Use this template when a submitted app replaces legacy plugin behavior.
Use these exact field names in the submitted migration plan, then expand each section below:
legacyPluginId
newAppId
stateClasses
manifestCapabilities
appDataNamespaces
contentSubscriptions
identityGrants
appServiceDependencies
migrationSteps
backupRestorePolicy
reviewEvidence
redactionPolicy
knownNonGoals
legacyPluginId:newAppId:migrationOwner:targetStability:stableorexperimentallegacyBehaviorSummary:publicBetaSupportStatus:supported,unsupported, orfuture-work
List each legacy state class and the public-beta destination.
| State class | Destination | Automatic migration | Notes |
|---|---|---|---|
| Public content | Content profile or public read URI summary | yes/no | |
| Local config | App-data namespace | yes/no | |
| App data | App-data namespace and schema version | yes/no | |
| Identity/secrets | AppVault grant | no private export | |
| Subscriptions | Content subscriptions | yes/no | |
| Trust statements | Trust Graph Local RC import | yes/no | |
| Messages | App data or future app design | yes/no | |
| Diagnostics | Summary/digest only | yes/no |
List requested capabilities and the smallest reviewed reason for each.
| Capability | Required or optional | Reason |
|---|---|---|
platform.contract.read |
required | Read the local Platform API contract for compatibility checks. |
| Namespace | Current schema | Records | Migration steps | Backup/restore behavior |
|---|---|---|---|---|
ui-state |
1 |
UI preferences and safe summaries | additive | included |
| Subscription purpose | Source kind | Budget behavior | Stored summary |
|---|---|---|---|
| Example public source follow | public USK source | shared app-network budget | digest and status only |
| Grant | Purpose | Private material export |
|---|---|---|
vault.identities.use |
Bounded signing for public documents | never |
| Provider | Service | Scope | Context | Dependency kind | Degrade behavior |
|---|---|---|---|---|---|
trust-graph |
trust.score |
score.read |
message-author |
optional | disable feature |
- Inventory legacy state and side effects.
- Run dry-run import and report counts, digests, skipped classes, and warnings.
- Create backup/export before destructive migration.
- Apply additive app-data migrations.
- Request operator consent for any app-service grant delta.
- Verify restored state after backup/restore.
- Record unsupported or manual-only state classes.
State whether app data participates in app-data backup/restore. List restore prerequisites, unsupported cases, and whether migration can be retried after restore.
- manifest validation:
- API compatibility:
- UI lint:
- permission rationale:
- app-data schema notes:
- backup/restore notes:
- security notes:
- content format profile notes:
- app-service dependency notes:
- redaction scan:
Artifacts and support evidence must include only safe ids, counts, digests, status labels, capability names, service ids, schema versions, and redaction booleans. They must not include private insert URIs, private keys, app tokens, browser session tokens, cookies, form passwords, raw plugin state, raw social messages, raw trust statements, raw profile/feed documents, raw app-data values, raw signatures, local paths, raw FProxy HTML, or raw support bundles.
List every old plugin behavior that is not migrated automatically, including old plugin ABI/FCP compatibility, protocol compatibility, daemon-core hooks, ambient localhost RPC, raw FProxy scraping, private-key export, and unbounded crawling.