Phase 3 of the routine-capability-detection plan (ADR 0011; planned via #2685). Depends on the
Phase 2 leaf sections (#2718) being merged.
The bridge the resolver needs and the single-home rule forbids authoring twice: one
machine-readable emission (JSON, in-plugin, generated) listing every v1 identity with its
derived prerequisite set, generated from the leaves with a --check drift gate — the
generate-plus-check pattern the catalog generator established. The leaves stay the authored
single home; the emission is derived output; drift between leaves and emission fails CI.
ADR-0004 incumbent evidence (inlined)
- No structured identity registry exists:
scripts/generate-catalog.mjs builds
docs/CATALOG.md from plugin manifests and never sees routine identities; the only
structured posture-qualified identities in the tree are security-binding test fixtures.
- The generate-plus-
--check drift-gate shape is the incumbent pattern being reused, not a new
mechanism.
Work items
Sanity checks
Related
Phase 3 of the routine-capability-detection plan (ADR 0011; planned via #2685). Depends on the
Phase 2 leaf sections (#2718) being merged.
The bridge the resolver needs and the single-home rule forbids authoring twice: one
machine-readable emission (JSON, in-plugin, generated) listing every
v1identity with itsderived prerequisite set, generated from the leaves with a
--checkdrift gate — thegenerate-plus-check pattern the catalog generator established. The leaves stay the authored
single home; the emission is derived output; drift between leaves and emission fails CI.
ADR-0004 incumbent evidence (inlined)
scripts/generate-catalog.mjsbuildsdocs/CATALOG.mdfrom plugin manifests and never sees routine identities; the onlystructured posture-qualified identities in the tree are security-binding test fixtures.
--checkdrift-gate shape is the incumbent pattern being reused, not a newmechanism.
Work items
--checkmode (Node.mjs, beside the setup skill's existing conformancescripts), with a co-located
*.test.shand test manifest per the plugin's existingconformance-script shape.
config-file family; consumers other than the resolver and CI are out of scope.
git update-index --chmod=+xfor any new shebang file before commit (the exec-bit gateis repo-wide and ungated; on Windows
core.filemodeis false andgit addrecords100644).
origin/mainANDscripts/check-changelog-parity.sh --check-bump origin/mainexits 0.Sanity checks
--checkmode exits non-zero on a hand-edited emission (drift fixture) and 0 on aregenerated one.
scripts/check-orphaned-fixtures.sh --checkexits 0 (every fixture consumed by the testharness).
Related