Skip to content

refactor: remove dead adapter, locator, storage and plugin subsystems (#487, part 1) - #566

Merged
mlieberman85 merged 9 commits into
darnitdevorg:mainfrom
mlieberman85:487-remove-dead-subsystems
Oct 8, 2026
Merged

mlieberman85 merged 9 commits into
darnitdevorg:mainfrom
mlieberman85:487-remove-dead-subsystems

Conversation

@mlieberman85

Copy link
Copy Markdown
Contributor

Summary

Part 1 of 3 for #487: remove subsystems that no audit or remediation reaches. Each was re-checked against current main before removal: packages/*/src, entry points, workspace config, CI, scripts, tests. This PR removes about 8,000 lines, including about 4,200 in product source. Each subsystem is its own commit, so it can be reviewed commit by commit. The spec commit comes first.

Commit Removed Why it was dead
spec adapters, AdapterRegistry, and UnifiedLocator.sync_to_project from framework-design.md (1.0.0-alpha.15; Appendix C lists the removals)
A remediation/routing.py, 15 of the 16 classes in threat_model/models.py (StrideCategory stays), RemediationResult.to_markdown no source callers
B darnit.storage and generate_attestation_from_results(storage_config=) no caller passes storage_config; replaced by darnit.stores
C darnit.locate (UnifiedLocator) and CheckContext.locator built on every audit, read by no handler. The control locator TOML config is a separate, live feature and stays
D packages/darnit-plugins never published or installed; its entry points were never registered
E darnit-testchecks adapters and their three entry-point groups no code reads those groups; its [adapters.builtin] named a class that doesn't exist
F darnit.core.adapters and the adapter half of PluginRegistry get_adapter_registry had no callers; framework discovery stays
G adapter config models, ControlConfig.check, FrameworkDefaults, the adapter= filter, adapter output in plan and validate parsed and printed, never dispatched

As decided for 0.2.0, there are no deprecation shims. Every removed public name has a BREAKING entry under CHANGELOG ### Removed.

Load behavior:

  • A control-level check = {...} now fails strict loading. ControlConfig forbids extra keys, and the key never did anything.
  • A leftover [adapters] table or [defaults] check_adapter still loads (top-level tables allow extras) and has no effect. The shipped frameworks drop their [defaults] blocks.
  • New tests in test_merger.py cover both cases.

The module-path policy from #490 is still tested for its two remaining callers, ToolRegistry.load_handler and HandlerRegistry.get_handler.

Parts 2 and 3, later PRs:

Refs #487

Type of Change

  • Bug fix (non-breaking change fixing an issue)
  • New feature (non-breaking change adding functionality)
  • Breaking change (fix or feature causing existing functionality to change)
  • Documentation update
  • Refactoring (no functional changes)

Framework Changes Checklist

  • Updated framework spec (docs/architecture/framework-design.md) if behavior changed
  • Ran uv run python scripts/validate_sync.py --verbose and it passes

Testing

  • Tests pass locally (uv run pytest tests/ -v): 5148 passed, 26 skipped
  • Added tests for new functionality (if applicable)
  • Linting passes (uv run ruff check .)

main has 5252 passing tests. Of the 104 fewer here:

  • 98 were in deleted test files for the removed code (routing, threat-model classes, storage, locate);
  • 8 were removed from files that remain;
  • 2 are new.

Integration tests with GitHub Actions environment variables set: 334 passed. Smoke runs:

  • darnit audit ., darnit audit . -f reproducibility: run as before;
  • darnit plan and darnit validate on testchecks and community-spec: work, without the adapter lines.

AI assistance

  • No AI assistance was used
  • AI assistance was used

Claude (Claude Code, claude-opus-5-5) re-checked each item in #487 against current main and made the removals, spec edits, and test updates. This description was also drafted with Claude. Commits carry an Assisted-by: Claude:claude-opus-5-5 trailer.

Additional Notes

  • Not from this PR: darnit plan and darnit validate on openssf-baseline crash on main with TypeError in sorted(by_level). Every baseline control loads with level=None.
  • Left for follow-ups:
    • The attestation predicate still writes adapters_used: ["builtin"]. Attestation consumers can see that field, so dropping it is a spec change.
    • EffectiveControl.remediation_handler and remediation_config are also unread.
    • Generated threat-model data (docs/threatmodel/raw-findings.json, .project/threatmodel/mitigations.yaml) still names deleted files. The rendered threat-model docs got "(removed in 0.2.0, Remove dead adapter system, legacy storage backend, unused protocol methods, and other unreachable code (~3,500 lines) #487)" notes instead of being rewritten.
    • docs/plugin-discovery-design.md is a design record. It gets a header note rather than a rewrite.

🤖 Generated with Claude Code

…work spec (darnitdevorg#487)

Assisted-by: Claude:claude-opus-5-5
Signed-off-by: Michael Lieberman <mlieberman85@gmail.com>
… to_markdown (darnitdevorg#487)

Assisted-by: Claude:claude-opus-5-5
Signed-off-by: Michael Lieberman <mlieberman85@gmail.com>
…#487)

darnit.storage was superseded by darnit.stores (feature 033); its only
caller was the unused storage_config parameter of
generate_attestation_from_results.

Assisted-by: Claude:claude-opus-5-5
Signed-off-by: Michael Lieberman <mlieberman85@gmail.com>
…#487)

The audit built one per run and put it on CheckContext.locator, but no
handler read it, and its sync_to_project writer had no caller. The TOML
locator configuration (locator.discover, use_locator) is unaffected.

Assisted-by: Claude:claude-opus-5-5
Signed-off-by: Michael Lieberman <mlieberman85@gmail.com>
It was never published or installed; it reached uv.lock only through
the packages/* workspace glob. Its adapters plugged into the adapter
system, which nothing dispatches to.

Assisted-by: Claude:claude-opus-5-5
Signed-off-by: Michael Lieberman <mlieberman85@gmail.com>
…evorg#487)

The testchecks controls are verified by their TOML passes; the adapter
classes, their three entry point groups, and [adapters.builtin] (whose
class name did not exist) were never dispatched to.

Assisted-by: Claude:claude-opus-5-5
Signed-off-by: Michael Lieberman <mlieberman85@gmail.com>
…itdevorg#487)

No audit or remediation path dispatched through CheckAdapter,
RemediationAdapter, AdapterRegistry, or the PluginRegistry adapter
methods. PluginRegistry keeps framework discovery (discover_frameworks,
list_frameworks, get_framework_info, get_framework_path). The module
path policy (darnitdevorg#490) now serves its two remaining callers,
ToolRegistry.load_handler and HandlerRegistry.get_handler.

Assisted-by: Claude:claude-opus-5-5
Signed-off-by: Michael Lieberman <mlieberman85@gmail.com>
…ema (darnitdevorg#487)

Removes AdapterType, the adapter config models, OutputMapping,
CheckConfig, FrameworkDefaults, ControlConfig.check, FrameworkConfig
defaults/adapters and their accessors, the EffectiveControl and
EffectiveConfig adapter fields, the adapter= filter, and the adapter
output of darnit plan and darnit validate. merge_control no longer takes
defaults.

A control-level check key now fails strict loading like any unknown
control key. FrameworkConfig still accepts unknown top-level tables, so
a leftover [adapters] or [defaults] table loads and is not read
(framework-design Appendix C). The shipped and fixture TOMLs drop their
[defaults] blocks.

Assisted-by: Claude:claude-opus-5-5
Signed-off-by: Michael Lieberman <mlieberman85@gmail.com>
…evorg#487)

Assisted-by: Claude:claude-opus-5-5
Signed-off-by: Michael Lieberman <mlieberman85@gmail.com>
@mlieberman85
mlieberman85 merged commit 06e905e into darnitdevorg:main Oct 8, 2026
8 checks passed
@mlieberman85
mlieberman85 deleted the 487-remove-dead-subsystems branch October 8, 2026 23:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant