Skip to content

chore!: retire the provenance shim, ban rename shims, and drop stale run output - #5790

Merged
kyle-sexton merged 3 commits into
mainfrom
chore/retire-provenance
Oct 2, 2026
Merged

kyle-sexton merged 3 commits into
mainfrom
chore/retire-provenance

Conversation

@kyle-sexton

@kyle-sexton kyle-sexton commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

No related issue: owner-directed cleanup that retires the provenance shim from #4589 and removes stale tracked run output.

Summary

  • Retires the provenance plugin, the one-release deprecation shim that pointed at attribution (Rename the provenance plugin to attribution #4589).
  • docs/migration-playbook.md no longer allows deprecation shims or aliases: a rename or retirement migrates every consumer in the same change, with no pointer to the old name.
  • Deletes tracked one-off output that no code, test, or current doc reads.

Fix

Plugin retirement, per docs/migration-playbook.md "Retiring a published plugin":

  • Removed the .claude-plugin/marketplace.json entry and plugins/provenance/ together; regenerated docs/catalog.md (the cheat sheet was already in sync).
  • Swept references: .claude/settings.json enabledPlugins key, scripts/cheatsheet-config.mjs exclusion, scripts/em-dash-purged-paths.txt line, scripts/skill-leaf-name-registry.txt audit row and its shim note.
  • attribution 0.9.1 records the removal in its changelog. The provenance changelog goes with its directory, so the retirement is recorded here.

Consumer guidance: an installed provenance copy keeps working until uninstalled; drop provenance@melodic-software from enabledPlugins and enable attribution@melodic-software. No tombstone, no renames entry. Capability lives in attribution.

Deleted run output:

  • .claude/unhobble/claude-code-plugins-fable-5-1-20260908-15744de6/ (8 files): one past /harness-config:unhobble run. The skill still writes to .claude/unhobble/<experiment-id>/; only this run's record goes. Dropped its two files from the ci-workflows edge in docs/architecture/landscape.json (count 153 to 150, measured with reference-edges.sh on the deleted files) and the .claude/unhobble/*/evidence/** em-dash allowance in .claude/ai-slop.json.
  • docs/hook-migration-audit.md: a self-described 2026-07-12 audit snapshot, "not durable policy". Dropped from the medley landscape edge (count 15 to 7).
  • docs/setup-contract-campaign-follow-ups.md: the close record for chore: follow-ups surfaced by the setup-contract campaign (toolchain pin, CLAUDE_PLUGIN_ROOT liveness, Windows worktree test failures) #3138; nothing references it, and the positions live in the code it names.

Verification

  • bash scripts/validate-plugins.sh: all manifests and the catalog validate.
  • VALIDATE_CONTRACTS_BASE_REF=origin/main node scripts/validate-plugin-contracts.mjs: pass (59 setup skills, 5 retirement manifests).
  • bash scripts/check-changed-skills.sh origin/main: 13 skills, 0 failed.
  • npx markdownlint-cli2 on the changed markdown: 0 issues.
  • check-changelog-parity.sh --check, --check-order, --check-bump origin/main, --check-preserved origin/main: pass.
  • check-plugin-manifest-presence.sh, check-plugin-catalog-enablement.sh, check-purged-em-dashes.sh, check-skill-leaf-names.sh (+ test), check-docs-naming.sh, generate-catalog.mjs --check, generate-cheatsheet.mjs --check (+ test): pass.
  • All 7 plugins/attribution shell suites and scripts/validate-plugin-contracts.test.sh (100/100): pass.

Related

🤖 Generated with Claude Code

@kyle-sexton
kyle-sexton force-pushed the chore/retire-provenance branch from 347bdf5 to ddaffb3 Compare October 2, 2026 04:16
…run output

Remove the provenance deprecation shim plugin: its catalog entry,
plugins/provenance/, the repo's enabledPlugins key, its cheat-sheet
exclusion, em-dash allowlist line, and leaf-name registry entry.
Regenerate docs/catalog.md.

The migration playbook no longer allows a one-release deprecation shim:
a rename or retirement migrates every consumer in the same change, with
no alias or pointer to the old name.

Delete tracked one-off output nothing reads: the 2026-09-08 unhobble
run under .claude/unhobble/, docs/hook-migration-audit.md (a 2026-07-12
audit snapshot), and docs/setup-contract-campaign-follow-ups.md (an
issue-close record for #3138). Drop the landscape edges and the ai-slop
em-dash allowance that named those files.

attribution 0.8.6 records the removal and drops its legacy
provenance.json warning and migration prose. Its two retirement
records stay, since the gate keeps them append-only.

BREAKING CHANGE: provenance@melodic-software no longer resolves in the
marketplace; enable attribution@melodic-software instead.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@kyle-sexton
kyle-sexton force-pushed the chore/retire-provenance branch from ddaffb3 to e049828 Compare October 2, 2026 15:21
@kyle-sexton
kyle-sexton marked this pull request as ready for review October 2, 2026 15:22
@kyle-sexton
kyle-sexton enabled auto-merge (squash) October 2, 2026 15:22
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-02T15:27:19.843663Z e049828 Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@claude

claude Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 1m 18s —— View job


Security review — no findings

  • Gather context (PR diff, changed files)
  • Check skip gate
  • Review instruction-surface deletions (docs/migration-playbook.md)
  • Review plugin retirement / file deletions for security-relevant surface
  • Post findings

This PR retires the provenance plugin and sweeps all references to it (marketplace manifest, .claude/settings.json, scripts/cheatsheet-config.mjs, scripts/em-dash-purged-paths.txt, scripts/skill-leaf-name-registry.txt, plugins/attribution/skills/audit/scripts/lib.sh legacy-config-name handling), plus deletes stale tracked run output (.claude/unhobble/.../20260908-15744de6/**, docs/hook-migration-audit.md, docs/setup-contract-campaign-follow-ups.md) and tightens docs/migration-playbook.md. I reviewed every changed file against gh pr diff 5790.

Instruction-surface check. The only standing-instruction edit is in docs/migration-playbook.md, which removes the "one-release deprecation shim" allowance and replaces it with a stricter no-shim/no-alias rule. This tightens the policy rather than loosening a guardrail, so it doesn't match any Gate 0 protected class (irreversible-action, secret-handling, data-integrity, external-publication, legal-compliance, agent-authority) from the instruction exception register — there's no removed check that leaves an action unguarded.

Other changes. All remaining diffs are reference sweeps (manifest/config/script list entries) and deletions of stale, non-executed markdown/JSON records. None touch authentication, authorization, secrets, injection-prone input handling, or GitHub Actions workflow permissions/triggers.

No security issues found.

@claude

claude Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 3m 34s —— View job


Code review complete

  • Gather context (PR diff, changed files, CLAUDE.md/AGENTS.md conventions)
  • Understand the request (run /review:code-review lane against PR chore!: retire the provenance shim, ban rename shims, and drop stale run output #5790)
  • Review retirement sweep completeness (marketplace, settings, scripts, docs)
  • Review deleted-output cleanup (unhobble run, hook-migration-audit, setup-contract-campaign-follow-ups)
  • Review migration-playbook.md changes for consistency
  • Post findings

No correctness or maintainability issues found. This is a clean, mechanical retirement sweep:

  • The provenance plugin removal is symmetric (.claude-plugin/marketplace.json entry + plugins/provenance/ directory together), and the catalog/cheatsheet regeneration, .claude/settings.json enabledPlugins key, scripts/cheatsheet-config.mjs, scripts/em-dash-purged-paths.txt, and scripts/skill-leaf-name-registry.txt sweeps are all internally consistent — I grepped the full tree for plugins/provenance, provenance@melodic-software, and the bare plugin name and found no remaining dangling references to the retired plugin.
  • plugins/attribution/skills/audit/scripts/lib.sh's cfg_layer_add simplification correctly drops the legacy-file warning branch, and the matching test block in list-corpus.test.sh is removed cleanly with no leftover references to the deleted legacy_run/LEG_ERR/LEG_FILES helpers.
  • docs/migration-playbook.md's shim ban reads consistently with the rest of the "Retiring a published plugin" section, and no other passage in that doc still treats provenance→attribution as a live example.
  • The docs/architecture/landscape.json edge-count edits (153→150 for ci-workflows, 15→7 for medley) line up with the files removed from each edge's file list.

One non-blocking observation, not a finding: two pre-existing docs still mention docs/hook-migration-audit.md by name after this PR deletes it —
docs/upstream/claude-code-mods/research-2026-09-19/research-repo-fit.md#L68
and
docs/adr/0029-admit-a-second-findings-producer-behind-a-targeted-run-clause.md#L96.
Both are dated, frozen snapshots (a research memo and an ADR) citing the file as a past measurement subject rather than a live pointer, consistent with this repo's own convention that such records aren't rewritten after the fact — so I'm not raising it as something to fix, just flagging it in case the convention doesn't cover this case the way I read it.

Author-claimed verification (validate-plugins.sh, contract/changelog/catalog checks, attribution test suites) is listed in the PR body but was not independently re-run by me.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: e0498289a9

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread docs/hook-migration-audit.md
kyle-sexton and others added 2 commits October 2, 2026 11:29
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@claude

claude Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 3m 11s —— View job


Code review complete

  • Gather context (PR diff at HEAD 4cce588 vs origin/main, changed files, CLAUDE.md/AGENTS.md conventions)
  • Run skip gate (PR open, not draft, has real review surface — proceeded)
  • Review new commits since the prior review round (6d67d94, merge 4cce588)
  • Review retirement sweep / deletions for correctness and maintainability
  • Post findings

No correctness or maintainability findings. No inline comments posted.

This round only adds two commits on top of the already-reviewed e049828: 6d67d94 (a docs-only fix) and the merge 4cce588 (brings in unrelated main history via git diff origin/main...HEAD, which confirms it contributes nothing new to this PR's diff — same 34 files as before).

6d67d94 resolves the one open review comment. It addresses Codex's P2 review comment on docs/hook-migration-audit.md (the deleted audit was still relied on by docs/upstream/claude-code-mods/research-2026-09-19/research-repo-fit.md and docs/adr/0029-...md):

Re-verified the rest of the sweep (unchanged from the prior review pass) against the actual tree, not just the diff:

  • grep-ed the full repo for provenance@melodic-software and plugins/provenance — the only hits left are plugins/attribution/CHANGELOG.md (legitimately documents the removal) and an untracked local .claude/settings.json/.claude/unhobble/ working-tree artifact that is not part of this PR's commits (confirmed via git diff origin/main...HEAD, which shows the committed .claude/settings.json correctly drops the provenance@melodic-software key).
  • Remaining provenance string hits in plugins/attribution/** (source-fetch.md, rubric.md, extract-breadcrumbs.sh, etc.) are all the generic English word ("provenance signals", "provenance markers"), not the retired plugin — confirmed by reading each hit.
  • plugins/attribution/skills/audit/scripts/lib.sh and list-corpus.test.sh: the legacy-config warning branch and its four test cases are removed symmetrically, with no leftover legacy_run/LEG_ERR/LEG_FILES references.
  • docs/migration-playbook.md's shim ban reads consistently with the surrounding "Retiring a published plugin" section.

One thing I could not independently verify: the docs/architecture/landscape.json edge-count edits (153→150 for ci-workflows, 15→7 for medley) rely on reference-edges.sh's own fixture/cap-aware extraction logic, which a plain grep over the tree doesn't replicate (it excludes fixtures/evals, caps the file list at 5, and type-scopes matches). I wasn't able to run that script in this sandbox, so those two counts remain author-claimed, not independently verified by me.

@claude

claude Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 1m 4s —— View job


Security review — no findings

  • Gather context (PR diff: git diff origin/main...HEAD, re-run against head 4cce588)
  • Check skip gate (PR open, not a no-op diff, no prior review covers this head)
  • Review instruction-surface change (docs/migration-playbook.md)
  • Review code change (plugins/attribution/skills/audit/scripts/lib.sh)
  • Review retirement sweep / deleted-file consistency (config, catalog, landscape edges)
  • Post findings

This review covers the full diff at head 4cce588 (git diff origin/main...HEAD), which is a superset of the earlier review posted against e049828: it adds a fixup commit (6d67d94, pointing two doc citations at a permalink after the Codex comment on this PR) plus a merge of origin/main.

Instruction-surface check. docs/migration-playbook.md removes the "one-release deprecation shim" allowance and replaces it with a stricter no-shim/no-alias/no-pointer rule. I checked this against the instruction exception register's Gate 0 classes (irreversible-action, secret-handling, data-integrity, external-publication, legal-compliance, agent-authority): the diff tightens a permissive carve-out rather than removing a guardrail, so no class applies and nothing is left unguarded by this change.

Fixup commit. 6d67d94 only edits prose in two already-changed docs (ADR 0029, the mods research memo) to point at a permalink of the deleted hook-migration-audit.md instead of a dead relative path. No security-relevant surface.

Other changes (plugin retirement sweep, lib.sh legacy-warning removal, .claude/ai-slop.json/landscape.json/registry edits) are unchanged from the prior pass and remain non-security-relevant: reference sweeps and deletions of stale, non-executed records. No authentication, authorization, secrets, injection-prone input handling, or GitHub Actions workflow changes anywhere in this diff.

No security issues found.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant