commit 84699dbf840a054dd4cc19e291b4b28bffa7d7e7
parent f4478a4fb2a758bf0862dde64aea529de3e98471
Author: triesap <tyson@radroots.org>
Date: Mon, 3 Aug 2026 13:05:48 +0000
facade: quarantine superseded package surface
- Record the all-capsule search for retired facade packages and namespaces.
- Confirm no facade experiment, wildcard SDK export, or placeholder survives.
- Classify the conflicting CLI application identity under its assigned cutover.
- Preserve publication freeze and exact release-policy package classification.
Diffstat:
1 file changed, 54 insertions(+), 0 deletions(-)
diff --git a/docs/implementation/FACADE_SUPERSEDED_SURFACE_AUDIT.md b/docs/implementation/FACADE_SUPERSEDED_SURFACE_AUDIT.md
@@ -0,0 +1,54 @@
+# Facade superseded-surface audit
+
+Step 260 searched every checked-out first-party OSS capsule before the first
+`radroots` crate release. No earlier facade crate, facade experiment, public
+`radroots::sdk` namespace, or wildcard SDK reexport exists in canonical source.
+There is therefore no compatibility package or module to retain, deprecate, or
+publish.
+
+## Canonical SDK capsule
+
+The only package named `radroots` in this workspace is `crates/radroots`. Its
+manifest is explicitly `publish = false` until Step 305, its exact dependency
+and feature graphs are governed, and its source is limited to the curated
+ordinary-user modules. The only advanced engine edge is its private Cargo
+dependency on `radroots_sdk`; the facade does not duplicate engine logic.
+
+The release policy approves only `radroots_sdk` and `radroots` for eventual
+package validation. Every other local Cargo package remains private, and the
+architecture gate rejects additional publishable identities. No deprecation
+placeholder package exists.
+
+## Other checked-out OSS capsules
+
+The separate CLI capsule currently uses Cargo package/binary name `radroots`.
+That is an application identity, not a facade experiment, but its Cargo package
+identity conflicts with the new library front door and its source still uses
+the previously recorded sibling SDK path and legacy APIs. Its complete cutover
+is assigned to Steps 269-272 and final consumer verification in Steps 294 and
+313. Step 260 does not mutate that separate repository early or introduce a
+shim for it.
+
+The daemon, Apple/mobile, Studio, web, and other checked-out capsules contain
+no alternate Rust facade package or `radroots::sdk` namespace. Their real
+consumer migrations remain owned by Steps 269-294.
+
+`oss/.sdk_step064_worktree` is an untracked local recovery checkout, not a
+canonical repository, workspace member, release input, or compatibility
+surface. It was intentionally left untouched and excluded from conclusions
+about releasable source.
+
+## Repeatable gate
+
+From the OSS parent, search canonical capsule source for:
+
+```sh
+rg -n 'radroots[_-](facade|client)|radroots::sdk|pub use radroots_sdk::\*|name = "radroots"' \
+ oss --glob 'Cargo.toml' --glob '*.rs' --glob '*.md' --glob '*.toml'
+```
+
+Then run the SDK capsule's workspace tests and `cargo xtask architecture-ci`.
+Expected matches are limited to the final facade, normative specifications and
+guards, clean-smoke fixture names, and the separately assigned CLI identity.
+Any new package or namespace match blocks release until it is removed or an
+explicit later migration step owns it.