !Path::new(env!("CARGO_MANIFEST_DIR")) + .join("COMPATIBILITY.md") + .exists(), + "the completed migration record must not ship as an active compatibility contract" + ); let public_modules = PUBLIC_API .lines() diff --git a/docs/implementation/PUBLICATION_FREEZE.md b/docs/implementation/PUBLICATION_FREEZE.md @@ -1,23 +1,21 @@ # Crates.io publication freeze -Crates.io publication is frozen for the complete release-v1 crate refactor. -Every workspace package, including packages intended to become public, must -set: +Crates.io upload remains frozen for the complete release-v1 crate refactor. +Step 305 enabled validation metadata for exactly the 17 approved public +packages: ```toml -publish = false +publish = ["crates-io"] ``` -`contracts/releases/publish_policy.toml` is the machine authority for this -freeze. Repository contract and release-preflight validation reject a missing -publication-control section, an unexpected registry, a different enablement -checkpoint, or any package that is implicitly or explicitly publishable. +`contracts/releases/publish_policy.toml` is the machine authority. Repository +contract and release-preflight validation reject an unexpected registry, +package, order, version, or enablement checkpoint; every private, preview, +build, and test-support package remains non-publishable. -The only planned exception is release plan Step 305, after the final package -inventory, resolved public dependency graph, API surface, target matrix, and -security gates are green. That checkpoint may set `publication.frozen = false` -and enable exactly the approved release packages for package-validation -staging. It does not authorize upload or any crates.io mutation. +This validation-only state permits packaging, crates.io dry-runs, and local +ephemeral-registry qualification. It does not authorize upload or any crates.io +mutation. Changing the freeze requires an independently reviewed release-control commit. Actual publication, tag creation, registry ownership changes, and diff --git a/docs/migration/release-v1.md b/docs/migration/release-v1.md @@ -0,0 +1,25 @@ +# Release V1 breaking migration + +Release V1 is an intentional breaking cut to the 17-package public library +surface. All packages remain in `oss/lib`, use version `0.1.0-alpha`, and are +qualified independently from the two front-door packages in `oss/sdk`. + +| Retired surface | Release V1 owner | +| --- | --- | +| authority and Nostr signer packages | `radroots_signing` and `radroots_nostr_connect` | +| vault and protected-store packages | `radroots_secrets` plus `radroots_storage` / `radroots_storage_sqlite` | +| event store, event index, outbox, and runtime store packages | `radroots_storage`, `radroots_storage_sqlite`, and `radroots_sync` | +| runtime and broad network packages | explicit host composition over `radroots_transport`, `radroots_transport_nostr`, storage, and sync | +| geocoder package | `radroots_geonames` | +| event-codec domain roots | `radroots_event_codec::{decode,encode,verify,admission}` | +| trade operational-listing and validation-receipt modules | `radroots_sdk::listing` for product operations; `radroots_event` retains the canonical listing model | +| prefixed transport target aliases and Reticulum helpers | `TransportId`, `Target`, `TargetSet`, and `target::{TargetScope,TargetLabel,TargetFingerprint}` | +| Nostr Connect prelude and prefixed client bridge | explicit `radroots_nostr_connect` root types and modules | + +No compatibility package, hidden prelude, type alias, dual schema, or sibling +source path remains. Consumers must migrate atomically to the final owner; the +release does not provide a deprecated intermediate API. + +The 17 packages are enabled only for package-realistic validation. Actual +crates.io publication remains blocked until the approval packet is complete +and a separate operator action is explicitly authorized.