This is the preservation and removal inventory for normalization issue #5. The reference is the archived sudoHG/AskKey-legacy tree at legacy-final, peeled commit ee709976f823104fe12fb68c3528adf67c3db3ef. Every path below is relative to that legacy tree, including resources, fixtures and harness files; the files need not exist in the normalized repository yet. Exception: files deleted or renamed by #31 (MigrationCommitter.swift, MigrationPlannerTests.swift, DebugRunMigrationKeyStore.swift) are replaced by the current files that now hold or test their responsibilities.
The inventory is grounded in the legacy README.md, CONTEXT.md, ADRs 0026 through 0030, the client integration matrix and architecture guide, then the declarations, call sites and assertions under Sources/ and Tests/. The current repository AGENTS.md, issue #5 and the maintainer decisions on PR #10 govern the decisions. The maintainer confirmed the remaining Keep rows and the additional removals on 2026-10-02. References in old documents to Multica, updater/release work, Lokalite migration or iCloud backup do not override these decisions. v0.1 remains macOS-only; release automation is disabled.
Keep preserves confirmed reachable behavior or the regression support for it. Remove records a fixed task-card or maintainer decision. All four former Proposed remove rows are now confirmed Remove; no undecided removal rows remain. A source or test can appear in multiple rows because it contains both retained and removed responsibilities. In particular, whole-file deletion is not implied for mixed files such as Vault.swift, VaultViewModel.swift, AskKeyApp.swift, Storage/VaultStoreMigrations.swift, Migration/VaultBootstrap.swift or Keychain/AppKeyStore.swift. Current-schema creation and App-owned key/bootstrap behavior must survive the removal of Lokalite import/upgrade paths.
The explicitly listed LocalVaultLifecycle.swift removal currently overlaps the reachable modern erase coordinator: Vault+LocalLifecycle.swift calls LocalVaultEraseCoordinator. The file decision is Remove, while local erase, quiescing and recovery behavior are Keep. A later implementation issue must preserve that behavior when replacing the file. The maintainer confirmed this file/behavior distinction in the PR #10 review. This document changes no runtime code; removal implementation still belongs to later scoped issues.
Saved plaintext never belongs in Agent responses. A target that has received an approved value can output or copy it; the guarantee covers AskKey's own responses, errors and logs. Discovery hooks are reminders, not authorization. File listings and tests show implementation coverage, not completed production release or real-credential acceptance.
| Feature | One-line description | Decision | Legacy source files | Legacy test files |
|---|---|---|---|---|
| Text credentials | Create, list, edit and reveal encrypted text credentials with Ask as the default permission. | Keep | Sources/AskKeyCore/Vault+TextCredentials.swiftSources/AskKeyCore/Models/CredentialName.swiftSources/AskKeyCore/Models/VNextCredential.swiftSources/AskKeyApp/VaultViewModel+Credentials.swiftSources/AskKeyApp/Views/CredentialManagementView.swift |
Tests/AskKeyCoreTests/HumanTextCredentialTests.swiftTests/AskKeyE2ETests/CredentialE2ETests.swift |
| File credentials | Freeze ordinary-file bytes, original filename, size and digest; reject links, directories, special files, oversize files and read races. | Keep | Sources/AskKeyCore/FileImport.swiftSources/AskKeyCore/Vault+TextCredentials.swiftSources/AskKeyCore/VaultError.swiftSources/AskKeyApp/VaultViewModel+Credentials.swift |
Tests/AskKeyCoreTests/HumanFileCredentialTests.swiftTests/AskKeyCoreTests/FileBoundaryRepairTests.swift |
| Multi-component credentials | Store text and file components together under one name and permission, with per-component delivery mappings and atomic validation. | Keep | Sources/AskKeyCore/Models/CredentialName.swiftSources/AskKeyCore/Vault+TextCredentials.swiftSources/AskKeyBroker/CredentialComponents.swiftSources/AskKeyApp/CredentialComponentDeliveryEditor.swift |
Tests/AskKeyCoreTests/HumanTextCredentialTests.swiftTests/AskKeyCoreTests/AuditBrokerBoundaryTests.swiftTests/AskKeyBrokerTests/TextRuntimeTests.swift |
| Credential templates and editor | Provide API, GitHub App, Apple, SSH, cloud, database and custom templates, optional fields, reveal controls and validated save actions. | Keep | Sources/AskKeyApp/Views/CredentialManagementView.swiftSources/AskKeyApp/CredentialComponentDeliveryEditor.swift |
Tests/AskKeyAppTests/ReviewEditorValidationTests.swiftTests/AskKeyAppTests/AgentClientConnectorTests.swiftTests/AskKeyAppTests/WorkspaceVisualContractTests.swift |
| Names and field validation | Trim display names, use NFC/case-folded global uniqueness, reject control or oversize fields, and validate environment-variable mappings. | Keep | Sources/AskKeyCore/Models/CredentialName.swiftSources/AskKeyCore/CredentialFieldValidation.swiftSources/AskKeyCore/Vault+TextCredentials.swift |
Tests/AskKeyCoreTests/HumanTextCredentialTests.swiftTests/AskKeyCoreTests/ReviewCatalogLimitTests.swiftTests/AskKeyAppTests/ReviewEditorValidationTests.swift |
| Usage instructions and private notes | Edit catalog-visible usage instructions separately from encrypted private notes; preserve unrevealed payload and notes during metadata edits. | Keep | Sources/AskKeyCore/Models/CredentialName.swiftSources/AskKeyCore/Vault+TextCredentials.swiftSources/AskKeyApp/Views/CredentialManagementView.swift |
Tests/AskKeyCoreTests/HumanTextCredentialTests.swiftTests/AskKeyCoreTests/BrokerCatalogTests.swiftTests/AskKeyAppTests/ReviewPrivateNotesTests.swift |
| Credential groups | Organize credentials without granting authority; metadata writes assign/create groups and organize_credentials freezes up to 64 ordered operations under one approval and system authentication. Agent-invisible targets freeze like absent names; the App shows existing-group no-ops or merges with both member counts, and commit rechecks the full target state. Group rename/delete includes Hidden and recycled members; deletion ungroups credentials. All stored-group writers merge inside one SQL transaction, and App edits take the exclusive gate. Catalog groups lists empty groups and groups with a visible member. |
Keep | Sources/AskKeyVault/Vault+CredentialGroups.swiftSources/AskKeyVault/Vault+AgentOrganizationFreeze.swiftSources/AskKeyVault/VaultStore+AgentOrganization.swiftSources/AskKeyBroker/BrokerOrganizationSummary.swiftdocs/adr/0010-agent-credential-metadata-writes.md |
Tests/AskKeyVaultTests/AgentOrganizationTests.swiftTests/AskKeyVaultTests/AgentOrganizationInvisibleTargetTests.swiftTests/AskKeyVaultTests/AgentGroupTransactionTests.swiftTests/AskKeyVaultTests/AgentOrganizationCommitBoundaryTests.swiftTests/AskKeyVaultTests/AgentOrganizationConcurrencyTests.swiftTests/AskKeyAppTests/OrganizationApprovalContentTests.swift |
| Library navigation and search | Navigate all credentials, named groups and ungrouped items; search names, groups and instructions in the all-credentials view and clear search on scope changes. | Keep | Sources/AskKeyApp/Views/CredentialManagementView.swiftSources/AskKeyApp/Views/SettingsView.swiftSources/AskKeyApp/WorkspaceVisualContract.swift |
Tests/AskKeyAppTests/ManagementWorkspaceNavigationTests.swiftTests/AskKeyAppTests/WorkspaceVisualContractTests.swiftTests/AskKeyAppTests/AppLanguageExperienceTests.swift |
| Editor lifecycle | Keep create and edit routes distinct and stop saving an editor whose credential has disappeared, including after locking or reopening. | Keep | Sources/AskKeyApp/Views/CredentialManagementView.swiftSources/AskKeyApp/Views/SettingsView.swift |
Tests/AskKeyAppTests/ReviewEditorMissingCredentialTests.swift |
| Trash, restore and permanent deletion | Recycle deleted credentials for 30 days, restore them from the App, and require explicit confirmation and authentication for permanent deletion. | Keep | Sources/AskKeyCore/Storage/VaultStoreCredentialQueries.swiftSources/AskKeyCore/Vault+TextCredentials.swiftSources/AskKeyCore/AgentTextWriteGovernance.swiftSources/AskKeyApp/VaultViewModel+Credentials.swiftSources/AskKeyApp/Views/CredentialManagementView.swift |
Tests/AskKeyCoreTests/AgentTextWriteGovernanceTests.swiftTests/AskKeyCoreTests/CredentialStorageAuthenticationTests.swiftTests/AskKeyCoreTests/ICloudBackupRecycleTests.swiftTests/AskKeyAppTests/WorkspaceVisualContractTests.swiftTests/AskKeyE2ETests/CredentialE2ETests.swift |
| Environment-file import | Parse pasted or frozen .env input with quotes, escapes and comments; reject duplicates, malformed lines and invalid UTF-8 without echoing values in errors. | Keep | Sources/AskKeyCore/EnvFileFormat.swiftSources/AskKeyCore/FileImport.swiftSources/AskKeyApp/FrozenEnvImport.swiftSources/AskKeyApp/Views/CredentialManagementView.swift |
Tests/AskKeyCoreTests/EnvFileFormatRepairTests.swiftTests/AskKeyCoreTests/AskKeyCoreTests.swiftTests/AskKeyAppTests/ReviewEnvImportTests.swift |
| Import preview and conflicts | Preview frozen values, choose destination groups and resolve duplicate names inline; replacement preserves the existing credential metadata. | Keep | Sources/AskKeyApp/Views/CredentialManagementView.swiftSources/AskKeyApp/VaultViewModel+Credentials.swiftSources/AskKeyCore/Vault+TextCredentials.swift |
Tests/AskKeyAppTests/WorkspaceVisualContractTests.swiftTests/AskKeyAppTests/AgentClientConnectorTests.swift |
| Expiry enforcement | Store optional expiry dates and reject expired runtime use or writes, cancelling approvals and invalidating deliveries at the deadline. | Keep | Sources/AskKeyCore/Vault+TextCredentials.swiftSources/AskKeyCore/AgentTextWriteGovernance.swiftSources/AskKeyCore/Models/CredentialName.swiftSources/AskKeyBroker/ApprovalStateMachine.swift |
Tests/AskKeyCoreTests/AgentAccessTests.swiftTests/AskKeyCoreTests/AgentTextWriteGovernanceTests.swiftTests/AskKeyCoreTests/RuntimeApprovalBoundaryTests.swift |
| Expiry notifications | Remind seven days before expiry, persist a deduplication ledger, and handle permission denial, rescheduling, deletion and delayed notification failures. | Keep | Sources/AskKeyCore/CredentialExpiryReminder.swiftSources/AskKeyApp/CredentialExpiryReminderController.swift |
Tests/AskKeyCoreTests/CredentialExpiryReminderTests.swiftTests/AskKeyAppTests/ExpiryReminderAsyncBoundaryTests.swiftTests/AskKeyAppTests/Batch4SettingsLanguageTests.swift |
| Authenticated reveal and copy | Require fresh authentication to reveal or copy stored values, expose file/component details only after reveal, and clear the owned clipboard after 60 seconds. | Keep | Sources/AskKeyCore/Vault+TextCredentials.swiftSources/AskKeyApp/ClipboardController.swiftSources/AskKeyApp/VaultViewModel+Credentials.swiftSources/AskKeyApp/Views/CredentialManagementView.swift |
Tests/AskKeyCoreTests/HumanTextCredentialTests.swiftTests/AskKeyCoreTests/HumanFileCredentialTests.swiftTests/AskKeyAppTests/ClipboardControllerTests.swiftTests/AskKeyAppTests/WorkspaceVisualContractTests.swiftTests/AskKeyAppTests/ReviewPrivateNotesTests.swift |
| Feature | One-line description | Decision | Legacy source files | Legacy test files |
|---|---|---|---|---|
| Authenticated encrypted storage | Encrypt credential names, payloads, notes, filenames and access records; authenticate record metadata and use a keyed name index to prevent keyless policy substitution. | Keep | Sources/AskKeyCore/Crypto/VaultCrypto.swiftSources/AskKeyCore/Crypto/CredentialRecordAuthentication.swiftSources/AskKeyCore/Storage/VaultStore.swiftSources/AskKeyCore/Storage/VaultRecords.swiftSources/AskKeyCore/Storage/VaultStoreCredentialQueries.swiftSources/AskKeyCore/Storage/VaultStoreSupport.swift |
Tests/AskKeyCoreTests/CredentialStorageAuthenticationTests.swiftTests/AskKeyCoreTests/AuditStorageBoundaryTests.swiftTests/AskKeyCoreTests/HumanTextCredentialTests.swiftTests/AskKeyCoreTests/AskKeyCoreTests.swift |
| Current database schema | Keep the current credential, write-operation, group and access-record schema and the Phase 4 legacy-table baseline; migration askkey-0002-drop-legacy-tables drops the old tables only when they hold nothing beyond the legacy Default seed and otherwise keeps every table and row. |
Keep | Sources/AskKeyCore/Storage/VaultStoreMigrations.swiftSources/AskKeyCore/Storage/VaultStore.swiftSources/AskKeyCore/Storage/VaultRecords.swiftSources/AskKeyCore/Storage/VaultStoreConfigQueries.swiftSources/AskKeyCore/Storage/VaultStoreCredentialQueries.swiftSources/AskKeyCore/Storage/VaultStoreCredentialAccessQueries.swift |
Tests/AskKeyCoreTests/AskKeyCoreTests.swiftTests/AskKeyCoreTests/CredentialStorageAuthenticationTests.swiftTests/AskKeyCoreTests/AgentTextWriteGovernanceTests.swift |
| App-owned key and current-library bootstrap | Open or create the current library for the App Broker without granting a management session; reject unsupported or incomplete legacy state. | Keep | Sources/AskKeyCore/Vault.swiftSources/AskKeyCore/VaultConfiguration.swiftSources/AskKeyCore/Migration/VaultBootstrap.swiftSources/AskKeyCore/Keychain/AppKeyStore.swiftSources/AskKeyCore/Storage/CurrentLibrarySnapshot.swiftSources/AskKeyCore/Keychain/KeychainStore.swift |
Tests/AskKeyCoreTests/VaultBootstrapTests.swiftTests/AskKeyCoreTests/CurrentLibraryAdoptionTests.swiftTests/AskKeyCoreTests/KeychainInteractionSafetyTests.swiftTests/AskKeyAppTests/AppLanguageExperienceTests.swift |
| Management session and vault lock | Authenticate management independently of Agent runtime, clear sensitive UI on session close/expiry, retire stale callbacks and avoid locking the App-held vault on management idle expiry. | Keep | Sources/AskKeyCore/Vault.swiftSources/AskKeyCore/Models/CredentialName.swiftSources/AskKeyApp/VaultViewModel.swiftSources/AskKeyApp/SessionPolicy.swiftSources/AskKeyApp/AskKeyApp.swift |
Tests/AskKeyCoreTests/HumanTextCredentialTests.swiftTests/AskKeyAppTests/SessionPolicyTests.swiftTests/AskKeyAppTests/ManagementWorkspaceNavigationTests.swiftTests/AskKeyAppTests/AgentAccessMenuSessionTests.swiftTests/AskKeyAppTests/AppLanguageExperienceTests.swiftTests/AskKeyE2ETests/CredentialE2ETests.swift |
| System authentication subprocess | Run bounded, localized owner authentication and frozen-approval description through the packaged App subprocess, with cancellation and safe pipe handling. | Keep | Sources/AskKeyApp/ManagementAuthenticationProcess.swiftSources/AskKeyApp/VaultViewModel.swiftSources/AskKeyApp/AskKeyApp.swift |
Tests/AskKeyAppTests/ManagementAuthenticationProcessTests.swiftTests/AskKeyAppTests/AuditApplicationContractTests.swiftTests/AskKeyAppTests/AppLanguageExperienceTests.swift |
| First-run onboarding | Offer first credential creation/import, restrict unauthenticated creation to an empty library, and persist completion and login-item choice; remove iCloud recovery/key steps separately. | Keep | Sources/AskKeyApp/Views/FirstRunOnboardingView.swiftSources/AskKeyApp/Views/SettingsView.swiftSources/AskKeyApp/VaultViewModel.swiftSources/AskKeyApp/WorkspaceVisualContract.swiftSources/AskKeyCore/Vault.swift |
Tests/AskKeyCoreTests/HumanTextCredentialTests.swiftTests/AskKeyAppTests/AppLanguageExperienceTests.swiftTests/AskKeyAppTests/ReviewICloudRecoveryTests.swiftTests/AskKeyAppTests/WorkspaceVisualContractTests.swift |
| Local library erase | Keep authenticated, language-specific confirmation, quiescing, delivery cleanup and crash recovery with local key deletion last; remove the separate iCloud backup/material hooks. | Keep | Sources/AskKeyCore/Vault+LocalLifecycle.swiftSources/AskKeyCore/Vault.swiftSources/AskKeyCore/LocalVaultLifecycle.swiftSources/AskKeyApp/VaultViewModel+Credentials.swiftSources/AskKeyApp/Views/CredentialManagementView.swift |
Tests/AskKeyCoreTests/LocalVaultLifecycleTests.swiftTests/AskKeyAppTests/LocalVaultLifecycleViewModelTests.swiftTests/AskKeyAppTests/WorkspaceVisualContractTests.swift |
| Safe errors and injected workspace operations | Present localized actionable errors, suppress authentication-cancellation noise, and ensure injected/read-only workspaces do not fall through to the shared vault. | Keep | Sources/AskKeyCore/VaultError.swiftSources/AskKeyApp/UserFacingCopy.swiftSources/AskKeyApp/CredentialWorkspaceMutations.swiftSources/AskKeyApp/VaultViewModel.swiftSources/AskKeyApp/VaultViewModel+Credentials.swift |
Tests/AskKeyAppTests/ReviewCredentialIsolationTests.swiftTests/AskKeyAppTests/AppLanguageExperienceTests.swiftTests/AskKeyAppTests/LocalizationRemediationTests.swift |
The legacy tables projects, environments, secrets, secret_values and activity_log remain in the Phase 4 schema baseline. Removing old models/query code does not remove these tables or rewrite historical migrations. Migration askkey-0002-drop-legacy-tables drops them only when they hold nothing beyond the legacy Default seed; otherwise every table and row is kept and the migration is still recorded. Current credential and access-record tables, encryption and App-owned key/bootstrap behavior remain Keep.
| Feature | One-line description | Decision | Legacy source files | Legacy test files |
|---|---|---|---|---|
| Allow / Ask / Hidden | Use one credential-wide permission with Ask by default; Hide excludes catalog/use/write access and grouping or caller identity does not widen authorization. | Keep | Sources/AskKeyCore/Models/VNextCredential.swiftSources/AskKeyCore/Vault+TextCredentials.swiftSources/AskKeyApp/Views/CredentialManagementView.swiftSources/AskKeyApp/VaultViewModel+Credentials.swift |
Tests/AskKeyCoreTests/AgentAccessTests.swiftTests/AskKeyCoreTests/BrokerCatalogTests.swiftTests/AskKeyCoreTests/ReadDeclarationAndAuditTests.swift |
| Metadata-only credential catalog | Return visible names, IDs, instructions, expiry state and component mappings without values, private notes or filenames, with bounded cancellable reads. | Keep | Sources/AskKeyCore/Vault+TextCredentials.swiftSources/AskKeyCore/Storage/VaultStoreCredentialQueries.swiftSources/AskKeyBroker/BrokerProtocol.swiftSources/AskKeyHelper/main.swift |
Tests/AskKeyCoreTests/BrokerCatalogTests.swiftTests/AskKeyCoreTests/BrokerCatalogCancellationTests.swiftTests/AskKeyCoreTests/ReviewCatalogLimitTests.swiftTests/AskKeyBrokerTests/BrokerProtocolTests.swift |
| Approval request identity and replay | Bind operation, target, immutable payload digest and deadlines to a request ID/capability; reuse only identical retransmissions and consume an approval once. | Keep | Sources/AskKeyBroker/ApprovalStateMachine.swiftSources/AskKeyBroker/BrokerProtocol.swift |
Tests/AskKeyBrokerTests/ApprovalStateMachineTests.swiftTests/AskKeyBrokerTests/BrokerProtocolTests.swiftTests/AskKeyE2ETests/AskKeyE2ETests.swift |
| Once, deny, cancel and expiry | Support allow-once or deny decisions, capability-bound status/cancel and five-minute pending expiry; denial has no cooldown and terminal requests cannot execute. | Keep | Sources/AskKeyBroker/ApprovalStateMachine.swiftSources/AskKeyBroker/BrokerProtocol.swiftSources/AskKeyApp/AskKeyApp.swift |
Tests/AskKeyBrokerTests/ApprovalStateMachineTests.swiftTests/AskKeyBrokerTests/HelperApprovalWaitTests.swiftTests/AskKeyCoreTests/AgentAccessTests.swiftTests/AskKeyE2ETests/AskKeyE2ETests.swift |
| Timed read allowance and revoke | Allow reads globally for one credential until its original deadline, with bounded configurable minutes, a disable setting, a visible countdown and explicit revocation. | Keep | Sources/AskKeyBroker/ApprovalStateMachine.swiftSources/AskKeyApp/AppPreferences.swiftSources/AskKeyApp/VaultViewModel.swiftSources/AskKeyApp/Views/CredentialManagementView.swiftSources/AskKeyCore/Vault.swift |
Tests/AskKeyBrokerTests/ApprovalStateMachineTests.swiftTests/AskKeyCoreTests/TimedAllowanceBoundsTests.swiftTests/AskKeyCoreTests/CredentialExpiryReminderTests.swiftTests/AskKeyAppTests/Batch4SettingsLanguageTests.swiftTests/AskKeyAppTests/WorkspaceVisualContractTests.swift |
| Read approval authentication preference | Enable read authentication by default and allow an explicitly confirmed opt-out; writes still authenticate each time, while the iCloud restore reset path is removed separately. | Keep | Sources/AskKeyBroker/ApprovalStateMachine.swiftSources/AskKeyApp/AppPreferences.swiftSources/AskKeyApp/Views/CredentialManagementView.swiftSources/AskKeyApp/VaultViewModel.swift |
Tests/AskKeyBrokerTests/ApprovalStateMachineTests.swiftTests/AskKeyAppTests/ICloudRestoreAuthenticationTests.swiftTests/AskKeyAppTests/Batch4SettingsLanguageTests.swiftTests/AskKeyAppTests/WorkspaceVisualContractTests.swift |
| Independent approval panel | Present a foreground confirmation with caller, purpose, target and countdown; authenticate frozen write reveal separately and show pending operations in management. | Keep | Sources/AskKeyApp/AgentApprovalPanelFactory.swiftSources/AskKeyApp/AskKeyApp.swiftSources/AskKeyApp/Views/CredentialManagementView.swift |
Tests/AskKeyAppTests/AgentApprovalPanelTests.swiftTests/AskKeyAppTests/Batch4SettingsLanguageTests.swiftTests/AskKeyAppTests/WorkspaceVisualContractTests.swiftTests/AskKeyCoreTests/AuditBrokerBoundaryTests.swift |
| Screen-lock approval privacy | Load request details only in the current unlocked console session and use a generic private reminder otherwise, recording delivery only after success. | Keep | Sources/AskKeyApp/AgentApprovalScreenSession.swiftSources/AskKeyApp/AskKeyApp.swift |
Tests/AskKeyAppTests/AgentApprovalScreenSessionTests.swiftTests/AskKeyAppTests/AgentClientConnectorTests.swiftTests/AskKeyAppTests/Batch4SettingsLanguageTests.swift |
| Pause and authenticated resume | Pause Agent access from the menu while management is locked, persist the pause, cancel requests/allowances and deliveries, and authenticate resume without opening management. | Keep | Sources/AskKeyCore/Vault+TextCredentials.swiftSources/AskKeyApp/VaultViewModel+Credentials.swiftSources/AskKeyApp/AskKeyApp.swiftSources/AskKeyApp/Views/VaultPopover.swift |
Tests/AskKeyCoreTests/AgentAccessTests.swiftTests/AskKeyAppTests/AgentAccessMenuSessionTests.swiftTests/AskKeyBrokerTests/ApprovalStateMachineTests.swift |
| Mutation and final-spawn revocation | Recheck original authorization and credential/file deadlines at the synchronized spawn boundary; mutation, hidden state, expiry and revoke prevent unstarted delivery. | Keep | Sources/AskKeyCore/Vault+TextCredentials.swiftSources/AskKeyCore/FileDeliveryManager.swiftSources/AskKeyBroker/ApprovalStateMachine.swiftSources/AskKeyBroker/TextRuntime.swift |
Tests/AskKeyCoreTests/RuntimeApprovalBoundaryTests.swiftTests/AskKeyCoreTests/AgentAccessTests.swiftTests/AskKeyCoreTests/AuditBrokerBoundaryTests.swift |
| Versioned and bounded socket protocol | Expose only the limited Agent RPC over a local length-prefixed socket; cap frames, fields, connections, work and deadlines and reject broad legacy management messages. | Keep | Sources/AskKeyBroker/BrokerProtocol.swiftSources/AskKeyBroker/BrokerSocket.swiftSources/AskKeyBroker/BrokerRuntimeDirectory.swift |
Tests/AskKeyBrokerTests/BrokerProtocolTests.swiftTests/AskKeyCoreTests/BrokerCatalogTests.swiftTests/AskKeyCoreTests/ReviewCatalogLimitTests.swift |
| Caller declaration | Carry sanitized caller name and purpose into frozen requests and encrypted records as untrusted display context, never as an Agent authorization boundary. | Keep | Sources/AskKeyBroker/TextRuntime.swiftSources/AskKeyBroker/ApprovalStateMachine.swiftSources/AskKeyCore/Models/VNextCredential.swiftSources/AskKeyCore/Vault+TextCredentials.swiftSources/AskKeyHelper/main.swift |
Tests/AskKeyBrokerTests/BrokerTextRunDeclarationTests.swiftTests/AskKeyCoreTests/ReadDeclarationAndAuditTests.swift |
| Broker startup recovery | Expose a persistent actionable retry when secure staging fails, without starting duplicate Brokers or discarding unrelated errors; remove restore-settings compensation separately. | Keep | Sources/AskKeyApp/BrokerRuntimeRecovery.swiftSources/AskKeyApp/AskKeyApp.swiftSources/AskKeyApp/VaultViewModel.swiftSources/AskKeyApp/Views/SettingsView.swiftSources/AskKeyApp/Views/VaultPopover.swiftSources/AskKeyBroker/BrokerRuntimeDirectory.swift |
Tests/AskKeyAppTests/BrokerRuntimeRecoveryTests.swiftTests/AskKeyAppTests/AutomaticICloudBackupLifecycleTests.swiftTests/AskKeyBrokerTests/FileWriteCoordinatorTests.swift |
| Feature | One-line description | Decision | Legacy source files | Legacy test files |
|---|---|---|---|---|
| Explicit text environment delivery | Launch a non-PTY target only with the selected smallest credential set and mappings, applying an inherited-environment whitelist and validating the whole set. | Keep | Sources/AskKeyBroker/TextRuntime.swiftSources/AskKeyBroker/CredentialComponents.swiftSources/AskKeyCore/Vault+TextCredentials.swift |
Tests/AskKeyBrokerTests/TextRuntimeTests.swiftTests/AskKeyCoreTests/HumanTextCredentialTests.swiftTests/AskKeyCoreTests/RuntimeApprovalBoundaryTests.swift |
| Short-lived file delivery | Deliver random 0600 files inside a private 0700 directory and revoke or sweep them on TTL, pause, mutation, lock, expiry, exit and restart. | Keep | Sources/AskKeyCore/FileDeliveryManager.swiftSources/AskKeyCore/Vault+TextCredentials.swift |
Tests/AskKeyCoreTests/FileRuntimeDeliveryTests.swiftTests/AskKeyCoreTests/RuntimeApprovalBoundaryTests.swiftTests/AskKeyCoreTests/ReviewCleanupLeaseTests.swiftTests/AskKeyCoreTests/FileBoundaryRepairTests.swift |
| Visible cleanup failures | Keep failed deletions visible and retry them while holding the owning lease; an old cleanup cannot delete a newly approved delivery. | Keep | Sources/AskKeyCore/FileDeliveryManager.swiftSources/AskKeyApp/VaultViewModel.swiftSources/AskKeyApp/VaultViewModel+Credentials.swift |
Tests/AskKeyAppTests/FileCleanupVisibilityTests.swiftTests/AskKeyCoreTests/ReviewCleanupLeaseTests.swiftTests/AskKeyCoreTests/RuntimeApprovalBoundaryTests.swiftTests/AskKeyCoreTests/FileBoundaryRepairTests.swift |
| Target streams, signals and cancellation | Pass CLI standard-stream descriptors directly to the target, return its exit code and terminate only the owned process group on signal, control or socket disconnect. | Keep | Sources/AskKeyBroker/BrokerSocket.swiftSources/AskKeyBroker/TextRuntime.swiftSources/AskKeyBrokerC/AskKeyBrokerC.cSources/AskKeyBrokerC/include/AskKeyBrokerC.hSources/AskKeyHelper/main.swift |
Tests/AskKeyBrokerTests/BrokerProtocolTests.swiftTests/AskKeyBrokerTests/TextRuntimeTests.swiftTests/AskKeyBrokerTests/HelperApprovalWaitTests.swiftTests/AskKeyE2ETests/AskKeyE2ETests.swift |
| Runtime receipts and unknown outcomes | Retain bounded per-runtime execution receipts, replay completed exit status without respawning or replaying output, and never automatically retry outcomeUnknown. | Keep | Sources/AskKeyBroker/RuntimeOperations.swiftSources/AskKeyBroker/TextRuntime.swiftSources/AskKeyBroker/BrokerSocket.swift |
Tests/AskKeyBrokerTests/RuntimeReceiptBoundsTests.swiftTests/AskKeyBrokerTests/TextRuntimeTests.swiftTests/AskKeyBrokerTests/BrokerProtocolTests.swiftTests/AskKeyBrokerTests/HelperMCPTests.swiftTests/AskKeyCoreTests/AuditBrokerBoundaryTests.swift |
| CLI run and approval wait | Provide explicit run selection, operation ID and caller declarations; optional --wait-for-approval resumes the identical in-memory request once all tickets approve. | Keep | Sources/AskKeyHelper/main.swiftSources/AskKeyHelper/CLIApprovalWait.swiftSources/AskKeyHelper/AgentUsageGuide.swift |
Tests/AskKeyBrokerTests/HelperApprovalWaitTests.swiftTests/AskKeyBrokerTests/HelperCommandContractTests.swift |
| MCP stdio and Agent guidance | Expose metadata discovery, run, write, upload and status/cancel tools with bounded JSON-RPC; MCP run discards target output and returns only execution/approval status. | Keep | Sources/AskKeyHelper/main.swiftSources/AskKeyHelper/AgentUsageGuide.swiftSources/AskKeyBroker/BrokerProtocol.swift |
Tests/AskKeyBrokerTests/HelperMCPTests.swiftTests/AskKeyCoreTests/ReviewMCPHelperContractTests.swiftTests/AskKeyCoreTests/CredentialAccessRecordTests.swift |
| Health, version, status and open | Forward health and version (CLI status aliases version) and open the verified host App; reject removed direct-management helper commands. | Keep | Sources/AskKeyHelper/main.swiftSources/AskKeyBroker/HelperHostApplication.swiftSources/AskKeyBroker/BrokerProtocol.swift |
Tests/AskKeyBrokerTests/HelperCommandContractTests.swiftTests/AskKeyBrokerTests/HelperHostApplicationTests.swiftTests/AskKeyBrokerTests/BrokerProtocolTests.swift |
| Discovery command hooks | Provide hook capabilities, hook cursor and hook grok; track catalog completion with bounded expiring hashed turn state and release stalled discovery reminders. | Keep | Sources/AskKeyHelper/main.swiftSources/AskKeyHelper/CommandDiscoveryHook.swiftSources/AskKeyHelper/CredentialDiscoveryGuard.swiftSources/AskKeyHelper/DiscoveryTurnStore.swift |
Tests/AskKeyBrokerTests/CommandDiscoveryHookTests.swiftTests/AskKeyBrokerTests/HelperMCPTests.swift |
| Official helper topology and trust | Keep the official bundled-helper topology, host/resource-seal and Developer ID checks; moved, renamed or mismatched release bundles fail closed. | Keep | Sources/AskKeyBroker/OfficialInstallTopology.swiftSources/AskKeyBroker/HelperHostApplication.swiftSources/AskKeyCore/CodexUserMCPAdapter.swiftSources/AskKeyApp/AgentClientConnector.swift |
Tests/AskKeyCoreTests/OfficialInstallTopologyTests.swiftTests/AskKeyCoreTests/HelperCodeSignatureTrustTests.swiftTests/AskKeyBrokerTests/HelperHostApplicationTests.swift |
| Isolated development runtime | Validate an explicitly selected private development directory and separate storage, preferences, socket and key material from production. | Keep | Sources/AskKeyBroker/DebugRunDirectory.swiftSources/AskKeyBroker/BrokerProtocol.swiftSources/AskKeyCore/VaultConfiguration.swiftSources/AskKeyCore/Keychain/IsolatedAppKeyStore.swiftSources/AskKeyApp/AppPreferences.swiftSources/AskKeyApp/Views/DevBadge.swift |
Tests/AskKeyBrokerTests/DebugRunDirectoryTests.swiftTests/AskKeyCoreTests/OfficialInstallTopologyTests.swiftTests/AskKeyAppTests/ReviewCredentialIsolationTests.swift |
| Feature | One-line description | Decision | Legacy source files | Legacy test files |
|---|---|---|---|---|
| Agent text and component create/modify | Freeze caller-known components and optional instructions/group, permit metadata-only modification, show full before/after metadata and new groups, and bind everything to approval plus separate system authentication regardless of Allow or timed allowances. Preserve omitted fields and permissions; text-only tools are unchanged. | Keep | Sources/AskKeyVault/Vault+AgentWriteFreeze.swiftSources/AskKeyVault/Vault+AgentWriteCommit.swiftSources/AskKeyBroker/CredentialComponents.swiftSources/AskKeyHelper/MCPTools.swiftSources/AskKeyAppKit/App/FrozenWriteApprovalContent.swift |
Tests/AskKeyVaultTests/AgentCredentialMetadataWriteTests.swiftTests/AskKeyBrokerTests/HelperMCPMetadataTests.swiftTests/AskKeyAppTests/ApprovalMetadataContentTests.swift |
| Agent file upload and frozen approval | Accept bounded ordered byte chunks rather than mutable paths, encrypt staging, bind frozen filename/digest and require authenticated reveal and approval before commit. | Keep | Sources/AskKeyBroker/FileWriteCoordinator.swiftSources/AskKeyBroker/BrokerProtocol.swiftSources/AskKeyBroker/BrokerRuntimeDirectory.swiftSources/AskKeyCore/Vault+TextCredentials.swiftSources/AskKeyHelper/main.swift |
Tests/AskKeyBrokerTests/FileWriteCoordinatorTests.swiftTests/AskKeyCoreTests/FileWriteCoordinatorTests.swift |
| Agent delete | Require a separate authenticated frozen operation to recycle any visible text, file or bundle credential; permanent deletion and hidden credentials remain App-only. | Keep | Sources/AskKeyCore/AgentTextWriteGovernance.swiftSources/AskKeyHelper/main.swift |
Tests/AskKeyCoreTests/AgentTextWriteGovernanceTests.swiftTests/AskKeyCoreTests/AuditBrokerBoundaryTests.swift |
| Write transaction and replay | Commit CRUD and operation receipts in one database transaction, reject swapped payload/capability or changed targets, and handle restart, rollback and expired frozen capacity. | Keep | Sources/AskKeyCore/AgentTextWriteGovernance.swiftSources/AskKeyCore/Vault+TextCredentials.swiftSources/AskKeyCore/Storage/VaultStoreCredentialQueries.swiftSources/AskKeyCore/Storage/VaultRecords.swiftSources/AskKeyBroker/FileWriteCoordinator.swift |
Tests/AskKeyCoreTests/AgentTextWriteGovernanceTests.swiftTests/AskKeyCoreTests/FileWriteCoordinatorTests.swiftTests/AskKeyCoreTests/ReviewCredentialMutationTests.swiftTests/AskKeyBrokerTests/FileWriteCoordinatorTests.swift |
| Encrypted access records | Keep metadata-only access events encrypted, bounded to 256 entries and 90 days, with generic hidden guesses and a persisted visible write-failure indicator. | Keep | Sources/AskKeyCore/Models/CredentialAccessEvent.swiftSources/AskKeyCore/Vault+CredentialAccessRecords.swiftSources/AskKeyCore/Storage/VaultStoreCredentialAccessQueries.swift |
Tests/AskKeyCoreTests/CredentialAccessRecordTests.swiftTests/AskKeyCoreTests/ReadDeclarationAndAuditTests.swift |
| Access-record management | List records only within management and clear them after fresh authentication; omit them from Broker/helper responses. | Keep | Sources/AskKeyApp/Views/CredentialManagementView.swiftSources/AskKeyApp/VaultViewModel+Credentials.swiftSources/AskKeyApp/CredentialWorkspaceMutations.swiftSources/AskKeyCore/Vault+CredentialAccessRecords.swift |
Tests/AskKeyAppTests/AccessRecordManagementTests.swiftTests/AskKeyAppTests/ReviewCredentialIsolationTests.swiftTests/AskKeyCoreTests/CredentialAccessRecordTests.swiftTests/AskKeyCoreTests/AutomaticICloudBackupSchedulerTests.swift |
v0.1 has no backup. All nine legacy capabilities below are Remove, including their iCloud-only tests and diagnostic support. A redesigned backup or encrypted export may come later as a separate feature. This decision also removes recovery-key/onboarding steps, backup settings, mutation-triggered scheduling, launch-time restore compensation, backup hooks in local erase and the iCloud entitlement/capability requirement. The following additional rows map those cross-cutting portions explicitly.
| Feature | One-line description | Decision | Legacy source files | Legacy test files |
|---|---|---|---|---|
| Capability and independent recovery key | Use only the product iCloud container with valid signing/entitlements and high-entropy recovery material; report development or missing capability honestly. | Remove | Sources/AskKeyCore/ICloudBackupCapability.swiftSources/AskKeyCore/ICloudBackupSnapshot.swiftSources/AskKeyCore/ICloudBackup.swiftSources/AskKeyApp/ICloudAppLifecycleController.swift |
Tests/AskKeyCoreTests/AutomaticICloudBackupSchedulerTests.swiftTests/AskKeyCoreTests/ICloudBackupTests.swiftTests/AskKeyAppTests/AutomaticICloudBackupLifecycleTests.swiftTests/AskKeyAppTests/WorkspaceVisualContractTests.swift |
| Authenticated immutable backup generations | Encrypt complete snapshots before upload, verify manifest/blob/digest/AEAD and format/key identity, and recover verified current or previous generations. | Remove | Sources/AskKeyCore/ICloudBackup.swiftSources/AskKeyCore/ICloudBackupSnapshot.swiftSources/AskKeyCore/FileICloudBackupPendingUploadStore.swiftSources/AskKeyCore/Vault+ICloudBackup.swift |
Tests/AskKeyCoreTests/ICloudBackupTests.swiftTests/AskKeyCoreTests/ICloudBackupBoundaryTests.swiftTests/AskKeyCoreTests/AuditStorageBoundaryTests.swift |
| Snapshot contents | Preserve active and recycled text/file/component credentials, metadata, delivery mappings, empty groups and ordinary settings while excluding access records, clients, pause and auth preferences. | Remove | Sources/AskKeyCore/ICloudBackupSnapshot.swiftSources/AskKeyCore/Vault+ICloudBackup.swiftSources/AskKeyApp/AppPreferences.swift |
Tests/AskKeyCoreTests/ICloudBackupRecycleTests.swiftTests/AskKeyCoreTests/ICloudBackupBoundaryTests.swiftTests/AskKeyCoreTests/AutomaticICloudBackupSchedulerTests.swift |
| Automatic backup and launch compensation | Coalesce successful relevant changes, persist change/confirmed versions and pending upload, retry failure and keep one writer across pauses, restarts and lifecycle rebinding. | Remove | Sources/AskKeyCore/AutomaticICloudBackupScheduler.swiftSources/AskKeyCore/FileICloudBackupPendingUploadStore.swiftSources/AskKeyCore/Vault.swiftSources/AskKeyApp/ICloudAppLifecycleController.swift |
Tests/AskKeyCoreTests/AutomaticICloudBackupSchedulerTests.swiftTests/AskKeyCoreTests/ICloudBackupRecoveryTests.swiftTests/AskKeyAppTests/AutomaticICloudBackupLifecycleTests.swift |
| Immediate backup and recovery-key presentation | Let authenticated management enable or stop automatic backup, create a new namespace, show the recovery key before first upload and request an immediate backup. | Remove | Sources/AskKeyApp/ICloudAppLifecycleController.swiftSources/AskKeyApp/VaultViewModel+Credentials.swiftSources/AskKeyApp/Views/CredentialManagementView.swiftSources/AskKeyCore/ICloudBackupSnapshot.swift |
Tests/AskKeyAppTests/WorkspaceVisualContractTests.swiftTests/AskKeyAppTests/AutomaticICloudBackupLifecycleTests.swift |
| Conflict, fork and writer takeover | Pause automatic backup on conflict copies or writer/parent forks, permit verified full restore selection, and require explicit authenticated ownership takeover. | Remove | Sources/AskKeyCore/ICloudBackup.swiftSources/AskKeyCore/ICloudBackupSnapshot.swiftSources/AskKeyApp/ICloudAppLifecycleController.swiftSources/AskKeyApp/Views/ICloudBackupRecoveryView.swift |
Tests/AskKeyCoreTests/ICloudBackupTests.swiftTests/AskKeyCoreTests/ICloudBackupRecoveryTests.swiftTests/AskKeyAppTests/ReviewICloudRecoveryTests.swiftTests/AskKeyAppTests/LocalVaultLifecycleViewModelTests.swift |
| Full-library recovery | Inspect valid generations and restore with recovery key and system authentication by complete atomic replacement, preserving recycle state and resetting every permission to Ask. | Remove | Sources/AskKeyCore/Vault+ICloudBackup.swiftSources/AskKeyCore/ICloudBackupSnapshot.swiftSources/AskKeyApp/Views/ICloudBackupRecoveryView.swiftSources/AskKeyApp/VaultViewModel+Credentials.swift |
Tests/AskKeyCoreTests/ICloudBackupTests.swiftTests/AskKeyCoreTests/ICloudBackupRecycleTests.swiftTests/AskKeyCoreTests/ICloudBackupBoundaryTests.swiftTests/AskKeyAppTests/ReviewICloudRecoveryTests.swift |
| Safety snapshot and interrupted restore | Create an encrypted local safety snapshot before replacement and recover pending restored settings before opening Agent access, reenabling read authentication and preserving subsequent edits. | Remove | Sources/AskKeyCore/LocalICloudSafetySnapshotStore.swiftSources/AskKeyCore/Vault+ICloudBackup.swiftSources/AskKeyApp/ICloudAppLifecycleController.swiftSources/AskKeyApp/VaultViewModel.swift |
Tests/AskKeyCoreTests/ICloudBackupRecycleTests.swiftTests/AskKeyCoreTests/ICloudBackupBoundaryTests.swiftTests/AskKeyAppTests/ICloudRestoreAuthenticationTests.swiftTests/AskKeyAppTests/ICloudRestoreLaunchRecoveryTests.swift |
| Namespace retention and cloud deletion | Use a new key-ID namespace for new material, show retained old namespaces as historical, and confirm cloud deletion separately from local erase or stopping backup. | Remove | Sources/AskKeyCore/ICloudBackupSnapshot.swiftSources/AskKeyCore/ICloudBackup.swiftSources/AskKeyApp/ICloudAppLifecycleController.swiftSources/AskKeyApp/VaultViewModel+Credentials.swiftSources/AskKeyApp/Views/CredentialManagementView.swift |
Tests/AskKeyCoreTests/ICloudBackupTests.swiftTests/AskKeyAppTests/LocalVaultLifecycleViewModelTests.swiftTests/AskKeyAppTests/WorkspaceVisualContractTests.swift |
| First-run recovery-key and restore steps | Remove onboarding recovery-key entry and backup inspection/restore routes while keeping ordinary credential creation/import and login-item onboarding. | Remove | Sources/AskKeyApp/Views/FirstRunOnboardingView.swiftSources/AskKeyApp/Views/SettingsView.swiftSources/AskKeyApp/Views/ICloudBackupRecoveryView.swiftSources/AskKeyApp/VaultViewModel.swiftSources/AskKeyApp/VaultViewModel+Credentials.swift | Tests/AskKeyAppTests/ReviewICloudRecoveryTests.swiftTests/AskKeyAppTests/AppLanguageExperienceTests.swift |
| Backup settings, authentication and copy | Remove backup enable/immediate-backup/recovery-key/restore/takeover/delete controls, state, authentication reasons and localized copy; keep unrelated settings and authentication. | Remove | Sources/AskKeyApp/AppPreferences.swiftSources/AskKeyApp/VaultViewModel.swiftSources/AskKeyApp/VaultViewModel+Credentials.swiftSources/AskKeyApp/Views/CredentialManagementView.swiftSources/AskKeyApp/Views/SettingsView.swiftSources/AskKeyApp/ManagementAuthenticationProcess.swiftSources/AskKeyApp/AppLanguage.swiftSources/AskKeyApp/Resources/Localizable.xcstrings | Tests/AskKeyAppTests/WorkspaceVisualContractTests.swiftTests/AskKeyAppTests/ICloudRestoreAuthenticationTests.swiftTests/AskKeyAppTests/ReviewICloudRecoveryTests.swiftTests/AskKeyAppTests/ManagementAuthenticationProcessTests.swift |
| Mutation and preference backup scheduling hooks | Remove snapshot-relevant change callbacks, backup dirty/version accounting and ordinary-setting backup notifications; keep credential mutations, groups and local preferences. | Remove | Sources/AskKeyCore/Vault.swiftSources/AskKeyCore/Vault+TextCredentials.swiftSources/AskKeyCore/AgentTextWriteGovernance.swiftSources/AskKeyCore/Storage/VaultStoreConfigQueries.swiftSources/AskKeyCore/AutomaticICloudBackupScheduler.swiftSources/AskKeyApp/AppPreferences.swiftSources/AskKeyApp/ICloudAppLifecycleController.swift | Tests/AskKeyCoreTests/AutomaticICloudBackupSchedulerTests.swiftTests/AskKeyAppTests/AutomaticICloudBackupLifecycleTests.swift |
| Launch-time restore and backup compensation | Remove iCloud preparation, pending restore-settings replay, restored preference/permission resets and backup scheduling at launch; keep normal App/Broker startup and staging recovery. | Remove | Sources/AskKeyApp/AskKeyApp.swiftSources/AskKeyApp/ICloudAppLifecycleController.swiftSources/AskKeyApp/VaultViewModel.swiftSources/AskKeyApp/BrokerRuntimeRecovery.swiftSources/AskKeyCore/Vault+ICloudBackup.swiftSources/AskKeyCore/Vault+TextCredentials.swiftSources/AskKeyBroker/ApprovalStateMachine.swift | Tests/AskKeyAppTests/ICloudRestoreLaunchRecoveryTests.swiftTests/AskKeyAppTests/ICloudRestoreAuthenticationTests.swiftTests/AskKeyAppTests/AutomaticICloudBackupLifecycleTests.swiftTests/AskKeyBrokerTests/ApprovalStateMachineTests.swift |
| Local-erase iCloud hooks and material cleanup | Remove backup cancellation/global-stop and iCloud recovery-material cleanup from erase; retain local quiescing, delivery cleanup, journal recovery and local key/data deletion. | Remove | Sources/AskKeyCore/Vault+LocalLifecycle.swiftSources/AskKeyCore/LocalVaultLifecycle.swiftSources/AskKeyCore/VaultConfiguration.swiftSources/AskKeyCore/Vault.swiftSources/AskKeyApp/VaultViewModel+Credentials.swift | Tests/AskKeyCoreTests/LocalVaultLifecycleTests.swiftTests/AskKeyAppTests/LocalVaultLifecycleViewModelTests.swift |
| iCloud entitlement and capability requirement | Remove iCloud container/ubiquity entitlement requirements and backup signing/capability checks; the pinned entitlements template is already empty, so no enabled entitlement is claimed here. | Remove | AskKeyApp.entitlementsSources/AskKeyCore/ICloudBackupCapability.swiftSources/AskKeyCore/ICloudBackup.swiftSources/AskKeyCore/VaultConfiguration.swift | Tests/AskKeyCoreTests/AutomaticICloudBackupSchedulerTests.swiftTests/AskKeyAppTests/AutomaticICloudBackupLifecycleTests.swift |
The iCloud rows record only the removed portions of shared files and shared tests. Dedicated backup files/tests are removed, while assertions for independent Keep behavior remain or move with that behavior. These files must not be deleted wholesale because of an iCloud reference:
| Legacy mixed file | Responsibilities retained | iCloud portions removed |
|---|---|---|
Sources/AskKeyApp/AskKeyApp.swift |
App/menu-bar lifecycle, management windows, approval presentation and Broker startup. | iCloud lifecycle setup, automatic scheduling, restore compensation and backup proof state. |
Sources/AskKeyApp/VaultViewModel.swift |
Management authentication/session, localization, credential state, client onboarding and errors. | Backup state/closures/status, restored preferences and recovery actions. |
Sources/AskKeyApp/VaultViewModel+Credentials.swift |
Credential CRUD, reveal/copy, pause/resume, access records and local erase. | Backup/restore/namespace/takeover/cloud-delete actions. |
Sources/AskKeyApp/Views/FirstRunOnboardingView.swift |
First credential creation/import, completion and login-item choice. | Backup recovery entry and recovery-key steps. |
Sources/AskKeyApp/Views/SettingsView.swift |
Management unlock, navigation and ordinary workspace routes. | First-run/settings backup recovery routes. |
Sources/AskKeyApp/Views/CredentialManagementView.swift |
Credential library/editor, approval/records/trash and ordinary preferences. | Backup controls, recovery material, status and cloud-delete UI. |
Sources/AskKeyApp/AppPreferences.swift |
Local appearance, language, session, approval and hotkey preferences. | Backup-relevant setting notifications. |
Sources/AskKeyApp/ManagementAuthenticationProcess.swift |
System authentication for management, approval and local destructive operations. | Recovery, namespace and cloud-backup authentication actions. |
Sources/AskKeyCore/Vault.swift |
App-owned key, current bootstrap, management and local vault operations. | Snapshot-change callbacks and backup stop/resume coupling. |
Sources/AskKeyCore/Vault+TextCredentials.swift |
Credential CRUD, permission/expiry, runtime authorization and pause/resume. | Backup notifications, restore-pending gates and backup stop/resume callbacks. |
Sources/AskKeyCore/AgentTextWriteGovernance.swift |
Frozen Agent writes, authenticated commit and replay. | Snapshot-relevant change notifications after mutations. |
Sources/AskKeyCore/Vault+LocalLifecycle.swift |
Local erase quiescing, delivery cleanup, crash recovery and local key/data deletion. | Backup stop/global pause and iCloud recovery-material deletion. |
Sources/AskKeyCore/VaultConfiguration.swift |
Local development/production namespace and vault/Broker paths. | iCloud backup service, material and safety-snapshot configuration. |
Sources/AskKeyApp/BrokerRuntimeRecovery.swift |
Safe staging-failure feedback and explicit single-Broker retry. | Restore-settings-specific compensation/error case. |
Sources/AskKeyBroker/ApprovalStateMachine.swift |
Current approval, deadline, revoke and read-authentication preference behavior. | The backup-restore-only reset path; default read authentication stays enabled. |
Sources/AskKeyApp/AppLanguage.swift and Sources/AskKeyApp/Resources/Localizable.xcstrings |
Owned English/Simplified Chinese catalog and live language changes. | Backup/restore authentication-message keys and strings. |
Only Codex, Cursor and Grok CLI are supported. Legacy Multica assertions inside shared tests are mapped to the removal rows below; the remaining supported-client behavior stays Keep.
| Feature | One-line description | Decision | Legacy source files | Legacy test files |
|---|---|---|---|---|
| Explicit onboarding state machine | Check only on user action, retain per-client results, freeze an apply plan, authenticate writes, suppress stale callbacks and show actionable inline failure/completion. | Keep | Sources/AskKeyApp/AgentClientConnector.swiftSources/AskKeyApp/AgentOnboardingModels.swiftSources/AskKeyApp/AgentOnboardingCoordinator.swiftSources/AskKeyApp/AgentOnboardingRuntime.swiftSources/AskKeyApp/Views/AgentOnboardingView.swift |
Tests/AskKeyAppTests/AgentOnboardingCallBoundaryTests.swiftTests/AskKeyAppTests/AgentOnboardingCompletionTests.swiftTests/AskKeyAppTests/AgentOnboardingViewWiringTests.swiftTests/AskKeyAppTests/AgentClientConnectorTests.swift |
| Onboarding cancellation and termination | Cancel live read-only checks with their owned process groups, preserve in-flight writes after page exit and defer App termination until writes settle. | Keep | Sources/AskKeyApp/AgentOnboardingCoordinator.swiftSources/AskKeyApp/AgentOnboardingRuntime.swiftSources/AskKeyApp/OnboardingTerminationGate.swiftSources/AskKeyCore/RestrictedProcessCancellation.swift |
Tests/AskKeyAppTests/AgentOnboardingConnectorCancelTests.swiftTests/AskKeyAppTests/AgentOnboardingLiveCancelTests.swiftTests/AskKeyAppTests/AgentOnboardingReviewRepairTests.swiftTests/AskKeyAppTests/AgentOnboardingEvidenceCloseTests.swift |
| Onboarding interaction and appearance | Use ordinary localized UI with explicit explanation/check/confirmation actions and Space/Return activation; entry and expansion do not probe clients or authenticate. | Keep | Sources/AskKeyApp/Views/AgentOnboardingView.swiftSources/AskKeyApp/AgentOnboardingCoordinator.swift |
Tests/AskKeyAppTests/AgentOnboardingIsolationUITests.swiftTests/AskKeyAppTests/AgentOnboardingKeyboardActivationTests.swiftTests/AskKeyAppTests/AgentOnboardingViewWiringTests.swiftTests/AskKeyAppTests/AgentOnboardingCallBoundaryTests.swift |
| Safe client-config transactions | Validate format, ownership and regular-file boundaries, preserve other settings and permissions, use private backups and atomic writes, and reject concurrent changes or unsafe rollback. | Keep | Sources/AskKeyCore/ClientConfigFileIO.swiftSources/AskKeyCore/CodexUserMCPAdapter.swiftSources/AskKeyCore/CursorUserMCPAdapter.swiftSources/AskKeyCore/GrokCLIAdapter.swift |
Tests/AskKeyCoreTests/ClientConfigFileIOTests.swiftTests/AskKeyCoreTests/CodexUserMCPAdapterTests.swiftTests/AskKeyCoreTests/CursorUserMCPAdapterTests.swiftTests/AskKeyCoreTests/GrokCLIAdapterTests.swiftTests/AskKeyAppTests/AgentClientConnectorTests.swift |
| MCP connection verification | Verify config readback, trusted bundled helper, compatible initialize identity/tool list and Broker health before calling a supported client connected. | Keep | Sources/AskKeyCore/MCPHelperContract.swiftSources/AskKeyCore/CodexUserMCPAdapter.swiftSources/AskKeyCore/CursorUserMCPAdapter.swiftSources/AskKeyCore/GrokCLIAdapter.swiftSources/AskKeyApp/AgentClientConnector.swift |
Tests/AskKeyCoreTests/ReviewMCPHelperContractTests.swiftTests/AskKeyCoreTests/AuditProcessBoundaryTests.swiftTests/AskKeyAppTests/AgentClientConnectorTests.swift |
| Codex user MCP configuration | Connect the user-level MCP using the native authority and lossless TOML transaction, with backups, supported capability/version checks and failure rollback. | Keep | Sources/AskKeyCore/CodexUserMCPAdapter.swiftSources/AskKeyApp/AgentClientConnector.swiftSources/AskKeyApp/AgentOnboardingRuntime.swift |
Tests/AskKeyCoreTests/CodexUserMCPAdapterTests.swiftTests/AskKeyAppTests/CodexOnboardingSetupTests.swiftTests/AskKeyAppTests/AgentClientConnectorTests.swift |
| Codex native discovery hook and trust | Install the reviewed PreToolUse rule, enable only its native app-server trust entry and read back hooks/list; keep verified MCP if later discovery setup is incomplete. | Keep | Sources/AskKeyCore/CodexDiscoveryHookConfiguration.swiftSources/AskKeyCore/CodexNativeHookClient.swiftSources/AskKeyApp/CodexOnboardingSetup.swiftSources/AskKeyHelper/CredentialDiscoveryGuard.swift |
Tests/AskKeyCoreTests/CodexDiscoveryHookConfigurationTests.swiftTests/AskKeyCoreTests/CodexNativeHookClientTests.swiftTests/AskKeyAppTests/CodexOnboardingSetupTests.swift |
| Cursor MCP and command hooks | Merge the user MCP and pre/post/failure discovery hooks without replacing other entries; distinguish configured discovery from verified MCP and require a new task. | Keep | Sources/AskKeyCore/CursorUserMCPAdapter.swiftSources/AskKeyCore/CommandDiscoveryHookConfiguration.swiftSources/AskKeyCore/CommandDiscoveryIntegration.swiftSources/AskKeyApp/CommandHookOnboardingSetup.swift |
Tests/AskKeyCoreTests/CursorUserMCPAdapterTests.swiftTests/AskKeyCoreTests/CommandDiscoveryHookConfigurationTests.swiftTests/AskKeyAppTests/CommandHookOnboardingSetupTests.swiftTests/AskKeyAppTests/AgentOnboardingCompletionTests.swift |
| Grok CLI MCP and command hooks | Preserve user TOML, verify list/doctor/helper/Broker and install a dedicated native discovery-hook file, rejecting unknown owned-file content. | Keep | Sources/AskKeyCore/GrokCLIAdapter.swiftSources/AskKeyCore/CommandDiscoveryHookConfiguration.swiftSources/AskKeyCore/CommandDiscoveryIntegration.swiftSources/AskKeyApp/CommandHookOnboardingSetup.swift |
Tests/AskKeyCoreTests/GrokCLIAdapterTests.swiftTests/AskKeyCoreTests/CommandDiscoveryHookConfigurationTests.swiftTests/AskKeyAppTests/CommandHookOnboardingSetupTests.swiftTests/AskKeyAppTests/AgentOnboardingCompletionTests.swift |
| Discovery reminder boundaries | Prompt catalog lookup before common direct SSH commands, bind completion to its turn, expire hashed state and stop stalled reminders; discovery is not credential authorization. | Keep | Sources/AskKeyHelper/CredentialDiscoveryGuard.swiftSources/AskKeyHelper/CommandDiscoveryHook.swiftSources/AskKeyHelper/DiscoveryTurnStore.swiftSources/AskKeyHelper/AgentUsageGuide.swift |
Tests/AskKeyBrokerTests/CommandDiscoveryHookTests.swiftTests/AskKeyBrokerTests/HelperMCPTests.swiftTests/Automation/test_hook_probes.py |
| Bounded client subprocesses | Bound command output, pipe reads and deadlines and stop only owned descendants; preserve cancellation context across detached work. | Keep | Sources/AskKeyCore/RestrictedProcess.swiftSources/AskKeyCore/RestrictedProcessCancellation.swiftSources/AskKeyCore/CodexNativeHookClient.swiftSources/AskKeyCore/MCPHelperContract.swiftSources/AskKeyBrokerC/AskKeyBrokerC.c |
Tests/AskKeyCoreTests/RestrictedProcessTests.swiftTests/AskKeyCoreTests/AuditProcessBoundaryTests.swiftTests/AskKeyCoreTests/CodexNativeHookClientTests.swiftTests/AskKeyAppTests/AgentOnboardingLiveCancelTests.swiftTests/RuntimeProbes/RestrictedProcessCancellationProbe.swiftlegacy regression notes under Tests/RuntimeProbes Tests/Automation/test_hook_probes.py |
| Feature | One-line description | Decision | Legacy source files | Legacy test files |
|---|---|---|---|---|
| Management window and resident menu bar | Keep the native close controls, locked workbench, status popover, approval access and Dock transitions tied to the actual management window. | Keep | Sources/AskKeyApp/AskKeyApp.swiftSources/AskKeyApp/ManagementDockPolicy.swiftSources/AskKeyApp/Views/VaultPopover.swiftSources/AskKeyApp/Views/SettingsView.swiftSources/AskKeyApp/WorkspaceVisualContract.swift |
Tests/AskKeyAppTests/ManagementDockPolicyTests.swiftTests/AskKeyAppTests/ManagementWorkspaceNavigationTests.swiftTests/AskKeyAppTests/AuditApplicationContractTests.swiftTests/AskKeyAppTests/WorkspaceVisualContractTests.swift |
| Menu artwork and development badge | Load bundled template menu-bar artwork and display development isolation status without exposing credential content. | Keep | Sources/AskKeyApp/Views/MenuBarIcon.swiftSources/AskKeyApp/Resources/MenuBarIcon.pngSources/AskKeyApp/Views/DevBadge.swift |
Tests/AskKeyAppTests/AppLanguageExperienceTests.swiftTests/AskKeyAppTests/AgentOnboardingIsolationUITests.swift |
| Global hotkey | Register the selected management shortcut, support turning it off and reflect preference changes immediately. | Keep | Sources/AskKeyApp/GlobalHotkeyManager.swiftSources/AskKeyApp/AppPreferences.swiftSources/AskKeyApp/AskKeyApp.swiftSources/AskKeyApp/Views/CredentialManagementView.swift |
Tests/AskKeyAppTests/Batch4SettingsLanguageTests.swiftTests/AskKeyAppTests/WorkspaceVisualContractTests.swift |
| Launch at login | Apply the SMAppService choice immediately, warn before disabling and keep login launch menu-bar resident until management is opened. | Keep | Sources/AskKeyApp/LoginItemController.swiftSources/AskKeyApp/Views/FirstRunOnboardingView.swiftSources/AskKeyApp/AppPreferences.swiftSources/AskKeyApp/AskKeyApp.swift |
Tests/AskKeyAppTests/AppLanguageExperienceTests.swiftTests/AskKeyAppTests/ManagementDockPolicyTests.swiftTests/AskKeyAppTests/WorkspaceVisualContractTests.swift |
| Appearance and ordinary preferences | Persist local system/light/dark appearance, language, timed-allowance settings, session configuration and onboarding state; remove backup settings and scheduling notifications separately. | Keep | Sources/AskKeyApp/AppPreferences.swiftSources/AskKeyApp/Views/SettingsSupport.swiftSources/AskKeyApp/Views/CredentialManagementView.swift |
Tests/AskKeyAppTests/WorkspaceVisualContractTests.swiftTests/AskKeyAppTests/Batch4SettingsLanguageTests.swiftTests/AskKeyCoreTests/AutomaticICloudBackupSchedulerTests.swift |
| English and Simplified Chinese | Use one owned string catalog for UI, errors, notifications and authentication; follow the system or change language live, preserving untranslated technical identifiers. | Keep | Sources/AskKeyApp/AppLanguage.swiftSources/AskKeyApp/UserFacingCopy.swiftSources/AskKeyApp/Views/SettingsSupport.swiftSources/AskKeyApp/Resources/Localizable.xcstringsSources/AskKeyApp/Resources/en.lproj/InfoPlist.stringsSources/AskKeyApp/Resources/zh-Hans.lproj/InfoPlist.strings |
Tests/AskKeyAppTests/AppLanguageExperienceTests.swiftTests/AskKeyAppTests/LocalizationRemediationTests.swiftTests/AskKeyAppTests/LocalizationUnificationTests.swiftTests/AskKeyAppTests/ReviewLocalizationTests.swiftTests/AskKeyAppTests/Batch4SettingsLanguageTests.swift |
| Product copy consistency | Keep supported-client, macOS-only and delivery statements aligned with behavior; reflect the confirmed Multica, updater and backup removals. | Keep | Sources/AskKeyApp/UserFacingCopy.swiftSources/AskKeyApp/WorkspaceVisualContract.swiftSources/AskKeyHelper/AgentUsageGuide.swift |
Tests/AskKeyAppTests/ProductFactAlignmentTests.swiftTests/AskKeyAppTests/AppLanguageExperienceTests.swiftTests/AskKeyBrokerTests/HelperMCPTests.swift |
These decisions come from issue #5, the current repository rules and the maintainer confirmation on PR #10 and override the older legacy README, ADRs and client matrix. They record decisions only; this inventory does not delete code or tests. Shared files and tests retain their Keep responsibilities elsewhere in this document.
| Feature | One-line description | Decision | Legacy source files | Legacy test files |
|---|---|---|---|---|
| Multica integration: adapter and diagnostics | Remove all workspace configuration/status/create/assignment/recovery, executable discovery, network retry, Multica diagnostic logs and onboarding branches. | Remove | Sources/AskKeyApp/MulticaWorkspaceMCPAdapter.swiftSources/AskKeyApp/MulticaProcessDiagnosticLog.swiftSources/AskKeyApp/AgentClientConnector.swiftSources/AskKeyApp/AgentOnboardingModels.swiftSources/AskKeyApp/AgentOnboardingRuntime.swiftSources/AskKeyApp/AgentOnboardingCoordinator.swiftSources/AskKeyApp/Views/AgentOnboardingView.swift |
Tests/AskKeyAppTests/MulticaConnectionFailureTests.swiftTests/AskKeyAppTests/MulticaExecutableDiscoveryTests.swiftTests/AskKeyAppTests/MulticaNetworkRecoveryTests.swiftTests/AskKeyAppTests/MulticaProcessDiagnosticLogTests.swiftTests/AskKeyAppTests/AgentOnboardingFlowTests.swiftTests/AskKeyAppTests/AgentOnboardingReviewRepairTests.swiftTests/AskKeyAppTests/AgentOnboardingEvidenceCloseTests.swiftTests/AskKeyAppTests/AgentClientConnectorTests.swiftTests/AskKeyAppTests/AgentOnboardingCompletionTests.swiftTests/AskKeyAppTests/AgentOnboardingConnectorCancelTests.swiftTests/AskKeyAppTests/AgentOnboardingLiveCancelTests.swiftTests/AskKeyAppTests/ProductFactAlignmentTests.swiftTests/AskKeyE2ETests/AskKeyE2ETests.swift |
| Multica helper configuration and runtime tests | Remove Multica server serialization, Multica-specific helper/runtime reconnect assertions, isolated stub scenarios and restart proofs; keep generic MCP reconnect behavior. | Remove | Sources/AskKeyBroker/MulticaServerConfiguration.swiftSources/AskKeyApp/AgentOnboardingRestartProof.swiftSources/AskKeyApp/E2EAppRuntime.swiftSources/AskKeyApp/AgentOnboardingDebugSupport.swiftSources/AskKeyHelper/main.swift |
Tests/AskKeyBrokerTests/MulticaServerConfigurationTests.swiftTests/AskKeyBrokerTests/HelperMCPTests.swiftTests/AskKeyAppTests/MulticaConfigurationSerializationTests.swiftTests/AskKeyE2ETests/AskKeyE2ETests.swift |
| Sparkle and in-app update checks | Remove SoftwareUpdater, Sparkle integration and manual update settings/copy until separately authorized release work. | Remove | Sources/AskKeyApp/SoftwareUpdater.swiftSources/AskKeyApp/AskKeyApp.swiftSources/AskKeyApp/Views/CredentialManagementView.swift |
Tests/AskKeyAppTests/ManualUpdatePolicyTests.swiftTests/AskKeyAppTests/ProductFactAlignmentTests.swift |
| Lokalite database migration and review | Remove legacy preview, conflict/permission review, source fingerprint and two-phase re-encryption/commit/recovery paths and their legacy fixture; retain current-library bootstrap/key ownership. | Remove | Sources/AskKeyCore/Migration/MigrationPlanner.swiftSources/AskKeyCore/Migration/MigrationSourceFingerprint.swiftSources/AskKeyCore/Keychain/AppKeyStore.swiftSources/AskKeyCore/Migration/VaultBootstrap.swiftSources/AskKeyCore/Models/VNextCredential.swiftSources/AskKeyCore/Vault.swiftSources/AskKeyApp/Views/MigrationReviewView.swiftSources/AskKeyApp/VaultViewModel.swift |
Tests/AskKeyCoreTests/VaultBootstrapTests.swiftTests/AskKeyCoreTests/CurrentLibraryAdoptionTests.swiftTests/AskKeyCoreTests/Fixtures/README.mdTests/AskKeyCoreTests/Fixtures/legacy-v7-vault.dbTests/AskKeyAppTests/AppLanguageExperienceTests.swift |
| Legacy daemon and direct-read cluster | Remove RemoteVaultService, VaultService, VaultSocket, VaultWireProtocol, SecretWorkspace and SecretReference, including broad administration/direct plaintext transport. | Remove | Sources/AskKeyCore/RemoteVaultService.swiftSources/AskKeyCore/VaultService.swiftSources/AskKeyCore/VaultSocket.swiftSources/AskKeyCore/VaultWireProtocol.swiftSources/AskKeyCore/SecretWorkspace.swiftSources/AskKeyCore/SecretReference.swift |
Tests/AskKeyCoreTests/VaultSocketTests.swiftTests/AskKeyCoreTests/VaultWireTests.swiftTests/AskKeyCoreTests/SecretReferenceTests.swiftTests/AskKeyCoreTests/DaemonUnlockTests.swiftTests/AskKeyCoreTests/VaultWriteValidationTests.swiftTests/AskKeyBrokerTests/HelperCommandContractTests.swift |
| LocalVaultLifecycle implementation | Remove the explicitly named LocalVaultLifecycle file from the legacy cluster; its currently reachable local-erase behavior is separately Keep and must survive replacement. | Remove | Sources/AskKeyCore/LocalVaultLifecycle.swiftSources/AskKeyCore/Vault+LocalLifecycle.swift |
Tests/AskKeyCoreTests/LocalVaultLifecycleTests.swiftTests/AskKeyAppTests/LocalVaultLifecycleViewModelTests.swift |
| Legacy Project / Environment / Secret models | Remove Project, VaultEnvironment (the Environment file), Secret, SecretCategory and SecretInfo, and their legacy-domain consumers; do not reinstate folder association. | Remove | Sources/AskKeyCore/Models/Project.swiftSources/AskKeyCore/Models/Environment.swiftSources/AskKeyCore/Models/Secret.swiftSources/AskKeyCore/Models/SecretCategory.swiftSources/AskKeyCore/Models/SecretInfo.swiftSources/AskKeyCore/Vault.swiftSources/AskKeyCore/Storage/VaultRecords.swiftSources/AskKeyCore/Storage/VaultStoreMigrations.swift |
Tests/AskKeyCoreTests/AskKeyCoreTests.swiftTests/AskKeyCoreTests/VaultWriteValidationTests.swiftTests/AskKeyCoreTests/CurrentLibraryAdoptionTests.swift |
The maintainer approved all four former candidates in PR #10. Remove their code and obsolete tests in the later scoped implementation issues; shared current credential, crypto and schema responsibilities remain Keep. Remove the argon2 product/package dependency from Package.swift and its phc-winner-argon2 resolution in Package.resolved together with the Argon2id export KDF.
| Feature | One-line description | Decision | Legacy source files | Legacy test files |
|---|---|---|---|---|
| Legacy AgentAccessPolicy | Only the removed Secret/Vault daemon paths, schema defaults and legacy migration interpret allowed/blocked/requiresApproval/strict; modern CredentialPermission remains Keep. | Remove | Sources/AskKeyCore/Models/AgentAccessPolicy.swiftSources/AskKeyCore/Vault.swiftSources/AskKeyCore/Storage/VaultRecords.swiftSources/AskKeyCore/Storage/VaultStoreMigrations.swiftSources/AskKeyCore/Migration/MigrationPlanner.swift |
Tests/AskKeyCoreTests/AskKeyCoreTests.swiftTests/AskKeyCoreTests/DaemonUnlockTests.swiftTests/AskKeyCoreTests/CurrentLibraryAdoptionTests.swift |
| Legacy caller detection and peer attribution | AgentDetection and PeerCodeSignature are consumed by the old Vault socket/wire and log paths; modern caller declarations and helper signature trust remain separate Keep behavior. | Remove | Sources/AskKeyCore/AgentDetection.swiftSources/AskKeyCore/PeerCodeSignature.swiftSources/AskKeyCore/VaultSocket.swiftSources/AskKeyCore/VaultWireProtocol.swift |
Tests/AskKeyCoreTests/AgentDetectionTests.swiftTests/AskKeyCoreTests/PeerCodeSignatureTests.swift |
| Legacy activity model and storage | Remove ActivityLogEntry/ActivityFilter and project/environment/secret/activity query code; retain current credential/access queries. Migration askkey-0002-drop-legacy-tables drops the old tables when they hold nothing beyond the legacy Default seed and keeps them otherwise. |
Remove | Sources/AskKeyCore/Models/ActivityLogEntry.swiftSources/AskKeyCore/Storage/VaultStoreActivityQueries.swiftSources/AskKeyCore/Storage/VaultStoreProjectQueries.swiftSources/AskKeyCore/Storage/VaultStoreEnvironmentQueries.swiftSources/AskKeyCore/Storage/VaultStoreSecretQueries.swift |
Tests/AskKeyCoreTests/AskKeyCoreTests.swiftTests/AskKeyCoreTests/VaultWriteValidationTests.swiftTests/AskKeyCoreTests/VaultWireTests.swiftTests/AskKeyCoreTests/PeerCodeSignatureTests.swift |
| Legacy project export and passphrase KDF | Remove legacy project export/import and Argon2id export-key derivation with the argon2 package dependency; retain current credential authenticated encryption. | Remove | Sources/AskKeyCore/Vault.swiftSources/AskKeyCore/Crypto/VaultCrypto.swiftSources/AskKeyCore/VaultService.swiftSources/AskKeyCore/VaultWireProtocol.swift |
Tests/AskKeyCoreTests/AskKeyCoreTests.swiftTests/AskKeyCoreTests/VaultWireTests.swift |
Keep the regression capability for retained features, but relocate test-only files, probes and embedded hooks out of production Sources in Phase 5. This is a location plan, not permission to expose test authentication in ordinary builds. Multica-only and iCloud-only support follow their fixed Remove decisions.
| Feature | One-line description | Decision | Legacy source files | Legacy test files |
|---|---|---|---|---|
| Onboarding debug UI driver | DEBUG-only press registry, stub operations, boundary recorder, simulated input/contrast probes and evidence capture; relocate the retained-client test support. | Keep | Sources/AskKeyApp/AgentOnboardingDebugSupport.swift |
Tests/AskKeyAppTests/AgentOnboardingBoundaryEvidenceTests.swiftTests/AskKeyAppTests/AgentOnboardingIsolationUITests.swiftTests/AskKeyAppTests/AgentOnboardingKeyboardActivationTests.swift |
| Onboarding real-input diagnostic helpers | DEBUG-only AppKit/accessibility keyboard and mouse input plus focus snapshots exist for real-window test evidence, not product credential management. | Keep | Sources/AskKeyApp/AgentOnboardingRealUIInput.swift |
Tests/AskKeyAppTests/AgentOnboardingKeyboardActivationTests.swiftTests/AskKeyAppTests/AgentOnboardingIsolationUITests.swift |
| Multica restart-proof driver | DEBUG-only restart journal export and injected cancelled operations are specific to removed Multica recovery; remove with that integration. | Remove | Sources/AskKeyApp/AgentOnboardingRestartProof.swift |
Tests/AskKeyAppTests/AgentOnboardingEvidenceCloseTests.swiftTests/AskKeyAppTests/AgentOnboardingReviewRepairTests.swift |
| Dedicated E2E App and Broker drivers | DEBUG plus ASKKEY_E2E_TESTING gates isolated runtime/control paths, fixture App creation, helper request evidence and approval/cancel/disconnect scenarios. | Keep | Sources/AskKeyApp/E2EAppRuntime.swiftSources/AskKeyApp/E2EBrokerScenario.swift |
Tests/AskKeyE2ETests/E2EBaseCase.swiftTests/AskKeyE2ETests/AskKeyE2ETests.swiftTests/AskKeyE2ETests/CredentialE2ETests.swiftTests/AskKeyE2ETests/E2ERequestEvidenceReader.swift |
| E2E core fixtures | DEBUG plus ASKKEY_E2E_TESTING gates synthetic persistent-vault creation and an owned slow process used to verify cancellation. | Keep | Sources/AskKeyCore/E2EVaultFixture.swiftSources/AskKeyCore/E2EProcessFixture.swift |
Tests/AskKeyE2ETests/E2EBaseCase.swiftTests/AskKeyE2ETests/AskKeyE2ETests.swiftTests/AskKeyE2ETests/CredentialE2ETests.swift |
The following files have production responsibilities and are not test-only files. Phase 5 should extract the named support while preserving the Keep behavior in the feature rows:
| Legacy source file | Embedded support to isolate |
|---|---|
Sources/AskKeyApp/AskKeyApp.swift |
E2E startup dispatch, synthetic visual-proof view model, scripted clicks/keys and evidence capture. |
Sources/AskKeyApp/AgentClientConnector.swift |
DebugClientE2ERequest, DebugClientE2ERunner, isolated client homes/stubs and E2E result reporting; remove the Multica-only variants. |
Sources/AskKeyApp/ManagementAuthenticationProcess.swift |
Explicit DebugAuthentication substitution gated by DEBUG, an opt-in environment value and a valid isolated run directory; keep the real authentication subprocess. |
Sources/AskKeyApp/VaultViewModel.swift |
DEBUG proof fixtures, prototype state and injected proof actions. |
Sources/AskKeyApp/VaultViewModel+Credentials.swift |
DEBUG proof mutations/overrides used by the isolated visual driver. |
Sources/AskKeyApp/Views/CredentialManagementView.swift |
DEBUG visual-proof fixtures, registry wiring and extra proof shortcuts. |
Sources/AskKeyApp/Views/AgentOnboardingView.swift |
DEBUG press-registry and proof accessibility wiring. |
Sources/AskKeyApp/Views/SettingsView.swift |
DEBUG sidebar press registry. |
Sources/AskKeyApp/Views/FirstRunOnboardingView.swift |
Environment-selected visual-proof state. |
Sources/AskKeyCore/RestrictedProcess.swift |
DEBUG OnboardingBoundaryObserver, counters and isolated positive-control probes. |
Sources/AskKeyCore/ClientConfigFileIO.swift |
DEBUG configuration-write boundary observer callback. |
Sources/AskKeyCore/CursorUserMCPAdapter.swift |
DEBUG cursor-helper boundary observation and isolated probe environment. |
Sources/AskKeyCore/Keychain/KeychainStore.swift |
DEBUG boundary observer callbacks; keep forbidden-UI keychain query protections. |
Sources/AskKeyCore/ICloudBackup.swift |
DEBUG exclusiveWriteProbe callbacks at partial-write and pre-publication boundaries; remove with the iCloud backup implementation. |
Sources/AskKeyCore/Models/CredentialName.swift |
DEBUG visual-proof authentication substitute. |
Sources/AskKeyCore/Storage/VaultStoreCredentialAccessQueries.swift |
failCredentialAccessRecordWritesForTesting fault injection. |
Sources/AskKeyCore/Storage/VaultStoreSecretQueries.swift |
insertSecretValueForTesting legacy storage fixture injection; remove with the confirmed old-domain query removal. |
Sources/AskKeyBroker/BrokerSocket.swift |
exercisePartialReadErrorForTesting partial-frame/error probe. |
Sources/AskKeyBroker/DebugRunDirectory.swift, Sources/AskKeyCore/VaultConfiguration.swift, Sources/AskKeyCore/Keychain/IsolatedAppKeyStore.swift and Sources/AskKeyApp/Views/DevBadge.swift also support isolated development. They are not classified as exclusively test/E2E files: ordinary development relies on their namespace isolation. The removal of migration-specific methods must preserve current-library development key/bootstrap safety.
These rows map harnesses and fixtures as well as feature tests. A listed test is evidence of an existing assertion, not a claim that it ran during this documentation task or that a real-client release gate passed. Historical iCloud assertions map the removed implementation only.
| Feature | One-line description | Decision | Legacy source files | Legacy test files |
|---|---|---|---|---|
| Synthetic bootstrap fixture generator | Keep isolated current-schema fixture generation used for normalization; legacy-state generation follows the fixed migration removal. | Keep | Sources/AskKeyCore/Migration/VaultBootstrap.swiftSources/AskKeyCore/Storage/VaultStoreMigrations.swift |
Tests/AskKeyCoreTests/NativeBootstrapFixtureGenerationTests.swift |
| Keychain interaction guard and probe | Check source and untrusted probe paths forbid authentication UI and keep synthetic tests from writing/deleting real keychain items. | Keep | Sources/AskKeyCore/Keychain/KeychainStore.swift |
Tests/AskKeyCoreTests/KeychainInteractionSafetyTests.swiftTests/AskKeyCoreTests/Fixtures/keychain-probe.m |
| Onboarding replay and no-side-effect oracle | Compare the former auto-probe replay to the explicit-check contract and record boundary counts for isolated supported-client regression. | Keep | Sources/AskKeyApp/AgentOnboardingCoordinator.swiftSources/AskKeyApp/AgentOnboardingRuntime.swift |
Tests/AskKeyAppTests/EF90AgentAccessAppearReplay.swiftTests/AskKeyAppTests/OnboardingAppearContract.swiftTests/AskKeyAppTests/AgentOnboardingViewWiringTests.swiftTests/AskKeyAppTests/AgentOnboardingBoundaryEvidenceTests.swift |
| E2E completeness and request evidence | Gate required E2E cases and fresh result fingerprints, and parse only atomically published request evidence while rejecting malformed/missing publication. | Keep | Sources/AskKeyApp/E2EBrokerScenario.swift |
Tests/AskKeyE2ETests/E2ERequestEvidenceReader.swiftTests/AskKeyE2ETests/E2EBaseCase.swiftTests/Automation/test_e2e_gate.pyTests/Automation/test_e2e_request_evidence.pyTests/Automation/Fixtures/E2ERequestEvidenceChecks.swift |
None.
All files under legacy Sources/ and Tests/, including non-Swift resources and fixtures, have explicit full-path references above. The throwaway coverage script compares the complete legacy file set to these references and checks that every reference exists; its output is included in the PR receipt. The script and execution evidence are kept outside the repository.