DD-333 Phase F.4 (plugins) — domain_scope schema + AJV gate #16
No reviewers
Labels
No labels
boundary:crosses
boundary:none
bug
devfu
documentation
duplicate
enhancement
epic
good first issue
help wanted
invalid
needs-info
needs-triage
question
ready-for-agent
ready-for-human
svd:fire
svd:go
svd:hold
svd:respec
svd:skip
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
Stallari/plugins!16
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "feat/dd-333-phase-f4-domain-scope"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary
Ships the stallari-plugins portion of DD-333 Phase F.4 — the 5th
granularity:dimension (domain_scope: single | multi | non-conforming-explicit) plus the build-catalog procedural cross-field gate that surfacesS-DOM-002findings when a tool'sdomain_scope=\"single\"declaration is contradicted by a user-domain-shapedscope/domain/domainNameargument.Cross-DD with DD-341 (domain substrate, all phases shipped 2026-05-22 in
v0.99.26.0) and DD-338 (forthcoming A.2.dom blade_meta.domain_attributionsubstrate). Sister to F.1'snon_conformance_rationalemechanism.Changes
Schema —
schemas/catalog-entry.schema.json:granularity.domain_scopeenum[single, multi, non-conforming-explicit]. Optional at F.4 (architect-lock #2 — promoted to required at F.4.b after A.2.dom blade backfill).non_conformance_rationale.domain_scope_unspecified: array<string>— additive escape hatch listing tools that cannot yet declaredomain_scope.scripts/build-catalog.js— newenforceDomainScope(raw, filename)procedural pass invoked per plugin entry inside the build loop:domain_scope_unspecifiedwithout own declaration receivegranularity.domain_scope=\"non-conforming-explicit\"in place (sister to existingscope_filteringderivation).domain_scope_unspecifiedmust cross-reference an actualtools[].name; throws on mismatch.domain_scope=\"single\"advertising a user-domain-shaped argument matching/^(scope|domain|domains|domainName|domain_name)$/iwith string-or-enum type, emit awarning-level finding. Iftool.descriptioncontains a// scope-arg-disclaimer: <reason>annotation (architect-lock #5), downgrade toinfo.Findings surface alongside Manifest UX warnings; severity
.warningat F.4 ship (mirrors S-DOM-001 v1 posture per architect-lock #7; promotion to.errorfollows A.2.dom backfill via separate spec).Fixtures —
schemas/fixtures/catalog-entries/tool-domain-scope-*.json(6 new):single-honest,multi-honest,single-with-scope-arg-violation,unspecified-derives,disclaimer,bogus-enum.Example packs —
examples/domain-scope-pack/(3 new YAMLs):Tests —
scripts/domain-scope.test.js(8 cases):Verification
npm test— 178/178 green (incl. 8 new domain-scope cases; pre-existing 170 unaffected).node scripts/build-catalog.js— clean against existing 11 packs + 59 plugin entries (zero new S-DOM-002 findings, zero new AJV rejections; nodomain_scope:declared anywhere in the corpus yet).Out of scope (per spec)
_meta.domain_attributionsubstrate (DD-338 A.2.dom).domain_scopeto required ingranularity.required(F.4.b)..error(post-A.2.dom).domain_scope).Test plan
Convention compliance
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>; commit ssh-signed by Piers.domain_scopeoptional; legacy corpus continues to validate.tools[].arguments[]for scope-arg heuristic). Architect appends DD-333 reader-audit table extension post-merge.🤖 Generated with Claude Code