Documentation
¶
Overview ¶
Package frontierrepo binds the Change Frontier V0 seams to real Git authority. `internal/frontier` holds `frontier.Verifier` and `frontier.TCQRecomputer` as interfaces so its cascade ordering and its CF-V0-022 translation stay testable without a repository; this package is the one implementation of both over the verified machinery that already exists in `internal/lrfrepo`, `internal/cem/...` and `internal/tcq`.
Per CF-V0-027 nothing here may be wired into the agent harness, and per CF-V0-026 path acquisition stays outside: an Adapter is handed artifact BYTES and a repository root, never artifact paths.
Index ¶
- type Adapter
- func (adapter *Adapter) Recompute(request frontier.TCQRequest) (frontier.TCQResult, error)
- func (adapter *Adapter) Verify(ctx context.Context, request frontier.VerifyRequest) (frontier.VerifiedUniverse, error)
- func (adapter *Adapter) VerifyOCM(cemRaw, ocmRaw []byte, expectedBase, target string) (tcq.Resolved, error)
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type Adapter ¶
type Adapter struct {
// contains filtered or unexported fields
}
Adapter is one repository root bound to every Frontier V0 seam. A single value satisfies `frontier.Verifier`, `frontier.TCQRecomputer` and `tcq.UpstreamVerifier`, which is what lets one invocation make exactly ONE shared OCM-consuming verification call (CF-V0-002, CF-V0-021 step 5): the call Frontier makes at stage 5 is the same call TCQ consumes at stage 7.
The context is held on the value because two of the three seams — TCQ's upstream verifier and TCQ's bounded tree reader — are context-free interfaces owned by their producer, and widening them here would change a frozen upstream contract to suit a consumer.
func New ¶
New binds an adapter to one repository root. It performs no Git work: the repository boundary is opened inside the shared verification call, where CF-V0-021 step 5 puts it.
func (*Adapter) Recompute ¶
Recompute is cascade stage 7. CF-V0-002 forbids accepting a caller-supplied TCQ result as authority or as a shortcut, so this runs the real producer over the verified inputs and the target Git objects and then binds the recomputed identity — in both static and dynamic mode (CF-V0-003).
func (*Adapter) Verify ¶
func (adapter *Adapter) Verify(ctx context.Context, request frontier.VerifyRequest) (frontier.VerifiedUniverse, error)
Verify is cascade stage 5: one shared OCM-consuming verification call whose native order is neither interleaved nor reimplemented here. Every ordering decision — repository boundary and alternate denial, expected-base resolution and equality, caller-target resolution and equality, base-side historical-sidecar check, target-side CEM artifact binding, canonical patch derivation and exclusion, then the remaining CEM/OCM map verification — lives inside lrfrepo.VerifyUniverse, which runs the sequence this repository already ships. Native CEM/OCM precedence therefore wins over every later Frontier check, exactly as CF-V0-021 requires.
func (*Adapter) VerifyOCM ¶
func (adapter *Adapter) VerifyOCM(cemRaw, ocmRaw []byte, expectedBase, target string) (tcq.Resolved, error)
VerifyOCM implements tcq.UpstreamVerifier. TCQ-V0-001 requires the same bounded raw byte copies and both revision inputs to pass through the shared CEM/OCM verifier, and TCQ-V0-042 forbids reordering anything internal to it.
Within one Frontier invocation this returns the outcome of the stage-5 call rather than making a second one, because CF-V0-021 admits exactly ONE shared verification call. That is a memo and not a bypass: the hit requires the exact same CEM and OCM bytes by digest and both revisions to name the same two commits, so bytes the shared call never saw fall through to a real verification below. A standalone TCQ caller therefore also gets a real one.