ic-memory 0.28.0

Durable stable-memory allocation governance for Internet Computer canisters
Documentation
# Authorized module cleanup

This procedure implements findings from [module surface hardening](module-surface-hardening.md)
or another named owning review. It does not issue an independent audit verdict.
Apply the [common authority and evidence contract](README.md).

1. Confirm the requested module and implementation scope, current source/dirty
   state, owner, finding and required proof. Existing bounded cleanup authority
   remains valid; an inspection-only request stops at recommendations.
2. Inspect callers and classify the candidate before editing. A small internal
   change can use a compact finding; public/generated/persisted/recovery and
   hot-path boundaries need their actual proof, not a mandatory large template.
3. Make the smallest justified deletion, visibility reduction, inline or owner
   move. Preserve unrelated work, product invariants, retained-state obligations
   and useful tests. Do not redesign the module or add generic machinery merely
   to shorten it. Low-confidence deletion waits for the missing evidence.
4. Update directly affected callers, generated producers/outputs, tests, docs
   and current changelog together within the authorized scope. Use the canonical
   generator. A compatibility-breaking removal needs the correct pending release
   line; metadata changes and release execution retain separate authority.
5. Format changed source and run the smallest meaningful owner/boundary checks.
   Apply the named measurement proof for changed hot or Wasm-sensitive shape.
   Do not substitute a broad gate for missing focused assertions or run one
   without authority. Preserve failed artifacts and report remaining limits.
6. Report changed behavior, validation, state-space/ownership effect, intentional
   retention and unresolved work. List every removed function, method and type
   with former owner, reason and replacement if any; distinguish moves/renames.

The original finding remains evidence. Record implementation and new checks with
their own source identity, and update the owning GitHub issue only within
authorized issue-write scope. Never rewrite a historical audit to imply the
repair was already present.