Package Uninstall

The rule (policy package-uninstall-request, register). A platform admin uninstalls a package through ONE durable request, in two phases. Phase 1 needs no confirmation and destroys no data. Phase 2 — the irreversible drop of the package's partition — runs only after the requester repeats the partition name; without that the package stays uninstalled with its data retained, and the request says so.

It sits beside Module Reload and has the same shape: a node at Admin/_PackageUninstall/{id} (PackageUninstallRequest), written only by PackageUninstall.Request as System after the caller was authorised, executed by PackageUninstallExecutor on the request node's own hub, every step a stream.Update.

Phase 1 — uninstall, retain the data

Refused by name, before anything is touched:

Then, in order: the module is retired (its landed generation disabled; unloaded live through IModuleLiveActivation.Retire where the loader can, else exactly one automatic restart through the self-update restart path, stamped first); the partition's hubs are closed (DisposeRequest to every hosted hub at or under it, from the off-router issuing hub); the install record is removed; and the request moves to AwaitingConfirmation with the preview — per partition: whether a storage provider reports a per-partition store (Postgres: the schema), rows per table (mesh_nodes, and each satellite segment _Access, _Thread, …), whether a sync configuration ({partition}/_GitSync) is present, and what cannot be counted here, named:

From this point no unattended pass installs the package again — not the seed, not the platform baseline, not a feature flag (InstanceAutoRegistrationService.InstallAll consults PackageUninstallExecutor.UninstalledHere). A person installing it again lifts that: the block only applies while no install record exists.

Phase 2 — drop the data, on confirmation

ConfirmationRequired is the partition name. The requester sends it back (PackageUninstall.Confirm, recorded with who and when). A confirmation is accepted only while the request AWAITS one — it answers the preview, so one sent before the preview exists is refused and records nothing, and phase 1 clears any confirmation it finds and stamps awaitingConfirmationAt. The executor is the authority: a different string, a confirmation from anyone but the requester, a request that names no requester, or a confirmation older than the preview is refused by name (confirmationRefusal) and nothing is dropped. A matching one runs the platform's governed whole-partition teardown, as System, after closing the partition's hubs again: PartitionTeardown.TearDownPartition — the store dropped on every storage provider (Postgres DROP SCHEMA … CASCADE, satellite tables with it, so the _GitSync configuration and the partition's NodeType nodes go too), the cached queries anchored to it evicted, and the Admin/Partition/{partition} registry record deleted. The request records each partition's teardown sentence and ends Done. Never raw SQL.

Surfaces

surface how
MCP uninstall_package (MeshWeaver.Plugins) MeshOperations.UninstallPackage(package, reason) answers the preview and the exact confirmation string; UninstallPackage(requestPath: …, confirmation: …) confirms. Platform admins only.
the platform's own code PackageUninstall.Request / PackageUninstall.Confirm

What is NOT established