Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
18 changes: 9 additions & 9 deletions extensibility/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -14,15 +14,15 @@ sidebar_order: 10
Index of the plugin-ecosystem extensibility contracts. Normative detail
lives in the linked pages; this index carries no duplicate normative prose.

| Document | Status | Purpose |
| -------------------------------------------------------------------------------- | ------ | ----------------------------------------------------------------------------------------------------------- |
| [Plugin system](plugin-system.md) | Draft | Plugin boundaries, isolation, composition, capabilities, and lifecycle. |
| [Plugin package management](package-management.md) | Draft | Manifests, sources, updates, rollback, and trust. |
| [Plugin history and storage policy](history-and-storage-policy.md) | Draft | Plugin-facing history and storage ownership, privacy, retention, capabilities, and page sets. |
| [Lua UI Component Model (Candidate)](lua-ui-component-model-candidate.md) | Draft | Candidate five-level Lua UI component ecosystem, theming, accessibility, and panel services. |
| [Plugin UI Slot Inventory (Candidate)](plugin-ui-slot-inventory-candidate.md) | Draft | Candidate per-slot purpose, multiplicity, bounds, and conflict resolution for the accepted closed slot set. |
| [TUI to Native Migration Path (Candidate)](tui-to-native-migration-candidate.md) | Draft | Candidate L0-L4 migration ladder, per-application-type guidance, and Backend Service Plugin pattern. |
| [Frequently asked questions](faq.md) | Draft | Sandboxing, Fuel budgeting, Layer 2 external tools, Host Fuzzy Service, and lifecycle management. |
| Document | Status | Purpose |
| -------------------------------------------------------------------------------- | -------- | ----------------------------------------------------------------------------------------------------------- |
| [Plugin system](plugin-system.md) | Draft | Plugin boundaries, isolation, composition, capabilities, and lifecycle. |
| [Plugin package management](package-management.md) | Draft | Manifests, sources, updates, rollback, and trust. |
| [Plugin history and storage policy](history-and-storage-policy.md) | Accepted | Plugin-facing history and storage ownership, privacy, retention, capabilities, and page sets. |
| [Lua UI Component Model (Candidate)](lua-ui-component-model-candidate.md) | Draft | Candidate five-level Lua UI component ecosystem, theming, accessibility, and panel services. |
| [Plugin UI Slot Inventory (Candidate)](plugin-ui-slot-inventory-candidate.md) | Draft | Candidate per-slot purpose, multiplicity, bounds, and conflict resolution for the accepted closed slot set. |
| [TUI to Native Migration Path (Candidate)](tui-to-native-migration-candidate.md) | Draft | Candidate L0-L4 migration ladder, per-application-type guidance, and Backend Service Plugin pattern. |
| [Frequently asked questions](faq.md) | Draft | Sandboxing, Fuel budgeting, Layer 2 external tools, Host Fuzzy Service, and lifecycle management. |

## Authority and status

Expand Down
52 changes: 28 additions & 24 deletions extensibility/history-and-storage-policy.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ description: Plugin-facing policy for history and storage ownership privacy rete
category: extensibility
audience: plugin-author
document_type: specification
status: draft
status: accepted
website_publish: true
sidebar_order: 21
---
Expand All @@ -13,23 +13,25 @@ sidebar_order: 21

## Document status

Draft. This document is the `W-137` deliverable for the plugin-facing history
Accepted. This document is the `W-137` deliverable for the plugin-facing history
and storage policy that sits above the Core storage boundary. That boundary -
the reconciliation of the four storage objects (segmented transcript, command
history, session snapshots, and per-plugin key-value state) - is owned by
`W-131` and remains a draft; this page specializes it for plugin authors and
must not weaken it. This document does not accept any candidate contract, does
not authorize implementation, and does not describe implemented behavior.
Because the upstream reconciliation is not yet authoritative, every ownership,
privacy, and retention statement here is proposed direction until both the
boundary and this policy pass independent review. Frontmatter `status` is
`draft` per the repository metadata schema.

- Owning task: `W-137` (bitty-plugins-docs), CarryCtx `CTX-0072`, Issue
[#131](https://github.com/bitty-terminal/bitty-plugins-docs/issues/131).
`W-131` and now accepted; this page specializes it for plugin authors and
must not weaken it. This document accepts the plugin-facing boundary decision;
it does not accept downstream SDK/Core/plugin contracts, does not authorize
implementation, and does not describe implemented behavior. Every ownership,
privacy, and retention statement here is decided direction for plugins;
downstream spellings and mechanics remain candidate per Open points.
Frontmatter `status` is `accepted` per the repository metadata schema.

- Owning task: `W-137` promotion (bitty-plugins-docs), CarryCtx `CTX-0075`,
Issue
[#137](https://github.com/bitty-terminal/bitty-plugins-docs/issues/137).
Created by `W-137` (CarryCtx `CTX-0072`, Issue #131); see References.
- Upstream reconciliation:
[Storage and History Boundary](https://github.com/bitty-terminal/bitty-docs/blob/main/docs/development/storage-and-history-boundary.md)
(`W-131`, draft), grounded in
(`W-131`, accepted), grounded in
[ADR 0016](https://github.com/bitty-terminal/bitty-docs/blob/main/docs/decisions/adrs/ADR-0016-execution-graphics-accessibility-storage-platform-boundaries.md)
Boundary 4 and binding constraints 8 and 9.
- Downstream owners named but not decided here: `W-139`
Expand Down Expand Up @@ -319,8 +321,9 @@ what the page set must cover and does not decide the plugin's content.

## Security review

Independent security review is required before this policy merges. The
reviewers must confirm that no object is persisted by default when it carries
Independent security review sign-off is recorded for this promotion (boundary-decision scope; verification evidence stays with `W-139`/`W-146`). The
reviewers confirmed that no object is persisted by default when it carries
sensitive terminal-derived content, that capture and input recording stay
sensitive terminal-derived content, that capture and input recording stay
separate opt-ins, that per-plugin KV is not used as a shim for terminal output
or secrets, that no plugin-reachable path opens a database, segment file, or
Expand Down Expand Up @@ -455,25 +458,26 @@ milestone, and no implementation evidence forces one yet.
and evidence, not placeholders.
- The Core storage boundary, the SDK surface, and the history plugin package
are cross-linked without deciding their content.
- Candidate status remains candidate, no object or boundary is described as
accepted or implemented, and no P0 control is weakened.
- Policy boundary is accepted; downstream SDK/Core/plugin objects remain candidate, nothing is described as implemented, and no P0 control is weakened.
- The documentation index routes to this page, and `just check` passes with
zero issues.

## P0 Review Sign-off

| Role | Scope | Requirement |
| ------------------- | --------------------------------------------------------------------------------------- | ------------------------------------------------------------------------- |
| `category-owner` | Object ownership, capability rules, and public-API policy correctness | Approve; confirms plugin ownership, no-bypass, and delegation to `W-139`. |
| `security-reviewer` | Privacy default, capture opt-in, redaction, purge, capability, external-argument safety | Independent security review required before merge. |
| `docs-curator` | Taxonomy, metadata, links, terminology, and index synchronization | Approve; confirms discoverability, schema, and page-set guidance. |
| Role | Scope | Requirement |
| ------------------- | --------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------- |
| `category-owner` | Object ownership, capability rules, and public-API policy correctness | Approve; confirms plugin ownership, no-bypass, and delegation to `W-139`. |
| `security-reviewer` | Privacy default, capture opt-in, redaction, purge, capability, external-argument safety | Approve recorded for promotion; verification evidence stays with `W-139`/`W-146`. |
| `docs-curator` | Taxonomy, metadata, links, terminology, and index synchronization | Approve; confirms discoverability, schema, and page-set guidance. |

## References

- Issue [#131](https://github.com/bitty-terminal/bitty-plugins-docs/issues/131)
(CarryCtx `CTX-0072`, plan key `W-137`).
(CarryCtx `CTX-0072`, plan key `W-137`) and promotion Issue
[#137](https://github.com/bitty-terminal/bitty-plugins-docs/issues/137)
(CarryCtx `CTX-0075`).
- [Storage and History Boundary](https://github.com/bitty-terminal/bitty-docs/blob/main/docs/development/storage-and-history-boundary.md)
(`W-131`, draft) and
(`W-131`, accepted) and
[ADR 0016](https://github.com/bitty-terminal/bitty-docs/blob/main/docs/decisions/adrs/ADR-0016-execution-graphics-accessibility-storage-platform-boundaries.md).
- [Security overview](https://github.com/bitty-terminal/bitty-docs/blob/main/docs/security/overview.md),
[threat model](https://github.com/bitty-terminal/bitty-docs/blob/main/docs/security/threat-model.md),
Expand Down
Loading