internal/

directory
v0.0.0-...-804b954 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Aug 13, 2026 License: MIT

Directories

Path Synopsis
Package afkevidence validates bounded, secret-safe direct-main evidence logs.
Package afkevidence validates bounded, secret-safe direct-main evidence logs.
Package agentspecbackfill owns the pure immutable request, verification, and archive seam for Agent-spec backfill.
Package agentspecbackfill owns the pure immutable request, verification, and archive seam for Agent-spec backfill.
Package agentspecbackfillcr owns the structural, canonical AgentSpecBackfill request and status wires.
Package agentspecbackfillcr owns the structural, canonical AgentSpecBackfill request and status wires.
Package agentspecbackfillcrd renders and validates the structural AgentSpecBackfill Kubernetes CRD.
Package agentspecbackfillcrd renders and validates the structural AgentSpecBackfill Kubernetes CRD.
Package agentspecbackfillexportprocess composes the separately-authorized terminal archive exporter.
Package agentspecbackfillexportprocess composes the separately-authorized terminal archive exporter.
Package agentspecbackfillkube adapts the fixed AgentSpecBackfill Kubernetes resource to controller ports.
Package agentspecbackfillkube adapts the fixed AgentSpecBackfill Kubernetes resource to controller ports.
Package agentspecbackfillprocess composes the AgentSpecBackfill controller from explicit, narrow ports.
Package agentspecbackfillprocess composes the AgentSpecBackfill controller from explicit, narrow ports.
Package approval owns the pure, persistence-free human-approval state machine.
Package approval owns the pure, persistence-free human-approval state machine.
Package clock provides explicit time sources for deterministic runtime decisions.
Package clock provides explicit time sources for deterministic runtime decisions.
Package docsrefresh deterministically renders allow-listed public documentation.
Package docsrefresh deterministically renders allow-listed public documentation.
Package egressproxy provides an exact-target forward proxy for trust-scoped workloads.
Package egressproxy provides an exact-target forward proxy for trust-scoped workloads.
Package firecracker owns the Linux/KVM-only, internal Firecracker host profile.
Package firecracker owns the Linux/KVM-only, internal Firecracker host profile.
Package firecrackerbootprobecomposition owns the private M4 command handoff.
Package firecrackerbootprobecomposition owns the private M4 command handoff.
Package firecrackerbootprobejournal owns the host-instance-exclusive durable launch-intent record required before an M4 Jailer may start.
Package firecrackerbootprobejournal owns the host-instance-exclusive durable launch-intent record required before an M4 Jailer may start.
Package firecrackerbootprobelease owns the private persisted lease guard for one sealed Firecracker boot probe.
Package firecrackerbootprobelease owns the private persisted lease guard for one sealed Firecracker boot probe.
Package firecrackerbootprobeprotocol owns the private signed M3-to-M4 boot-probe command and M4 observation wire.
Package firecrackerbootprobeprotocol owns the private signed M3-to-M4 boot-probe command and M4 observation wire.
Package firecrackerbootprobev2 owns the private, persisted successor and acknowledgement contract for one sealed Firecracker boot-probe lease.
Package firecrackerbootprobev2 owns the private, persisted successor and acknowledgement contract for one sealed Firecracker boot-probe lease.
Package firecrackerlaunchgrant owns the private, operator-only M3/M4 boot-probe binding.
Package firecrackerlaunchgrant owns the private, operator-only M3/M4 boot-probe binding.
Package identity defines runtime-owned opaque identifiers.
Package identity defines runtime-owned opaque identifiers.
Package localdemoworker composes the declared deterministic local Stack fixture.
Package localdemoworker composes the declared deterministic local Stack fixture.
Package mcptool implements the private, bounded Streamable HTTP MCP client used by the runtime tool adapter.
Package mcptool implements the private, bounded Streamable HTTP MCP client used by the runtime tool adapter.
Package milestone builds retained status evidence and notification attempts.
Package milestone builds retained status evidence and notification attempts.
Package nowait checks owned Go code for nondeterministic real-time waiting.
Package nowait checks owned Go code for nondeterministic real-time waiting.
Package openapicontract validates the repository-owned public Agent Runtime OpenAPI contract.
Package openapicontract validates the repository-owned public Agent Runtime OpenAPI contract.
providers
codexsubscription
Package codexsubscription owns the fail-closed Codex subscription release gate.
Package codexsubscription owns the fail-closed Codex subscription release gate.
Package roles validates trust-scoped runtime process composition.
Package roles validates trust-scoped runtime process composition.
runtime
kernel
Package kernel owns deterministic Agent, Session, Input, Turn, and Product-event transitions.
Package kernel owns deterministic Agent, Session, Input, Turn, and Product-event transitions.
Package runtimeadmission owns the content-reference and durable SendInput admission seam.
Package runtimeadmission owns the content-reference and durable SendInput admission seam.
Package runtimeapi exposes the public, Temporal-free HTTP boundary of Agent Runtime.
Package runtimeapi exposes the public, Temporal-free HTTP boundary of Agent Runtime.
Package runtimeapiprocess composes the separately runnable public API role from explicit operator configuration.
Package runtimeapiprocess composes the separately runnable public API role from explicit operator configuration.
Package runtimeconfig defines explicit, validated process configuration.
Package runtimeconfig defines explicit, validated process configuration.
Package runtimecontent owns runtime-scoped immutable Agent specification and Input content.
Package runtimecontent owns runtime-scoped immutable Agent specification and Input content.
Package runtimeerror adds safe context at runtime boundaries.
Package runtimeerror adds safe context at runtime boundaries.
Package runtimemodel owns the narrow model-effect worker seam.
Package runtimemodel owns the narrow model-effect worker seam.
Package runtimeoperations owns the protected operational-evidence drill.
Package runtimeoperations owns the protected operational-evidence drill.
Package runtimeorchestration contains the private Temporal composition for state-backed Session work.
Package runtimeorchestration contains the private Temporal composition for state-backed Session work.
Package runtimepostgres owns the PostgreSQL implementation of runtime-state persistence.
Package runtimepostgres owns the PostgreSQL implementation of runtime-state persistence.
Package runtimestate defines the metadata-only S2/S7 runtime lifecycle authority.
Package runtimestate defines the metadata-only S2/S7 runtime lifecycle authority.
Package runtimetool owns capability-bound external tool execution.
Package runtimetool owns capability-bound external tool execution.
Package sandboxauthority implements internal command-secret and egress authority contracts.
Package sandboxauthority implements internal command-secret and egress authority contracts.
Package sandboxcontrolapi serves the private sandbox.control/v1 control process without exposing persistence, authentication, or transport types in the public sandbox SDK.
Package sandboxcontrolapi serves the private sandbox.control/v1 control process without exposing persistence, authentication, or transport types in the public sandbox SDK.
Package sandboxcontrolprocess composes the separately runnable sandbox control role from one strict operator document and explicit secret sources.
Package sandboxcontrolprocess composes the separately runnable sandbox control role from one strict operator document and explicit secret sources.
Package sandboxhostapi exposes the private mutually authenticated host control surface.
Package sandboxhostapi exposes the private mutually authenticated host control surface.
Package sandboxhostbootstrap enrolls one already-mounted local or CI host identity in the sandbox control ledger.
Package sandboxhostbootstrap enrolls one already-mounted local or CI host identity in the sandbox control ledger.
Package sandboxhostjournal persists the reference host's receipt journal before any fake effect.
Package sandboxhostjournal persists the reference host's receipt journal before any fake effect.
Package sandboxhostprocess composes the separately runnable reference host.
Package sandboxhostprocess composes the separately runnable reference host.
Package sandboxhostprotocol owns the private, bounded host-control wire contract.
Package sandboxhostprotocol owns the private, bounded host-control wire contract.
Package sandboxreaperprocess composes the independently deployable durable sandbox reconciliation owner.
Package sandboxreaperprocess composes the independently deployable durable sandbox reconciliation owner.
Package sandboxresource owns durable, principal-scoped volume, snapshot and mount-lease manifests.
Package sandboxresource owns durable, principal-scoped volume, snapshot and mount-lease manifests.
Package sandboxtransfer implements the bounded portable workspace transfer data plane used by sandbox host adapters.
Package sandboxtransfer implements the bounded portable workspace transfer data plane used by sandbox host adapters.
Package stack defines the typed desired-state input for operator-owned infrastructure.
Package stack defines the typed desired-state input for operator-owned infrastructure.
Package subscriptioncanary validates the operator contract required before a protected subscription-model canary.
Package subscriptioncanary validates the operator contract required before a protected subscription-model canary.
Package temporalpayloadruntime owns the sole runtime Temporal client and worker converter factory.
Package temporalpayloadruntime owns the sole runtime Temporal client and worker converter factory.
Package temporalpayloaduiprocess composes the local Temporal UI payload-inspection handler from explicit policy.
Package temporalpayloaduiprocess composes the local Temporal UI payload-inspection handler from explicit policy.
Package tooldispatch exposes the private trigger boundary for broker-owned tool dispatch.
Package tooldispatch exposes the private trigger boundary for broker-owned tool dispatch.
Package toolpolicy evaluates one already-normalized tool intent against one immutable operator-authored policy projection.
Package toolpolicy evaluates one already-normalized tool intent against one immutable operator-authored policy projection.
Package toolschema owns the deliberately small, versioned JSON Schema profile used by model-visible tool catalogs.
Package toolschema owns the deliberately small, versioned JSON Schema profile used by model-visible tool catalogs.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL