corvint

module
v0.7.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 23, 2026 License: AGPL-3.0, AGPL-3.0-or-later

README

Corvint

Context your agents can cite. Changes your reviewers can check.

Corvint is a local-first context compiler for coding agents. Before an edit it hands the agent Git-pinned evidence with the reason each item is there. After the edit it binds every diff hunk to cited evidence, an explicit unknown, or a verifiable mechanical exception, in a portable sidecar that CI checks without an LLM.

One native Go binary. No account, hosted service, database, embeddings, or permanent daemon. go.mod declares no module requirements. Read commands change nothing. Version 0.7.0 is an experimental prerelease; what works today and what is still an open gate.

Why Corvint

Coding agents do not run out of tokens. They run out of evidence. A grep or an embedding search returns text; the agent still has to guess which file governs the change, which test constrains it, and what it never saw. The reviewer then inherits a diff with no trail back to why.

Corvint replaces the guess with a receipt and the opaque diff with a map.

  • Every result explains itself. Each item in a packet carries the Git blob it came from, the path and line, the authority that admitted it, a confidence level, and a plain-language inclusion reason. A reviewer can follow any citation to immutable content.
  • Your repository is the authority. Agent instructions, accepted decisions, and specs you already keep outrank syntax matches, history correlations, and learned traces. Corvint uses the documents you have; it introduces no new spec language.
  • It says what it does not know. Coverage, omissions, uncertainty, freshness, and explicit abstention are fields in the receipt, not an afterthought. Missing evidence produces an unknown, never invented certainty.
  • Reviewers get a disposition for every hunk. A Change Evidence Map (CEM) links each textual hunk of a diff to cited evidence, an explicit unknown, or a mechanical exception. The verifier checks patch, hunk, blob, and span identity locally, with no LLM, no index, and no shared service. The protocol is Apache-2.0, so anyone can implement or verify it.
  • Nothing to run, nothing to trust. The core reads Git and prints JSON. Default evidence flows make no network call. query, context, impact, affected, and prove report mutates: false; learning happens only on an explicit record, stays local, bounded, and secret-screened, and cannot change ranking without passing a pinned evaluation gate.

Sixty seconds on this repository

You need Git and Go 1.27 (go.mod requires 1.27.1; the full gate pins exactly go1.27.1). From a checkout on Darwin or Linux:

GOTOOLCHAIN=local go run ./cmd/corvint impact cmd/corvint/main.go --limit 5

That asks what a change to the CLI entry point could affect. The receipt names the requested path, the tests that constrain it, the reason each result was admitted, and what the result limit left out. No installation or account is needed. Abridged output from a 0.4.0a4 checkout (fields, results, and evidence records omitted; shown values unchanged):

{
  "context": {
    "results": [
      {
        "id": "cmd/corvint/main.go",
        "kind": "path",
        "evidence": [
          {
            "authority": "git-tree",
            "confidence": "authoritative",
            "blob_hash": "b6a95d5864bcbaaebb4832e8eea9f0d4966478ea",
            "line": 1,
            "reason": "requested changed path"
          }
        ]
      },
      {
        "id": "cmd/corvint/harness_context_test.go",
        "kind": "test",
        "evidence": [
          {
            "authority": "test-marker",
            "confidence": "high",
            "blob_hash": "4ea3efb9bc13016ec38f4df1d6a4f1ee363366a2",
            "line": 30,
            "reason": "same-package test carries feature:session-revocation"
          },
          {
            "authority": "test-convention",
            "confidence": "medium",
            "blob_hash": "4ea3efb9bc13016ec38f4df1d6a4f1ee363366a2",
            "line": 1,
            "reason": "same-package test for cmd/corvint/main.go"
          }
        ]
      }
    ],
    "freshness": {
      "scope": "git",
      "state": "fresh"
    },
    "coverage": {
      "included_results": 5,
      "omitted_results": 175,
      "uncertainty": [
        "175 ranked results omitted by result limit"
      ]
    }
  },
  "mutates": false,
  "tool": "impact"
}

Install the binary to use Corvint in any supported Git repository:

mkdir -p "$HOME/.local/bin"
GOTOOLCHAIN=local go build -ldflags "-X main.build=$(git rev-list --count --first-parent HEAD)" -o "$HOME/.local/bin/corvint" ./cmd/corvint
export PATH="$HOME/.local/bin:$PATH"
corvint --version

Versioned release assets are on the releases page; the native archive whose attached qualification evidence names your platform needs Git but no Go compiler. The installation guide covers archive checks, first use, optional workflow tools, upgrades, and removal.

The workflow

When Ask Corvint to What you get back
Before an edit Find the context and the likely impact Git-pinned paths, governing documents, related tests, and the reason each was included
While working Show the evidence boundary Freshness, coverage, omissions, uncertainty, and explicit abstention
At review and in CI Attach a Change Evidence Map to the diff A disposition for every textual hunk that CI verifies locally
Command Purpose
corvint query --task "change session revocation" --budget-bytes 8000 Find task evidence within a byte budget
corvint context --task "change session revocation" --subject src/session.py Build a packet around a tracked subject
corvint impact src/session.py Inspect the likely impact of a tracked path
corvint affected Plan Go test packages for the dirty worktree; run none
corvint prove --task "change session revocation" Produce a falsifiable packet with freshness and uncertainty
corvint overview / corvint features Inspect a clean repository overview or inferred feature candidates
corvint review --base FULL_BASE_SHA --max-refs 8 Prepare immutable-range test advice and bounded branch-overlap hints

Replace src/session.py with a path tracked in your repository. Go, Python, and JS/TS have reverse-import impact rules; other indexed languages do not all receive equivalent analysis. corvint COMMAND --help prints each command's contract. To select a repository explicitly, put --root /path/to/repo before the command.

The experimental features, overview, and review commands require a clean tree and expose inferred scope, omissions, and unsupported cases. They do not accept requirements or execute suggested commands. review requires a full ancestor base SHA and does not replace CEM or tests.

Give the agent a useful next step

A context packet can identify a test counterpart and say why it matters. From the session-revocation fixture (fields omitted; values unchanged):

{
  "id": "src/test_session.py",
  "kind": "pair",
  "action": "Update this test: it is the subject's test counterpart, so a behaviour change in the subject changes what it must assert.",
  "evidence": [{
    "authority": "test-convention",
    "confidence": "high",
    "blob_hash": "50404716f6d80b4cbfc88c61529c78bd748250c4",
    "reason": "test counterpart of src/session.py"
  }]
}

After src/session.py is edited, prove reports mixed-worktree freshness and names the changed path. Trace recording is blocked for that mixed state. The receipt keeps working changes apart from committed evidence, so the agent and the reviewer can see the difference.

Put the evidence beside the diff

A Change Evidence Map is a portable sidecar that travels in the repository and verifies with no LLM, no index, and no shared service. For a committed change, replace BASE_SHA with its base commit and the example citation with a span that exists at that base:

corvint cem prepare --base BASE_SHA --target HEAD
corvint cem cite --map .corvint/change.cem.json --hunk 1 \
  --evidence-path docs/decisions/0001-session-revocation.md --lines 5:5 --relation decision
corvint cem status --map .corvint/change.cem.json \
  --expected-base BASE_SHA --target HEAD --max-unknown 0 --max-mechanical 0

For a one-hunk change, prepare produces an incomplete worklist; after the citation, status reports "state": "ready-for-ci" with a stable span. A larger diff needs a disposition for every hunk, and the worklist says what remains. The policy above permits no unknowns and no mechanical exceptions. CEM in CI wires that policy into a pipeline.

The nextActions argv that cem prepare and ocm prepare return starts with the command name corvint. Run it with a corvint binary in that first position, or build one under that name (go build -o corvint ./cmd/corvint).

The verifier proves structural integrity: patch, hunk, blob, span, and mapping identity. It does not prove semantic support, causality, test adequacy, or program correctness, and Corvint says so. The wire format, schemas, and conformance vectors are Apache-2.0.

Works where agents work

The host adapters run corvint from PATH, so install it there first. Every adapter is a developer preview reporting FALLBACK, not FULL (compatibility matrix):

  • Codex, Claude Code, Gemini CLI, OpenCode, and Pi share one bounded lifecycle receipt (corvint help harness event).
  • VS Code: evidence views plus opt-in automatic unit/E2E reruns on editor saves. Install the VSIX and providers, configure the project's toolchains and suite, then enable corvint.liveTests.enabled. It reruns the configured suite; passing tests do not establish test adequacy or authority. Setup and stop instructions.
  • MCP: corvint-mcp is an experimental local stdio server that exposes read-only receipts (GOTOOLCHAIN=local go build -o ./bin/corvint-mcp ./cmd/corvint-mcp). corvint-docs-mcp drafts source-bound documentation and checks a draft against source; corvint-test-validity-mcp lets agents inspect retained test observations. Both need a compatible client and an explicit root; setup and boundaries.
  • Source-bound documentation: the experimental docs maintain --watch command refreshes a generated page block as eligible source commits land, preserves surrounding prose, and stops on outside page edits. It runs explicitly in the foreground on macOS/Linux with time and write limits; preview, apply, and watch.
  • The optional workflow tools below: tickets, dashboard, console, test providers and release checks. None is a hosted service and none dispatches agents.

Corvint uses the corvint-* wire/profile namespace, corvint.* MCP tools, and canonical .corvint and .context-corvint repository paths. Those are protocol and state contracts and are versioned independently of the product.

The rest of the toolbox

The CLI is the product. Around it, this repository ships the tools that make a working session observable: what tests just said, what work is queued, what evidence exists and how fresh it is. Every one of them is local, explicit and read-through; none holds authority over the repository.

Editor: evidence views and live test feedback

The VS Code extension runs the same corvint binary (or corvint-mcp over stdio) and projects one bounded result into Evidence, Impact and Why views, diagnostics and decorations. Executables are pinned by identity and revalidated before every run; suggested verification commands are shown, never executed.

Opt in to corvint.liveTests.enabled and the extension becomes a save-triggered test loop:

Provider What it runs Receipt
corvint-js-test-provider unit The configured Vitest suite Test identity, pass/fail per test, failure locations as diagnostics
corvint-js-test-provider e2e Playwright with an explicit app server, readiness URL and browser Same shape; test failures separated from infrastructure failures
corvint-go-test-provider Go packages, in a preview-only foreground session that reruns on bounded file changes Discovery, plan, run and observation receipts; imported with Corvint: Import Test Observation

Saves in the declared watch paths rerun the full configured suite; rapid saves coalesce, and a new save clears the previous result. Completed runs stay in Test Explorer. With corvint.liveTests.retainEvidence, the same completed documents are retained under .corvint/test-evidence where corvint-test-validity-mcp lets an agent read them. A green run is a fact about that run: it does not establish freshness, adequacy or authority, and the unknown axes stay visible (contract, Go provider).

Task manager and work queue

corvint-tasks is the local ticket store and roadmap. It lives in its own source module, is built into the companion bundle beside corvint, and owns ticket state: the console delegates every ticket mutation to it. No server, no account, no agent dispatch.

corvint work observe and corvint work propose-wave (also corvint-work-queue) read a queue snapshot and return deterministic shadow proposals: derived path clashes between tickets and the largest collision-free wave that could run together. The proposals authorize nothing and carry their inputs' digests, so a second run over the same snapshot reproduces them byte for byte (Work Queue Observation V0).

To adopt the work queue in a repository, run corvint work init --repository NAME --corvint-executable "$(command -v corvint)", review and commit the three files it writes under .corvint/, and list tickets in .corvint/worklist.json with the paths each one changes. Verification work such as a suite batch, a failure repair, a test-validity receipt, or a cleanup and retry is an ordinary ticket. Tickets that share a path are never proposed together; the proposal names the excluded ticket and why. The executable may be in ~/.local/bin, /opt/homebrew/bin, /usr/local/bin, or another safe absolute location: init binds its path, bytes, version/build and source identity instead of searching ambient PATH. After an upgrade, run corvint work rebind --corvint-executable "$(command -v corvint)", review and commit the adapter change. See INSTALL for the states you get when a step is missing.

Dashboard and console

corvint-dashboard-snapshot compiles one read-only snapshot of what Corvint data exists for a repository: the revision and authority each artifact represents, what is stale or absent, which denominators were never observed, and the exact artifact and verifier behind every aggregate. Its roadmap subcommand projects the ticket roadmap the same way. A snapshot is an inspector, not a scoreboard: an unavailable denominator is reported as unavailable, never as zero (Local Observability Dashboard V0).

corvint-console serves that snapshot, the ticket board and detail, the specification index and a code pane on a loopback address you start explicitly:

corvint-console --repo /absolute/path/to/repo --tasks /path/to/corvint-tasks \
  --snapshot /path/to/corvint-dashboard-snapshot

Open http://127.0.0.1:7777, stop it with Ctrl-C. It installs nothing, opens no outbound connection and holds no database (Local Admin Console V0).

Agent-facing servers

Three stdio MCP servers, each bound to one repository root, each read-only:

Server Tools
corvint-mcp corvint.query, corvint.impact and corvint.status: the same bounded context, Go impact and repository-status receipts as the CLI
corvint-docs-mcp corvint.docs_draft writes source-pinned documentation from owner prose and indexed Go declarations; corvint.docs_consume rechecks a draft's exact bytes against source
corvint-corpus-mcp Experimental revision-pinned documentation corpus; capability-gated read tools over one explicitly supplied local artifact
corvint-test-validity-mcp Discovery and projection of retained test evidence in one five-axis shape

corvint docs maintain --watch is the foreground companion to the docs server: it refreshes a generated page block as eligible source commits land, preserves the surrounding prose, and stops on any outside edit or when its write and wall-clock limits are reached (setup, protocol).

Sixteen language analyzers

cmd/corvint-analyzer-* are candidate analyzers for Go, Python, JavaScript/TypeScript, Java, Kotlin/Android, Swift, Objective-C, C/JNI, .NET, Ruby, Rust, shell, SQL, shaders, HTML/CSS and structured data. Each emits facts with byte spans and evidence digests under a frozen candidate profile and is admitted to the product only through its own accepted profile (candidate profiles).

Coordination and release checks

  • corvint-pulse: a bounded local coordinator for snapshot lifecycle state with frozen transcripts; leases and deltas are not delivered (Pulse Snapshot Lease V0).
  • corvint-companion-release assembles the companion bundle from two clean checkouts and writes its manifest and checksums; corvint-public-release-check qualifies one retained bundle; corvint-release-gate is an offline evidence gate; corvint-go-toolchain-receipt digests a GOROOT tree into a receipt. None publishes anything.

Built to be checked

Spec-driven Every substantive capability has an executable spec with stable requirement IDs in docs/specs/REQUIREMENTS.tsv; go run ./script/spec-coverage-audit reports test, case, and fixture mentions separately from comments and missing mentions
Decision records Numbered, accepted intent with explicit promotion boundaries in docs/decisions/
Frozen conformance Exact receipt and state replay, CEM/LRF/TCQ vectors, and an independent Go interoperability consumer in interop/cem01-go
Honest disagreements Every known behavioural disagreement is adjudicated and dated in the divergence register
Hermetic archives make gate includes script/go-archive-gate, which rebuilds the release archives from the committed revision and checks the closed file set (spec)
Dogfooded Substantive Corvint changes must collect context with Corvint and bind the diff to a CEM (dogfood contract)

Status, stated plainly

[!IMPORTANT] Corvint is an extraction alpha (Corvint 0.7.0 prerelease); its three daily-workflow jobs are still UNPROVEN. Platform status comes from each release's exact assets and qualification evidence.

Surface Current state
Receipts, coverage, abstention Experimental, the delivery state recorded in the specification index; the shapes above are what the binary emits today.
context, affected, prove, index Experimental under their specs: Task-Context Packet, Affected Plan, Falsifiable Packet, and Index Snapshot V0.
Retrieval quality Experimental and unqualified. Bounded receipts around a named path or subject are the product today. Broad task-to-evidence retrieval has not passed held-out evaluation: the latest held-out attempt beat the exact-search baseline on top-5 (0.571 vs 0.343) and met the abstention and latency bars, but returned forbidden results on 7 of 36 must-exclude checks. Do not rely on ranking or abstention.
CEM 0.1 / 0.2 Experimental: reference producer, verifier, schemas, and conformance vectors. Independent third-party interoperability is still unproven.
Does CEM help a reviewer? Unproven. A five-pair pilot scored mean missed evidence of 0.90 for control and 0.86 with CEM. It is a pilot, not a held-out outcome study.
Performance Unmeasured for the current Go-only revision. Earlier measurements compared against the retired Python runtime and do not qualify this one.
Host adapters, VS Code, MCP Developer preview or experimental, reporting FALLBACK.
Tickets, work queue, dashboard, console, test providers, Pulse Experimental under their specs; the console and dashboard present evidence and never hold authority over it.
Learned traces Experimental and advisory; a learned-path change is admitted only through a pinned two-arm evaluation, and none is qualified for this release.

These boundaries are backed by committed artifacts: the release notes, the specification index, and benchmarks/.

Development

test "$(GOTOOLCHAIN=local go env GOVERSION)" = "go1.27.1"
GOTOOLCHAIN=local go test -count=1 -timeout 30m ./...
GOTOOLCHAIN=local go vet ./...
(cd interop/cem01-go && GOTOOLCHAIN=local go test -count=1 -timeout 30m ./... && GOTOOLCHAIN=local go vet ./...)
make gate
script/release-checklist      # read-only; seven rows, PASS/FAIL/NOT_RUN, exits 0 only when all pass

If GOTOOLCHAIN=local go env GOVERSION reports a different patch version than go1.27.1 (for example, a Homebrew go formula upgrade changed the linked toolchain), install the exact pinned version alongside it rather than relinking Homebrew's default, then prepend its bin directory to PATH for gate commands only, e.g. PATH=/opt/homebrew/Cellar/go/1.27.1/bin:$PATH GOTOOLCHAIN=local make gate (Intel Homebrew: /usr/local/Cellar/go/1.27.1/bin).

Gemini/OpenCode adapter tests use their hosts' Node runtime. Corvint itself and its developer tools do not require Python. See native regression ownership.

License

Corvint is free software under the GNU Affero General Public License v3.0 or later. The portable protocol descriptions, schemas, conformance material, examples, and interop implementations are Apache-2.0 instead, so anyone can implement the standard, including in proprietary software, without the copyleft attaching. See LICENSING.md for the exact path boundary, LICENSE for the AGPL text, LICENSE-APACHE-2.0 for the Apache text, and PROVENANCE.md.

Directories

Path Synopsis
benchmarks
dogfood-measure command
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
dogfood-workers command
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
runner command
Command benchmark-runner executes Corvint's pinned multi-repository retrieval benchmark.
Command benchmark-runner executes Corvint's pinned multi-repository retrieval benchmark.
selfuse-batch command
cmd
corvint command
corvint-analyzer-dotnet command
Command corvint-analyzer-dotnet is the isolated .NET analyzer candidate.
Command corvint-analyzer-dotnet is the isolated .NET analyzer candidate.
corvint-analyzer-go command
corvint-analyzer-go is an unregistered experimental fact extractor.
corvint-analyzer-go is an unregistered experimental fact extractor.
corvint-analyzer-html-css command
corvint-analyzer-html-css is an unselected experimental analyzer candidate.
corvint-analyzer-html-css is an unselected experimental analyzer candidate.
corvint-analyzer-ruby command
corvint-analyzer-ruby is an unregistered experimental static analyzer.
corvint-analyzer-ruby is an unregistered experimental static analyzer.
corvint-analyzer-rust command
corvint-analyzer-rust is an unselected experimental Rust analyzer candidate.
corvint-analyzer-rust is an unselected experimental Rust analyzer candidate.
corvint-analyzer-shader command
corvint-analyzer-shader is an unselected experimental shader analyzer candidate.
corvint-analyzer-shader is an unselected experimental shader analyzer candidate.
corvint-analyzer-shell command
corvint-analyzer-shell is an unregistered experimental static analyzer.
corvint-analyzer-shell is an unregistered experimental static analyzer.
corvint-analyzer-structured-data command
corvint-analyzer-structured-data is an unselected experimental analyzer.
corvint-analyzer-structured-data is an unselected experimental analyzer.
corvint-analyzer-swift command
corvint-analyzer-swift is an unregistered experimental fact extractor.
corvint-analyzer-swift is an unregistered experimental fact extractor.
corvint-behavior-falsify command
Command corvint-behavior-falsify is an explicitly approved experimental companion for browser-criterion falsification controls.
Command corvint-behavior-falsify is an explicitly approved experimental companion for browser-criterion falsification controls.
corvint-companion-release command
Command corvint-companion-release assembles the optional companion distribution bundle for a single pinned target (darwin/arm64 only; see docs/specs/public-release-v0.md).
Command corvint-companion-release assembles the optional companion distribution bundle for a single pinned target (darwin/arm64 only; see docs/specs/public-release-v0.md).
corvint-console command
Command corvint-console builds the Corvint Console executable described by `docs/specs/local-admin-console-v0.md` (decision 0081).
Command corvint-console builds the Corvint Console executable described by `docs/specs/local-admin-console-v0.md` (decision 0081).
corvint-docs-mcp command
Command corvint-docs-mcp is a separate local stdio MCP 2026-07-28 server that exposes only the experimental source-documentation draft/consume tools (docs/specs/source-documentation-draft-v0.md).
Command corvint-docs-mcp is a separate local stdio MCP 2026-07-28 server that exposes only the experimental source-documentation draft/consume tools (docs/specs/source-documentation-draft-v0.md).
corvint-js-test-provider command
Command corvint-js-test-provider is the experimental IPR-08 JS/TS live-test provider CLI: `unit` runs the bound Vitest adapter, `e2e` runs the bound Playwright adapter (internal/jstestprovider).
Command corvint-js-test-provider is the experimental IPR-08 JS/TS live-test provider CLI: `unit` runs the bound Vitest adapter, `e2e` runs the bound Playwright adapter (internal/jstestprovider).
corvint-mcp command
corvint-playwright-minimize command
Command corvint-playwright-minimize is an explicitly authorized experimental companion.
Command corvint-playwright-minimize is an explicitly authorized experimental companion.
corvint-public-release-check command
Command corvint-public-release-check qualifies one already-retained companion bundle.
Command corvint-public-release-check qualifies one already-retained companion bundle.
corvint-pulse command
corvint-release-candidate command
Command corvint-release-candidate assembles already-qualified retained artifacts into one immutable local candidate.
Command corvint-release-candidate assembles already-qualified retained artifacts into one immutable local candidate.
corvint-release-gate command
corvint-release-gate is an experimental offline evidence gate.
corvint-release-gate is an experimental offline evidence gate.
corvint-release-install command
Command corvint-release-install installs one verified host core archive into a fresh version/platform path.
Command corvint-release-install installs one verified host core archive into a fresh version/platform path.
corvint-test-validity-mcp command
Command corvint-test-validity-mcp is a separate local stdio MCP 2026-07-28 server for the experimental MCP test-validity profile (docs/specs/mcp-test-validity-profile-v0.md).
Command corvint-test-validity-mcp is a separate local stdio MCP 2026-07-28 server for the experimental MCP test-validity profile (docs/specs/mcp-test-validity-profile-v0.md).
corvint-web-flows command
Command corvint-web-flows is an explicitly invoked experimental browser companion.
Command corvint-web-flows is an explicitly invoked experimental browser companion.
conformance
cli-parity-v0 command
frontier-v0 command
Command frontier-v0 reports what this conformance suite covers and validates its own data.
Command frontier-v0 reports what this conformance suite covers and validates its own data.
go-live-test-v0 command
Command go-live-test-v0 independently verifies the discovery portion of the experimental Corvint Go live-test protocol.
Command go-live-test-v0 independently verifies the discovery portion of the experimental Corvint Go live-test protocol.
ocm-v0 command
Command ocm-v0 reports what this conformance suite covers and validates its own data.
Command ocm-v0 reports what this conformance suite covers and validates its own data.
perf-v0 command
release-artifact-v0 command
release-artifact-v0 is the offline reproducible-build gate for the Go candidate.
release-artifact-v0 is the offline reproducible-build gate for the Go candidate.
release-artifact-v0/archive-verifier command
archive-verifier is the separately compiled offline verifier process.
archive-verifier is the separately compiled offline verifier process.
release-artifact-v0/archivebuild
Package archivebuild assembles the canonical Go release containers.
Package archivebuild assembles the canonical Go release containers.
release-artifact-v0/archiveverify
Package archiveverify independently verifies Go release archives.
Package archiveverify independently verifies Go release archives.
release-artifact-v0/archivewire
Package archivewire contains data-only request and result types shared across the archive builder and the separately compiled offline verifier.
Package archivewire contains data-only request and result types shared across the archive builder and the separately compiled offline verifier.
use-cases-v0 command
work-queue-v0
Package workqueuev0 implements the native work-queue qualification fixtures.
Package workqueuev0 implements the native work-queue qualification fixtures.
examples
evidence-provider/v0 command
SPDX-License-Identifier: AGPL-3.0-or-later Copy this single file to author a local provider; it uses only Go's standard library.
SPDX-License-Identifier: AGPL-3.0-or-later Copy this single file to author a local provider; it uses only Go's standard library.
evidence-provider/v0/check command
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
experimental
integrations
testfixture command
This executable is an authored transport fixture, never the Corvint implementation.
This executable is an authored transport fixture, never the Corvint implementation.
internal
analyzerdotnet
Package analyzerdotnet is an isolated, static-only .NET fact candidate.
Package analyzerdotnet is an isolated, static-only .NET fact candidate.
analyzerexec
Package analyzerexec launches one digest-pinned staged native analyzer.
Package analyzerexec launches one digest-pinned staged native analyzer.
analyzergo
Package analyzergo implements an unregistered experimental Go fact extractor.
Package analyzergo implements an unregistered experimental Go fact extractor.
analyzerhtmlcss
Package analyzerhtmlcss is an unregistered experimental HTML/CSS fact extractor.
Package analyzerhtmlcss is an unregistered experimental HTML/CSS fact extractor.
analyzerkotlinandroid
Package analyzerkotlinandroid implements an unregistered experimental Kotlin/Android analyzer.
Package analyzerkotlinandroid implements an unregistered experimental Kotlin/Android analyzer.
analyzerpython
Package analyzerpython implements the unregistered Python 3.12 candidate.
Package analyzerpython implements the unregistered Python 3.12 candidate.
analyzerruby
Package analyzerruby is an isolated, static-only Ruby fact candidate.
Package analyzerruby is an isolated, static-only Ruby fact candidate.
analyzerrust
Package analyzerrust is an isolated, static-only Rust fact candidate.
Package analyzerrust is an isolated, static-only Rust fact candidate.
analyzershader
Package analyzershader is an unregistered, admission-candidate-only shader extractor.
Package analyzershader is an unregistered, admission-candidate-only shader extractor.
analyzershell
Package analyzershell is an isolated, static-only shell fact candidate.
Package analyzershell is an isolated, static-only shell fact candidate.
analyzerstructured
Package analyzerstructured is an unregistered, admission-candidate-only structured-data extractor.
Package analyzerstructured is an unregistered, admission-candidate-only structured-data extractor.
analyzerswift
Package analyzerswift is an unregistered experimental Swift/Apple fact extractor.
Package analyzerswift is an unregistered experimental Swift/Apple fact extractor.
appflows
Package appflows composes experimental, caller-reported application behavior evidence.
Package appflows composes experimental, caller-reported application behavior evidence.
attest
Package attest wraps a prove document (see cmd/corvint/prove.go and docs/specs/falsifiable-packet-v0.md, requirement FPK-V0-012) as an in-toto Statement v1 (https://in-toto.io/Statement/v1), and signs that statement inside a DSSE envelope (https://github.com/secure-systems-lab/dsse) so an external gate can consume it.
Package attest wraps a prove document (see cmd/corvint/prove.go and docs/specs/falsifiable-packet-v0.md, requirement FPK-V0-012) as an in-toto Statement v1 (https://in-toto.io/Statement/v1), and signs that statement inside a DSSE envelope (https://github.com/secure-systems-lab/dsse) so an external gate can consume it.
authorityevent
Package authorityevent defines the experimental native Stop transport.
Package authorityevent defines the experimental native Stop transport.
authoritystore
Package authoritystore is the fixed read-only protected publication consumer.
Package authoritystore is the fixed read-only protected publication consumer.
behaviorfalsify
Package behaviorfalsify runs explicitly approved, bounded falsification controls for one exact browser-behavior criterion.
Package behaviorfalsify runs explicitly approved, bounded falsification controls for one exact browser-behavior criterion.
betarung
Package betarung expresses the GPK-V0-042 beta rung: the third compatibility label BETA, the per-command/per-surface admission record that decides it, and the disclosure obligation that makes an admission valid.
Package betarung expresses the GPK-V0-042 beta rung: the third compatibility label BETA, the per-command/per-surface admission record that decides it, and the disclosure obligation that makes an admission valid.
cem/cemcode
Package cemcode registers the stable CEM error taxonomy shared by every CEM seam.
Package cemcode registers the stable CEM error taxonomy shared by every CEM seam.
cem/cli
Package cli is the thin CEM command dispatch.
Package cli is the thin CEM command dispatch.
cem/coverprofile
Package coverprofile is the Go coverprofile grammar shared by the bounded runner (internal/liveverify/gorunner) and `cem cover` (TCQ-V0-051).
Package coverprofile is the Go coverprofile grammar shared by the bounded runner (internal/liveverify/gorunner) and `cem cover` (TCQ-V0-051).
cem/gitauth
Package gitauth is the isolated Git authority kernel for CEM: it validates the repository boundary (reciprocal worktree metadata, alternates denial, attribute isolation), resolves revisions, reads tree entries and blobs through Git object identity, and derives canonical CEM 0.2 patch bytes that are independent of repository configuration, attributes, diff drivers, object redirection, shallow/partial state, and linked-worktree layout.
Package gitauth is the isolated Git authority kernel for CEM: it validates the repository boundary (reciprocal worktree metadata, alternates denial, attribute isolation), resolves revisions, reads tree entries and blobs through Git object identity, and derives canonical CEM 0.2 patch bytes that are independent of repository configuration, attributes, diff drivers, object redirection, shallow/partial state, and linked-worktree layout.
cem/gitrun
Package gitrun executes bounded, contained Git child processes for the CEM seams.
Package gitrun executes bounded, contained Git child processes for the CEM seams.
cem/mdreport
Package mdreport renders values into CEM and OCM review-report Markdown safely.
Package mdreport renders values into CEM and OCM review-report Markdown safely.
cem/patch
Package patch implements the frozen CEM 0.1 bounded unified-diff parser specified by interop/cem-0.1/ALGORITHMS.md.
Package patch implements the frozen CEM 0.1 bounded unified-diff parser specified by interop/cem-0.1/ALGORITHMS.md.
cem/publish
Package publish is the descriptor-rooted bounded reader and transactional output publisher for CEM artifacts.
Package publish is the descriptor-rooted bounded reader and transactional output publisher for CEM artifacts.
cem/sim
Package sim proves a parsed CEM patch against exact base-tree bytes, per interop/cem-0.1/ALGORITHMS.md "Patch/base simulation".
Package sim proves a parsed CEM patch against exact base-tree bytes, per interop/cem-0.1/ALGORITHMS.md "Patch/base simulation".
cem/verify
Package verify composes the CEM seams into the frozen repository-conformant verifier: exact-patch (cem/0.1) and canonical (cem/0.2, cem/0.3) verification with the frozen validation precedence, mechanical byte and Go structural proofs, and same-path evidence drift.
Package verify composes the CEM seams into the frozen repository-conformant verifier: exact-patch (cem/0.1) and canonical (cem/0.2, cem/0.3) verification with the frozen validation precedence, mechanical byte and Go structural proofs, and same-path evidence drift.
cem/wire
Package wire reads and validates CEM 0.1/0.2 wire documents.
Package wire reads and validates CEM 0.1/0.2 wire documents.
cem/workflow
Package workflow implements the CEM producer/verifier operations — begin, prepare, cite, mark, status, verify, and report — over the CEM seams, with the frozen CEM-CB envelope table, validation precedence, and resume rules.
Package workflow implements the CEM producer/verifier operations — begin, prepare, cite, mark, status, verify, and report — over the CEM seams, with the frozen CEM-CB envelope table, validation precedence, and resume rules.
cemdiscriminate
Package cemdiscriminate is the mutation runner behind `cem discriminate` (TCQ-V0-055..058).
Package cemdiscriminate is the mutation runner behind `cem discriminate` (TCQ-V0-055..058).
changewitness
Package changewitness is the experimental pure evaluator for the `ocm-change-witnessed-v0` relation (docs/specs/change-witness-relation-v0.md).
Package changewitness is the experimental pure evaluator for the `ocm-change-witnessed-v0` relation (docs/specs/change-witness-relation-v0.md).
compactionkernel
Package compactionkernel makes compaction survival a checkable property.
Package compactionkernel makes compaction survival a checkable property.
companionrelease
Package companionrelease assembles the optional companion distribution bundle (nine Go binaries plus five agent-host packages) for a single pinned target.
Package companionrelease assembles the optional companion distribution bundle (nine Go binaries plus five agent-host packages) for a single pinned target.
console
Package console is the read-through local admin console of `docs/specs/local-admin-console-v0.md` (decision 0081).
Package console is the read-through local admin console of `docs/specs/local-admin-console-v0.md` (decision 0081).
dashboard/model
Package model compiles already-normalized dashboard adapter results into the canonical corvint-dashboard-snapshot/0 wire representation.
Package model compiles already-normalized dashboard adapter results into the canonical corvint-dashboard-snapshot/0 wire representation.
dashboard/roadmap
Package roadmap joins the human-owned roadmap ticket store (`atm`) to current source evidence (docs/specs/REQUIREMENTS.tsv), current test receipts (a configured testvalidity.Projection receipts directory), and generated-doc state (a configured docs-state file) for the local dashboard snapshot (IPR-10, docs/plans/integrated-product-roadmap-2026-09-12.md).
Package roadmap joins the human-owned roadmap ticket store (`atm`) to current source evidence (docs/specs/REQUIREMENTS.tsv), current test receipts (a configured testvalidity.Projection receipts directory), and generated-doc state (a configured docs-state file) for the local dashboard snapshot (IPR-10, docs/plans/integrated-product-roadmap-2026-09-12.md).
depsource
Package depsource answers one read-only question: what are the pinned bytes of a third-party Go module this repository depends on, and do they match the checksum the committed go.sum records?
Package depsource answers one read-only question: what are the pinned bytes of a third-party Go module this repository depends on, and do they match the checksum the committed go.sum records?
diagnostic
Package diagnostic is the refusal envelope of docs/specs/diagnostic-repair-contract-v0.md (DRC-V0): a refused subject, the facts measured while refusing, and the closed set of registry-owned repairs, carried beside an existing {code, message} error.
Package diagnostic is the refusal envelope of docs/specs/diagnostic-repair-contract-v0.md (DRC-V0): a refused subject, the facts measured while refusing, and the closed set of registry-owned repairs, carried beside an existing {code, message} error.
disagree
Package disagree reports whether two independent retrieval channels agree on the files a task needs (retriever-disagreement-v0).
Package disagree reports whether two independent retrieval channels agree on the files a task needs (retriever-disagreement-v0).
doccorpus
Package doccorpus compiles the proposed DCP-V1 documentation evidence profile.
Package doccorpus compiles the proposed DCP-V1 documentation evidence profile.
docmaintain
Package docmaintain implements an explicitly enabled, bounded local session that keeps one human documentation page's generated blocks in sync with immutable Git source, per the IPR-05 slice of docs/plans/integrated-product-roadmap-2026-09-12.md and the maintenance requirements in docs/specs/source-documentation-draft-v0.md (SDD-V0-007+).
Package docmaintain implements an explicitly enabled, bounded local session that keeps one human documentation page's generated blocks in sync with immutable Git source, per the IPR-05 slice of docs/plans/integrated-product-roadmap-2026-09-12.md and the maintenance requirements in docs/specs/source-documentation-draft-v0.md (SDD-V0-007+).
docviews
Package docviews compiles proof-bound audience projections from an existing admitted Human Documentation Compiler plan.
Package docviews compiles proof-bound audience projections from an existing admitted Human Documentation Compiler plan.
dogfoodocm
Package dogfoodocm verifies the private ordered set of unchanged OCM maps used by Corvint's repository dogfood loop.
Package dogfoodocm verifies the private ordered set of unchanged OCM maps used by Corvint's repository dogfood loop.
evalrepo
Package evalrepo evaluates a frozen Corvint retrieval corpus without mutation.
Package evalrepo evaluates a frozen Corvint retrieval corpus without mutation.
extevidence
Package extevidence attaches external evidence provider records to the path-impact receipt as a separated section (docs/specs/external-evidence-provider-v0.md).
Package extevidence attaches external evidence provider records to the path-impact receipt as a separated section (docs/specs/external-evidence-provider-v0.md).
frontier
Package frontier implements Change Frontier V0 (`frontier/0`), the deterministic composition of canonical CEM 0.2, OCM 0.1, Lexical Relevance Floor V0, and Test Claim Qualification V0 specified in docs/specs/change-frontier-v0.md.
Package frontier implements Change Frontier V0 (`frontier/0`), the deterministic composition of canonical CEM 0.2, OCM 0.1, Lexical Relevance Floor V0, and Test Claim Qualification V0 specified in docs/specs/change-frontier-v0.md.
frontiernext
Package frontiernext implements the additive experimental closing relation.
Package frontiernext implements the additive experimental closing relation.
frontiernextrepo
Package frontiernextrepo independently re-derives the experimental universe from immutable Git objects using the existing canonical CEM/OCM verifier.
Package frontiernextrepo independently re-derives the experimental universe from immutable Git objects using the existing canonical CEM/OCM verifier.
frontierrepo
Package frontierrepo binds the Change Frontier V0 seams to real Git authority.
Package frontierrepo binds the Change Frontier V0 seams to real Git authority.
gitnotes
Package gitnotes anchors a committed Change Evidence Map to a commit in a Corvint notes ref and reads Git-native provenance beside it: the Git AI `refs/notes/ai` authorship log and the `Assisted-by` / `Agent-Logs-Url` commit trailers (FPK-V0-037..040, decision 0355).
Package gitnotes anchors a committed Change Evidence Map to a commit in a Corvint notes ref and reads Git-native provenance beside it: the Git AI `refs/notes/ai` authorship log and the `Assisted-by` / `Agent-Logs-Url` commit trailers (FPK-V0-037..040, decision 0355).
gitstatus
Package gitstatus observes status with frozen configuration and explicit repository paths.
Package gitstatus observes status with frozen configuration and explicit repository paths.
gokernel
Package gokernel contains the experimental dependency-free Corvint production kernel.
Package gokernel contains the experimental dependency-free Corvint production kernel.
jstestprovider
Package jstestprovider is an experimental IPR-08 provider slice: one JS/TS unit adapter (Vitest) and one E2E adapter (Playwright) that each produce a receipt binding test/config/app-build/environment identity to per-test execution outcomes, then feed those facts through internal/testvalidity.Project (see ../testvalidity/projection.go).
Package jstestprovider is an experimental IPR-08 provider slice: one JS/TS unit adapter (Vitest) and one E2E adapter (Playwright) that each produce a receipt binding test/config/app-build/environment identity to per-test execution outcomes, then feed those facts through internal/testvalidity.Project (see ../testvalidity/projection.go).
liveverify/affected
Package affected selects the verification units reachable from a dirty worktree.
Package affected selects the verification units reachable from a dirty worktree.
liveverify/affected/dotnet
Package dotnet is the C# implementation of the affected-selection language seam.
Package dotnet is the C# implementation of the affected-selection language seam.
liveverify/affected/golang
Package golang is the Go implementation of the affected-selection language seam.
Package golang is the Go implementation of the affected-selection language seam.
liveverify/affected/kotlin
Package kotlin is the Kotlin/JVM implementation of the affected-selection language seam.
Package kotlin is the Kotlin/JVM implementation of the affected-selection language seam.
liveverify/affected/python
Package python is the Python implementation of the affected-selection language seam.
Package python is the Python implementation of the affected-selection language seam.
liveverify/affected/ruby
Package ruby is the Ruby implementation of the affected-selection language seam.
Package ruby is the Ruby implementation of the affected-selection language seam.
liveverify/affected/rust
Package rust is the Rust implementation of the affected-selection language seam.
Package rust is the Rust implementation of the affected-selection language seam.
liveverify/affected/swift
Package swift is the Swift implementation of the affected-selection language seam.
Package swift is the Swift implementation of the affected-selection language seam.
liveverify/affected/typescript
Package typescript is the JavaScript and TypeScript implementation of the affected-selection language seam.
Package typescript is the JavaScript and TypeScript implementation of the affected-selection language seam.
liveverify/godiscovery
Package godiscovery decodes the closed Go 1.27 package-discovery stream.
Package godiscovery decodes the closed Go 1.27 package-discovery stream.
liveverify/gorunner
Package gorunner executes one bounded, explicit Go test plan.
Package gorunner executes one bounded, explicit Go test plan.
liveverify/gotest
Package gotest observes the bounded JSON event stream emitted by Go 1.27's `go test -json` mode without retaining test or build output text.
Package gotest observes the bounded JSON event stream emitted by Go 1.27's `go test -json` mode without retaining test or build output text.
liveverify/jsresolve
Package jsresolve answers, from JavaScript or TypeScript source bytes alone, the three questions the `reference-resolves` falsifier asks of a web citation (FPK-V0-018): does an import on the cited line carry a given specifier, does an identifier sit on the cited line, and does a blob declare a name at top level.
Package jsresolve answers, from JavaScript or TypeScript source bytes alone, the three questions the `reference-resolves` falsifier asks of a web citation (FPK-V0-018): does an import on the cited line carry a given specifier, does an identifier sit on the cited line, and does a blob declare a name at top level.
liveverify/mutate
Package mutate implements the test-kills-mutant falsifier described by docs/specs/falsifiable-packet-v0.md.
Package mutate implements the test-kills-mutant falsifier described by docs/specs/falsifiable-packet-v0.md.
liveverify/parentverify
Package parentverify implements the local parent authority required by the experimental Go live-test producer.
Package parentverify implements the local parent authority required by the experimental Go live-test producer.
liveverify/provider
Package provider coordinates one explicitly requested, local Go test run.
Package provider coordinates one explicitly requested, local Go test run.
liveverify/pymutate
Package pymutate is the Python arm of the test-kills-mutant falsifier (docs/specs/falsifiable-packet-v0.md, FPK-V0-019).
Package pymutate is the Python arm of the test-kills-mutant falsifier (docs/specs/falsifiable-packet-v0.md, FPK-V0-019).
liveverify/pyresolve
Package pyresolve answers, from Python source bytes alone, whether an import statement that begins on a given line imports a given dotted module.
Package pyresolve answers, from Python source bytes alone, whether an import statement that begins on a given line imports a given dotted module.
liveverify/session
Package session implements the experimental Go live-test provider's foreground session: a bounded-file poll loop that debounces edits, computes a current-input identity, and runs the frozen `go test -json` invocation (via gorunner.Run, the same contained runner provider.Execute uses) once per settled edit.
Package session implements the experimental Go live-test provider's foreground session: a bounded-file poll loop that debounces edits, computes a current-input identity, and runs the frozen `go test -json` invocation (via gorunner.Run, the same contained runner provider.Execute uses) once per settled edit.
localauthority
Package localauthority verifies the experimental protected execution profile.
Package localauthority verifies the experimental protected execution profile.
localcompletion
Package localcompletion coordinates a caller-owned local workflow.
Package localcompletion coordinates a caller-owned local workflow.
lrf
Package lrf implements the frozen Lexical Relevance Floor V0 projection.
Package lrf implements the frozen Lexical Relevance Floor V0 projection.
lrfrepo
Package lrfrepo issues canonical LRF results from verified repository authority.
Package lrfrepo issues canonical LRF results from verified repository authority.
mcp/bridge
Package bridge exposes the currently qualified Corvint read surfaces without coupling them to an MCP transport implementation.
Package bridge exposes the currently qualified Corvint read surfaces without coupling them to an MCP transport implementation.
mcp/corpusbridge
Package corpusbridge exposes only capabilities declared by a revalidated documentation corpus.
Package corpusbridge exposes only capabilities declared by a revalidated documentation corpus.
mcp/docsbridge
Package docsbridge exposes the experimental source-documentation draft/consume implementation (docs/specs/source-documentation-draft-v0.md) as read-only MCP tools.
Package docsbridge exposes the experimental source-documentation draft/consume implementation (docs/specs/source-documentation-draft-v0.md) as read-only MCP tools.
mcp/protocol
Package protocol implements bounded MCP 2026-07-28 wire types.
Package protocol implements bounded MCP 2026-07-28 wire types.
mcp/server
Package server implements the local child-owned MCP 2026-07-28 stdio server.
Package server implements the local child-owned MCP 2026-07-28 stdio server.
mcp/testvaliditybridge
Package testvaliditybridge exposes the shared test-validity projection as the single read-only tool of the experimental MCP test-validity profile (docs/specs/mcp-test-validity-profile-v0.md).
Package testvaliditybridge exposes the shared test-validity projection as the single read-only tool of the experimental MCP test-validity profile (docs/specs/mcp-test-validity-profile-v0.md).
migrationratchet
Package migrationratchet compares immutable migration evidence snapshots.
Package migrationratchet compares immutable migration evidence snapshots.
necessity
Package necessity answers one read-only question about a task-context packet: which of the files the packet included does the packet actually depend on? Each included path is removed from a copy of the index and the packet is recompiled; a path whose removal costs the packet an anchor, grows its missing-critical set, or moves it off a resolved answerability verdict is `load-bearing`, and every other included path is `supporting`.
Package necessity answers one read-only question about a task-context packet: which of the files the packet included does the packet actually depend on? Each included path is removed from a copy of the index and the packet is recompiled; a path whose removal costs the packet an anchor, grows its missing-critical set, or moves it off a resolved answerability verdict is `load-bearing`, and every other included path is `supporting`.
obscorpus
Package obscorpus is the experimental OCA-V0 contract (docs/specs/observation-corpus-authority-v0.md): bounded harness observations and a sealed owner-labelled corpus replay.
Package obscorpus is the experimental OCA-V0 contract (docs/specs/observation-corpus-authority-v0.md): bounded harness observations and a sealed owner-labelled corpus replay.
observations
Package observations keeps bounded, local-only self-observation proposals.
Package observations keeps bounded, local-only self-observation proposals.
outcomecal
Package outcomecal joins recorded local task outcomes with the packet stance (answered or abstained) that preceded them and reports calibration only.
Package outcomecal joins recorded local task outcomes with the packet stance (answered or abstained) that preceded them and reports calibration only.
plansnapshot
Package plansnapshot validates caller-owned immutable planning inputs.
Package plansnapshot validates caller-owned immutable planning inputs.
playwrightminimize
Package playwrightminimize plans bounded Playwright suite-interaction trials.
Package playwrightminimize plans bounded Playwright suite-interaction trials.
projectpath
Package projectpath normalizes existing and verified-absent project paths.
Package projectpath normalizes existing and verified-absent project paths.
projectprofile
Package projectprofile holds the downstream-project conventions the kernel used to hardcode: how a project is recognised, which ledgers it keeps, and which verification command each changed path implies.
Package projectprofile holds the downstream-project conventions the kernel used to hardcode: how a project is recognised, which ledgers it keeps, and which verification command each changed path implies.
proofabstraction
Package proofabstraction implements the experimental exact proof-projection relation described by PPA-V0.
Package proofabstraction implements the experimental exact proof-projection relation described by PPA-V0.
pulse
Package pulse contains the in-memory coordination primitives for Corvint Pulse.
Package pulse contains the in-memory coordination primitives for Corvint Pulse.
pythongrammar
Package pythongrammar holds the closed Python 3.12 subset lexer and parser.
Package pythongrammar holds the closed Python 3.12 subset lexer and parser.
releasecandidate
Package releasecandidate closes the already-qualified core and companion artifacts into one immutable, versioned local publication candidate.
Package releasecandidate closes the already-qualified core and companion artifacts into one immutable, versioned local publication candidate.
releasegate
Package releasegate verifies one manifest-selected, immutable Git release tree.
Package releasegate verifies one manifest-selected, immutable Git release tree.
remoteprovider
Package remoteprovider belongs exclusively to the optional remote adapter.
Package remoteprovider belongs exclusively to the optional remote adapter.
repoenvelope
Package repoenvelope frames repository-derived JSON as untrusted data for agent context (AHI-004).
Package repoenvelope frames repository-derived JSON as untrusted data for agent context (AHI-004).
runtimeenv
Package runtimeenv resolves runtime settings from the CORVINT_ environment namespace.
Package runtimeenv resolves runtime settings from the CORVINT_ environment namespace.
scopelease
Package scopelease implements bounded local scope leases so several agents sharing one worktree cannot silently edit overlapping files or the same ticket.
Package scopelease implements bounded local scope leases so several agents sharing one worktree cannot silently edit overlapping files or the same ticket.
secretscreen
Package secretscreen holds the secret-shaped-text detector Corvint's local writers share plus immutable stored-format compatibility matchers.
Package secretscreen holds the secret-shaped-text detector Corvint's local writers share plus immutable stored-format compatibility matchers.
semescalate
Package semescalate is the experimental deterministic core of the Semantic Escalation Gate (docs/specs/semantic-escalation-gate-v0.md).
Package semescalate is the experimental deterministic core of the Semantic Escalation Gate (docs/specs/semantic-escalation-gate-v0.md).
skillexport
Package skillexport renders admitted learned traces as Agent Skills documents: one directory per admitted rule holding a short SKILL.md with YAML frontmatter and a references/trace.md that carries the full detail (LTA-V0-006 to LTA-V0-008).
Package skillexport renders admitted learned traces as Agent Skills documents: one directory per admitted rule holding a short SKILL.md with YAML frontmatter and a references/trace.md that carries the full detail (LTA-V0-006 to LTA-V0-008).
taskman
Package taskman implements the explicitly trusted-local native fixture planner.
Package taskman implements the explicitly trusted-local native fixture planner.
tcq
Package tcq implements Test Claim Qualification V0 (`tcq/0`) as specified in docs/specs/test-claim-qualification-v0.md.
Package tcq implements Test Claim Qualification V0 (`tcq/0`) as specified in docs/specs/test-claim-qualification-v0.md.
testevidence
Package testevidence is the opt-in producer half of retained test evidence (LPCV-V0-055, decision 0218): a provider run with --retain writes its exact stdout document into the one location testvaliditydoc.Discover reads.
Package testevidence is the opt-in producer half of retained test evidence (LPCV-V0-055, decision 0218): a provider run with --retain writes its exact stdout document into the one location testvaliditydoc.Discover reads.
testsupport
Package testsupport holds small load-detection helpers shared by timing- sensitive tests across packages, so a wall-clock ceiling can be skipped under a loaded host instead of flaking (decision 0036).
Package testsupport holds small load-detection helpers shared by timing- sensitive tests across packages, so a wall-clock ceiling can be skipped under a loaded host instead of flaking (decision 0036).
testvalidity
Package testvalidity defines one shared test-validity projection consumed by both the Go CLI/MCP surface and the VS Code extension's TypeScript mirror (extensions/vscode/src/testvalidity.ts).
Package testvalidity defines one shared test-validity projection consumed by both the Go CLI/MCP surface and the VS Code extension's TypeScript mirror (extensions/vscode/src/testvalidity.ts).
testvaliditydoc
Package testvaliditydoc builds the corvint-test-validity/0 document (docs/specs/live-proof-carrying-verification-v0.md LPCV-V0-051): the shared five-axis projection of every test-level result a JavaScript receipt or Go preview-session event carries.
Package testvaliditydoc builds the corvint-test-validity/0 document (docs/specs/live-proof-carrying-verification-v0.md LPCV-V0-051): the shared five-axis projection of every test-level result a JavaScript receipt or Go preview-session event carries.
touchsurprise
Package touchsurprise measures, for one completed task, how much of the change the task-context packet never named: the touch-set surprise.
Package touchsurprise measures, for one completed task, how much of the change the task-context packet never named: the touch-set surprise.
tracemigraterepo
Package tracemigraterepo binds trace migration to stable Git repository authority.
Package tracemigraterepo binds trace migration to stable Git repository authority.
tracerecordrepo
Package tracerecordrepo binds trace recording to stable Git repository authority.
Package tracerecordrepo binds trace recording to stable Git repository authority.
unplannedread
Package unplannedread measures reads that Corvint failed to prevent: tool calls that opened a project file the delivered context packet did not already carry.
Package unplannedread measures reads that Corvint failed to prevent: tool calls that opened a project file the delivered context packet did not already carry.
untrackedallowance
Package untrackedallowance decides which untracked worktree paths a committed-content result may tolerate without degrading (decision 0142).
Package untrackedallowance decides which untracked worktree paths a committed-content result may tolerate without degrading (decision 0142).
witness
Package witness reports the unwitnessed surface of one committed change range: of the obligations that range opens, how many were closed by evidence from a party other than the change's author, how many stand unproven, and how many could not be determined at all.
Package witness reports the unwitnessed surface of one committed change range: of the obligations that range opens, how many were closed by evidence from a party other than the change's author, how many stand unproven, and how many could not be determined at all.
witnesscollapse
Package witnesscollapse compiles explicitly declared common causes over one exact CEM into a conservative upper bound on independent witnesses.
Package witnesscollapse compiles explicitly declared common causes over one exact CEM into a conservative upper bound on independent witnesses.
worklistadapter
Package worklistadapter is the repository-work-queue-adapter/0 producer for a committed JSON worklist.
Package worklistadapter is the repository-work-queue-adapter/0 producer for a committed JSON worklist.
workqueue
Package workqueue validates Work Queue Observation V0 wire artifacts and computes deterministic, non-operative wave proposals.
Package workqueue validates Work Queue Observation V0 wire artifacts and computes deterministic, non-operative wave proposals.
worksource
Package worksource qualifies the read-only source shared by the work observer and the repository-owned producer.
Package worksource qualifies the read-only source shared by the work observer and the repository-owned producer.
wp3codec
Package wp3codec implements the WP3 commitment codec: the dependency-free canonical JSON subset frozen under "Canonical evaluation commitments" in docs/specs/lexical-relevance-floor-v0.md and restated word-for-word by docs/specs/change-frontier-v0.md CF-V0-019.
Package wp3codec implements the WP3 commitment codec: the dependency-free canonical JSON subset frozen under "Canonical evaluation commitments" in docs/specs/lexical-relevance-floor-v0.md and restated word-for-word by docs/specs/change-frontier-v0.md CF-V0-019.
interop
cem01-go module
script
tools
beamfall-shadow command
beamfall-shadow/wrapper command
beamfall-shadow-wrapper is intentionally tiny: it gives run.sh a portable process-group signal and reaping boundary around `go run`.
beamfall-shadow-wrapper is intentionally tiny: it gives run.sh a portable process-group signal and reaping boundary around `go run`.
cem-interop-runner command
cem-interop-runner is the native, Corvint-free CEM 0.1 external consumer harness.
cem-interop-runner is the native, Corvint-free CEM 0.1 external consumer harness.
cem-trial command
Command cem-trial is the external agent-harness dispatcher for the CEM reviewer trial in docs/specs/cem-reviewer-trial-v0.md.
Command cem-trial is the external agent-harness dispatcher for the CEM reviewer trial in docs/specs/cem-reviewer-trial-v0.md.
compat-trial command
compat-trial/build-fixtures command
Build the closed native fixture registry into a replay runner.
Build the closed native fixture registry into a replay runner.
compat-trial/fixtures/new command
Owned replay fixture: its variant is fixed by the repository build helper.
Owned replay fixture: its variant is fixed by the repository build helper.
compat-trial/fixtures/old command
Owned replay fixture: its variant is fixed by the repository build helper.
Owned replay fixture: its variant is fixed by the repository build helper.
corvint-pr-tests command
Command corvint-pr-tests executes typed Go test argv from a separately trusted affected planner and the existing gate-affected-select.
Command corvint-pr-tests executes typed Go test argv from a separately trusted affected planner and the existing gate-affected-select.
cw-trial command
Command cw-trial is the external agent-harness dispatcher for the confidently-wrong trial in docs/specs/confidently-wrong-trial-v0.md.
Command cw-trial is the external agent-harness dispatcher for the confidently-wrong trial in docs/specs/confidently-wrong-trial-v0.md.
gate-affected-select command
Command gate-affected-select is the selection step of script/gate-affected.sh (AFP-V0-011, AFP-V0-012).
Command gate-affected-select is the selection step of script/gate-affected.sh (AFP-V0-011, AFP-V0-012).
gate-ledger command
Command gate-ledger is the memory of `make gate` (docs/specs/gate-ledger-v0.md).
Command gate-ledger is the memory of `make gate` (docs/specs/gate-ledger-v0.md).
retrieval-bench command
Command retrieval-bench runs Agent Retrieval Bench samples (arXiv 2607.24882) against `corvint query`, `corvint context`, `corvint impact`, and `corvint affected` beside a deterministic grep baseline and reports recall, MRR, file F1, and selective success with confidence intervals.
Command retrieval-bench runs Agent Retrieval Bench samples (arXiv 2607.24882) against `corvint query`, `corvint context`, `corvint impact`, and `corvint affected` beside a deterministic grep baseline and reports recall, MRR, file F1, and selective success with confidence intervals.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL