Skip to content

Latest commit

 

History

History
248 lines (201 loc) · 77.9 KB

File metadata and controls

248 lines (201 loc) · 77.9 KB

AskKey v0.1 feature inventory

This is the preservation and removal inventory for normalization issue #5. The reference is the archived sudoHG/AskKey-legacy tree at legacy-final, peeled commit ee709976f823104fe12fb68c3528adf67c3db3ef. Every path below is relative to that legacy tree, including resources, fixtures and harness files; the files need not exist in the normalized repository yet. Exception: files deleted or renamed by #31 (MigrationCommitter.swift, MigrationPlannerTests.swift, DebugRunMigrationKeyStore.swift) are replaced by the current files that now hold or test their responsibilities.

The inventory is grounded in the legacy README.md, CONTEXT.md, ADRs 0026 through 0030, the client integration matrix and architecture guide, then the declarations, call sites and assertions under Sources/ and Tests/. The current repository AGENTS.md, issue #5 and the maintainer decisions on PR #10 govern the decisions. The maintainer confirmed the remaining Keep rows and the additional removals on 2026-10-02. References in old documents to Multica, updater/release work, Lokalite migration or iCloud backup do not override these decisions. v0.1 remains macOS-only; release automation is disabled.

Keep preserves confirmed reachable behavior or the regression support for it. Remove records a fixed task-card or maintainer decision. All four former Proposed remove rows are now confirmed Remove; no undecided removal rows remain. A source or test can appear in multiple rows because it contains both retained and removed responsibilities. In particular, whole-file deletion is not implied for mixed files such as Vault.swift, VaultViewModel.swift, AskKeyApp.swift, Storage/VaultStoreMigrations.swift, Migration/VaultBootstrap.swift or Keychain/AppKeyStore.swift. Current-schema creation and App-owned key/bootstrap behavior must survive the removal of Lokalite import/upgrade paths.

The explicitly listed LocalVaultLifecycle.swift removal currently overlaps the reachable modern erase coordinator: Vault+LocalLifecycle.swift calls LocalVaultEraseCoordinator. The file decision is Remove, while local erase, quiescing and recovery behavior are Keep. A later implementation issue must preserve that behavior when replacing the file. The maintainer confirmed this file/behavior distinction in the PR #10 review. This document changes no runtime code; removal implementation still belongs to later scoped issues.

Saved plaintext never belongs in Agent responses. A target that has received an approved value can output or copy it; the guarantee covers AskKey's own responses, errors and logs. Discovery hooks are reminders, not authorization. File listings and tests show implementation coverage, not completed production release or real-credential acceptance.

Credentials and the management workspace

Feature One-line description Decision Legacy source files Legacy test files
Text credentials Create, list, edit and reveal encrypted text credentials with Ask as the default permission. Keep Sources/AskKeyCore/Vault+TextCredentials.swift
Sources/AskKeyCore/Models/CredentialName.swift
Sources/AskKeyCore/Models/VNextCredential.swift
Sources/AskKeyApp/VaultViewModel+Credentials.swift
Sources/AskKeyApp/Views/CredentialManagementView.swift
Tests/AskKeyCoreTests/HumanTextCredentialTests.swift
Tests/AskKeyE2ETests/CredentialE2ETests.swift
File credentials Freeze ordinary-file bytes, original filename, size and digest; reject links, directories, special files, oversize files and read races. Keep Sources/AskKeyCore/FileImport.swift
Sources/AskKeyCore/Vault+TextCredentials.swift
Sources/AskKeyCore/VaultError.swift
Sources/AskKeyApp/VaultViewModel+Credentials.swift
Tests/AskKeyCoreTests/HumanFileCredentialTests.swift
Tests/AskKeyCoreTests/FileBoundaryRepairTests.swift
Multi-component credentials Store text and file components together under one name and permission, with per-component delivery mappings and atomic validation. Keep Sources/AskKeyCore/Models/CredentialName.swift
Sources/AskKeyCore/Vault+TextCredentials.swift
Sources/AskKeyBroker/CredentialComponents.swift
Sources/AskKeyApp/CredentialComponentDeliveryEditor.swift
Tests/AskKeyCoreTests/HumanTextCredentialTests.swift
Tests/AskKeyCoreTests/AuditBrokerBoundaryTests.swift
Tests/AskKeyBrokerTests/TextRuntimeTests.swift
Credential templates and editor Provide API, GitHub App, Apple, SSH, cloud, database and custom templates, optional fields, reveal controls and validated save actions. Keep Sources/AskKeyApp/Views/CredentialManagementView.swift
Sources/AskKeyApp/CredentialComponentDeliveryEditor.swift
Tests/AskKeyAppTests/ReviewEditorValidationTests.swift
Tests/AskKeyAppTests/AgentClientConnectorTests.swift
Tests/AskKeyAppTests/WorkspaceVisualContractTests.swift
Names and field validation Trim display names, use NFC/case-folded global uniqueness, reject control or oversize fields, and validate environment-variable mappings. Keep Sources/AskKeyCore/Models/CredentialName.swift
Sources/AskKeyCore/CredentialFieldValidation.swift
Sources/AskKeyCore/Vault+TextCredentials.swift
Tests/AskKeyCoreTests/HumanTextCredentialTests.swift
Tests/AskKeyCoreTests/ReviewCatalogLimitTests.swift
Tests/AskKeyAppTests/ReviewEditorValidationTests.swift
Usage instructions and private notes Edit catalog-visible usage instructions separately from encrypted private notes; preserve unrevealed payload and notes during metadata edits. Keep Sources/AskKeyCore/Models/CredentialName.swift
Sources/AskKeyCore/Vault+TextCredentials.swift
Sources/AskKeyApp/Views/CredentialManagementView.swift
Tests/AskKeyCoreTests/HumanTextCredentialTests.swift
Tests/AskKeyCoreTests/BrokerCatalogTests.swift
Tests/AskKeyAppTests/ReviewPrivateNotesTests.swift
Credential groups Organize credentials without granting authority; metadata writes assign/create groups and organize_credentials freezes up to 64 ordered operations under one approval and system authentication. Agent-invisible targets freeze like absent names; the App shows existing-group no-ops or merges with both member counts, and commit rechecks the full target state. Group rename/delete includes Hidden and recycled members; deletion ungroups credentials. All stored-group writers merge inside one SQL transaction, and App edits take the exclusive gate. Catalog groups lists empty groups and groups with a visible member. Keep Sources/AskKeyVault/Vault+CredentialGroups.swift
Sources/AskKeyVault/Vault+AgentOrganizationFreeze.swift
Sources/AskKeyVault/VaultStore+AgentOrganization.swift
Sources/AskKeyBroker/BrokerOrganizationSummary.swift
docs/adr/0010-agent-credential-metadata-writes.md
Tests/AskKeyVaultTests/AgentOrganizationTests.swift
Tests/AskKeyVaultTests/AgentOrganizationInvisibleTargetTests.swift
Tests/AskKeyVaultTests/AgentGroupTransactionTests.swift
Tests/AskKeyVaultTests/AgentOrganizationCommitBoundaryTests.swift
Tests/AskKeyVaultTests/AgentOrganizationConcurrencyTests.swift
Tests/AskKeyAppTests/OrganizationApprovalContentTests.swift
Library navigation and search Navigate all credentials, named groups and ungrouped items; search names, groups and instructions in the all-credentials view and clear search on scope changes. Keep Sources/AskKeyApp/Views/CredentialManagementView.swift
Sources/AskKeyApp/Views/SettingsView.swift
Sources/AskKeyApp/WorkspaceVisualContract.swift
Tests/AskKeyAppTests/ManagementWorkspaceNavigationTests.swift
Tests/AskKeyAppTests/WorkspaceVisualContractTests.swift
Tests/AskKeyAppTests/AppLanguageExperienceTests.swift
Editor lifecycle Keep create and edit routes distinct and stop saving an editor whose credential has disappeared, including after locking or reopening. Keep Sources/AskKeyApp/Views/CredentialManagementView.swift
Sources/AskKeyApp/Views/SettingsView.swift
Tests/AskKeyAppTests/ReviewEditorMissingCredentialTests.swift
Trash, restore and permanent deletion Recycle deleted credentials for 30 days, restore them from the App, and require explicit confirmation and authentication for permanent deletion. Keep Sources/AskKeyCore/Storage/VaultStoreCredentialQueries.swift
Sources/AskKeyCore/Vault+TextCredentials.swift
Sources/AskKeyCore/AgentTextWriteGovernance.swift
Sources/AskKeyApp/VaultViewModel+Credentials.swift
Sources/AskKeyApp/Views/CredentialManagementView.swift
Tests/AskKeyCoreTests/AgentTextWriteGovernanceTests.swift
Tests/AskKeyCoreTests/CredentialStorageAuthenticationTests.swift
Tests/AskKeyCoreTests/ICloudBackupRecycleTests.swift
Tests/AskKeyAppTests/WorkspaceVisualContractTests.swift
Tests/AskKeyE2ETests/CredentialE2ETests.swift
Environment-file import Parse pasted or frozen .env input with quotes, escapes and comments; reject duplicates, malformed lines and invalid UTF-8 without echoing values in errors. Keep Sources/AskKeyCore/EnvFileFormat.swift
Sources/AskKeyCore/FileImport.swift
Sources/AskKeyApp/FrozenEnvImport.swift
Sources/AskKeyApp/Views/CredentialManagementView.swift
Tests/AskKeyCoreTests/EnvFileFormatRepairTests.swift
Tests/AskKeyCoreTests/AskKeyCoreTests.swift
Tests/AskKeyAppTests/ReviewEnvImportTests.swift
Import preview and conflicts Preview frozen values, choose destination groups and resolve duplicate names inline; replacement preserves the existing credential metadata. Keep Sources/AskKeyApp/Views/CredentialManagementView.swift
Sources/AskKeyApp/VaultViewModel+Credentials.swift
Sources/AskKeyCore/Vault+TextCredentials.swift
Tests/AskKeyAppTests/WorkspaceVisualContractTests.swift
Tests/AskKeyAppTests/AgentClientConnectorTests.swift
Expiry enforcement Store optional expiry dates and reject expired runtime use or writes, cancelling approvals and invalidating deliveries at the deadline. Keep Sources/AskKeyCore/Vault+TextCredentials.swift
Sources/AskKeyCore/AgentTextWriteGovernance.swift
Sources/AskKeyCore/Models/CredentialName.swift
Sources/AskKeyBroker/ApprovalStateMachine.swift
Tests/AskKeyCoreTests/AgentAccessTests.swift
Tests/AskKeyCoreTests/AgentTextWriteGovernanceTests.swift
Tests/AskKeyCoreTests/RuntimeApprovalBoundaryTests.swift
Expiry notifications Remind seven days before expiry, persist a deduplication ledger, and handle permission denial, rescheduling, deletion and delayed notification failures. Keep Sources/AskKeyCore/CredentialExpiryReminder.swift
Sources/AskKeyApp/CredentialExpiryReminderController.swift
Tests/AskKeyCoreTests/CredentialExpiryReminderTests.swift
Tests/AskKeyAppTests/ExpiryReminderAsyncBoundaryTests.swift
Tests/AskKeyAppTests/Batch4SettingsLanguageTests.swift
Authenticated reveal and copy Require fresh authentication to reveal or copy stored values, expose file/component details only after reveal, and clear the owned clipboard after 60 seconds. Keep Sources/AskKeyCore/Vault+TextCredentials.swift
Sources/AskKeyApp/ClipboardController.swift
Sources/AskKeyApp/VaultViewModel+Credentials.swift
Sources/AskKeyApp/Views/CredentialManagementView.swift
Tests/AskKeyCoreTests/HumanTextCredentialTests.swift
Tests/AskKeyCoreTests/HumanFileCredentialTests.swift
Tests/AskKeyAppTests/ClipboardControllerTests.swift
Tests/AskKeyAppTests/WorkspaceVisualContractTests.swift
Tests/AskKeyAppTests/ReviewPrivateNotesTests.swift

Local storage and management authentication

Feature One-line description Decision Legacy source files Legacy test files
Authenticated encrypted storage Encrypt credential names, payloads, notes, filenames and access records; authenticate record metadata and use a keyed name index to prevent keyless policy substitution. Keep Sources/AskKeyCore/Crypto/VaultCrypto.swift
Sources/AskKeyCore/Crypto/CredentialRecordAuthentication.swift
Sources/AskKeyCore/Storage/VaultStore.swift
Sources/AskKeyCore/Storage/VaultRecords.swift
Sources/AskKeyCore/Storage/VaultStoreCredentialQueries.swift
Sources/AskKeyCore/Storage/VaultStoreSupport.swift
Tests/AskKeyCoreTests/CredentialStorageAuthenticationTests.swift
Tests/AskKeyCoreTests/AuditStorageBoundaryTests.swift
Tests/AskKeyCoreTests/HumanTextCredentialTests.swift
Tests/AskKeyCoreTests/AskKeyCoreTests.swift
Current database schema Keep the current credential, write-operation, group and access-record schema and the Phase 4 legacy-table baseline; migration askkey-0002-drop-legacy-tables drops the old tables only when they hold nothing beyond the legacy Default seed and otherwise keeps every table and row. Keep Sources/AskKeyCore/Storage/VaultStoreMigrations.swift
Sources/AskKeyCore/Storage/VaultStore.swift
Sources/AskKeyCore/Storage/VaultRecords.swift
Sources/AskKeyCore/Storage/VaultStoreConfigQueries.swift
Sources/AskKeyCore/Storage/VaultStoreCredentialQueries.swift
Sources/AskKeyCore/Storage/VaultStoreCredentialAccessQueries.swift
Tests/AskKeyCoreTests/AskKeyCoreTests.swift
Tests/AskKeyCoreTests/CredentialStorageAuthenticationTests.swift
Tests/AskKeyCoreTests/AgentTextWriteGovernanceTests.swift
App-owned key and current-library bootstrap Open or create the current library for the App Broker without granting a management session; reject unsupported or incomplete legacy state. Keep Sources/AskKeyCore/Vault.swift
Sources/AskKeyCore/VaultConfiguration.swift
Sources/AskKeyCore/Migration/VaultBootstrap.swift
Sources/AskKeyCore/Keychain/AppKeyStore.swift
Sources/AskKeyCore/Storage/CurrentLibrarySnapshot.swift
Sources/AskKeyCore/Keychain/KeychainStore.swift
Tests/AskKeyCoreTests/VaultBootstrapTests.swift
Tests/AskKeyCoreTests/CurrentLibraryAdoptionTests.swift
Tests/AskKeyCoreTests/KeychainInteractionSafetyTests.swift
Tests/AskKeyAppTests/AppLanguageExperienceTests.swift
Management session and vault lock Authenticate management independently of Agent runtime, clear sensitive UI on session close/expiry, retire stale callbacks and avoid locking the App-held vault on management idle expiry. Keep Sources/AskKeyCore/Vault.swift
Sources/AskKeyCore/Models/CredentialName.swift
Sources/AskKeyApp/VaultViewModel.swift
Sources/AskKeyApp/SessionPolicy.swift
Sources/AskKeyApp/AskKeyApp.swift
Tests/AskKeyCoreTests/HumanTextCredentialTests.swift
Tests/AskKeyAppTests/SessionPolicyTests.swift
Tests/AskKeyAppTests/ManagementWorkspaceNavigationTests.swift
Tests/AskKeyAppTests/AgentAccessMenuSessionTests.swift
Tests/AskKeyAppTests/AppLanguageExperienceTests.swift
Tests/AskKeyE2ETests/CredentialE2ETests.swift
System authentication subprocess Run bounded, localized owner authentication and frozen-approval description through the packaged App subprocess, with cancellation and safe pipe handling. Keep Sources/AskKeyApp/ManagementAuthenticationProcess.swift
Sources/AskKeyApp/VaultViewModel.swift
Sources/AskKeyApp/AskKeyApp.swift
Tests/AskKeyAppTests/ManagementAuthenticationProcessTests.swift
Tests/AskKeyAppTests/AuditApplicationContractTests.swift
Tests/AskKeyAppTests/AppLanguageExperienceTests.swift
First-run onboarding Offer first credential creation/import, restrict unauthenticated creation to an empty library, and persist completion and login-item choice; remove iCloud recovery/key steps separately. Keep Sources/AskKeyApp/Views/FirstRunOnboardingView.swift
Sources/AskKeyApp/Views/SettingsView.swift
Sources/AskKeyApp/VaultViewModel.swift
Sources/AskKeyApp/WorkspaceVisualContract.swift
Sources/AskKeyCore/Vault.swift
Tests/AskKeyCoreTests/HumanTextCredentialTests.swift
Tests/AskKeyAppTests/AppLanguageExperienceTests.swift
Tests/AskKeyAppTests/ReviewICloudRecoveryTests.swift
Tests/AskKeyAppTests/WorkspaceVisualContractTests.swift
Local library erase Keep authenticated, language-specific confirmation, quiescing, delivery cleanup and crash recovery with local key deletion last; remove the separate iCloud backup/material hooks. Keep Sources/AskKeyCore/Vault+LocalLifecycle.swift
Sources/AskKeyCore/Vault.swift
Sources/AskKeyCore/LocalVaultLifecycle.swift
Sources/AskKeyApp/VaultViewModel+Credentials.swift
Sources/AskKeyApp/Views/CredentialManagementView.swift
Tests/AskKeyCoreTests/LocalVaultLifecycleTests.swift
Tests/AskKeyAppTests/LocalVaultLifecycleViewModelTests.swift
Tests/AskKeyAppTests/WorkspaceVisualContractTests.swift
Safe errors and injected workspace operations Present localized actionable errors, suppress authentication-cancellation noise, and ensure injected/read-only workspaces do not fall through to the shared vault. Keep Sources/AskKeyCore/VaultError.swift
Sources/AskKeyApp/UserFacingCopy.swift
Sources/AskKeyApp/CredentialWorkspaceMutations.swift
Sources/AskKeyApp/VaultViewModel.swift
Sources/AskKeyApp/VaultViewModel+Credentials.swift
Tests/AskKeyAppTests/ReviewCredentialIsolationTests.swift
Tests/AskKeyAppTests/AppLanguageExperienceTests.swift
Tests/AskKeyAppTests/LocalizationRemediationTests.swift

The legacy tables projects, environments, secrets, secret_values and activity_log remain in the Phase 4 schema baseline. Removing old models/query code does not remove these tables or rewrite historical migrations. Migration askkey-0002-drop-legacy-tables drops them only when they hold nothing beyond the legacy Default seed; otherwise every table and row is kept and the migration is still recorded. Current credential and access-record tables, encryption and App-owned key/bootstrap behavior remain Keep.

Agent permissions, approvals and the Broker

Feature One-line description Decision Legacy source files Legacy test files
Allow / Ask / Hidden Use one credential-wide permission with Ask by default; Hide excludes catalog/use/write access and grouping or caller identity does not widen authorization. Keep Sources/AskKeyCore/Models/VNextCredential.swift
Sources/AskKeyCore/Vault+TextCredentials.swift
Sources/AskKeyApp/Views/CredentialManagementView.swift
Sources/AskKeyApp/VaultViewModel+Credentials.swift
Tests/AskKeyCoreTests/AgentAccessTests.swift
Tests/AskKeyCoreTests/BrokerCatalogTests.swift
Tests/AskKeyCoreTests/ReadDeclarationAndAuditTests.swift
Metadata-only credential catalog Return visible names, IDs, instructions, expiry state and component mappings without values, private notes or filenames, with bounded cancellable reads. Keep Sources/AskKeyCore/Vault+TextCredentials.swift
Sources/AskKeyCore/Storage/VaultStoreCredentialQueries.swift
Sources/AskKeyBroker/BrokerProtocol.swift
Sources/AskKeyHelper/main.swift
Tests/AskKeyCoreTests/BrokerCatalogTests.swift
Tests/AskKeyCoreTests/BrokerCatalogCancellationTests.swift
Tests/AskKeyCoreTests/ReviewCatalogLimitTests.swift
Tests/AskKeyBrokerTests/BrokerProtocolTests.swift
Approval request identity and replay Bind operation, target, immutable payload digest and deadlines to a request ID/capability; reuse only identical retransmissions and consume an approval once. Keep Sources/AskKeyBroker/ApprovalStateMachine.swift
Sources/AskKeyBroker/BrokerProtocol.swift
Tests/AskKeyBrokerTests/ApprovalStateMachineTests.swift
Tests/AskKeyBrokerTests/BrokerProtocolTests.swift
Tests/AskKeyE2ETests/AskKeyE2ETests.swift
Once, deny, cancel and expiry Support allow-once or deny decisions, capability-bound status/cancel and five-minute pending expiry; denial has no cooldown and terminal requests cannot execute. Keep Sources/AskKeyBroker/ApprovalStateMachine.swift
Sources/AskKeyBroker/BrokerProtocol.swift
Sources/AskKeyApp/AskKeyApp.swift
Tests/AskKeyBrokerTests/ApprovalStateMachineTests.swift
Tests/AskKeyBrokerTests/HelperApprovalWaitTests.swift
Tests/AskKeyCoreTests/AgentAccessTests.swift
Tests/AskKeyE2ETests/AskKeyE2ETests.swift
Timed read allowance and revoke Allow reads globally for one credential until its original deadline, with bounded configurable minutes, a disable setting, a visible countdown and explicit revocation. Keep Sources/AskKeyBroker/ApprovalStateMachine.swift
Sources/AskKeyApp/AppPreferences.swift
Sources/AskKeyApp/VaultViewModel.swift
Sources/AskKeyApp/Views/CredentialManagementView.swift
Sources/AskKeyCore/Vault.swift
Tests/AskKeyBrokerTests/ApprovalStateMachineTests.swift
Tests/AskKeyCoreTests/TimedAllowanceBoundsTests.swift
Tests/AskKeyCoreTests/CredentialExpiryReminderTests.swift
Tests/AskKeyAppTests/Batch4SettingsLanguageTests.swift
Tests/AskKeyAppTests/WorkspaceVisualContractTests.swift
Read approval authentication preference Enable read authentication by default and allow an explicitly confirmed opt-out; writes still authenticate each time, while the iCloud restore reset path is removed separately. Keep Sources/AskKeyBroker/ApprovalStateMachine.swift
Sources/AskKeyApp/AppPreferences.swift
Sources/AskKeyApp/Views/CredentialManagementView.swift
Sources/AskKeyApp/VaultViewModel.swift
Tests/AskKeyBrokerTests/ApprovalStateMachineTests.swift
Tests/AskKeyAppTests/ICloudRestoreAuthenticationTests.swift
Tests/AskKeyAppTests/Batch4SettingsLanguageTests.swift
Tests/AskKeyAppTests/WorkspaceVisualContractTests.swift
Independent approval panel Present a foreground confirmation with caller, purpose, target and countdown; authenticate frozen write reveal separately and show pending operations in management. Keep Sources/AskKeyApp/AgentApprovalPanelFactory.swift
Sources/AskKeyApp/AskKeyApp.swift
Sources/AskKeyApp/Views/CredentialManagementView.swift
Tests/AskKeyAppTests/AgentApprovalPanelTests.swift
Tests/AskKeyAppTests/Batch4SettingsLanguageTests.swift
Tests/AskKeyAppTests/WorkspaceVisualContractTests.swift
Tests/AskKeyCoreTests/AuditBrokerBoundaryTests.swift
Screen-lock approval privacy Load request details only in the current unlocked console session and use a generic private reminder otherwise, recording delivery only after success. Keep Sources/AskKeyApp/AgentApprovalScreenSession.swift
Sources/AskKeyApp/AskKeyApp.swift
Tests/AskKeyAppTests/AgentApprovalScreenSessionTests.swift
Tests/AskKeyAppTests/AgentClientConnectorTests.swift
Tests/AskKeyAppTests/Batch4SettingsLanguageTests.swift
Pause and authenticated resume Pause Agent access from the menu while management is locked, persist the pause, cancel requests/allowances and deliveries, and authenticate resume without opening management. Keep Sources/AskKeyCore/Vault+TextCredentials.swift
Sources/AskKeyApp/VaultViewModel+Credentials.swift
Sources/AskKeyApp/AskKeyApp.swift
Sources/AskKeyApp/Views/VaultPopover.swift
Tests/AskKeyCoreTests/AgentAccessTests.swift
Tests/AskKeyAppTests/AgentAccessMenuSessionTests.swift
Tests/AskKeyBrokerTests/ApprovalStateMachineTests.swift
Mutation and final-spawn revocation Recheck original authorization and credential/file deadlines at the synchronized spawn boundary; mutation, hidden state, expiry and revoke prevent unstarted delivery. Keep Sources/AskKeyCore/Vault+TextCredentials.swift
Sources/AskKeyCore/FileDeliveryManager.swift
Sources/AskKeyBroker/ApprovalStateMachine.swift
Sources/AskKeyBroker/TextRuntime.swift
Tests/AskKeyCoreTests/RuntimeApprovalBoundaryTests.swift
Tests/AskKeyCoreTests/AgentAccessTests.swift
Tests/AskKeyCoreTests/AuditBrokerBoundaryTests.swift
Versioned and bounded socket protocol Expose only the limited Agent RPC over a local length-prefixed socket; cap frames, fields, connections, work and deadlines and reject broad legacy management messages. Keep Sources/AskKeyBroker/BrokerProtocol.swift
Sources/AskKeyBroker/BrokerSocket.swift
Sources/AskKeyBroker/BrokerRuntimeDirectory.swift
Tests/AskKeyBrokerTests/BrokerProtocolTests.swift
Tests/AskKeyCoreTests/BrokerCatalogTests.swift
Tests/AskKeyCoreTests/ReviewCatalogLimitTests.swift
Caller declaration Carry sanitized caller name and purpose into frozen requests and encrypted records as untrusted display context, never as an Agent authorization boundary. Keep Sources/AskKeyBroker/TextRuntime.swift
Sources/AskKeyBroker/ApprovalStateMachine.swift
Sources/AskKeyCore/Models/VNextCredential.swift
Sources/AskKeyCore/Vault+TextCredentials.swift
Sources/AskKeyHelper/main.swift
Tests/AskKeyBrokerTests/BrokerTextRunDeclarationTests.swift
Tests/AskKeyCoreTests/ReadDeclarationAndAuditTests.swift
Broker startup recovery Expose a persistent actionable retry when secure staging fails, without starting duplicate Brokers or discarding unrelated errors; remove restore-settings compensation separately. Keep Sources/AskKeyApp/BrokerRuntimeRecovery.swift
Sources/AskKeyApp/AskKeyApp.swift
Sources/AskKeyApp/VaultViewModel.swift
Sources/AskKeyApp/Views/SettingsView.swift
Sources/AskKeyApp/Views/VaultPopover.swift
Sources/AskKeyBroker/BrokerRuntimeDirectory.swift
Tests/AskKeyAppTests/BrokerRuntimeRecoveryTests.swift
Tests/AskKeyAppTests/AutomaticICloudBackupLifecycleTests.swift
Tests/AskKeyBrokerTests/FileWriteCoordinatorTests.swift

Runtime delivery and helper commands

Feature One-line description Decision Legacy source files Legacy test files
Explicit text environment delivery Launch a non-PTY target only with the selected smallest credential set and mappings, applying an inherited-environment whitelist and validating the whole set. Keep Sources/AskKeyBroker/TextRuntime.swift
Sources/AskKeyBroker/CredentialComponents.swift
Sources/AskKeyCore/Vault+TextCredentials.swift
Tests/AskKeyBrokerTests/TextRuntimeTests.swift
Tests/AskKeyCoreTests/HumanTextCredentialTests.swift
Tests/AskKeyCoreTests/RuntimeApprovalBoundaryTests.swift
Short-lived file delivery Deliver random 0600 files inside a private 0700 directory and revoke or sweep them on TTL, pause, mutation, lock, expiry, exit and restart. Keep Sources/AskKeyCore/FileDeliveryManager.swift
Sources/AskKeyCore/Vault+TextCredentials.swift
Tests/AskKeyCoreTests/FileRuntimeDeliveryTests.swift
Tests/AskKeyCoreTests/RuntimeApprovalBoundaryTests.swift
Tests/AskKeyCoreTests/ReviewCleanupLeaseTests.swift
Tests/AskKeyCoreTests/FileBoundaryRepairTests.swift
Visible cleanup failures Keep failed deletions visible and retry them while holding the owning lease; an old cleanup cannot delete a newly approved delivery. Keep Sources/AskKeyCore/FileDeliveryManager.swift
Sources/AskKeyApp/VaultViewModel.swift
Sources/AskKeyApp/VaultViewModel+Credentials.swift
Tests/AskKeyAppTests/FileCleanupVisibilityTests.swift
Tests/AskKeyCoreTests/ReviewCleanupLeaseTests.swift
Tests/AskKeyCoreTests/RuntimeApprovalBoundaryTests.swift
Tests/AskKeyCoreTests/FileBoundaryRepairTests.swift
Target streams, signals and cancellation Pass CLI standard-stream descriptors directly to the target, return its exit code and terminate only the owned process group on signal, control or socket disconnect. Keep Sources/AskKeyBroker/BrokerSocket.swift
Sources/AskKeyBroker/TextRuntime.swift
Sources/AskKeyBrokerC/AskKeyBrokerC.c
Sources/AskKeyBrokerC/include/AskKeyBrokerC.h
Sources/AskKeyHelper/main.swift
Tests/AskKeyBrokerTests/BrokerProtocolTests.swift
Tests/AskKeyBrokerTests/TextRuntimeTests.swift
Tests/AskKeyBrokerTests/HelperApprovalWaitTests.swift
Tests/AskKeyE2ETests/AskKeyE2ETests.swift
Runtime receipts and unknown outcomes Retain bounded per-runtime execution receipts, replay completed exit status without respawning or replaying output, and never automatically retry outcomeUnknown. Keep Sources/AskKeyBroker/RuntimeOperations.swift
Sources/AskKeyBroker/TextRuntime.swift
Sources/AskKeyBroker/BrokerSocket.swift
Tests/AskKeyBrokerTests/RuntimeReceiptBoundsTests.swift
Tests/AskKeyBrokerTests/TextRuntimeTests.swift
Tests/AskKeyBrokerTests/BrokerProtocolTests.swift
Tests/AskKeyBrokerTests/HelperMCPTests.swift
Tests/AskKeyCoreTests/AuditBrokerBoundaryTests.swift
CLI run and approval wait Provide explicit run selection, operation ID and caller declarations; optional --wait-for-approval resumes the identical in-memory request once all tickets approve. Keep Sources/AskKeyHelper/main.swift
Sources/AskKeyHelper/CLIApprovalWait.swift
Sources/AskKeyHelper/AgentUsageGuide.swift
Tests/AskKeyBrokerTests/HelperApprovalWaitTests.swift
Tests/AskKeyBrokerTests/HelperCommandContractTests.swift
MCP stdio and Agent guidance Expose metadata discovery, run, write, upload and status/cancel tools with bounded JSON-RPC; MCP run discards target output and returns only execution/approval status. Keep Sources/AskKeyHelper/main.swift
Sources/AskKeyHelper/AgentUsageGuide.swift
Sources/AskKeyBroker/BrokerProtocol.swift
Tests/AskKeyBrokerTests/HelperMCPTests.swift
Tests/AskKeyCoreTests/ReviewMCPHelperContractTests.swift
Tests/AskKeyCoreTests/CredentialAccessRecordTests.swift
Health, version, status and open Forward health and version (CLI status aliases version) and open the verified host App; reject removed direct-management helper commands. Keep Sources/AskKeyHelper/main.swift
Sources/AskKeyBroker/HelperHostApplication.swift
Sources/AskKeyBroker/BrokerProtocol.swift
Tests/AskKeyBrokerTests/HelperCommandContractTests.swift
Tests/AskKeyBrokerTests/HelperHostApplicationTests.swift
Tests/AskKeyBrokerTests/BrokerProtocolTests.swift
Discovery command hooks Provide hook capabilities, hook cursor and hook grok; track catalog completion with bounded expiring hashed turn state and release stalled discovery reminders. Keep Sources/AskKeyHelper/main.swift
Sources/AskKeyHelper/CommandDiscoveryHook.swift
Sources/AskKeyHelper/CredentialDiscoveryGuard.swift
Sources/AskKeyHelper/DiscoveryTurnStore.swift
Tests/AskKeyBrokerTests/CommandDiscoveryHookTests.swift
Tests/AskKeyBrokerTests/HelperMCPTests.swift
Official helper topology and trust Keep the official bundled-helper topology, host/resource-seal and Developer ID checks; moved, renamed or mismatched release bundles fail closed. Keep Sources/AskKeyBroker/OfficialInstallTopology.swift
Sources/AskKeyBroker/HelperHostApplication.swift
Sources/AskKeyCore/CodexUserMCPAdapter.swift
Sources/AskKeyApp/AgentClientConnector.swift
Tests/AskKeyCoreTests/OfficialInstallTopologyTests.swift
Tests/AskKeyCoreTests/HelperCodeSignatureTrustTests.swift
Tests/AskKeyBrokerTests/HelperHostApplicationTests.swift
Isolated development runtime Validate an explicitly selected private development directory and separate storage, preferences, socket and key material from production. Keep Sources/AskKeyBroker/DebugRunDirectory.swift
Sources/AskKeyBroker/BrokerProtocol.swift
Sources/AskKeyCore/VaultConfiguration.swift
Sources/AskKeyCore/Keychain/IsolatedAppKeyStore.swift
Sources/AskKeyApp/AppPreferences.swift
Sources/AskKeyApp/Views/DevBadge.swift
Tests/AskKeyBrokerTests/DebugRunDirectoryTests.swift
Tests/AskKeyCoreTests/OfficialInstallTopologyTests.swift
Tests/AskKeyAppTests/ReviewCredentialIsolationTests.swift

Agent writes and access records

Feature One-line description Decision Legacy source files Legacy test files
Agent text and component create/modify Freeze caller-known components and optional instructions/group, permit metadata-only modification, show full before/after metadata and new groups, and bind everything to approval plus separate system authentication regardless of Allow or timed allowances. Preserve omitted fields and permissions; text-only tools are unchanged. Keep Sources/AskKeyVault/Vault+AgentWriteFreeze.swift
Sources/AskKeyVault/Vault+AgentWriteCommit.swift
Sources/AskKeyBroker/CredentialComponents.swift
Sources/AskKeyHelper/MCPTools.swift
Sources/AskKeyAppKit/App/FrozenWriteApprovalContent.swift
Tests/AskKeyVaultTests/AgentCredentialMetadataWriteTests.swift
Tests/AskKeyBrokerTests/HelperMCPMetadataTests.swift
Tests/AskKeyAppTests/ApprovalMetadataContentTests.swift
Agent file upload and frozen approval Accept bounded ordered byte chunks rather than mutable paths, encrypt staging, bind frozen filename/digest and require authenticated reveal and approval before commit. Keep Sources/AskKeyBroker/FileWriteCoordinator.swift
Sources/AskKeyBroker/BrokerProtocol.swift
Sources/AskKeyBroker/BrokerRuntimeDirectory.swift
Sources/AskKeyCore/Vault+TextCredentials.swift
Sources/AskKeyHelper/main.swift
Tests/AskKeyBrokerTests/FileWriteCoordinatorTests.swift
Tests/AskKeyCoreTests/FileWriteCoordinatorTests.swift
Agent delete Require a separate authenticated frozen operation to recycle any visible text, file or bundle credential; permanent deletion and hidden credentials remain App-only. Keep Sources/AskKeyCore/AgentTextWriteGovernance.swift
Sources/AskKeyHelper/main.swift
Tests/AskKeyCoreTests/AgentTextWriteGovernanceTests.swift
Tests/AskKeyCoreTests/AuditBrokerBoundaryTests.swift
Write transaction and replay Commit CRUD and operation receipts in one database transaction, reject swapped payload/capability or changed targets, and handle restart, rollback and expired frozen capacity. Keep Sources/AskKeyCore/AgentTextWriteGovernance.swift
Sources/AskKeyCore/Vault+TextCredentials.swift
Sources/AskKeyCore/Storage/VaultStoreCredentialQueries.swift
Sources/AskKeyCore/Storage/VaultRecords.swift
Sources/AskKeyBroker/FileWriteCoordinator.swift
Tests/AskKeyCoreTests/AgentTextWriteGovernanceTests.swift
Tests/AskKeyCoreTests/FileWriteCoordinatorTests.swift
Tests/AskKeyCoreTests/ReviewCredentialMutationTests.swift
Tests/AskKeyBrokerTests/FileWriteCoordinatorTests.swift
Encrypted access records Keep metadata-only access events encrypted, bounded to 256 entries and 90 days, with generic hidden guesses and a persisted visible write-failure indicator. Keep Sources/AskKeyCore/Models/CredentialAccessEvent.swift
Sources/AskKeyCore/Vault+CredentialAccessRecords.swift
Sources/AskKeyCore/Storage/VaultStoreCredentialAccessQueries.swift
Tests/AskKeyCoreTests/CredentialAccessRecordTests.swift
Tests/AskKeyCoreTests/ReadDeclarationAndAuditTests.swift
Access-record management List records only within management and clear them after fresh authentication; omit them from Broker/helper responses. Keep Sources/AskKeyApp/Views/CredentialManagementView.swift
Sources/AskKeyApp/VaultViewModel+Credentials.swift
Sources/AskKeyApp/CredentialWorkspaceMutations.swift
Sources/AskKeyCore/Vault+CredentialAccessRecords.swift
Tests/AskKeyAppTests/AccessRecordManagementTests.swift
Tests/AskKeyAppTests/ReviewCredentialIsolationTests.swift
Tests/AskKeyCoreTests/CredentialAccessRecordTests.swift
Tests/AskKeyCoreTests/AutomaticICloudBackupSchedulerTests.swift

iCloud backup, recovery and lifecycle

v0.1 has no backup. All nine legacy capabilities below are Remove, including their iCloud-only tests and diagnostic support. A redesigned backup or encrypted export may come later as a separate feature. This decision also removes recovery-key/onboarding steps, backup settings, mutation-triggered scheduling, launch-time restore compensation, backup hooks in local erase and the iCloud entitlement/capability requirement. The following additional rows map those cross-cutting portions explicitly.

Feature One-line description Decision Legacy source files Legacy test files
Capability and independent recovery key Use only the product iCloud container with valid signing/entitlements and high-entropy recovery material; report development or missing capability honestly. Remove Sources/AskKeyCore/ICloudBackupCapability.swift
Sources/AskKeyCore/ICloudBackupSnapshot.swift
Sources/AskKeyCore/ICloudBackup.swift
Sources/AskKeyApp/ICloudAppLifecycleController.swift
Tests/AskKeyCoreTests/AutomaticICloudBackupSchedulerTests.swift
Tests/AskKeyCoreTests/ICloudBackupTests.swift
Tests/AskKeyAppTests/AutomaticICloudBackupLifecycleTests.swift
Tests/AskKeyAppTests/WorkspaceVisualContractTests.swift
Authenticated immutable backup generations Encrypt complete snapshots before upload, verify manifest/blob/digest/AEAD and format/key identity, and recover verified current or previous generations. Remove Sources/AskKeyCore/ICloudBackup.swift
Sources/AskKeyCore/ICloudBackupSnapshot.swift
Sources/AskKeyCore/FileICloudBackupPendingUploadStore.swift
Sources/AskKeyCore/Vault+ICloudBackup.swift
Tests/AskKeyCoreTests/ICloudBackupTests.swift
Tests/AskKeyCoreTests/ICloudBackupBoundaryTests.swift
Tests/AskKeyCoreTests/AuditStorageBoundaryTests.swift
Snapshot contents Preserve active and recycled text/file/component credentials, metadata, delivery mappings, empty groups and ordinary settings while excluding access records, clients, pause and auth preferences. Remove Sources/AskKeyCore/ICloudBackupSnapshot.swift
Sources/AskKeyCore/Vault+ICloudBackup.swift
Sources/AskKeyApp/AppPreferences.swift
Tests/AskKeyCoreTests/ICloudBackupRecycleTests.swift
Tests/AskKeyCoreTests/ICloudBackupBoundaryTests.swift
Tests/AskKeyCoreTests/AutomaticICloudBackupSchedulerTests.swift
Automatic backup and launch compensation Coalesce successful relevant changes, persist change/confirmed versions and pending upload, retry failure and keep one writer across pauses, restarts and lifecycle rebinding. Remove Sources/AskKeyCore/AutomaticICloudBackupScheduler.swift
Sources/AskKeyCore/FileICloudBackupPendingUploadStore.swift
Sources/AskKeyCore/Vault.swift
Sources/AskKeyApp/ICloudAppLifecycleController.swift
Tests/AskKeyCoreTests/AutomaticICloudBackupSchedulerTests.swift
Tests/AskKeyCoreTests/ICloudBackupRecoveryTests.swift
Tests/AskKeyAppTests/AutomaticICloudBackupLifecycleTests.swift
Immediate backup and recovery-key presentation Let authenticated management enable or stop automatic backup, create a new namespace, show the recovery key before first upload and request an immediate backup. Remove Sources/AskKeyApp/ICloudAppLifecycleController.swift
Sources/AskKeyApp/VaultViewModel+Credentials.swift
Sources/AskKeyApp/Views/CredentialManagementView.swift
Sources/AskKeyCore/ICloudBackupSnapshot.swift
Tests/AskKeyAppTests/WorkspaceVisualContractTests.swift
Tests/AskKeyAppTests/AutomaticICloudBackupLifecycleTests.swift
Conflict, fork and writer takeover Pause automatic backup on conflict copies or writer/parent forks, permit verified full restore selection, and require explicit authenticated ownership takeover. Remove Sources/AskKeyCore/ICloudBackup.swift
Sources/AskKeyCore/ICloudBackupSnapshot.swift
Sources/AskKeyApp/ICloudAppLifecycleController.swift
Sources/AskKeyApp/Views/ICloudBackupRecoveryView.swift
Tests/AskKeyCoreTests/ICloudBackupTests.swift
Tests/AskKeyCoreTests/ICloudBackupRecoveryTests.swift
Tests/AskKeyAppTests/ReviewICloudRecoveryTests.swift
Tests/AskKeyAppTests/LocalVaultLifecycleViewModelTests.swift
Full-library recovery Inspect valid generations and restore with recovery key and system authentication by complete atomic replacement, preserving recycle state and resetting every permission to Ask. Remove Sources/AskKeyCore/Vault+ICloudBackup.swift
Sources/AskKeyCore/ICloudBackupSnapshot.swift
Sources/AskKeyApp/Views/ICloudBackupRecoveryView.swift
Sources/AskKeyApp/VaultViewModel+Credentials.swift
Tests/AskKeyCoreTests/ICloudBackupTests.swift
Tests/AskKeyCoreTests/ICloudBackupRecycleTests.swift
Tests/AskKeyCoreTests/ICloudBackupBoundaryTests.swift
Tests/AskKeyAppTests/ReviewICloudRecoveryTests.swift
Safety snapshot and interrupted restore Create an encrypted local safety snapshot before replacement and recover pending restored settings before opening Agent access, reenabling read authentication and preserving subsequent edits. Remove Sources/AskKeyCore/LocalICloudSafetySnapshotStore.swift
Sources/AskKeyCore/Vault+ICloudBackup.swift
Sources/AskKeyApp/ICloudAppLifecycleController.swift
Sources/AskKeyApp/VaultViewModel.swift
Tests/AskKeyCoreTests/ICloudBackupRecycleTests.swift
Tests/AskKeyCoreTests/ICloudBackupBoundaryTests.swift
Tests/AskKeyAppTests/ICloudRestoreAuthenticationTests.swift
Tests/AskKeyAppTests/ICloudRestoreLaunchRecoveryTests.swift
Namespace retention and cloud deletion Use a new key-ID namespace for new material, show retained old namespaces as historical, and confirm cloud deletion separately from local erase or stopping backup. Remove Sources/AskKeyCore/ICloudBackupSnapshot.swift
Sources/AskKeyCore/ICloudBackup.swift
Sources/AskKeyApp/ICloudAppLifecycleController.swift
Sources/AskKeyApp/VaultViewModel+Credentials.swift
Sources/AskKeyApp/Views/CredentialManagementView.swift
Tests/AskKeyCoreTests/ICloudBackupTests.swift
Tests/AskKeyAppTests/LocalVaultLifecycleViewModelTests.swift
Tests/AskKeyAppTests/WorkspaceVisualContractTests.swift

| First-run recovery-key and restore steps | Remove onboarding recovery-key entry and backup inspection/restore routes while keeping ordinary credential creation/import and login-item onboarding. | Remove | Sources/AskKeyApp/Views/FirstRunOnboardingView.swift
Sources/AskKeyApp/Views/SettingsView.swift
Sources/AskKeyApp/Views/ICloudBackupRecoveryView.swift
Sources/AskKeyApp/VaultViewModel.swift
Sources/AskKeyApp/VaultViewModel+Credentials.swift | Tests/AskKeyAppTests/ReviewICloudRecoveryTests.swift
Tests/AskKeyAppTests/AppLanguageExperienceTests.swift | | Backup settings, authentication and copy | Remove backup enable/immediate-backup/recovery-key/restore/takeover/delete controls, state, authentication reasons and localized copy; keep unrelated settings and authentication. | Remove | Sources/AskKeyApp/AppPreferences.swift
Sources/AskKeyApp/VaultViewModel.swift
Sources/AskKeyApp/VaultViewModel+Credentials.swift
Sources/AskKeyApp/Views/CredentialManagementView.swift
Sources/AskKeyApp/Views/SettingsView.swift
Sources/AskKeyApp/ManagementAuthenticationProcess.swift
Sources/AskKeyApp/AppLanguage.swift
Sources/AskKeyApp/Resources/Localizable.xcstrings | Tests/AskKeyAppTests/WorkspaceVisualContractTests.swift
Tests/AskKeyAppTests/ICloudRestoreAuthenticationTests.swift
Tests/AskKeyAppTests/ReviewICloudRecoveryTests.swift
Tests/AskKeyAppTests/ManagementAuthenticationProcessTests.swift | | Mutation and preference backup scheduling hooks | Remove snapshot-relevant change callbacks, backup dirty/version accounting and ordinary-setting backup notifications; keep credential mutations, groups and local preferences. | Remove | Sources/AskKeyCore/Vault.swift
Sources/AskKeyCore/Vault+TextCredentials.swift
Sources/AskKeyCore/AgentTextWriteGovernance.swift
Sources/AskKeyCore/Storage/VaultStoreConfigQueries.swift
Sources/AskKeyCore/AutomaticICloudBackupScheduler.swift
Sources/AskKeyApp/AppPreferences.swift
Sources/AskKeyApp/ICloudAppLifecycleController.swift | Tests/AskKeyCoreTests/AutomaticICloudBackupSchedulerTests.swift
Tests/AskKeyAppTests/AutomaticICloudBackupLifecycleTests.swift | | Launch-time restore and backup compensation | Remove iCloud preparation, pending restore-settings replay, restored preference/permission resets and backup scheduling at launch; keep normal App/Broker startup and staging recovery. | Remove | Sources/AskKeyApp/AskKeyApp.swift
Sources/AskKeyApp/ICloudAppLifecycleController.swift
Sources/AskKeyApp/VaultViewModel.swift
Sources/AskKeyApp/BrokerRuntimeRecovery.swift
Sources/AskKeyCore/Vault+ICloudBackup.swift
Sources/AskKeyCore/Vault+TextCredentials.swift
Sources/AskKeyBroker/ApprovalStateMachine.swift | Tests/AskKeyAppTests/ICloudRestoreLaunchRecoveryTests.swift
Tests/AskKeyAppTests/ICloudRestoreAuthenticationTests.swift
Tests/AskKeyAppTests/AutomaticICloudBackupLifecycleTests.swift
Tests/AskKeyBrokerTests/ApprovalStateMachineTests.swift | | Local-erase iCloud hooks and material cleanup | Remove backup cancellation/global-stop and iCloud recovery-material cleanup from erase; retain local quiescing, delivery cleanup, journal recovery and local key/data deletion. | Remove | Sources/AskKeyCore/Vault+LocalLifecycle.swift
Sources/AskKeyCore/LocalVaultLifecycle.swift
Sources/AskKeyCore/VaultConfiguration.swift
Sources/AskKeyCore/Vault.swift
Sources/AskKeyApp/VaultViewModel+Credentials.swift | Tests/AskKeyCoreTests/LocalVaultLifecycleTests.swift
Tests/AskKeyAppTests/LocalVaultLifecycleViewModelTests.swift | | iCloud entitlement and capability requirement | Remove iCloud container/ubiquity entitlement requirements and backup signing/capability checks; the pinned entitlements template is already empty, so no enabled entitlement is claimed here. | Remove | AskKeyApp.entitlements
Sources/AskKeyCore/ICloudBackupCapability.swift
Sources/AskKeyCore/ICloudBackup.swift
Sources/AskKeyCore/VaultConfiguration.swift | Tests/AskKeyCoreTests/AutomaticICloudBackupSchedulerTests.swift
Tests/AskKeyAppTests/AutomaticICloudBackupLifecycleTests.swift |

Mixed files that retain other responsibilities

The iCloud rows record only the removed portions of shared files and shared tests. Dedicated backup files/tests are removed, while assertions for independent Keep behavior remain or move with that behavior. These files must not be deleted wholesale because of an iCloud reference:

Legacy mixed file Responsibilities retained iCloud portions removed
Sources/AskKeyApp/AskKeyApp.swift App/menu-bar lifecycle, management windows, approval presentation and Broker startup. iCloud lifecycle setup, automatic scheduling, restore compensation and backup proof state.
Sources/AskKeyApp/VaultViewModel.swift Management authentication/session, localization, credential state, client onboarding and errors. Backup state/closures/status, restored preferences and recovery actions.
Sources/AskKeyApp/VaultViewModel+Credentials.swift Credential CRUD, reveal/copy, pause/resume, access records and local erase. Backup/restore/namespace/takeover/cloud-delete actions.
Sources/AskKeyApp/Views/FirstRunOnboardingView.swift First credential creation/import, completion and login-item choice. Backup recovery entry and recovery-key steps.
Sources/AskKeyApp/Views/SettingsView.swift Management unlock, navigation and ordinary workspace routes. First-run/settings backup recovery routes.
Sources/AskKeyApp/Views/CredentialManagementView.swift Credential library/editor, approval/records/trash and ordinary preferences. Backup controls, recovery material, status and cloud-delete UI.
Sources/AskKeyApp/AppPreferences.swift Local appearance, language, session, approval and hotkey preferences. Backup-relevant setting notifications.
Sources/AskKeyApp/ManagementAuthenticationProcess.swift System authentication for management, approval and local destructive operations. Recovery, namespace and cloud-backup authentication actions.
Sources/AskKeyCore/Vault.swift App-owned key, current bootstrap, management and local vault operations. Snapshot-change callbacks and backup stop/resume coupling.
Sources/AskKeyCore/Vault+TextCredentials.swift Credential CRUD, permission/expiry, runtime authorization and pause/resume. Backup notifications, restore-pending gates and backup stop/resume callbacks.
Sources/AskKeyCore/AgentTextWriteGovernance.swift Frozen Agent writes, authenticated commit and replay. Snapshot-relevant change notifications after mutations.
Sources/AskKeyCore/Vault+LocalLifecycle.swift Local erase quiescing, delivery cleanup, crash recovery and local key/data deletion. Backup stop/global pause and iCloud recovery-material deletion.
Sources/AskKeyCore/VaultConfiguration.swift Local development/production namespace and vault/Broker paths. iCloud backup service, material and safety-snapshot configuration.
Sources/AskKeyApp/BrokerRuntimeRecovery.swift Safe staging-failure feedback and explicit single-Broker retry. Restore-settings-specific compensation/error case.
Sources/AskKeyBroker/ApprovalStateMachine.swift Current approval, deadline, revoke and read-authentication preference behavior. The backup-restore-only reset path; default read authentication stays enabled.
Sources/AskKeyApp/AppLanguage.swift and Sources/AskKeyApp/Resources/Localizable.xcstrings Owned English/Simplified Chinese catalog and live language changes. Backup/restore authentication-message keys and strings.

Supported clients and discovery onboarding

Only Codex, Cursor and Grok CLI are supported. Legacy Multica assertions inside shared tests are mapped to the removal rows below; the remaining supported-client behavior stays Keep.

Feature One-line description Decision Legacy source files Legacy test files
Explicit onboarding state machine Check only on user action, retain per-client results, freeze an apply plan, authenticate writes, suppress stale callbacks and show actionable inline failure/completion. Keep Sources/AskKeyApp/AgentClientConnector.swift
Sources/AskKeyApp/AgentOnboardingModels.swift
Sources/AskKeyApp/AgentOnboardingCoordinator.swift
Sources/AskKeyApp/AgentOnboardingRuntime.swift
Sources/AskKeyApp/Views/AgentOnboardingView.swift
Tests/AskKeyAppTests/AgentOnboardingCallBoundaryTests.swift
Tests/AskKeyAppTests/AgentOnboardingCompletionTests.swift
Tests/AskKeyAppTests/AgentOnboardingViewWiringTests.swift
Tests/AskKeyAppTests/AgentClientConnectorTests.swift
Onboarding cancellation and termination Cancel live read-only checks with their owned process groups, preserve in-flight writes after page exit and defer App termination until writes settle. Keep Sources/AskKeyApp/AgentOnboardingCoordinator.swift
Sources/AskKeyApp/AgentOnboardingRuntime.swift
Sources/AskKeyApp/OnboardingTerminationGate.swift
Sources/AskKeyCore/RestrictedProcessCancellation.swift
Tests/AskKeyAppTests/AgentOnboardingConnectorCancelTests.swift
Tests/AskKeyAppTests/AgentOnboardingLiveCancelTests.swift
Tests/AskKeyAppTests/AgentOnboardingReviewRepairTests.swift
Tests/AskKeyAppTests/AgentOnboardingEvidenceCloseTests.swift
Onboarding interaction and appearance Use ordinary localized UI with explicit explanation/check/confirmation actions and Space/Return activation; entry and expansion do not probe clients or authenticate. Keep Sources/AskKeyApp/Views/AgentOnboardingView.swift
Sources/AskKeyApp/AgentOnboardingCoordinator.swift
Tests/AskKeyAppTests/AgentOnboardingIsolationUITests.swift
Tests/AskKeyAppTests/AgentOnboardingKeyboardActivationTests.swift
Tests/AskKeyAppTests/AgentOnboardingViewWiringTests.swift
Tests/AskKeyAppTests/AgentOnboardingCallBoundaryTests.swift
Safe client-config transactions Validate format, ownership and regular-file boundaries, preserve other settings and permissions, use private backups and atomic writes, and reject concurrent changes or unsafe rollback. Keep Sources/AskKeyCore/ClientConfigFileIO.swift
Sources/AskKeyCore/CodexUserMCPAdapter.swift
Sources/AskKeyCore/CursorUserMCPAdapter.swift
Sources/AskKeyCore/GrokCLIAdapter.swift
Tests/AskKeyCoreTests/ClientConfigFileIOTests.swift
Tests/AskKeyCoreTests/CodexUserMCPAdapterTests.swift
Tests/AskKeyCoreTests/CursorUserMCPAdapterTests.swift
Tests/AskKeyCoreTests/GrokCLIAdapterTests.swift
Tests/AskKeyAppTests/AgentClientConnectorTests.swift
MCP connection verification Verify config readback, trusted bundled helper, compatible initialize identity/tool list and Broker health before calling a supported client connected. Keep Sources/AskKeyCore/MCPHelperContract.swift
Sources/AskKeyCore/CodexUserMCPAdapter.swift
Sources/AskKeyCore/CursorUserMCPAdapter.swift
Sources/AskKeyCore/GrokCLIAdapter.swift
Sources/AskKeyApp/AgentClientConnector.swift
Tests/AskKeyCoreTests/ReviewMCPHelperContractTests.swift
Tests/AskKeyCoreTests/AuditProcessBoundaryTests.swift
Tests/AskKeyAppTests/AgentClientConnectorTests.swift
Codex user MCP configuration Connect the user-level MCP using the native authority and lossless TOML transaction, with backups, supported capability/version checks and failure rollback. Keep Sources/AskKeyCore/CodexUserMCPAdapter.swift
Sources/AskKeyApp/AgentClientConnector.swift
Sources/AskKeyApp/AgentOnboardingRuntime.swift
Tests/AskKeyCoreTests/CodexUserMCPAdapterTests.swift
Tests/AskKeyAppTests/CodexOnboardingSetupTests.swift
Tests/AskKeyAppTests/AgentClientConnectorTests.swift
Codex native discovery hook and trust Install the reviewed PreToolUse rule, enable only its native app-server trust entry and read back hooks/list; keep verified MCP if later discovery setup is incomplete. Keep Sources/AskKeyCore/CodexDiscoveryHookConfiguration.swift
Sources/AskKeyCore/CodexNativeHookClient.swift
Sources/AskKeyApp/CodexOnboardingSetup.swift
Sources/AskKeyHelper/CredentialDiscoveryGuard.swift
Tests/AskKeyCoreTests/CodexDiscoveryHookConfigurationTests.swift
Tests/AskKeyCoreTests/CodexNativeHookClientTests.swift
Tests/AskKeyAppTests/CodexOnboardingSetupTests.swift
Cursor MCP and command hooks Merge the user MCP and pre/post/failure discovery hooks without replacing other entries; distinguish configured discovery from verified MCP and require a new task. Keep Sources/AskKeyCore/CursorUserMCPAdapter.swift
Sources/AskKeyCore/CommandDiscoveryHookConfiguration.swift
Sources/AskKeyCore/CommandDiscoveryIntegration.swift
Sources/AskKeyApp/CommandHookOnboardingSetup.swift
Tests/AskKeyCoreTests/CursorUserMCPAdapterTests.swift
Tests/AskKeyCoreTests/CommandDiscoveryHookConfigurationTests.swift
Tests/AskKeyAppTests/CommandHookOnboardingSetupTests.swift
Tests/AskKeyAppTests/AgentOnboardingCompletionTests.swift
Grok CLI MCP and command hooks Preserve user TOML, verify list/doctor/helper/Broker and install a dedicated native discovery-hook file, rejecting unknown owned-file content. Keep Sources/AskKeyCore/GrokCLIAdapter.swift
Sources/AskKeyCore/CommandDiscoveryHookConfiguration.swift
Sources/AskKeyCore/CommandDiscoveryIntegration.swift
Sources/AskKeyApp/CommandHookOnboardingSetup.swift
Tests/AskKeyCoreTests/GrokCLIAdapterTests.swift
Tests/AskKeyCoreTests/CommandDiscoveryHookConfigurationTests.swift
Tests/AskKeyAppTests/CommandHookOnboardingSetupTests.swift
Tests/AskKeyAppTests/AgentOnboardingCompletionTests.swift
Discovery reminder boundaries Prompt catalog lookup before common direct SSH commands, bind completion to its turn, expire hashed state and stop stalled reminders; discovery is not credential authorization. Keep Sources/AskKeyHelper/CredentialDiscoveryGuard.swift
Sources/AskKeyHelper/CommandDiscoveryHook.swift
Sources/AskKeyHelper/DiscoveryTurnStore.swift
Sources/AskKeyHelper/AgentUsageGuide.swift
Tests/AskKeyBrokerTests/CommandDiscoveryHookTests.swift
Tests/AskKeyBrokerTests/HelperMCPTests.swift
Tests/Automation/test_hook_probes.py
Bounded client subprocesses Bound command output, pipe reads and deadlines and stop only owned descendants; preserve cancellation context across detached work. Keep Sources/AskKeyCore/RestrictedProcess.swift
Sources/AskKeyCore/RestrictedProcessCancellation.swift
Sources/AskKeyCore/CodexNativeHookClient.swift
Sources/AskKeyCore/MCPHelperContract.swift
Sources/AskKeyBrokerC/AskKeyBrokerC.c
Tests/AskKeyCoreTests/RestrictedProcessTests.swift
Tests/AskKeyCoreTests/AuditProcessBoundaryTests.swift
Tests/AskKeyCoreTests/CodexNativeHookClientTests.swift
Tests/AskKeyAppTests/AgentOnboardingLiveCancelTests.swift
Tests/RuntimeProbes/RestrictedProcessCancellationProbe.swift
legacy regression notes under Tests/RuntimeProbes
Tests/Automation/test_hook_probes.py

Menu bar, preferences and localization

Feature One-line description Decision Legacy source files Legacy test files
Management window and resident menu bar Keep the native close controls, locked workbench, status popover, approval access and Dock transitions tied to the actual management window. Keep Sources/AskKeyApp/AskKeyApp.swift
Sources/AskKeyApp/ManagementDockPolicy.swift
Sources/AskKeyApp/Views/VaultPopover.swift
Sources/AskKeyApp/Views/SettingsView.swift
Sources/AskKeyApp/WorkspaceVisualContract.swift
Tests/AskKeyAppTests/ManagementDockPolicyTests.swift
Tests/AskKeyAppTests/ManagementWorkspaceNavigationTests.swift
Tests/AskKeyAppTests/AuditApplicationContractTests.swift
Tests/AskKeyAppTests/WorkspaceVisualContractTests.swift
Menu artwork and development badge Load bundled template menu-bar artwork and display development isolation status without exposing credential content. Keep Sources/AskKeyApp/Views/MenuBarIcon.swift
Sources/AskKeyApp/Resources/MenuBarIcon.png
Sources/AskKeyApp/Views/DevBadge.swift
Tests/AskKeyAppTests/AppLanguageExperienceTests.swift
Tests/AskKeyAppTests/AgentOnboardingIsolationUITests.swift
Global hotkey Register the selected management shortcut, support turning it off and reflect preference changes immediately. Keep Sources/AskKeyApp/GlobalHotkeyManager.swift
Sources/AskKeyApp/AppPreferences.swift
Sources/AskKeyApp/AskKeyApp.swift
Sources/AskKeyApp/Views/CredentialManagementView.swift
Tests/AskKeyAppTests/Batch4SettingsLanguageTests.swift
Tests/AskKeyAppTests/WorkspaceVisualContractTests.swift
Launch at login Apply the SMAppService choice immediately, warn before disabling and keep login launch menu-bar resident until management is opened. Keep Sources/AskKeyApp/LoginItemController.swift
Sources/AskKeyApp/Views/FirstRunOnboardingView.swift
Sources/AskKeyApp/AppPreferences.swift
Sources/AskKeyApp/AskKeyApp.swift
Tests/AskKeyAppTests/AppLanguageExperienceTests.swift
Tests/AskKeyAppTests/ManagementDockPolicyTests.swift
Tests/AskKeyAppTests/WorkspaceVisualContractTests.swift
Appearance and ordinary preferences Persist local system/light/dark appearance, language, timed-allowance settings, session configuration and onboarding state; remove backup settings and scheduling notifications separately. Keep Sources/AskKeyApp/AppPreferences.swift
Sources/AskKeyApp/Views/SettingsSupport.swift
Sources/AskKeyApp/Views/CredentialManagementView.swift
Tests/AskKeyAppTests/WorkspaceVisualContractTests.swift
Tests/AskKeyAppTests/Batch4SettingsLanguageTests.swift
Tests/AskKeyCoreTests/AutomaticICloudBackupSchedulerTests.swift
English and Simplified Chinese Use one owned string catalog for UI, errors, notifications and authentication; follow the system or change language live, preserving untranslated technical identifiers. Keep Sources/AskKeyApp/AppLanguage.swift
Sources/AskKeyApp/UserFacingCopy.swift
Sources/AskKeyApp/Views/SettingsSupport.swift
Sources/AskKeyApp/Resources/Localizable.xcstrings
Sources/AskKeyApp/Resources/en.lproj/InfoPlist.strings
Sources/AskKeyApp/Resources/zh-Hans.lproj/InfoPlist.strings
Tests/AskKeyAppTests/AppLanguageExperienceTests.swift
Tests/AskKeyAppTests/LocalizationRemediationTests.swift
Tests/AskKeyAppTests/LocalizationUnificationTests.swift
Tests/AskKeyAppTests/ReviewLocalizationTests.swift
Tests/AskKeyAppTests/Batch4SettingsLanguageTests.swift
Product copy consistency Keep supported-client, macOS-only and delivery statements aligned with behavior; reflect the confirmed Multica, updater and backup removals. Keep Sources/AskKeyApp/UserFacingCopy.swift
Sources/AskKeyApp/WorkspaceVisualContract.swift
Sources/AskKeyHelper/AgentUsageGuide.swift
Tests/AskKeyAppTests/ProductFactAlignmentTests.swift
Tests/AskKeyAppTests/AppLanguageExperienceTests.swift
Tests/AskKeyBrokerTests/HelperMCPTests.swift

Fixed removals

These decisions come from issue #5, the current repository rules and the maintainer confirmation on PR #10 and override the older legacy README, ADRs and client matrix. They record decisions only; this inventory does not delete code or tests. Shared files and tests retain their Keep responsibilities elsewhere in this document.

Feature One-line description Decision Legacy source files Legacy test files
Multica integration: adapter and diagnostics Remove all workspace configuration/status/create/assignment/recovery, executable discovery, network retry, Multica diagnostic logs and onboarding branches. Remove Sources/AskKeyApp/MulticaWorkspaceMCPAdapter.swift
Sources/AskKeyApp/MulticaProcessDiagnosticLog.swift
Sources/AskKeyApp/AgentClientConnector.swift
Sources/AskKeyApp/AgentOnboardingModels.swift
Sources/AskKeyApp/AgentOnboardingRuntime.swift
Sources/AskKeyApp/AgentOnboardingCoordinator.swift
Sources/AskKeyApp/Views/AgentOnboardingView.swift
Tests/AskKeyAppTests/MulticaConnectionFailureTests.swift
Tests/AskKeyAppTests/MulticaExecutableDiscoveryTests.swift
Tests/AskKeyAppTests/MulticaNetworkRecoveryTests.swift
Tests/AskKeyAppTests/MulticaProcessDiagnosticLogTests.swift
Tests/AskKeyAppTests/AgentOnboardingFlowTests.swift
Tests/AskKeyAppTests/AgentOnboardingReviewRepairTests.swift
Tests/AskKeyAppTests/AgentOnboardingEvidenceCloseTests.swift
Tests/AskKeyAppTests/AgentClientConnectorTests.swift
Tests/AskKeyAppTests/AgentOnboardingCompletionTests.swift
Tests/AskKeyAppTests/AgentOnboardingConnectorCancelTests.swift
Tests/AskKeyAppTests/AgentOnboardingLiveCancelTests.swift
Tests/AskKeyAppTests/ProductFactAlignmentTests.swift
Tests/AskKeyE2ETests/AskKeyE2ETests.swift
Multica helper configuration and runtime tests Remove Multica server serialization, Multica-specific helper/runtime reconnect assertions, isolated stub scenarios and restart proofs; keep generic MCP reconnect behavior. Remove Sources/AskKeyBroker/MulticaServerConfiguration.swift
Sources/AskKeyApp/AgentOnboardingRestartProof.swift
Sources/AskKeyApp/E2EAppRuntime.swift
Sources/AskKeyApp/AgentOnboardingDebugSupport.swift
Sources/AskKeyHelper/main.swift
Tests/AskKeyBrokerTests/MulticaServerConfigurationTests.swift
Tests/AskKeyBrokerTests/HelperMCPTests.swift
Tests/AskKeyAppTests/MulticaConfigurationSerializationTests.swift
Tests/AskKeyE2ETests/AskKeyE2ETests.swift
Sparkle and in-app update checks Remove SoftwareUpdater, Sparkle integration and manual update settings/copy until separately authorized release work. Remove Sources/AskKeyApp/SoftwareUpdater.swift
Sources/AskKeyApp/AskKeyApp.swift
Sources/AskKeyApp/Views/CredentialManagementView.swift
Tests/AskKeyAppTests/ManualUpdatePolicyTests.swift
Tests/AskKeyAppTests/ProductFactAlignmentTests.swift
Lokalite database migration and review Remove legacy preview, conflict/permission review, source fingerprint and two-phase re-encryption/commit/recovery paths and their legacy fixture; retain current-library bootstrap/key ownership. Remove Sources/AskKeyCore/Migration/MigrationPlanner.swift
Sources/AskKeyCore/Migration/MigrationSourceFingerprint.swift
Sources/AskKeyCore/Keychain/AppKeyStore.swift
Sources/AskKeyCore/Migration/VaultBootstrap.swift
Sources/AskKeyCore/Models/VNextCredential.swift
Sources/AskKeyCore/Vault.swift
Sources/AskKeyApp/Views/MigrationReviewView.swift
Sources/AskKeyApp/VaultViewModel.swift
Tests/AskKeyCoreTests/VaultBootstrapTests.swift
Tests/AskKeyCoreTests/CurrentLibraryAdoptionTests.swift
Tests/AskKeyCoreTests/Fixtures/README.md
Tests/AskKeyCoreTests/Fixtures/legacy-v7-vault.db
Tests/AskKeyAppTests/AppLanguageExperienceTests.swift
Legacy daemon and direct-read cluster Remove RemoteVaultService, VaultService, VaultSocket, VaultWireProtocol, SecretWorkspace and SecretReference, including broad administration/direct plaintext transport. Remove Sources/AskKeyCore/RemoteVaultService.swift
Sources/AskKeyCore/VaultService.swift
Sources/AskKeyCore/VaultSocket.swift
Sources/AskKeyCore/VaultWireProtocol.swift
Sources/AskKeyCore/SecretWorkspace.swift
Sources/AskKeyCore/SecretReference.swift
Tests/AskKeyCoreTests/VaultSocketTests.swift
Tests/AskKeyCoreTests/VaultWireTests.swift
Tests/AskKeyCoreTests/SecretReferenceTests.swift
Tests/AskKeyCoreTests/DaemonUnlockTests.swift
Tests/AskKeyCoreTests/VaultWriteValidationTests.swift
Tests/AskKeyBrokerTests/HelperCommandContractTests.swift
LocalVaultLifecycle implementation Remove the explicitly named LocalVaultLifecycle file from the legacy cluster; its currently reachable local-erase behavior is separately Keep and must survive replacement. Remove Sources/AskKeyCore/LocalVaultLifecycle.swift
Sources/AskKeyCore/Vault+LocalLifecycle.swift
Tests/AskKeyCoreTests/LocalVaultLifecycleTests.swift
Tests/AskKeyAppTests/LocalVaultLifecycleViewModelTests.swift
Legacy Project / Environment / Secret models Remove Project, VaultEnvironment (the Environment file), Secret, SecretCategory and SecretInfo, and their legacy-domain consumers; do not reinstate folder association. Remove Sources/AskKeyCore/Models/Project.swift
Sources/AskKeyCore/Models/Environment.swift
Sources/AskKeyCore/Models/Secret.swift
Sources/AskKeyCore/Models/SecretCategory.swift
Sources/AskKeyCore/Models/SecretInfo.swift
Sources/AskKeyCore/Vault.swift
Sources/AskKeyCore/Storage/VaultRecords.swift
Sources/AskKeyCore/Storage/VaultStoreMigrations.swift
Tests/AskKeyCoreTests/AskKeyCoreTests.swift
Tests/AskKeyCoreTests/VaultWriteValidationTests.swift
Tests/AskKeyCoreTests/CurrentLibraryAdoptionTests.swift

Maintainer-confirmed dependency removals

The maintainer approved all four former candidates in PR #10. Remove their code and obsolete tests in the later scoped implementation issues; shared current credential, crypto and schema responsibilities remain Keep. Remove the argon2 product/package dependency from Package.swift and its phc-winner-argon2 resolution in Package.resolved together with the Argon2id export KDF.

Feature One-line description Decision Legacy source files Legacy test files
Legacy AgentAccessPolicy Only the removed Secret/Vault daemon paths, schema defaults and legacy migration interpret allowed/blocked/requiresApproval/strict; modern CredentialPermission remains Keep. Remove Sources/AskKeyCore/Models/AgentAccessPolicy.swift
Sources/AskKeyCore/Vault.swift
Sources/AskKeyCore/Storage/VaultRecords.swift
Sources/AskKeyCore/Storage/VaultStoreMigrations.swift
Sources/AskKeyCore/Migration/MigrationPlanner.swift
Tests/AskKeyCoreTests/AskKeyCoreTests.swift
Tests/AskKeyCoreTests/DaemonUnlockTests.swift
Tests/AskKeyCoreTests/CurrentLibraryAdoptionTests.swift
Legacy caller detection and peer attribution AgentDetection and PeerCodeSignature are consumed by the old Vault socket/wire and log paths; modern caller declarations and helper signature trust remain separate Keep behavior. Remove Sources/AskKeyCore/AgentDetection.swift
Sources/AskKeyCore/PeerCodeSignature.swift
Sources/AskKeyCore/VaultSocket.swift
Sources/AskKeyCore/VaultWireProtocol.swift
Tests/AskKeyCoreTests/AgentDetectionTests.swift
Tests/AskKeyCoreTests/PeerCodeSignatureTests.swift
Legacy activity model and storage Remove ActivityLogEntry/ActivityFilter and project/environment/secret/activity query code; retain current credential/access queries. Migration askkey-0002-drop-legacy-tables drops the old tables when they hold nothing beyond the legacy Default seed and keeps them otherwise. Remove Sources/AskKeyCore/Models/ActivityLogEntry.swift
Sources/AskKeyCore/Storage/VaultStoreActivityQueries.swift
Sources/AskKeyCore/Storage/VaultStoreProjectQueries.swift
Sources/AskKeyCore/Storage/VaultStoreEnvironmentQueries.swift
Sources/AskKeyCore/Storage/VaultStoreSecretQueries.swift
Tests/AskKeyCoreTests/AskKeyCoreTests.swift
Tests/AskKeyCoreTests/VaultWriteValidationTests.swift
Tests/AskKeyCoreTests/VaultWireTests.swift
Tests/AskKeyCoreTests/PeerCodeSignatureTests.swift
Legacy project export and passphrase KDF Remove legacy project export/import and Argon2id export-key derivation with the argon2 package dependency; retain current credential authenticated encryption. Remove Sources/AskKeyCore/Vault.swift
Sources/AskKeyCore/Crypto/VaultCrypto.swift
Sources/AskKeyCore/VaultService.swift
Sources/AskKeyCore/VaultWireProtocol.swift
Tests/AskKeyCoreTests/AskKeyCoreTests.swift
Tests/AskKeyCoreTests/VaultWireTests.swift

Test support in Sources

Keep the regression capability for retained features, but relocate test-only files, probes and embedded hooks out of production Sources in Phase 5. This is a location plan, not permission to expose test authentication in ordinary builds. Multica-only and iCloud-only support follow their fixed Remove decisions.

Feature One-line description Decision Legacy source files Legacy test files
Onboarding debug UI driver DEBUG-only press registry, stub operations, boundary recorder, simulated input/contrast probes and evidence capture; relocate the retained-client test support. Keep Sources/AskKeyApp/AgentOnboardingDebugSupport.swift Tests/AskKeyAppTests/AgentOnboardingBoundaryEvidenceTests.swift
Tests/AskKeyAppTests/AgentOnboardingIsolationUITests.swift
Tests/AskKeyAppTests/AgentOnboardingKeyboardActivationTests.swift
Onboarding real-input diagnostic helpers DEBUG-only AppKit/accessibility keyboard and mouse input plus focus snapshots exist for real-window test evidence, not product credential management. Keep Sources/AskKeyApp/AgentOnboardingRealUIInput.swift Tests/AskKeyAppTests/AgentOnboardingKeyboardActivationTests.swift
Tests/AskKeyAppTests/AgentOnboardingIsolationUITests.swift
Multica restart-proof driver DEBUG-only restart journal export and injected cancelled operations are specific to removed Multica recovery; remove with that integration. Remove Sources/AskKeyApp/AgentOnboardingRestartProof.swift Tests/AskKeyAppTests/AgentOnboardingEvidenceCloseTests.swift
Tests/AskKeyAppTests/AgentOnboardingReviewRepairTests.swift
Dedicated E2E App and Broker drivers DEBUG plus ASKKEY_E2E_TESTING gates isolated runtime/control paths, fixture App creation, helper request evidence and approval/cancel/disconnect scenarios. Keep Sources/AskKeyApp/E2EAppRuntime.swift
Sources/AskKeyApp/E2EBrokerScenario.swift
Tests/AskKeyE2ETests/E2EBaseCase.swift
Tests/AskKeyE2ETests/AskKeyE2ETests.swift
Tests/AskKeyE2ETests/CredentialE2ETests.swift
Tests/AskKeyE2ETests/E2ERequestEvidenceReader.swift
E2E core fixtures DEBUG plus ASKKEY_E2E_TESTING gates synthetic persistent-vault creation and an owned slow process used to verify cancellation. Keep Sources/AskKeyCore/E2EVaultFixture.swift
Sources/AskKeyCore/E2EProcessFixture.swift
Tests/AskKeyE2ETests/E2EBaseCase.swift
Tests/AskKeyE2ETests/AskKeyE2ETests.swift
Tests/AskKeyE2ETests/CredentialE2ETests.swift

Embedded test support in mixed production files

The following files have production responsibilities and are not test-only files. Phase 5 should extract the named support while preserving the Keep behavior in the feature rows:

Legacy source file Embedded support to isolate
Sources/AskKeyApp/AskKeyApp.swift E2E startup dispatch, synthetic visual-proof view model, scripted clicks/keys and evidence capture.
Sources/AskKeyApp/AgentClientConnector.swift DebugClientE2ERequest, DebugClientE2ERunner, isolated client homes/stubs and E2E result reporting; remove the Multica-only variants.
Sources/AskKeyApp/ManagementAuthenticationProcess.swift Explicit DebugAuthentication substitution gated by DEBUG, an opt-in environment value and a valid isolated run directory; keep the real authentication subprocess.
Sources/AskKeyApp/VaultViewModel.swift DEBUG proof fixtures, prototype state and injected proof actions.
Sources/AskKeyApp/VaultViewModel+Credentials.swift DEBUG proof mutations/overrides used by the isolated visual driver.
Sources/AskKeyApp/Views/CredentialManagementView.swift DEBUG visual-proof fixtures, registry wiring and extra proof shortcuts.
Sources/AskKeyApp/Views/AgentOnboardingView.swift DEBUG press-registry and proof accessibility wiring.
Sources/AskKeyApp/Views/SettingsView.swift DEBUG sidebar press registry.
Sources/AskKeyApp/Views/FirstRunOnboardingView.swift Environment-selected visual-proof state.
Sources/AskKeyCore/RestrictedProcess.swift DEBUG OnboardingBoundaryObserver, counters and isolated positive-control probes.
Sources/AskKeyCore/ClientConfigFileIO.swift DEBUG configuration-write boundary observer callback.
Sources/AskKeyCore/CursorUserMCPAdapter.swift DEBUG cursor-helper boundary observation and isolated probe environment.
Sources/AskKeyCore/Keychain/KeychainStore.swift DEBUG boundary observer callbacks; keep forbidden-UI keychain query protections.
Sources/AskKeyCore/ICloudBackup.swift DEBUG exclusiveWriteProbe callbacks at partial-write and pre-publication boundaries; remove with the iCloud backup implementation.
Sources/AskKeyCore/Models/CredentialName.swift DEBUG visual-proof authentication substitute.
Sources/AskKeyCore/Storage/VaultStoreCredentialAccessQueries.swift failCredentialAccessRecordWritesForTesting fault injection.
Sources/AskKeyCore/Storage/VaultStoreSecretQueries.swift insertSecretValueForTesting legacy storage fixture injection; remove with the confirmed old-domain query removal.
Sources/AskKeyBroker/BrokerSocket.swift exercisePartialReadErrorForTesting partial-frame/error probe.

Sources/AskKeyBroker/DebugRunDirectory.swift, Sources/AskKeyCore/VaultConfiguration.swift, Sources/AskKeyCore/Keychain/IsolatedAppKeyStore.swift and Sources/AskKeyApp/Views/DevBadge.swift also support isolated development. They are not classified as exclusively test/E2E files: ordinary development relies on their namespace isolation. The removal of migration-specific methods must preserve current-library development key/bootstrap safety.

Test and diagnostic support outside Sources

These rows map harnesses and fixtures as well as feature tests. A listed test is evidence of an existing assertion, not a claim that it ran during this documentation task or that a real-client release gate passed. Historical iCloud assertions map the removed implementation only.

Feature One-line description Decision Legacy source files Legacy test files
Synthetic bootstrap fixture generator Keep isolated current-schema fixture generation used for normalization; legacy-state generation follows the fixed migration removal. Keep Sources/AskKeyCore/Migration/VaultBootstrap.swift
Sources/AskKeyCore/Storage/VaultStoreMigrations.swift
Tests/AskKeyCoreTests/NativeBootstrapFixtureGenerationTests.swift
Keychain interaction guard and probe Check source and untrusted probe paths forbid authentication UI and keep synthetic tests from writing/deleting real keychain items. Keep Sources/AskKeyCore/Keychain/KeychainStore.swift Tests/AskKeyCoreTests/KeychainInteractionSafetyTests.swift
Tests/AskKeyCoreTests/Fixtures/keychain-probe.m
Onboarding replay and no-side-effect oracle Compare the former auto-probe replay to the explicit-check contract and record boundary counts for isolated supported-client regression. Keep Sources/AskKeyApp/AgentOnboardingCoordinator.swift
Sources/AskKeyApp/AgentOnboardingRuntime.swift
Tests/AskKeyAppTests/EF90AgentAccessAppearReplay.swift
Tests/AskKeyAppTests/OnboardingAppearContract.swift
Tests/AskKeyAppTests/AgentOnboardingViewWiringTests.swift
Tests/AskKeyAppTests/AgentOnboardingBoundaryEvidenceTests.swift
E2E completeness and request evidence Gate required E2E cases and fresh result fingerprints, and parse only atomically published request evidence while rejecting malformed/missing publication. Keep Sources/AskKeyApp/E2EBrokerScenario.swift Tests/AskKeyE2ETests/E2ERequestEvidenceReader.swift
Tests/AskKeyE2ETests/E2EBaseCase.swift
Tests/Automation/test_e2e_gate.py
Tests/Automation/test_e2e_request_evidence.py
Tests/Automation/Fixtures/E2ERequestEvidenceChecks.swift

Unmapped

None.

All files under legacy Sources/ and Tests/, including non-Swift resources and fixtures, have explicit full-path references above. The throwaway coverage script compares the complete legacy file set to these references and checks that every reference exists; its output is included in the PR receipt. The script and execution evidence are kept outside the repository.