Repository navigation
refactor: remove dead adapter, locator, storage and plugin subsystems (#487, part 1) - #566
Merged
mlieberman85 merged 9 commits intoOct 8, 2026
Conversation
…work spec (darnitdevorg#487) Assisted-by: Claude:claude-opus-5-5 Signed-off-by: Michael Lieberman <mlieberman85@gmail.com>
… to_markdown (darnitdevorg#487) Assisted-by: Claude:claude-opus-5-5 Signed-off-by: Michael Lieberman <mlieberman85@gmail.com>
…#487) darnit.storage was superseded by darnit.stores (feature 033); its only caller was the unused storage_config parameter of generate_attestation_from_results. Assisted-by: Claude:claude-opus-5-5 Signed-off-by: Michael Lieberman <mlieberman85@gmail.com>
…#487) The audit built one per run and put it on CheckContext.locator, but no handler read it, and its sync_to_project writer had no caller. The TOML locator configuration (locator.discover, use_locator) is unaffected. Assisted-by: Claude:claude-opus-5-5 Signed-off-by: Michael Lieberman <mlieberman85@gmail.com>
It was never published or installed; it reached uv.lock only through the packages/* workspace glob. Its adapters plugged into the adapter system, which nothing dispatches to. Assisted-by: Claude:claude-opus-5-5 Signed-off-by: Michael Lieberman <mlieberman85@gmail.com>
…evorg#487) The testchecks controls are verified by their TOML passes; the adapter classes, their three entry point groups, and [adapters.builtin] (whose class name did not exist) were never dispatched to. Assisted-by: Claude:claude-opus-5-5 Signed-off-by: Michael Lieberman <mlieberman85@gmail.com>
…itdevorg#487) No audit or remediation path dispatched through CheckAdapter, RemediationAdapter, AdapterRegistry, or the PluginRegistry adapter methods. PluginRegistry keeps framework discovery (discover_frameworks, list_frameworks, get_framework_info, get_framework_path). The module path policy (darnitdevorg#490) now serves its two remaining callers, ToolRegistry.load_handler and HandlerRegistry.get_handler. Assisted-by: Claude:claude-opus-5-5 Signed-off-by: Michael Lieberman <mlieberman85@gmail.com>
…ema (darnitdevorg#487) Removes AdapterType, the adapter config models, OutputMapping, CheckConfig, FrameworkDefaults, ControlConfig.check, FrameworkConfig defaults/adapters and their accessors, the EffectiveControl and EffectiveConfig adapter fields, the adapter= filter, and the adapter output of darnit plan and darnit validate. merge_control no longer takes defaults. A control-level check key now fails strict loading like any unknown control key. FrameworkConfig still accepts unknown top-level tables, so a leftover [adapters] or [defaults] table loads and is not read (framework-design Appendix C). The shipped and fixture TOMLs drop their [defaults] blocks. Assisted-by: Claude:claude-opus-5-5 Signed-off-by: Michael Lieberman <mlieberman85@gmail.com>
…evorg#487) Assisted-by: Claude:claude-opus-5-5 Signed-off-by: Michael Lieberman <mlieberman85@gmail.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Part 1 of 3 for #487: remove subsystems that no audit or remediation reaches. Each was re-checked against current main before removal:
packages/*/src, entry points, workspace config, CI, scripts, tests. This PR removes about 8,000 lines, including about 4,200 in product source. Each subsystem is its own commit, so it can be reviewed commit by commit. The spec commit comes first.AdapterRegistry, andUnifiedLocator.sync_to_projectfromframework-design.md(1.0.0-alpha.15; Appendix C lists the removals)remediation/routing.py, 15 of the 16 classes inthreat_model/models.py(StrideCategorystays),RemediationResult.to_markdowndarnit.storageandgenerate_attestation_from_results(storage_config=)storage_config; replaced bydarnit.storesdarnit.locate(UnifiedLocator) andCheckContext.locatorlocatorTOML config is a separate, live feature and stayspackages/darnit-pluginsdarnit-testchecksadapters and their three entry-point groups[adapters.builtin]named a class that doesn't existdarnit.core.adaptersand the adapter half ofPluginRegistryget_adapter_registryhad no callers; framework discovery staysControlConfig.check,FrameworkDefaults, theadapter=filter, adapter output inplanandvalidateAs decided for 0.2.0, there are no deprecation shims. Every removed public name has a BREAKING entry under CHANGELOG
### Removed.Load behavior:
check = {...}now fails strict loading.ControlConfigforbids extra keys, and the key never did anything.[adapters]table or[defaults] check_adapterstill loads (top-level tables allow extras) and has no effect. The shipped frameworks drop their[defaults]blocks.test_merger.pycover both cases.The module-path policy from #490 is still tested for its two remaining callers,
ToolRegistry.load_handlerandHandlerRegistry.get_handler.Parts 2 and 3, later PRs:
ComplianceImplementationmethods (get_rules_catalog,get_remediation_registry,get_all_controls,get_controls_by_level,register_controls), coordinated with Standardize on one sieve-handler registration method across plugins #451.darnit-exampleintodarnit-testchecks.Refs #487
Type of Change
Framework Changes Checklist
docs/architecture/framework-design.md) if behavior changeduv run python scripts/validate_sync.py --verboseand it passesTesting
uv run pytest tests/ -v): 5148 passed, 26 skippeduv run ruff check .)main has 5252 passing tests. Of the 104 fewer here:
Integration tests with GitHub Actions environment variables set: 334 passed. Smoke runs:
darnit audit .,darnit audit . -f reproducibility: run as before;darnit plananddarnit validateon testchecks and community-spec: work, without the adapter lines.AI assistance
Claude (Claude Code, claude-opus-5-5) re-checked each item in #487 against current main and made the removals, spec edits, and test updates. This description was also drafted with Claude. Commits carry an
Assisted-by: Claude:claude-opus-5-5trailer.Additional Notes
darnit plananddarnit validateon openssf-baseline crash on main withTypeErrorinsorted(by_level). Every baseline control loads withlevel=None.adapters_used: ["builtin"]. Attestation consumers can see that field, so dropping it is a spec change.EffectiveControl.remediation_handlerandremediation_configare also unread.docs/threatmodel/raw-findings.json,.project/threatmodel/mitigations.yaml) still names deleted files. The rendered threat-model docs got "(removed in 0.2.0, Remove dead adapter system, legacy storage backend, unused protocol methods, and other unreachable code (~3,500 lines) #487)" notes instead of being rewritten.docs/plugin-discovery-design.mdis a design record. It gets a header note rather than a rewrite.🤖 Generated with Claude Code