argand-site-registry/docs/superpowers/plans/2026-09-12-standalone.md

2.7 KiB

Standalone Site Registry Implementation Plan

For agentic workers: Use superpowers:executing-plans inline. No subagents or Argand worktrees.

Goal: Produce a reusable standalone repository and verifiable source release.

Architecture: Retain the registry and atomic helper as two workspace crates. Preserve runtime bytes and wire packaging, consumer examples and release gates around their existing APIs. Use an isolated build directory.

Tech Stack: Rust, SQLite, Python 3.11 standard library tooling, OpenSSH, Forgejo Actions.

Task 1: Extract the verified baseline

  • Verify signed Argand commit 47911062b00d87f215ba61c41965faf8a7f4b7f7.
  • Export only engine/crates/argand-site-registry and engine/crates/argand-atomic.
  • Write UPSTREAM.json with original path/blob/hash evidence and a two-crate Cargo.toml.
  • Prune the inherited lock with cargo metadata --offline --format-version 1; retain exact dependency versions.

Task 2: Make standalone use and trust policy concrete

  • Add root README, LICENSE, source-license entrypoint, CONTRIBUTING, SECURITY and governance docs.
  • Add Rust examples/lookup.rs and Python examples/lookup.py consumers of existing query contracts.
  • Run both consumers on the native fixture and compare full lookup outputs, including attribution.

Task 3: Package and verify source releases

  • Add deterministic source archive and verification commands in scripts/source_release.py.
  • Test determinism, dirty-tree refusal, no-clobber, tampering and unsafe archive members in tests/test_source_release.py.
  • Add scripts/check.sh and .forgejo/workflows/ci.yml using an isolated runner without release secrets.
  • Document explicit release signing, downstream pins and incident response in docs/RELEASING.md and docs/TRUST.md.

Task 4: Validate and land the bounded task

  • Run cargo fmt --all -- --check, cargo check --workspace --all-targets --locked --offline, cargo clippy --workspace --all-targets --locked --offline -- -D warnings, cargo test --workspace --locked --offline and strict cargo doc.
  • Build the native executable and retain the all-five-source CLI fixture outside the repo.
  • Rebuild/run tests from the release archive outside the original workspace.
  • Review every initial tracked file and dependency change, sign the local commit and release receipt.
  • Record exact validation, publication and Argand cutover state; release any coordination window.

Acceptance and operational limits are recorded in docs/VALIDATION.md. The public repository is created with Actions disabled until an isolated runner is provisioned. Argand remains on its embedded dependency; no shared window was taken.