commit 47dabd049d57be6efd9741d966adabb01bd8b433
parent 451b58b9eb465b5e0d3755f82d0459fb172de096
Author: triesap <tyson@radroots.org>
Date: Thu, 30 Jul 2026 14:43:31 +0000
signing: quarantine superseded sdk surface
- hide retained SDK signer reexports and adapter module from documentation
- record audited CLI and Studio consumers that still require the facade
- bind the internal and downstream cutovers to their assigned checkpoints
- enforce private status and exact Step 313 removal in source-boundary tests
Diffstat:
4 files changed, 29 insertions(+), 0 deletions(-)
diff --git a/crates/sdk/src/adapters/mod.rs b/crates/sdk/src/adapters/mod.rs
@@ -3,4 +3,5 @@ pub mod nostr;
#[cfg(feature = "radrootsd-execution")]
pub mod radrootsd;
#[cfg(feature = "signer-adapters")]
+#[doc(hidden)]
pub mod signer;
diff --git a/crates/sdk/src/lib.rs b/crates/sdk/src/lib.rs
@@ -148,6 +148,7 @@ pub use crate::runtime::{
StorageStatusReceipt, StorageStatusRequest,
};
#[cfg(all(feature = "runtime", feature = "signer-adapters"))]
+#[doc(hidden)]
pub use crate::signer_provider::{
RADROOTS_SDK_MYC_NIP46_DEFAULT_REQUEST_TIMEOUT_MS,
RADROOTS_SDK_MYC_NIP46_PRODUCT_SIGN_EVENT_KINDS, RadrootsSdkLocalKeySigner,
diff --git a/crates/sdk/tests/source_boundary.rs b/crates/sdk/tests/source_boundary.rs
@@ -204,3 +204,21 @@ fn sdk_consumes_only_the_final_signing_boundary() {
}
}
}
+
+#[test]
+fn signer_transition_surface_is_private_hidden_and_scheduled_for_removal() {
+ let manifest = manifest_dir();
+ let package_manifest = read_source(&manifest.join("Cargo.toml"));
+ let lib = read_source(&manifest.join("src/lib.rs"));
+ let adapters = read_source(&manifest.join("src/adapters/mod.rs"));
+ let transition_record =
+ read_source(&manifest.join("../../docs/implementation/COMPATIBILITY_SHIMS.md"));
+
+ assert!(package_manifest.contains("publish = false"));
+ assert!(lib.contains("#[doc(hidden)]\npub use crate::signer_provider::{"));
+ assert!(adapters.contains("#[doc(hidden)]\npub mod signer;"));
+ assert!(transition_record.contains("SDK signer provider façade"));
+ assert!(transition_record.contains("Step 313"));
+ assert!(transition_record.contains("oss/cli"));
+ assert!(transition_record.contains("oss/studio_app"));
+}
diff --git a/docs/implementation/COMPATIBILITY_SHIMS.md b/docs/implementation/COMPATIBILITY_SHIMS.md
@@ -7,6 +7,7 @@ second protocol authority.
| Shim | Final owner | Remaining consumers | Final removal |
| --- | --- | --- | --- |
| `radroots_runtime_contract_v1` | `radroots_protocol::runtime::v1` | SDK CLI-host generator; standalone `oss/cli` runtime registry and command code | Step 270 |
+| SDK signer provider façade and `adapters::signer` | `radroots_signing` plus host-owned `radroots_nostr_connect` adapters | SDK runtime/examples/tests; standalone `oss/cli` and `oss/studio_app` | Step 313, after SDK Step 248, downstream Steps 269-293, and matrix Step 294 |
The `radroots_sdk` library no longer depends on or reexports the runtime shim.
Its radrootsd execution path also consumes
@@ -19,3 +20,11 @@ Source searches at this checkpoint also found the transport-publish shim in
standalone `oss/radrootsd` and the runtime/protocol shims in standalone
`oss/cli`; those consumers are assigned to Steps 286 and 270 respectively.
No new consumer may be added before those cutovers.
+
+Step 109's first-party source search also found that immediate removal of the
+SDK-prefixed signer provider types would break the standalone CLI and Studio
+repositories. The SDK crate remains `publish = false`; the retained root
+reexports and signer adapter module are hidden from generated documentation.
+They must not gain new consumers or behavior. Step 248 owns the SDK-internal
+cutover, Step 294 must prove the downstream cutovers, and Step 313 removes the
+feature, dependency, module, reexports, and old names in full.