[docs] keyman: rewrite the README, close the audit
Phase 9 of packages/keyman/docs/PLAN.md; closes AUDIT §5.2, §5.3, §5.4, §5.5, and the §4 one-liners no phase had claimed (§4.1–§4.4, §3.7). The README is the only document that ships (package.json files: dist, README.md, LICENSE), and it described four of nine menu entries, invented key rotation, told the user to run ssh-keygen by hand, asked them to write a .gitignore keyman now writes, and mentioned none of the command line. It is rewritten against the code: every operation, the rotate/retire sequence, the id_ prefix and what happens to keys without it, installation with the scope mapping (never a bare --registry, which would send 55 transitive dependencies to a registry that has never heard of them), the configuration semantics including which relative path resolves against what, and the Phase 5 migration for a split vault. The CLI section is helpText() verbatim, with tests/readme.test.ts asserting the two are identical and that every menu label appears — so a flag or an operation added later fails the gate instead of shipping undocumented. That is the part that keeps this from drifting again. Also: index.ts loses the bin's shebang (it is only ever imported), exports the config types so a consumer can name what loadConfig returns, and re-exports the update module wholesale rather than half of it by name — verified by importing the built dist/index.js and reading its keys. The narrow surface is now a comment stating the rule rather than an accident. AUDIT.md marks all 30 findings closed except the second half of §1.8, keeping each finding's text as the record with what closed it quoted underneath, the way DOCS-AUDIT.md does. PLAN.md gains a status section naming the three deviations. Root CLAUDE.md records the keyman architecture as it now is, including the deliberate `resolution` divergence from nopy. DOCS-AUDIT.md §2.10, §6.4 and the §7 keyman-config entry are amended in the working tree but left unstaged, since that file carries unrelated WIP. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -9,6 +9,25 @@ boundary comes first because it makes every later phase's failure mode legible,
|
||||
and the config threading comes late because it is the only phase that rewrites
|
||||
existing test assertions.
|
||||
|
||||
## Status
|
||||
|
||||
**All ten phases have landed**, one commit each, on the `keyman-remediation`
|
||||
branch. Three deviations worth knowing about:
|
||||
|
||||
- **Phase 6's literal instruction was impossible.** "Move the `mkdirSync` after
|
||||
`age` succeeds" cannot be done — `age -o` will not create its output directory.
|
||||
The goal (no leftover directory) is met by cleaning up on failure instead, which
|
||||
also removes a truncated `.age` the plan had not accounted for.
|
||||
- **§1.8 is half done, deliberately**, exactly as the plan asked: the skipped-key
|
||||
report is in, the layout change that would make non-`id_*` keys manageable is
|
||||
not. See `AUDIT.md` §1.8.
|
||||
- **Rollout has not been done.** No version bump, no tag, nothing published — the
|
||||
cut points below are still proposals, and pushing this branch to `main` would
|
||||
publish a snapshot, so that is the user's call to make.
|
||||
|
||||
Both open decisions were resolved the way the plan recommended: the `resolution`
|
||||
machinery was deleted, and rotation was built.
|
||||
|
||||
## Verified before planning
|
||||
|
||||
Four things the fixes depend on, checked by running them rather than assumed —
|
||||
|
||||
Reference in New Issue
Block a user