corvint

module
v1.0.0-rc.2 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 6, 2026 License: AGPL-3.0, AGPL-3.0-or-later

README

Corvint

Corvint

A Beamfall project.

Context your agents can cite. Changes your reviewers can check.

Corvint is a local-first context compiler for coding agents. Before an edit it hands the agent Git-pinned evidence with the reason each item is there. After the edit it binds every diff hunk to cited evidence, an explicit unknown, or a verifiable mechanical exception, in a portable sidecar that CI checks without an LLM.

Install · Workflow · Status · Documentation

One native Go binary. No account, hosted service, database, embeddings, or permanent daemon. go.mod declares no module requirements. Read commands do not mutate repository or trace state; the two bounded exceptions are a local .corvint/self-observations.jsonl ledger and, only while the operator marker .corvint/unplanned-reads.enabled exists, .corvint/unplanned-reads.jsonl — neither is a direct input to ranking, evidence, or authority. Learning from these ledgers requires an explicit operator step and a frozen held-out gate (AGENTS.md invariant 4). Version 1.0.0-rc.2 is the next release candidate for Corvint 1.0, and 1.0.0-rc.1 is the published prerelease; what 1.0 promises and what is still being qualified.

Why Corvint

Finding relevant text is only part of a coding task. An agent also needs to know which document governs the change, which tests constrain it, and what evidence is missing. A reviewer needs to follow those decisions back to their sources.

Corvint makes that evidence inspectable through context receipts and a map beside the diff.

  • Every result explains itself. Each item in a packet carries the Git blob it came from, the path and line, the authority that admitted it, a confidence level, and a plain-language inclusion reason. A reviewer can follow any citation to immutable content.
  • Your repository is the authority. Agent instructions, accepted decisions, and specs you already keep outrank syntax matches, history correlations, and learned traces. Corvint uses the documents you have; it introduces no new spec language.
  • It says what it does not know. Coverage, omissions, uncertainty, and freshness are fields in the receipt, and a hunk without cited evidence is an explicit unknown. Task-level retrieval abstention is experimental and unqualified; see Status.
  • Reviewers get a disposition for every hunk. A Change Evidence Map (CEM) links each textual hunk of a diff to cited evidence, an explicit unknown, or a mechanical exception. The verifier checks patch, hunk, blob, and span identity locally, with no LLM, no index, and no shared service. The protocol is Apache-2.0, so anyone can implement or verify it.
  • Local and explicit. The core reads Git and prints JSON. Default evidence flows make no network call. query, context, impact, affected, and non-executing prove modes report mutates: false, subject to the private-ledger exceptions above. record explicitly retains task outcomes; learning stays local, bounded, secret-screened, and evaluation-gated.

Sixty seconds on this repository

You need Git and Go 1.27.1 or later; the full development gate pins exactly go1.27.1. Run this from the root of a Corvint checkout on macOS or Linux:

GOTOOLCHAIN=local go run ./cmd/corvint impact cmd/corvint/main.go --limit 5

That asks what a change to the CLI entry point could affect. The receipt names the requested path, the tests that constrain it, the reason each result was admitted, and what the result limit left out. No installation or account is needed. Abridged output captured from public commit f51f3c9e6fbfc5a6b219692e8bf46e4e43297a36 with its source-built CLI (fields, results, and evidence records omitted; shown values unchanged). Your checkout determines the hashes and counts:

{
  "context": {
    "results": [
      {
        "id": "cmd/corvint/main.go",
        "kind": "path",
        "evidence": [
          {
            "authority": "git-tree",
            "blob_hash": "3f1a1e9e858b7531c186ad05e42cde01c9d87222",
            "confidence": "authoritative",
            "line": 1,
            "path": "cmd/corvint/main.go",
            "reason": "requested changed path"
          }
        ]
      },
      {
        "id": "cmd/corvint/main_test.go",
        "kind": "test",
        "evidence": [
          {
            "authority": "test-convention",
            "blob_hash": "1b757630da987860fd3b2d321981d8fc6f09dcca",
            "confidence": "high",
            "line": 1,
            "path": "cmd/corvint/main_test.go",
            "reason": "same-package test for cmd/corvint/main.go"
          }
        ]
      }
    ],
    "freshness": {
      "revision": "099c102b26602c83ec91a9f8f7eb7491e0b3f040",
      "scope": "git",
      "state": "fresh"
    },
    "coverage": {
      "included_results": 5,
      "omitted_results": 267,
      "uncertainty": [
        "267 ranked results omitted by result limit"
      ]
    }
  },
  "mutates": false,
  "tool": "impact"
}

Install the binary to use Corvint in any supported Git repository:

mkdir -p "$HOME/.local/bin"
GOTOOLCHAIN=local go build -ldflags "-X main.build=$(git rev-list --count --first-parent HEAD)" -o "$HOME/.local/bin/corvint" ./cmd/corvint
export PATH="$HOME/.local/bin:$PATH"
corvint --version

Versioned assets are on the releases page. The Core rc.1 release contains only corvint, with four macOS/Linux archives, SHA256SUMS and verification-report.json. A matching native archive needs Git but no Go compiler; verify both the downloaded archive and its internal checksums before running it. Read the exact platform's qualification, including native versus emulated runs. Tasks has its own developer release; source companions are not automatically included in a Core archive. Source builds report 1.0.0-rc.2; until that candidate is published, rc.1 is the newest Core release. Like rc.1, rc.2 and 1.0 are unsigned: SHA256SUMS only, publisher identity NOT_VERIFIED (decision 0433). The installation guide covers checks, first use, optional tools, upgrades and removal.

The workflow

When Ask Corvint to What you get back
Before an edit Find the context and the likely impact Git-pinned paths, governing documents, related tests, and the reason each was included
While working Show the evidence boundary Freshness, coverage, omissions, uncertainty, and explicit abstention
At review and in CI Attach a Change Evidence Map to the diff A disposition for every textual hunk that CI verifies locally
Command Purpose
corvint query --task "change session revocation" --budget-bytes 8000 Find task evidence within a byte budget
corvint context --task "change session revocation" --subject src/session.py Build a packet around a tracked subject
corvint impact src/session.py Inspect the likely impact of a tracked path
corvint affected Plan Go test packages for the dirty worktree; run none
corvint prove --task "change session revocation" Produce a falsifiable packet with freshness and uncertainty
corvint overview / corvint features Inspect a clean repository overview or inferred feature candidates
corvint review --base FULL_BASE_SHA --max-refs 8 Prepare immutable-range test advice and bounded branch-overlap hints

Replace src/session.py with a path tracked in your repository. Go, Python, and JS/TS have reverse-import impact rules; other indexed languages do not all receive equivalent analysis. corvint COMMAND --help prints each command's contract. To select a repository explicitly, put --root /path/to/repo before the command.

The experimental features, overview, and review commands require a clean tree and expose inferred scope, omissions, and unsupported cases. They do not accept requirements or execute suggested commands. review requires a full ancestor base SHA and does not replace CEM or tests.

Give the agent a useful next step

A context packet can identify a test counterpart and say why it matters. From the session-revocation fixture (fields omitted; values unchanged):

{
  "id": "src/test_session.py",
  "kind": "pair",
  "action": "Update this test: it is the subject's test counterpart, so a behaviour change in the subject changes what it must assert.",
  "evidence": [{
    "authority": "test-convention",
    "confidence": "high",
    "blob_hash": "50404716f6d80b4cbfc88c61529c78bd748250c4",
    "reason": "test counterpart of src/session.py"
  }]
}

After src/session.py is edited, prove reports mixed-worktree freshness and names the changed path. Trace recording is blocked for that mixed state. The receipt keeps working changes apart from committed evidence, so the agent and the reviewer can see the difference.

Put the evidence beside the diff

A Change Evidence Map is a portable sidecar that travels in the repository and verifies with no LLM, no index, and no shared service. For a committed change, replace BASE_SHA with its base commit and the example citation with a span that exists at that base:

corvint cem prepare --base BASE_SHA --target HEAD
corvint cem cite --map .corvint/change.cem.json --hunk 1 \
  --evidence-path docs/decisions/0001-session-revocation.md --lines 5:5 --relation decision
corvint cem status --map .corvint/change.cem.json \
  --expected-base BASE_SHA --target HEAD --max-unknown 0 --max-mechanical 0

For a one-hunk change, prepare produces an incomplete worklist; after the citation, status reports "state": "ready-for-ci" with a stable span. A larger diff needs a disposition for every hunk, and the worklist says what remains. The policy above permits no unknowns and no mechanical exceptions. CEM in CI wires that policy into a pipeline.

The nextActions argv that cem prepare and ocm prepare return starts with the command name corvint. Run it with a corvint binary in that first position, or build one under that name (go build -o corvint ./cmd/corvint).

The verifier proves structural integrity: patch, hunk, blob, span, and mapping identity. It does not prove semantic support, causality, test adequacy, or program correctness, and Corvint says so. The wire format, schemas, and conformance vectors are Apache-2.0.

Optional Go LSP evidence

The following CLI/MCP selectors are newer than the published Core rc.1 binary and are present in 1.0.0-rc.2 source builds. Build the current source and matching MCP companion, or check your installed corvint help context before using them.

Corvint can use gopls, the Go language server, to add definition and reference relationships to a context packet. This integration is experimental and opt-in; it does not change ranked results or project authority. Install gopls explicitly and have your workspace dependencies available locally, then select a tracked Go file (here, in Corvint’s checkout):

corvint context --task "Find callers and dependencies" \
  --subject cmd/corvint/main.go --lsp gopls

Use --lsp off to disable enrichment, including when the legacy environment setting enables it. For MCP, start corvint-mcp with --tool-profile task-review-lsp and pass "lsp": "gopls" to corvint.context; omitting that argument starts no language server. Other MCP profiles do not enable LSP. See the Go LSP guide for installation, full CLI/MCP examples, limits, qualification, and troubleshooting. Other language servers are outside this milestone.

Works where agents work

The host adapters run corvint from PATH, so install it there first. Core lifecycle adapters report FALLBACK (compatibility matrix). The optional OpenCode native integration has a separate exact-tuple qualification; its integrationSupport: FULL does not confer execution or closing Frontier authority (OpenCode support). The Codex and Claude Code adapters are Core host rows; Gemini CLI, OpenCode and Pi are companions:

  • Codex, Claude Code, Gemini CLI, OpenCode, and Pi share one bounded lifecycle receipt (corvint help harness event).
  • VS Code, deferred and not part of 1.0: evidence views plus opt-in automatic unit/E2E reruns on editor saves. Install the VSIX and providers, configure the project's toolchains and suite, then enable corvint.liveTests.enabled. It reruns the configured suite; passing tests do not establish test adequacy or authority. Setup and stop instructions.
  • MCP: corvint-mcp is a companion local stdio server that exposes read-only receipts (GOTOOLCHAIN=local go build -o ./bin/corvint-mcp ./cmd/corvint-mcp). corvint-docs-mcp drafts source-bound documentation and checks a draft against source; corvint-test-validity-mcp lets agents inspect retained test observations. Both need a compatible client and an explicit root; setup and boundaries.
  • Source-bound documentation: the companion docs maintain --watch command refreshes a generated page block as eligible source commits land, preserves surrounding prose, and stops on outside page edits. It runs explicitly in the foreground on macOS/Linux with time and write limits; preview, apply, and watch.
  • The workflow tools below: tickets, dashboard, console, test providers and release checks. Optional Tasks supervision and dispatch start only through explicit operator configuration; they have their own qualification and process-lifecycle limits.

Corvint uses the corvint-* wire/profile namespace, corvint.* MCP tools, and canonical .corvint and .context-corvint repository paths. Those are protocol and state contracts and are versioned independently of the product. The frozen minimum CEM wire is cem/0.2 with an N-1 cem/0.1 reader. The separate experimental cem/0.3 adds structural mechanical reasons and optional test witnesses; it is not the default Core sidecar or a new stability claim (profile boundaries).

The rest of the toolbox

The core CLI works on its own. Separately packaged tools expose test results, tickets, and evidence; some also run tests, supervise agents or perform explicit local writes. They are qualified separately from Core and do not inherit its stability promise. Selected Flows, Tasks, documentation and MCP outcomes are required for stable 1.0 promotion (expanded scope).

Explore optional companions, deferred editor tooling, and experimental tools

Editor: evidence views and live test feedback

The VS Code extension, deferred from 1.0, runs the same corvint binary (or corvint-mcp over stdio) and projects one bounded result into Evidence, Impact and Why views, diagnostics and decorations. Executables are pinned by identity and revalidated before every run; suggested verification commands are shown, never executed.

Opt in to corvint.liveTests.enabled and the extension becomes a save-triggered test loop:

Provider What it runs Receipt
corvint-js-test-provider unit The configured Vitest suite Test identity, pass/fail per test, failure locations as diagnostics
corvint-js-test-provider e2e Playwright with an explicit app server, readiness URL and browser Same shape; test failures separated from infrastructure failures
corvint-go-test-provider Go packages, in a preview-only foreground session that reruns on bounded file changes Discovery, plan, run and observation receipts; imported with Corvint: Import Test Observation

Saves in the declared watch paths rerun the full configured suite; rapid saves coalesce, and a new save clears the previous result. Completed runs stay in Test Explorer. With corvint.liveTests.retainEvidence, the same completed documents are retained under .corvint/test-evidence where corvint-test-validity-mcp lets an agent read them. A green run is a fact about that run: it does not establish freshness, adequacy or authority, and the unknown axes stay visible (contract, Go provider).

Framework-aware test selection

The live providers above are only part of the test tooling. corvint affected also reads source and configuration to recognize test units across the following ecosystems. It produces a plan; it does not launch these runners or establish that omitted tests are safe to skip.

Ecosystem Recognized test conventions and runners
Go go test packages
JavaScript/TypeScript Vitest, Jest, AVA, Node node:test, Bun, Deno, Playwright, Cypress, WebdriverIO, TestCafe, Nightwatch, Detox, Storybook test-runner and Storybook Vitest
Python pytest and unittest file conventions
Ruby RSpec, Minitest/Test::Unit and Rails test conventions
Rust Cargo packages and source test anchors
Swift SwiftPM/Xcode targets, XCTest and Swift Testing
Kotlin/Android JUnit 4/5 and kotlin.test class conventions
C#/.NET VSTest-addressable test methods in SDK-style projects

Dynamic configuration, ambiguous frameworks, unresolved imports, external runtime/device inputs and other unsupported cases remain explicit unknowns in the plan. See the affected-plan contract and the language implementations for the exact bounds. The experimental corvint prove --mutate can run bounded Go and pytest mutation checks when its sandbox and offline prerequisites are available; that is a separate execution path.

Task manager and work queue

corvint-tasks is the local ticket store and roadmap. It is a separate companion binary built from this repository's cmd/corvint-tasks (never a corvint subcommand) and owns ticket state: the console delegates every ticket mutation to it. The store needs no server or account. The standalone Tasks developer release provides a macOS Apple silicon archive, checksums and build-verification evidence; its unverified version and runtime qualification limits remain explicit. Use corvint-tasks version and corvint-tasks help to check the installed build and commands. Other targets can be built from source; build success is not runtime qualification.

Optional foreground Codex supervision and continuous dispatch are operator-started source capabilities. Supervision has scoped local qualification; dispatch and newer source commands require their own checks and are not all present in that developer archive. Neither route inherits Core stability or grants publication authority. Optional named environment pools allocate isolated members with claims and quarantine them until explicit safe-reuse confirmation; see external-agent usage.

corvint work observe and corvint work propose-wave (also corvint-work-queue) read a queue snapshot and return deterministic shadow proposals: derived path clashes between tickets and the largest collision-free wave that could run together. The proposals authorize nothing and carry their inputs' digests, so a second run over the same snapshot reproduces them byte for byte (Work Queue Observation V0).

To adopt the work queue in a repository, run corvint work init --repository NAME --corvint-executable "$(command -v corvint)", review and commit the three files it writes under .corvint/, and list tickets in .corvint/worklist.json with the paths each one changes. Verification work such as a suite batch, a failure repair, a test-validity receipt, or a cleanup and retry is an ordinary ticket. Tickets that share a path are never proposed together; the proposal names the excluded ticket and why. The executable may be in ~/.local/bin, /opt/homebrew/bin, /usr/local/bin, or another safe absolute location: init binds its path, bytes, version/build and source identity instead of searching ambient PATH. After an upgrade, run corvint work rebind --corvint-executable "$(command -v corvint)", review and commit the adapter change. See INSTALL for the states you get when a step is missing.

Dashboard and console

corvint-dashboard-snapshot compiles one read-only snapshot of what Corvint data exists for a repository: the revision and authority each artifact represents, what is stale or absent, which denominators were never observed, and the exact artifact and verifier behind every aggregate. Its roadmap subcommand projects the ticket roadmap the same way. A snapshot is an inspector, not a scoreboard: an unavailable denominator is reported as unavailable, never as zero (Local Observability Dashboard V0).

corvint-console serves that snapshot, the ticket board and detail, the specification index and a code pane on a loopback address you start explicitly:

corvint-console --repo /absolute/path/to/repo --tasks /path/to/corvint-tasks \
  --snapshot /path/to/corvint-dashboard-snapshot

Open http://127.0.0.1:7777, stop it with Ctrl-C. It installs nothing, opens no outbound connection and holds no database (Local Admin Console V0).

Agent-facing servers

Four stdio MCP servers, each bound to one repository root, each read-only. The companion bundle builder includes corvint-mcp, corvint-docs-mcp and corvint-test-validity-mcp; use a published bundle only when its exact assets and qualification evidence exist. They are not in the Core archive. corvint-corpus-mcp is source-only and experimental:

Server Tools
corvint-mcp corvint.query, corvint.impact and corvint.status: the same bounded context, Go impact and repository-status receipts as the CLI; with --tool-profile task-review, corvint.context and corvint.cem.report also return the task-context packet and a non-publishing CEM report preview
corvint-docs-mcp corvint.docs_draft returns a source-pinned documentation draft from owner prose and indexed Go declarations; corvint.docs_consume rechecks a draft's exact bytes against source
corvint-corpus-mcp (source-only) Experimental revision-pinned documentation corpus; capability-gated read tools over one explicitly supplied local artifact
corvint-test-validity-mcp Discovery and projection of retained test evidence in one five-axis shape

corvint docs maintain --watch is the foreground companion to the docs server: it refreshes a generated page block as eligible source commits land, preserves the surrounding prose, and stops on any outside edit or when its write and wall-clock limits are reached (setup, protocol).

Sixteen language analyzers

cmd/corvint-analyzer-* are candidate analyzers for Go, Python, JavaScript/TypeScript, Java, Kotlin/Android, Swift, Objective-C, C/JNI, .NET, Ruby, Rust, shell, SQL, shaders, HTML/CSS and structured data. Each emits facts with byte spans and evidence digests under a frozen candidate profile and is admitted to the product only through its own accepted profile (candidate profiles).

Coordination and release checks

  • corvint-pulse: a bounded local coordinator for snapshot lifecycle state with frozen transcripts; leases and deltas are not delivered (Pulse Snapshot Lease V0).
  • corvint-companion-release assembles the companion bundle from two clean checkouts and writes its manifest and checksums; corvint-public-release-check qualifies one retained bundle; corvint-release-gate is an offline evidence gate; corvint-go-toolchain-receipt digests a GOROOT tree into a receipt. None publishes anything.

Experimental Core commands

Three commands added after rc.1 are experimental and carry no 1.0 promise:

  • corvint breakage inspects declared cross-repository API relationships (Cross-repository breakage map V0).
  • corvint step checks declared authoring scope against local read-only observations and emits citeable receipts; host enforcement is separate (Authoring step scope V0).
  • corvint delta compiles one source-content-free record for an explicit immutable change (Immutable delta V0).

Flow variation coverage

Flow variation coverage compares the complete declared documentation inventory with accepted flow variations and retained original Playwright /3 receipts. The CLI can explicitly write a fresh documentation projection; the opt-in MCP flows profile is read-only. Proof binds immutable bytes and declared application identity; deployment attestation remains outside /3. Use the guide's exact input/profile and qualification requirements.

Experimental editor definition companion

The separate corvint-lsp prototype can use an explicitly supplied local gopls binary for definitions between open Go overlays in one explicitly supplied root:

go build -o /tmp/corvint-lsp ./cmd/corvint-lsp
/tmp/corvint-lsp --experimental --gopls /absolute/path/to/gopls --root /absolute/project/root

The editor must launch the process over stdio and declare the same canonical root. The companion uses full-text synchronization and UTF-8/16/32 positions; non-open targets return unavailable. The backend receives offline Go settings, but the executable is trusted local code, not sandboxed.

In a Git root, add --workspace-drift-guard to refuse definitions after observed disk, save, branch or root drift until a new session. The guard hashes the whole workspace within fixed bounds; larger repositories may exceed its budget. External SDK and caches remain unbound, so this is a partial experimental guard. Omit the flag to disable it.

This operator-started experiment changes no Core defaults and installs no editor configuration. It exposes a corvintDefinitionProbe experimental marker and accepts direct development textDocument/definition requests, but does not advertise the standard definition capability. Automatic editor navigation remains unavailable until an exact client tuple is qualified. See the experimental contract for bounds and rollback.

The optional Go editor companion also accepts experimental corvint/context with closed params {"textDocument":{"uri":"file:///absolute/root/file.go"},"task":"investigate a requirement","limit":10}. The document must be open. Discover the method/schema under capabilities.experimental.corvintContext. The response preserves the task-review Core object, including abstentions, separately from an unsaved overlay observation (random session ID, decimal-string capture ID, version and SHA-256). It starts one bounded native context worker, with no second gopls, tests or repository writes. Point-in-time Git/branch/root and overlay checks fail closed on observed drift. This remains experimental; exact client tuples and outcome/performance floors are unqualified. See the LSP editor context contract for bounds, fixed errors and observation limits.

Built to be checked

Spec-driven Every substantive capability has an executable spec with stable requirement IDs in docs/specs/REQUIREMENTS.tsv; go run ./script/spec-coverage-audit reports test, case, and fixture mentions separately from comments and missing mentions
Decision records Numbered, accepted intent with explicit promotion boundaries in docs/decisions/
Frozen conformance Exact receipt and state replay, CEM/LRF/TCQ vectors, and an in-repo second consumer for cem/0.1 in interop/cem01-go
Honest disagreements Every known behavioural disagreement is adjudicated and dated in the divergence register
Hermetic archives make gate includes script/go-archive-gate, which rebuilds the release archives from the committed revision and checks the closed file set (spec)
Dogfooded Substantive Corvint changes must collect context with Corvint and bind the diff to a CEM (dogfood contract)

Status, stated plainly

[!IMPORTANT] 1.0.0-rc.1 is the published release candidate for Corvint 1.0, and 1.0.0-rc.2 is the next candidate, not yet built or published. The 1.0 stability promise (frozen contracts, N-1 readers or deterministic migrations) covers the Core surfaces below and nothing else (1.0 scope, decision 0373). Stable 1.0 also requires the expanded Flows, safe navigation, documentation/MCP, full Beamfall roadmap takeover by Tasks and automatic documentation outcomes accepted in decision 0426. Those requirements do not expand Core's binary boundary or transfer its stability promise to companions. The three Core jobs must pass on Corvint, Beamfall and one untouched public repository (PRS-V1-008; urfave/cli for rc.2, decision 0432), alongside the expanded product qualification. Platform status comes from each release's exact assets and evidence. The table distinguishes retained rc.1 evidence from the expanded scope; it does not qualify later source changes.

Surface 1.0 label Release evidence and current scope
init, adopt, index, query, context, impact, affected, prove Core Command, wire and migration contracts frozen; init, adopt and the deterministic index lifecycle qualified. Receipts carry coverage, omissions and uncertainty as specified.
CEM 0.1 / 0.2, OCM, change frontier Core Frozen with canonical conformance vectors. interop/cem01-go is an in-repo second consumer for cem/0.1 only; 1.0 claims no third-party interoperability.
Dogfood loop Core Substantive Corvint changes are bound to a CEM and sealed with a retained local outcome (dogfood contract).
Core jobs Core The rc.1 evaluation failed overall. Orientation missed critical test files in 3/20 cases on go-chi/chi and 1/20 on Beamfall. Consequence and completion passed on those repositories; the Corvint run aborted before scoring. These results block 1.0 final (release evidence). The rc.2 run on urfave/cli, Corvint and Beamfall has not run yet.
Native release artifact and install lifecycle Core darwin/arm64 and linux/amd64 have retained rc.1 install-lifecycle qualification. darwin/amd64 was tested under Rosetta 2 and linux/arm64 in a container; both remain FALLBACK. Windows is unsupported. rc.1 is unsigned, and decision 0433 selects no signing for rc.2 and 1.0 as well: SHA256SUMS only, publisher identity NOT_VERIFIED (release evidence).
Retrieval quality Core surface, unqualified ranking Bounded receipts around a named path or subject are the product. Broad task-to-evidence retrieval has not passed held-out evaluation: the retained held-out attempt beat the exact-search baseline on top-5 (0.571 vs 0.343) and met the abstention and latency bars, but returned forbidden results on 7 of 36 must-exclude checks. Do not rely on ranking or abstention.
Does CEM help a reviewer? Not claimed Unproven. A five-pair pilot scored mean missed evidence of 0.90 for control and 0.86 with CEM. It is a pilot, not a held-out outcome study.
Performance Not claimed No native performance qualification is claimed for rc.1 or rc.2. Earlier measurements compared against the retired Python runtime and do not qualify the Go-only release.
Host adapters Core (Codex, Claude Code), companion (Gemini CLI, OpenCode, Pi) Core lifecycle receipts report FALLBACK; formal FULL host authority is post-1.0. OpenCode native integration has separate exact-tuple qualification and no execution authority. The VS Code extension is deferred.
Flows, safe navigation, Tasks takeover, documentation and MCP Required 1.0 product outcomes, independently packaged Expanded stable-release qualification remains pending under decision 0426; source presence and local gates do not establish whole-product acceptance.
MCP servers, corvint-tasks, dashboard, console, test providers, docs Companion Qualified separately, with no Core stability promise. Selected outcomes above are required for stable 1.0; unrelated consoles and providers remain optional. The console and dashboard present evidence and never hold authority over it.
Learned traces, work queue, Pulse, evaluation verbs Experimental Shipped without a promise. A learned-path change is admitted only through a pinned two-arm evaluation, and none is qualified for this release.

These boundaries are backed by committed artifacts: the 1.0 scope, the release notes, the specification index, and benchmarks/.

Development

For a scoped change, use corvint affected --base FULL_BASE_SHA, retain its unknowns, then run focused tests and the checks required by the owning contract. Follow the dogfood contract and obtain independent review. Release or repository-wide validation uses the exhaustive gate below, which includes root tests/vet, interoperability, archive and documentation checks:

test "$(GOTOOLCHAIN=local go env GOVERSION)" = "go1.27.1"
GOTOOLCHAIN=local make gate
script/release-checklist      # read-only; PASS/FAIL/NOT_RUN, exits 0 only when all required rows pass

Standalone root or interoperability tests use go test -count=1 -timeout 30m ./... and go vet ./... in the corresponding module with GOTOOLCHAIN=local. The 30-minute limit is a per-package hang detector. Do not rerun the same checks before make gate unless changed inputs or a failure require it.

If GOTOOLCHAIN=local go env GOVERSION reports a different patch version than go1.27.1 (for example, a Homebrew go formula upgrade changed the linked toolchain), install the exact pinned version alongside it rather than relinking Homebrew's default, then prepend its bin directory to PATH for gate commands only, e.g. PATH=/opt/homebrew/Cellar/go/1.27.1/bin:$PATH GOTOOLCHAIN=local make gate (Intel Homebrew: /usr/local/Cellar/go/1.27.1/bin).

Gemini/OpenCode adapter tests use their hosts' Node runtime. Core builds and the native regression suite do not require Python; optional qualification scripts, such as the live Go LSP campaign, may require Python 3 and their declared external tools. See native regression ownership.

License

Corvint is free software under the GNU Affero General Public License v3.0 or later. The portable protocol descriptions, schemas, conformance material, examples, and interop implementations are Apache-2.0 instead, so anyone can implement the standard, including in proprietary software, without the copyleft attaching. See LICENSING.md for the exact path boundary, LICENSE for the AGPL text, LICENSE-APACHE-2.0 for the Apache text, and PROVENANCE.md.

Directories

Path Synopsis
benchmarks
dogfood-measure command
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
dogfood-workers command
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
runner command
Command benchmark-runner executes Corvint's pinned multi-repository retrieval benchmark.
Command benchmark-runner executes Corvint's pinned multi-repository retrieval benchmark.
selfuse-batch command
cmd
corvint command
corvint-analyzer-dotnet command
Command corvint-analyzer-dotnet is the isolated .NET analyzer candidate.
Command corvint-analyzer-dotnet is the isolated .NET analyzer candidate.
corvint-analyzer-go command
corvint-analyzer-go is an unregistered experimental fact extractor.
corvint-analyzer-go is an unregistered experimental fact extractor.
corvint-analyzer-html-css command
corvint-analyzer-html-css is an unselected experimental analyzer candidate.
corvint-analyzer-html-css is an unselected experimental analyzer candidate.
corvint-analyzer-ruby command
corvint-analyzer-ruby is an unregistered experimental static analyzer.
corvint-analyzer-ruby is an unregistered experimental static analyzer.
corvint-analyzer-rust command
corvint-analyzer-rust is an unselected experimental Rust analyzer candidate.
corvint-analyzer-rust is an unselected experimental Rust analyzer candidate.
corvint-analyzer-shader command
corvint-analyzer-shader is an unselected experimental shader analyzer candidate.
corvint-analyzer-shader is an unselected experimental shader analyzer candidate.
corvint-analyzer-shell command
corvint-analyzer-shell is an unregistered experimental static analyzer.
corvint-analyzer-shell is an unregistered experimental static analyzer.
corvint-analyzer-structured-data command
corvint-analyzer-structured-data is an unselected experimental analyzer.
corvint-analyzer-structured-data is an unselected experimental analyzer.
corvint-analyzer-swift command
corvint-analyzer-swift is an unregistered experimental fact extractor.
corvint-analyzer-swift is an unregistered experimental fact extractor.
corvint-behavior-falsify command
Command corvint-behavior-falsify is an explicitly approved experimental companion for browser-criterion falsification controls.
Command corvint-behavior-falsify is an explicitly approved experimental companion for browser-criterion falsification controls.
corvint-cem-candidate command
corvint-cem-candidate is an optional experimental reference-integrity companion.
corvint-cem-candidate is an optional experimental reference-integrity companion.
corvint-cem-experiments command
corvint-cem-experiments is an opt-in experimental local companion, excluded from the Core release.
corvint-cem-experiments is an opt-in experimental local companion, excluded from the Core release.
corvint-companion-release command
Command corvint-companion-release assembles the optional companion distribution bundle for a single pinned target (darwin/arm64 only; see docs/specs/public-release-v0.md).
Command corvint-companion-release assembles the optional companion distribution bundle for a single pinned target (darwin/arm64 only; see docs/specs/public-release-v0.md).
corvint-console command
Command corvint-console builds the Corvint Console executable described by `docs/specs/local-admin-console-v0.md` (decision 0081).
Command corvint-console builds the Corvint Console executable described by `docs/specs/local-admin-console-v0.md` (decision 0081).
corvint-corpus-http command
corvint-corpus-http is an explicitly started experimental companion transport.
corvint-corpus-http is an explicitly started experimental companion transport.
corvint-corpus-parity command
corvint-corpus-parity is an experimental local immutable-corpus companion.
corvint-corpus-parity is an experimental local immutable-corpus companion.
corvint-corpus-republish command
corvint-corpus-republish is an experimental trusted-local companion.
corvint-corpus-republish is an experimental trusted-local companion.
corvint-docs-mcp command
Command corvint-docs-mcp is a separate local stdio MCP 2026-07-28 server that exposes only the experimental source-documentation draft/consume tools (docs/specs/source-documentation-draft-v0.md).
Command corvint-docs-mcp is a separate local stdio MCP 2026-07-28 server that exposes only the experimental source-documentation draft/consume tools (docs/specs/source-documentation-draft-v0.md).
corvint-intake command
corvint-intake validates reader output without fetching or exposing raw context.
corvint-intake validates reader output without fetching or exposing raw context.
corvint-js-test-provider command
Command corvint-js-test-provider is the experimental IPR-08 JS/TS live-test provider CLI: `unit` runs the bound Vitest adapter, `e2e` runs the bound Playwright adapter (internal/jstestprovider).
Command corvint-js-test-provider is the experimental IPR-08 JS/TS live-test provider CLI: `unit` runs the bound Vitest adapter, `e2e` runs the bound Playwright adapter (internal/jstestprovider).
corvint-lsp command
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
corvint-mcp command
corvint-playwright-minimize command
Command corvint-playwright-minimize is an explicitly authorized experimental companion.
Command corvint-playwright-minimize is an explicitly authorized experimental companion.
corvint-postmerge-connect command
Command corvint-postmerge-connect is a separate experimental companion.
Command corvint-postmerge-connect is a separate experimental companion.
corvint-postmerge-metrics command
corvint-postmerge-metrics is an optional, local, recommendation-only companion.
corvint-postmerge-metrics is an optional, local, recommendation-only companion.
corvint-postmerge-workflow command
Command corvint-postmerge-workflow is an experimental local replay companion, not a live writer.
Command corvint-postmerge-workflow is an experimental local replay companion, not a live writer.
corvint-public-release-check command
Command corvint-public-release-check qualifies one already-retained companion bundle.
Command corvint-public-release-check qualifies one already-retained companion bundle.
corvint-pulse command
corvint-readiness-record command
Command corvint-readiness-record builds or verifies the stable readiness record for one verified candidate (SRR-V1-012).
Command corvint-readiness-record builds or verifies the stable readiness record for one verified candidate (SRR-V1-012).
corvint-release-candidate command
Command corvint-release-candidate assembles already-qualified retained artifacts into one immutable local candidate.
Command corvint-release-candidate assembles already-qualified retained artifacts into one immutable local candidate.
corvint-release-gate command
corvint-release-gate is an experimental offline evidence gate.
corvint-release-gate is an experimental offline evidence gate.
corvint-release-install command
Command corvint-release-install installs one verified host core archive into a fresh version/platform path.
Command corvint-release-install installs one verified host core archive into a fresh version/platform path.
corvint-tasks command
Command corvint-tasks is the Corvint task control plane executor and ticket store.
Command corvint-tasks is the Corvint task control plane executor and ticket store.
corvint-test-runner command
corvint-test-runner is an experimental optional companion.
corvint-test-runner is an experimental optional companion.
corvint-test-validity-mcp command
Command corvint-test-validity-mcp is a separate local stdio MCP 2026-07-28 server for the experimental MCP test-validity profile (docs/specs/mcp-test-validity-profile-v0.md).
Command corvint-test-validity-mcp is a separate local stdio MCP 2026-07-28 server for the experimental MCP test-validity profile (docs/specs/mcp-test-validity-profile-v0.md).
corvint-tests-accept command
corvint-tests-accept is an optional experimental local companion.
corvint-tests-accept is an optional experimental local companion.
corvint-update command
corvint-web-flows command
Command corvint-web-flows is an explicitly invoked experimental browser companion.
Command corvint-web-flows is an explicitly invoked experimental browser companion.
conformance
cli-parity-v0 command
frontier-v0 command
Command frontier-v0 reports what this conformance suite covers and validates its own data.
Command frontier-v0 reports what this conformance suite covers and validates its own data.
go-live-test-v0 command
Command go-live-test-v0 independently verifies the discovery portion of the experimental Corvint Go live-test protocol.
Command go-live-test-v0 independently verifies the discovery portion of the experimental Corvint Go live-test protocol.
host-lifecycle-v1 command
host-lifecycle-v1 runs the nine host lifecycle cases of HLQ-V1 (docs/specs/host-lifecycle-qualification-v1.md) for one host tuple against installed executables, in a private temporary workspace.
host-lifecycle-v1 runs the nine host lifecycle cases of HLQ-V1 (docs/specs/host-lifecycle-qualification-v1.md) for one host tuple against installed executables, in a private temporary workspace.
ocm-v0 command
Command ocm-v0 reports what this conformance suite covers and validates its own data.
Command ocm-v0 reports what this conformance suite covers and validates its own data.
perf-v0 command
release-artifact-v0 command
release-artifact-v0 is the offline reproducible-build gate for the Go candidate.
release-artifact-v0 is the offline reproducible-build gate for the Go candidate.
release-artifact-v0/archive-verifier command
archive-verifier is the separately compiled offline verifier process.
archive-verifier is the separately compiled offline verifier process.
release-artifact-v0/archivebuild
Package archivebuild assembles the canonical Go release containers.
Package archivebuild assembles the canonical Go release containers.
release-artifact-v0/archiveverify
Package archiveverify independently verifies Go release archives.
Package archiveverify independently verifies Go release archives.
release-artifact-v0/archivewire
Package archivewire contains data-only request and result types shared across the archive builder and the separately compiled offline verifier.
Package archivewire contains data-only request and result types shared across the archive builder and the separately compiled offline verifier.
use-cases-v0 command
work-queue-v0
Package workqueuev0 implements the native work-queue qualification fixtures.
Package workqueuev0 implements the native work-queue qualification fixtures.
examples
evidence-provider/v0 command
SPDX-License-Identifier: AGPL-3.0-or-later Copy this single file to author a local provider; it uses only Go's standard library.
SPDX-License-Identifier: AGPL-3.0-or-later Copy this single file to author a local provider; it uses only Go's standard library.
evidence-provider/v0/check command
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
evidence-provider/v0/conformance command
SPDX-License-Identifier: AGPL-3.0-or-later Command conformance builds one authored provider from a copy of the kit's main.go and exercises it through Corvint's file and contained command transports.
SPDX-License-Identifier: AGPL-3.0-or-later Command conformance builds one authored provider from a copy of the kit's main.go and exercises it through Corvint's file and contained command transports.
experimental
integrations
testfixture command
This executable is an authored transport fixture, never the Corvint implementation.
This executable is an authored transport fixture, never the Corvint implementation.
internal
analyzerdotnet
Package analyzerdotnet is an isolated, static-only .NET fact candidate.
Package analyzerdotnet is an isolated, static-only .NET fact candidate.
analyzerexec
Package analyzerexec launches one digest-pinned staged native analyzer.
Package analyzerexec launches one digest-pinned staged native analyzer.
analyzergo
Package analyzergo implements an unregistered experimental Go fact extractor.
Package analyzergo implements an unregistered experimental Go fact extractor.
analyzerhtmlcss
Package analyzerhtmlcss is an unregistered experimental HTML/CSS fact extractor.
Package analyzerhtmlcss is an unregistered experimental HTML/CSS fact extractor.
analyzerkotlinandroid
Package analyzerkotlinandroid implements an unregistered experimental Kotlin/Android analyzer.
Package analyzerkotlinandroid implements an unregistered experimental Kotlin/Android analyzer.
analyzerpython
Package analyzerpython implements the unregistered Python 3.12 candidate.
Package analyzerpython implements the unregistered Python 3.12 candidate.
analyzerruby
Package analyzerruby is an isolated, static-only Ruby fact candidate.
Package analyzerruby is an isolated, static-only Ruby fact candidate.
analyzerrust
Package analyzerrust is an isolated, static-only Rust fact candidate.
Package analyzerrust is an isolated, static-only Rust fact candidate.
analyzershader
Package analyzershader is an unregistered, admission-candidate-only shader extractor.
Package analyzershader is an unregistered, admission-candidate-only shader extractor.
analyzershell
Package analyzershell is an isolated, static-only shell fact candidate.
Package analyzershell is an isolated, static-only shell fact candidate.
analyzerstructured
Package analyzerstructured is an unregistered, admission-candidate-only structured-data extractor.
Package analyzerstructured is an unregistered, admission-candidate-only structured-data extractor.
analyzerswift
Package analyzerswift is an unregistered experimental Swift/Apple fact extractor.
Package analyzerswift is an unregistered experimental Swift/Apple fact extractor.
appflows
Package appflows composes experimental, caller-reported application behavior evidence.
Package appflows composes experimental, caller-reported application behavior evidence.
attest
Package attest wraps a prove document (see cmd/corvint/prove.go and docs/specs/falsifiable-packet-v0.md, requirement FPK-V0-012) as an in-toto Statement v1 (https://in-toto.io/Statement/v1), and signs that statement inside a DSSE envelope (https://github.com/secure-systems-lab/dsse) so an external gate can consume it.
Package attest wraps a prove document (see cmd/corvint/prove.go and docs/specs/falsifiable-packet-v0.md, requirement FPK-V0-012) as an in-toto Statement v1 (https://in-toto.io/Statement/v1), and signs that statement inside a DSSE envelope (https://github.com/secure-systems-lab/dsse) so an external gate can consume it.
authorityevent
Package authorityevent defines the experimental native Stop transport.
Package authorityevent defines the experimental native Stop transport.
authoritystore
Package authoritystore is the fixed read-only protected publication consumer.
Package authoritystore is the fixed read-only protected publication consumer.
behaviorfalsify
Package behaviorfalsify runs explicitly approved, bounded falsification controls for one exact browser-behavior criterion.
Package behaviorfalsify runs explicitly approved, bounded falsification controls for one exact browser-behavior criterion.
betarung
Package betarung expresses the GPK-V0-042 beta rung: the third compatibility label BETA, the per-command/per-surface admission record that decides it, and the disclosure obligation that makes an admission valid.
Package betarung expresses the GPK-V0-042 beta rung: the third compatibility label BETA, the per-command/per-surface admission record that decides it, and the disclosure obligation that makes an admission valid.
breakagemap
Package breakagemap composes explicitly scoped immutable witnesses.
Package breakagemap composes explicitly scoped immutable witnesses.
cem/cemcode
Package cemcode registers the stable CEM error taxonomy shared by every CEM seam.
Package cemcode registers the stable CEM error taxonomy shared by every CEM seam.
cem/cli
Package cli is the thin CEM command dispatch.
Package cli is the thin CEM command dispatch.
cem/coverprofile
Package coverprofile is the Go coverprofile grammar shared by the bounded runner (internal/liveverify/gorunner) and `cem cover` (TCQ-V0-051).
Package coverprofile is the Go coverprofile grammar shared by the bounded runner (internal/liveverify/gorunner) and `cem cover` (TCQ-V0-051).
cem/gitauth
Package gitauth is the isolated Git authority kernel for CEM: it validates the repository boundary (reciprocal worktree metadata, alternates denial, attribute isolation), resolves revisions, reads tree entries and blobs through Git object identity, and derives canonical CEM 0.2 patch bytes that are independent of repository configuration, attributes, diff drivers, object redirection, shallow/partial state, and linked-worktree layout.
Package gitauth is the isolated Git authority kernel for CEM: it validates the repository boundary (reciprocal worktree metadata, alternates denial, attribute isolation), resolves revisions, reads tree entries and blobs through Git object identity, and derives canonical CEM 0.2 patch bytes that are independent of repository configuration, attributes, diff drivers, object redirection, shallow/partial state, and linked-worktree layout.
cem/gitrun
Package gitrun executes bounded, contained Git child processes for the CEM seams.
Package gitrun executes bounded, contained Git child processes for the CEM seams.
cem/mdreport
Package mdreport renders values into CEM and OCM review-report Markdown safely.
Package mdreport renders values into CEM and OCM review-report Markdown safely.
cem/patch
Package patch implements the frozen CEM 0.1 bounded unified-diff parser specified by interop/cem-0.1/ALGORITHMS.md.
Package patch implements the frozen CEM 0.1 bounded unified-diff parser specified by interop/cem-0.1/ALGORITHMS.md.
cem/publish
Package publish is the descriptor-rooted bounded reader and transactional output publisher for CEM artifacts.
Package publish is the descriptor-rooted bounded reader and transactional output publisher for CEM artifacts.
cem/sim
Package sim proves a parsed CEM patch against exact base-tree bytes, per interop/cem-0.1/ALGORITHMS.md "Patch/base simulation".
Package sim proves a parsed CEM patch against exact base-tree bytes, per interop/cem-0.1/ALGORITHMS.md "Patch/base simulation".
cem/verify
Package verify composes the CEM seams into the frozen repository-conformant verifier: exact-patch (cem/0.1) and canonical (cem/0.2, cem/0.3) verification with the frozen validation precedence, mechanical byte and Go structural proofs, and same-path evidence drift.
Package verify composes the CEM seams into the frozen repository-conformant verifier: exact-patch (cem/0.1) and canonical (cem/0.2, cem/0.3) verification with the frozen validation precedence, mechanical byte and Go structural proofs, and same-path evidence drift.
cem/wire
Package wire reads and validates CEM 0.1/0.2 wire documents.
Package wire reads and validates CEM 0.1/0.2 wire documents.
cem/workflow
Package workflow implements the CEM producer/verifier operations — begin, prepare, cite, mark, status, verify, and report — over the CEM seams, with the frozen CEM-CB envelope table, validation precedence, and resume rules.
Package workflow implements the CEM producer/verifier operations — begin, prepare, cite, mark, status, verify, and report — over the CEM seams, with the frozen CEM-CB envelope table, validation precedence, and resume rules.
cemcandidate
Package cemcandidate joins explicit reference evidence without promoting native Tasks authority, historical execution or criterion adequacy.
Package cemcandidate joins explicit reference evidence without promoting native Tasks authority, historical execution or criterion adequacy.
cemdiscriminate
Package cemdiscriminate is the mutation runner behind `cem discriminate` (TCQ-V0-055..058).
Package cemdiscriminate is the mutation runner behind `cem discriminate` (TCQ-V0-055..058).
changewitness
Package changewitness is the experimental pure evaluator for the `ocm-change-witnessed-v0` relation (docs/specs/change-witness-relation-v0.md).
Package changewitness is the experimental pure evaluator for the `ocm-change-witnessed-v0` relation (docs/specs/change-witness-relation-v0.md).
compactionkernel
Package compactionkernel makes compaction survival a checkable property.
Package compactionkernel makes compaction survival a checkable property.
companionrelease
Package companionrelease assembles the optional companion distribution bundle (nine Go binaries plus five agent-host packages) for a single pinned target.
Package companionrelease assembles the optional companion distribution bundle (nine Go binaries plus five agent-host packages) for a single pinned target.
console
Package console is the read-through local admin console of `docs/specs/local-admin-console-v0.md` (decision 0081).
Package console is the read-through local admin console of `docs/specs/local-admin-console-v0.md` (decision 0081).
corpusindex
Package corpusindex is an experimental immutable companion artifact profile.
Package corpusindex is an experimental immutable companion artifact profile.
corpusrepublish
Package corpusrepublish is an experimental trusted-local companion.
Package corpusrepublish is an experimental trusted-local companion.
corpusserve
Package corpusserve implements an optional experimental JSON HTTP companion.
Package corpusserve implements an optional experimental JSON HTTP companion.
criterionexperiment
Package criterionexperiment implements the experimental, caller-reported criterion experiment companion.
Package criterionexperiment implements the experimental, caller-reported criterion experiment companion.
dashboard/model
Package model compiles already-normalized dashboard adapter results into the canonical corvint-dashboard-snapshot/0 wire representation.
Package model compiles already-normalized dashboard adapter results into the canonical corvint-dashboard-snapshot/0 wire representation.
dashboard/roadmap
Package roadmap joins the human-owned roadmap ticket store (`atm`) to current source evidence (docs/specs/REQUIREMENTS.tsv), current test receipts (a configured testvalidity.Projection receipts directory), and generated-doc state (a configured docs-state file) for the local dashboard snapshot (IPR-10, docs/plans/integrated-product-roadmap-2026-09-12.md).
Package roadmap joins the human-owned roadmap ticket store (`atm`) to current source evidence (docs/specs/REQUIREMENTS.tsv), current test receipts (a configured testvalidity.Projection receipts directory), and generated-doc state (a configured docs-state file) for the local dashboard snapshot (IPR-10, docs/plans/integrated-product-roadmap-2026-09-12.md).
delta
Package delta joins immutable change evidence without emitting source prose.
Package delta joins immutable change evidence without emitting source prose.
depsource
Package depsource answers one read-only question: what are the pinned bytes of a third-party Go module this repository depends on, and do they match the checksum the committed go.sum records?
Package depsource answers one read-only question: what are the pinned bytes of a third-party Go module this repository depends on, and do they match the checksum the committed go.sum records?
diagnostic
Package diagnostic is the refusal envelope of docs/specs/diagnostic-repair-contract-v0.md (DRC-V0): a refused subject, the facts measured while refusing, and the closed set of registry-owned repairs, carried beside an existing {code, message} error.
Package diagnostic is the refusal envelope of docs/specs/diagnostic-repair-contract-v0.md (DRC-V0): a refused subject, the facts measured while refusing, and the closed set of registry-owned repairs, carried beside an existing {code, message} error.
disagree
Package disagree reports whether two independent retrieval channels agree on the files a task needs (retriever-disagreement-v0).
Package disagree reports whether two independent retrieval channels agree on the files a task needs (retriever-disagreement-v0).
doccorpus
Package doccorpus compiles the proposed DCP-V1 documentation evidence profile.
Package doccorpus compiles the proposed DCP-V1 documentation evidence profile.
docmaintain
Package docmaintain implements an explicitly enabled, bounded local session that keeps one human documentation page's generated blocks in sync with immutable Git source, per the IPR-05 slice of docs/plans/integrated-product-roadmap-2026-09-12.md and the maintenance requirements in docs/specs/source-documentation-draft-v0.md (SDD-V0-007+).
Package docmaintain implements an explicitly enabled, bounded local session that keeps one human documentation page's generated blocks in sync with immutable Git source, per the IPR-05 slice of docs/plans/integrated-product-roadmap-2026-09-12.md and the maintenance requirements in docs/specs/source-documentation-draft-v0.md (SDD-V0-007+).
docviews
Package docviews compiles proof-bound audience projections from an existing admitted Human Documentation Compiler plan.
Package docviews compiles proof-bound audience projections from an existing admitted Human Documentation Compiler plan.
dogfoodflow
Package dogfoodflow runs the daily dogfood change, check and seal steps of docs/DOGFOOD.md inside the Corvint binary, so any Git repository can run them without Corvint's scripts, VERSION file or source tree (DCW-V0-020 and DCW-V0-021).
Package dogfoodflow runs the daily dogfood change, check and seal steps of docs/DOGFOOD.md inside the Corvint binary, so any Git repository can run them without Corvint's scripts, VERSION file or source tree (DCW-V0-020 and DCW-V0-021).
dogfoodocm
Package dogfoodocm verifies the private ordered set of unchanged OCM maps used by Corvint's repository dogfood loop.
Package dogfoodocm verifies the private ordered set of unchanged OCM maps used by Corvint's repository dogfood loop.
dogfoodoperation
Package dogfoodoperation serializes local-completion and public dogfood writers through the same private administrative lock.
Package dogfoodoperation serializes local-completion and public dogfood writers through the same private administrative lock.
evalrepo
Package evalrepo evaluates a frozen Corvint retrieval corpus without mutation.
Package evalrepo evaluates a frozen Corvint retrieval corpus without mutation.
extevidence
Package extevidence attaches external evidence provider records to the path-impact receipt as a separated section (docs/specs/external-evidence-provider-v0.md).
Package extevidence attaches external evidence provider records to the path-impact receipt as a separated section (docs/specs/external-evidence-provider-v0.md).
flowcoverage
Package flowcoverage binds accepted variation inventories to retained /3 observations.
Package flowcoverage binds accepted variation inventories to retained /3 observations.
flowcoverage/testfixture
Package testfixture supplies a real committed, uncovered denominator for adapter parity tests.
Package testfixture supplies a real committed, uncovered denominator for adapter parity tests.
flowdocs
Package flowdocs produces bounded source observations, never accepted intent or witnessed runtime behavior, from immutable native-index source bytes.
Package flowdocs produces bounded source observations, never accepted intent or witnessed runtime behavior, from immutable native-index source bytes.
frontier
Package frontier implements Change Frontier V0 (`frontier/0`), the deterministic composition of canonical CEM 0.2, OCM 0.1, Lexical Relevance Floor V0, and Test Claim Qualification V0 specified in docs/specs/change-frontier-v0.md.
Package frontier implements Change Frontier V0 (`frontier/0`), the deterministic composition of canonical CEM 0.2, OCM 0.1, Lexical Relevance Floor V0, and Test Claim Qualification V0 specified in docs/specs/change-frontier-v0.md.
frontiernext
Package frontiernext implements the additive experimental closing relation.
Package frontiernext implements the additive experimental closing relation.
frontiernextrepo
Package frontiernextrepo independently re-derives the experimental universe from immutable Git objects using the existing canonical CEM/OCM verifier.
Package frontiernextrepo independently re-derives the experimental universe from immutable Git objects using the existing canonical CEM/OCM verifier.
frontierrepo
Package frontierrepo binds the Change Frontier V0 seams to real Git authority.
Package frontierrepo binds the Change Frontier V0 seams to real Git authority.
gitnotes
Package gitnotes anchors a committed Change Evidence Map to a commit in a Corvint notes ref and reads Git-native provenance beside it: the Git AI `refs/notes/ai` authorship log and the `Assisted-by` / `Agent-Logs-Url` commit trailers (FPK-V0-037..040, decision 0355).
Package gitnotes anchors a committed Change Evidence Map to a commit in a Corvint notes ref and reads Git-native provenance beside it: the Git AI `refs/notes/ai` authorship log and the `Assisted-by` / `Agent-Logs-Url` commit trailers (FPK-V0-037..040, decision 0355).
gitstatus
Package gitstatus observes status with frozen configuration and explicit repository paths.
Package gitstatus observes status with frozen configuration and explicit repository paths.
gokernel
Package gokernel contains the experimental dependency-free Corvint production kernel.
Package gokernel contains the experimental dependency-free Corvint production kernel.
goplsclient
Package goplsclient provides an experimental explicitly configured local gopls session.
Package goplsclient provides an experimental explicitly configured local gopls session.
groupreap
Package groupreap reaps a process-group leader started with Setpgid and SIGKILLs whatever is left in its group, signalling while the exited leader is still unreaped so the group ID cannot name a process that reused its PID.
Package groupreap reaps a process-group leader started with Setpgid and SIGKILLs whatever is left in its group, signalling while the exited leader is still unreaped so the group ID cannot name a process that reused its PID.
intake
Package intake admits closed-vocabulary reader claims before an author sees them.
Package intake admits closed-vocabulary reader claims before an author sees them.
jstestprovider
Package jstestprovider is an experimental IPR-08 provider slice: one JS/TS unit adapter (Vitest) and one E2E adapter (Playwright) that each produce a receipt binding test/config/app-build/environment identity to per-test execution outcomes, then feed those facts through internal/testvalidity.Project (see ../testvalidity/projection.go).
Package jstestprovider is an experimental IPR-08 provider slice: one JS/TS unit adapter (Vitest) and one E2E adapter (Playwright) that each produce a receipt binding test/config/app-build/environment identity to per-test execution outcomes, then feed those facts through internal/testvalidity.Project (see ../testvalidity/projection.go).
liveverify/affected
Package affected selects the verification units reachable from a dirty worktree.
Package affected selects the verification units reachable from a dirty worktree.
liveverify/affected/dotnet
Package dotnet is the C# implementation of the affected-selection language seam.
Package dotnet is the C# implementation of the affected-selection language seam.
liveverify/affected/golang
Package golang is the Go implementation of the affected-selection language seam.
Package golang is the Go implementation of the affected-selection language seam.
liveverify/affected/kotlin
Package kotlin is the Kotlin/JVM implementation of the affected-selection language seam.
Package kotlin is the Kotlin/JVM implementation of the affected-selection language seam.
liveverify/affected/languages
Package languages lists every affected-selection language provider, so each caller that builds an impact graph walks the same languages.
Package languages lists every affected-selection language provider, so each caller that builds an impact graph walks the same languages.
liveverify/affected/python
Package python is the Python implementation of the affected-selection language seam.
Package python is the Python implementation of the affected-selection language seam.
liveverify/affected/ruby
Package ruby is the Ruby implementation of the affected-selection language seam.
Package ruby is the Ruby implementation of the affected-selection language seam.
liveverify/affected/rust
Package rust is the Rust implementation of the affected-selection language seam.
Package rust is the Rust implementation of the affected-selection language seam.
liveverify/affected/swift
Package swift is the Swift implementation of the affected-selection language seam.
Package swift is the Swift implementation of the affected-selection language seam.
liveverify/affected/typescript
Package typescript is the JavaScript and TypeScript implementation of the affected-selection language seam.
Package typescript is the JavaScript and TypeScript implementation of the affected-selection language seam.
liveverify/godiscovery
Package godiscovery decodes the closed Go 1.27 package-discovery stream.
Package godiscovery decodes the closed Go 1.27 package-discovery stream.
liveverify/gorunner
Package gorunner executes one bounded, explicit Go test plan.
Package gorunner executes one bounded, explicit Go test plan.
liveverify/gotest
Package gotest observes the bounded JSON event stream emitted by Go 1.27's `go test -json` mode without retaining test or build output text.
Package gotest observes the bounded JSON event stream emitted by Go 1.27's `go test -json` mode without retaining test or build output text.
liveverify/jsresolve
Package jsresolve answers, from JavaScript or TypeScript source bytes alone, the three questions the `reference-resolves` falsifier asks of a web citation (FPK-V0-018): does an import on the cited line carry a given specifier, does an identifier sit on the cited line, and does a blob declare a name at top level.
Package jsresolve answers, from JavaScript or TypeScript source bytes alone, the three questions the `reference-resolves` falsifier asks of a web citation (FPK-V0-018): does an import on the cited line carry a given specifier, does an identifier sit on the cited line, and does a blob declare a name at top level.
liveverify/mutate
Package mutate implements the test-kills-mutant falsifier described by docs/specs/falsifiable-packet-v0.md.
Package mutate implements the test-kills-mutant falsifier described by docs/specs/falsifiable-packet-v0.md.
liveverify/parentverify
Package parentverify implements the local parent authority required by the experimental Go live-test producer.
Package parentverify implements the local parent authority required by the experimental Go live-test producer.
liveverify/provider
Package provider coordinates one explicitly requested, local Go test run.
Package provider coordinates one explicitly requested, local Go test run.
liveverify/pymutate
Package pymutate is the Python arm of the test-kills-mutant falsifier (docs/specs/falsifiable-packet-v0.md, FPK-V0-019).
Package pymutate is the Python arm of the test-kills-mutant falsifier (docs/specs/falsifiable-packet-v0.md, FPK-V0-019).
liveverify/pyresolve
Package pyresolve answers, from Python source bytes alone, whether an import statement that begins on a given line imports a given dotted module.
Package pyresolve answers, from Python source bytes alone, whether an import statement that begins on a given line imports a given dotted module.
liveverify/session
Package session implements the experimental Go live-test provider's foreground session: a bounded-file poll loop that debounces edits, computes a current-input identity, and runs the frozen `go test -json` invocation (via gorunner.Run, the same contained runner provider.Execute uses) once per settled edit.
Package session implements the experimental Go live-test provider's foreground session: a bounded-file poll loop that debounces edits, computes a current-input identity, and runs the frozen `go test -json` invocation (via gorunner.Run, the same contained runner provider.Execute uses) once per settled edit.
localauthority
Package localauthority verifies the experimental protected execution profile.
Package localauthority verifies the experimental protected execution profile.
localcompletion
Package localcompletion coordinates a caller-owned local workflow.
Package localcompletion coordinates a caller-owned local workflow.
lrf
Package lrf implements the frozen Lexical Relevance Floor V0 projection.
Package lrf implements the frozen Lexical Relevance Floor V0 projection.
lrfrepo
Package lrfrepo issues canonical LRF results from verified repository authority.
Package lrfrepo issues canonical LRF results from verified repository authority.
lspevidence
Package lspevidence attaches explicitly requested semantic evidence to a task-context packet without changing its ranked results or authority.
Package lspevidence attaches explicitly requested semantic evidence to a task-context packet without changing its ranked results or authority.
lspprovider
Package lspprovider is Corvint's optional local language-server evidence provider (external-evidence-provider-v0 EEP-V0-023..026, task-context-packet-v0 TCP-V0-043..046, decision 0371).
Package lspprovider is Corvint's optional local language-server evidence provider (external-evidence-provider-v0 EEP-V0-023..026, task-context-packet-v0 TCP-V0-043..046, decision 0371).
lspsnapshot
Package lspsnapshot implements experimental, in-memory LSP snapshot identities.
Package lspsnapshot implements experimental, in-memory LSP snapshot identities.
lspstdio
SPDX-License-Identifier: AGPL-3.0-or-later
SPDX-License-Identifier: AGPL-3.0-or-later
mcp/bridge
Package bridge exposes the currently qualified Corvint read surfaces without coupling them to an MCP transport implementation.
Package bridge exposes the currently qualified Corvint read surfaces without coupling them to an MCP transport implementation.
mcp/corpusbridge
Package corpusbridge exposes only capabilities declared by a revalidated documentation corpus.
Package corpusbridge exposes only capabilities declared by a revalidated documentation corpus.
mcp/docsbridge
Package docsbridge exposes the experimental source-documentation draft/consume implementation (docs/specs/source-documentation-draft-v0.md) as read-only MCP tools.
Package docsbridge exposes the experimental source-documentation draft/consume implementation (docs/specs/source-documentation-draft-v0.md) as read-only MCP tools.
mcp/protocol
Package protocol implements bounded MCP 2026-07-28 wire types.
Package protocol implements bounded MCP 2026-07-28 wire types.
mcp/server
Package server implements the local child-owned MCP 2026-07-28 stdio server.
Package server implements the local child-owned MCP 2026-07-28 stdio server.
mcp/testvaliditybridge
Package testvaliditybridge exposes the shared test-validity projection as the single read-only tool of the experimental MCP test-validity profile (docs/specs/mcp-test-validity-profile-v0.md).
Package testvaliditybridge exposes the shared test-validity projection as the single read-only tool of the experimental MCP test-validity profile (docs/specs/mcp-test-validity-profile-v0.md).
migrationratchet
Package migrationratchet compares immutable migration evidence snapshots.
Package migrationratchet compares immutable migration evidence snapshots.
necessity
Package necessity answers one read-only question about a task-context packet: which of the files the packet included does the packet actually depend on? Each included path is removed from a copy of the index and the packet is recompiled; a path whose removal costs the packet an anchor, grows its missing-critical set, or moves it off a resolved answerability verdict is `load-bearing`, and every other included path is `supporting`.
Package necessity answers one read-only question about a task-context packet: which of the files the packet included does the packet actually depend on? Each included path is removed from a copy of the index and the packet is recompiled; a path whose removal costs the packet an anchor, grows its missing-critical set, or moves it off a resolved answerability verdict is `load-bearing`, and every other included path is `supporting`.
obscorpus
Package obscorpus is the experimental OCA-V0 contract (docs/specs/observation-corpus-authority-v0.md): bounded harness observations and a sealed owner-labelled corpus replay.
Package obscorpus is the experimental OCA-V0 contract (docs/specs/observation-corpus-authority-v0.md): bounded harness observations and a sealed owner-labelled corpus replay.
observations
Package observations keeps bounded, local-only self-observation proposals.
Package observations keeps bounded, local-only self-observation proposals.
opencodequalification
Package opencodequalification produces local maintainer evidence, never execution authority.
Package opencodequalification produces local maintainer evidence, never execution authority.
outcomecal
Package outcomecal joins recorded local task outcomes with the packet stance (answered or abstained) that preceded them and reports calibration only.
Package outcomecal joins recorded local task outcomes with the packet stance (answered or abstained) that preceded them and reports calibration only.
plansnapshot
Package plansnapshot validates caller-owned immutable planning inputs.
Package plansnapshot validates caller-owned immutable planning inputs.
playwrightminimize
Package playwrightminimize plans bounded Playwright suite-interaction trials.
Package playwrightminimize plans bounded Playwright suite-interaction trials.
postmergeconnector
Package postmergeconnector is an experimental, local reference companion.
Package postmergeconnector is an experimental, local reference companion.
postmergemetrics
Package postmergemetrics produces caller-owned, recommendation-only evidence.
Package postmergemetrics produces caller-owned, recommendation-only evidence.
postmergeproof
Package postmergeproof owns the closed post-merge /2 process proof wire and its concrete offline verifier (PMR-V2-006).
Package postmergeproof owns the closed post-merge /2 process proof wire and its concrete offline verifier (PMR-V2-006).
postmergeproof/procfs
Package procfs is the Linux procfs raw tuple reader for post-merge /2 process proofs (PMR-V2-006).
Package procfs is the Linux procfs raw tuple reader for post-merge /2 process proofs (PMR-V2-006).
postmergeworkflow
SPDX-License-Identifier: AGPL-3.0-or-later Derived from internal/tasks/safeopen/at_linux.go at 29a6db884ed795f7694c316433896d190e1ab508; kept private for decision 0397.
SPDX-License-Identifier: AGPL-3.0-or-later Derived from internal/tasks/safeopen/at_linux.go at 29a6db884ed795f7694c316433896d190e1ab508; kept private for decision 0397.
projectpath
Package projectpath normalizes existing and verified-absent project paths.
Package projectpath normalizes existing and verified-absent project paths.
projectprofile
Package projectprofile holds the downstream-project conventions the kernel used to hardcode: how a project is recognised, which ledgers it keeps, and which verification command each changed path implies.
Package projectprofile holds the downstream-project conventions the kernel used to hardcode: how a project is recognised, which ledgers it keeps, and which verification command each changed path implies.
proofabstraction
Package proofabstraction implements the experimental exact proof-projection relation described by PPA-V0.
Package proofabstraction implements the experimental exact proof-projection relation described by PPA-V0.
pulse
Package pulse contains the in-memory coordination primitives for Corvint Pulse.
Package pulse contains the in-memory coordination primitives for Corvint Pulse.
pythongrammar
Package pythongrammar holds the closed Python 3.12 subset lexer and parser.
Package pythongrammar holds the closed Python 3.12 subset lexer and parser.
receiptbundle
Package receiptbundle exports the receipts that one change already carries (its CEM, witness report, dogfood report and gate receipt) as exact byte copies into a new directory with a line-oriented manifest, so an auditor can recompute every digest offline with script/verify-receipt-bundle.sh (docs/specs/receipt-bundle-v0.md, RCB-V0).
Package receiptbundle exports the receipts that one change already carries (its CEM, witness report, dogfood report and gate receipt) as exact byte copies into a new directory with a line-oriented manifest, so an auditor can recompute every digest offline with script/verify-receipt-bundle.sh (docs/specs/receipt-bundle-v0.md, RCB-V0).
releasecandidate
Package releasecandidate closes the already-qualified core and companion artifacts into one immutable, versioned local publication candidate.
Package releasecandidate closes the already-qualified core and companion artifacts into one immutable, versioned local publication candidate.
releasegate
Package releasegate verifies one manifest-selected, immutable Git release tree.
Package releasegate verifies one manifest-selected, immutable Git release tree.
remoteprovider
Package remoteprovider belongs exclusively to the optional remote adapter.
Package remoteprovider belongs exclusively to the optional remote adapter.
repoenvelope
Package repoenvelope frames repository-derived JSON as untrusted data for agent context (AHI-004).
Package repoenvelope frames repository-derived JSON as untrusted data for agent context (AHI-004).
runhygiene
Package runhygiene is the fail-safe test-attempt hygiene (AFU-V1-038) shared by the run-evidence adapters (internal/appflows) and the Playwright provider receipt (internal/jstestprovider).
Package runhygiene is the fail-safe test-attempt hygiene (AFU-V1-038) shared by the run-evidence adapters (internal/appflows) and the Playwright provider receipt (internal/jstestprovider).
runtimeenv
Package runtimeenv resolves runtime settings from the CORVINT_ environment namespace.
Package runtimeenv resolves runtime settings from the CORVINT_ environment namespace.
scopelease
Package scopelease implements bounded local scope leases so several agents sharing one worktree cannot silently edit overlapping files or the same ticket.
Package scopelease implements bounded local scope leases so several agents sharing one worktree cannot silently edit overlapping files or the same ticket.
secretscreen
Package secretscreen holds the secret-shaped-text detector Corvint's local writers share plus immutable stored-format compatibility matchers.
Package secretscreen holds the secret-shaped-text detector Corvint's local writers share plus immutable stored-format compatibility matchers.
semescalate
Package semescalate is the experimental deterministic core of the Semantic Escalation Gate (docs/specs/semantic-escalation-gate-v0.md).
Package semescalate is the experimental deterministic core of the Semantic Escalation Gate (docs/specs/semantic-escalation-gate-v0.md).
skillexport
Package skillexport renders admitted learned traces as Agent Skills documents: one directory per admitted rule holding a short SKILL.md with YAML frontmatter and a references/trace.md that carries the full detail (LTA-V0-006 to LTA-V0-008).
Package skillexport renders admitted learned traces as Agent Skills documents: one directory per admitted rule holding a short SKILL.md with YAML frontmatter and a references/trace.md that carries the full detail (LTA-V0-006 to LTA-V0-008).
slotlearn
Package slotlearn turns the local read ledgers into negative labels for context slot order and proposes bounded slot-weight traces that only the frozen held-out gate may admit (learned-trace-admission-v0, LTA-V0-009..012).
Package slotlearn turns the local read ledgers into negative labels for context slot order and proposes bounded slot-weight traces that only the frozen held-out gate may admit (learned-trace-admission-v0, LTA-V0-009..012).
stepverify
Package stepverify observes a quiescent, host-confined authoring step.
Package stepverify observes a quiescent, host-confined authoring step.
stepverify/safeopen
SPDX-License-Identifier: AGPL-3.0-or-later Derived from internal/tasks/safeopen/at_linux.go at 25971bda1ca1664d8a546d751cb2bb9bbd454daf.
SPDX-License-Identifier: AGPL-3.0-or-later Derived from internal/tasks/safeopen/at_linux.go at 25971bda1ca1664d8a546d751cb2bb9bbd454daf.
taskman
Package taskman implements the explicitly trusted-local native fixture planner.
Package taskman implements the explicitly trusted-local native fixture planner.
tasks/archive
Package archive implements `archive export` and `archive verify` (TM-V0-022, §3.5 taskman-archive/0).
Package archive implements `archive export` and `archive verify` (TM-V0-022, §3.5 taskman-archive/0).
tasks/authority
Package authority supplies the explicit, mutation-only filesystem primitives of SPEC §3.4, §5.1 and §5.2 for the repository authority that internal/intent resolves: the bounded exclusive flock on `<git-common-dir>/taskman.lock`, filesystem qualification by actual OS observation, descriptor-based durable sync, and the exclusive link-in creation primitive used for `receipts/<seq>.json`, `.boot` and `.ack`.
Package authority supplies the explicit, mutation-only filesystem primitives of SPEC §3.4, §5.1 and §5.2 for the repository authority that internal/intent resolves: the bounded exclusive flock on `<git-common-dir>/taskman.lock`, filesystem qualification by actual OS observation, descriptor-based durable sync, and the exclusive link-in creation primitive used for `receipts/<seq>.json`, `.boot` and `.ack`.
tasks/cli
Package cli routes the `corvint-tasks` verbs: pure reads and archive export/verification under TM-V0-008, plus init and fourteen ticket mutations through the §5.2 journal writer.
Package cli routes the `corvint-tasks` verbs: pure reads and archive export/verification under TM-V0-008, plus init and fourteen ticket mutations through the §5.2 journal writer.
tasks/criterionbinding
Package criterionbinding validates optional criterion capture artifacts using the native record decoders.
Package criterionbinding validates optional criterion capture artifacts using the native record decoders.
tasks/dispatch
Package dispatch is the CAL-V0-052..058 continuous dispatcher: a deterministic roster over native queue state that launches, supervises and heals independent host worker processes.
Package dispatch is the CAL-V0-052..058 continuous dispatcher: a deterministic roster over native queue state that launches, supervises and heals independent host worker processes.
tasks/fixture
Package fixture builds realistic on-disk fixtures for TCP-01 tests: a primary worktree with its `.git` common directory, a `.taskman/` intent store and a `<git-common-dir>/taskman/` state dir with a valid receipt chain.
Package fixture builds realistic on-disk fixtures for TCP-01 tests: a primary worktree with its `.git` common directory, a `.taskman/` intent store and a `<git-common-dir>/taskman/` state dir with a valid receipt chain.
tasks/importer
Package importer maps a foreign roadmap export onto shadow IMPORT ticket records (CTS-V0-003).
Package importer maps a foreign roadmap export onto shadow IMPORT ticket records (CTS-V0-003).
tasks/intent
Package intent reads the Git-tracked intent store of SPEC §3.1 (`.taskman/`), resolves the primary worktree (§3.1, §3.4) and the intent worktree that holds the projection (CTW-V0), and computes the intent tree digest and publication facts.
Package intent reads the Git-tracked intent store of SPEC §3.1 (`.taskman/`), resolves the primary worktree (§3.1, §3.4) and the intent worktree that holds the projection (CTW-V0), and computes the intent tree digest and publication facts.
tasks/journal
Package journal audits immutable experimental ledgers.
Package journal audits immutable experimental ledgers.
tasks/mutation
Package mutation implements the taskman-mutation/0 envelope of SPEC §3.3, its operation-specific closed payloads, the taskman-outcome/0 result, the pure post-record computation of every §3.3 operation (TM-V0-003, TM-V0-005), the request-ID replay rule of TM-V0-006 against an explicit index, and the §3.3 ADOPT_FILE composition (R2 F3, AS-35).
Package mutation implements the taskman-mutation/0 envelope of SPEC §3.3, its operation-specific closed payloads, the taskman-outcome/0 result, the pure post-record computation of every §3.3 operation (TM-V0-003, TM-V0-005), the request-ID replay rule of TM-V0-006 against an explicit index, and the §3.3 ADOPT_FILE composition (R2 F3, AS-35).
tasks/release
Package release implements the pure taskman-release/0 release-control model.
Package release implements the pure taskman-release/0 release-control model.
tasks/safeopen
Package safeopen provides the narrow no-follow opening boundary for local stores.
Package safeopen provides the narrow no-follow opening boundary for local stores.
tasks/scopes
Package scopes derives experimental claim scopes from an explicitly enabled Corvint index pack.
Package scopes derives experimental claim scopes from an explicitly enabled Corvint index pack.
tasks/service
Package service is the experimental, opt-in taskman-user-service/0 profile.
Package service is the experimental, opt-in taskman-user-service/0 profile.
tasks/snapshot
Package snapshot implements the TM-V0-008 read snapshot protocol over the private state directory of §3.4: read head.json, prove that the `<lastSeq+1>` and `<lastSeq+2>` receipt slots are absent, read, re-check, retry at most three times, else NOT_RUN/SNAPSHOT_MOVED.
Package snapshot implements the TM-V0-008 read snapshot protocol over the private state directory of §3.4: read head.json, prove that the `<lastSeq+1>` and `<lastSeq+2>` receipt slots are absent, read, re-check, retry at most three times, else NOT_RUN/SNAPSHOT_MOVED.
tasks/store
Package store is the callable durable writer (decision 0003): it applies a validated transaction.Plan to a real repository authority following the §5.2 sequence, and it creates the state dir at genesis.
Package store is the callable durable writer (decision 0003): it applies a validated transaction.Plan to a real repository authority following the §5.2 sequence, and it creates the state dir at genesis.
tasks/ticket
Package ticket implements the taskman-ticket/0 record of SPEC §3.1, its closed validation (TM-V0-002, TM-V0-003), the dependency checks of TM-V0-005 and the derived eligibility of §3.2 (TM-V0-004).
Package ticket implements the taskman-ticket/0 record of SPEC §3.1, its closed validation (TM-V0-002, TM-V0-003), the dependency checks of TM-V0-005 and the derived eligibility of §3.2 (TM-V0-004).
tasks/transaction
Package transaction computes hypothetical fixture transactions and capacity.
Package transaction computes hypothetical fixture transactions and capacity.
tasks/wire
Package wire implements SPEC §2 (identity and canonical encoding), the §1 numeric limits, the §11 closed detail codes and the taskman-command-result/0 envelope of §3.3.
Package wire implements SPEC §2 (identity and canonical encoding), the §1 numeric limits, the §11 closed detail codes and the taskman-command-result/0 envelope of §3.3.
tcq
Package tcq implements Test Claim Qualification V0 (`tcq/0`) as specified in docs/specs/test-claim-qualification-v0.md.
Package tcq implements Test Claim Qualification V0 (`tcq/0`) as specified in docs/specs/test-claim-qualification-v0.md.
testacceptance
Package testacceptance composes actual, operator-approved experimental browser observations.
Package testacceptance composes actual, operator-approved experimental browser observations.
testevidence
Package testevidence is the opt-in producer half of retained test evidence (LPCV-V0-055, decision 0218): a provider run with --retain writes its exact stdout document into the one location testvaliditydoc.Discover reads.
Package testevidence is the opt-in producer half of retained test evidence (LPCV-V0-055, decision 0218): a provider run with --retain writes its exact stdout document into the one location testvaliditydoc.Discover reads.
testrunner
Package testrunner defines experimental, runner-neutral execution observations.
Package testrunner defines experimental, runner-neutral execution observations.
testrunner/dynamic
Package dynamic implements explicit experimental dynamic-language runner profiles.
Package dynamic implements explicit experimental dynamic-language runner profiles.
testrunner/mobile
Package mobile observes a bounded experimental Appium Android runner tuple.
Package mobile observes a bounded experimental Appium Android runner tuple.
testrunner/native
Package native adapts explicit native runner profiles.
Package native adapts explicit native runner profiles.
testrunner/platform
Package platform reads runner-specific JVM, Apple and shell observations.
Package platform reads runner-specific JVM, Apple and shell observations.
testrunner/registry
Package registry composes explicit experimental runner profiles without letting one language's result hide another provider's unknown frontier.
Package registry composes explicit experimental runner profiles without letting one language's result hide another provider's unknown frontier.
testrunner/sql
Package sql observes two bounded experimental native SQL runner profiles.
Package sql observes two bounded experimental native SQL runner profiles.
testsupport
Package testsupport holds small load-detection helpers shared by timing- sensitive tests across packages, so a wall-clock ceiling can be skipped under a loaded host instead of flaking (decision 0036).
Package testsupport holds small load-detection helpers shared by timing- sensitive tests across packages, so a wall-clock ceiling can be skipped under a loaded host instead of flaking (decision 0036).
testvalidity
Package testvalidity defines one shared test-validity projection consumed by both the Go CLI/MCP surface and the VS Code extension's TypeScript mirror (extensions/vscode/src/testvalidity.ts).
Package testvalidity defines one shared test-validity projection consumed by both the Go CLI/MCP surface and the VS Code extension's TypeScript mirror (extensions/vscode/src/testvalidity.ts).
testvaliditydoc
Package testvaliditydoc builds the corvint-test-validity/0 document (docs/specs/live-proof-carrying-verification-v0.md LPCV-V0-051): the shared five-axis projection of every test-level result a JavaScript receipt or Go preview-session event carries.
Package testvaliditydoc builds the corvint-test-validity/0 document (docs/specs/live-proof-carrying-verification-v0.md LPCV-V0-051): the shared five-axis projection of every test-level result a JavaScript receipt or Go preview-session event carries.
touchsurprise
Package touchsurprise measures, for one completed task, how much of the change the task-context packet never named: the touch-set surprise.
Package touchsurprise measures, for one completed task, how much of the change the task-context packet never named: the touch-set surprise.
tracemigraterepo
Package tracemigraterepo binds trace migration to stable Git repository authority.
Package tracemigraterepo binds trace migration to stable Git repository authority.
tracerecordrepo
Package tracerecordrepo binds trace recording to stable Git repository authority.
Package tracerecordrepo binds trace recording to stable Git repository authority.
tracerepopaths
Package tracerepopaths defines the current-tree path authority shared by trace adapters.
Package tracerepopaths defines the current-tree path authority shared by trace adapters.
unplannedread
Package unplannedread measures reads that Corvint failed to prevent: tool calls that opened a project file the delivered context packet did not already carry.
Package unplannedread measures reads that Corvint failed to prevent: tool calls that opened a project file the delivered context packet did not already carry.
untrackedallowance
Package untrackedallowance decides which untracked worktree paths a committed-content result may tolerate without degrading (decision 0142).
Package untrackedallowance decides which untracked worktree paths a committed-content result may tolerate without degrading (decision 0142).
update
Package update implements the optional, operator-invoked release updater.
Package update implements the optional, operator-invoked release updater.
witness
Package witness reports the unwitnessed surface of one committed change range: of the obligations that range opens, how many were closed by evidence from a party other than the change's author, how many stand unproven, and how many could not be determined at all.
Package witness reports the unwitnessed surface of one committed change range: of the obligations that range opens, how many were closed by evidence from a party other than the change's author, how many stand unproven, and how many could not be determined at all.
witnesscollapse
Package witnesscollapse compiles explicitly declared common causes over one exact CEM into a conservative upper bound on independent witnesses.
Package witnesscollapse compiles explicitly declared common causes over one exact CEM into a conservative upper bound on independent witnesses.
worklistadapter
Package worklistadapter is the repository-work-queue-adapter/0 producer for a committed JSON worklist.
Package worklistadapter is the repository-work-queue-adapter/0 producer for a committed JSON worklist.
workqueue
Package workqueue validates Work Queue Observation V0 wire artifacts and computes deterministic, non-operative wave proposals.
Package workqueue validates Work Queue Observation V0 wire artifacts and computes deterministic, non-operative wave proposals.
worksource
Package worksource qualifies the read-only source shared by the work observer and the repository-owned producer.
Package worksource qualifies the read-only source shared by the work observer and the repository-owned producer.
wp3codec
Package wp3codec implements the WP3 commitment codec: the dependency-free canonical JSON subset frozen under "Canonical evaluation commitments" in docs/specs/lexical-relevance-floor-v0.md and restated word-for-word by docs/specs/change-frontier-v0.md CF-V0-019.
Package wp3codec implements the WP3 commitment codec: the dependency-free canonical JSON subset frozen under "Canonical evaluation commitments" in docs/specs/lexical-relevance-floor-v0.md and restated word-for-word by docs/specs/change-frontier-v0.md CF-V0-019.
interop
cem01-go module
script
tools
beamfall-shadow command
beamfall-shadow/wrapper command
beamfall-shadow-wrapper is intentionally tiny: it gives run.sh a portable process-group signal and reaping boundary around `go run`.
beamfall-shadow-wrapper is intentionally tiny: it gives run.sh a portable process-group signal and reaping boundary around `go run`.
cem-interop-runner command
cem-interop-runner is the native, Corvint-free CEM 0.1 external consumer harness.
cem-interop-runner is the native, Corvint-free CEM 0.1 external consumer harness.
cem-trial command
Command cem-trial is the external agent-harness dispatcher for the CEM reviewer trial in docs/specs/cem-reviewer-trial-v0.md.
Command cem-trial is the external agent-harness dispatcher for the CEM reviewer trial in docs/specs/cem-reviewer-trial-v0.md.
ci-reuse-plan command
SPDX-License-Identifier: AGPL-3.0-or-later ci-reuse-plan implements the repository-specific AFP-V0-024 main-push reuse decision.
SPDX-License-Identifier: AGPL-3.0-or-later ci-reuse-plan implements the repository-specific AFP-V0-024 main-push reuse decision.
ci-shard-costs command
Command ci-shard-costs refreshes and checks the advisory package costs that place packages in CI shards (AFP-V0-022).
Command ci-shard-costs refreshes and checks the advisory package costs that place packages in CI shards (AFP-V0-022).
compat-trial command
compat-trial/build-fixtures command
Build the closed native fixture registry into a replay runner.
Build the closed native fixture registry into a replay runner.
compat-trial/fixtures/new command
Owned replay fixture: its variant is fixed by the repository build helper.
Owned replay fixture: its variant is fixed by the repository build helper.
compat-trial/fixtures/old command
Owned replay fixture: its variant is fixed by the repository build helper.
Owned replay fixture: its variant is fixed by the repository build helper.
corvint-pr-tests command
Command corvint-pr-tests executes typed Go test argv from a separately trusted affected planner and the existing gate-affected-select.
Command corvint-pr-tests executes typed Go test argv from a separately trusted affected planner and the existing gate-affected-select.
cw-trial command
Command cw-trial is the external agent-harness dispatcher for the confidently-wrong trial in docs/specs/confidently-wrong-trial-v0.md.
Command cw-trial is the external agent-harness dispatcher for the confidently-wrong trial in docs/specs/confidently-wrong-trial-v0.md.
docs-ci-plan command
SPDX-License-Identifier: AGPL-3.0-or-later docs-ci-plan implements the repository-specific DCI-V0 policy, not affected-plan narrowing.
SPDX-License-Identifier: AGPL-3.0-or-later docs-ci-plan implements the repository-specific DCI-V0 policy, not affected-plan narrowing.
gate-affected-select command
Command gate-affected-select is the selection step of script/gate-affected.sh (AFP-V0-011, AFP-V0-012).
Command gate-affected-select is the selection step of script/gate-affected.sh (AFP-V0-011, AFP-V0-012).
gate-ledger command
Command gate-ledger is the memory of `make gate` (docs/specs/gate-ledger-v0.md).
Command gate-ledger is the memory of `make gate` (docs/specs/gate-ledger-v0.md).
heading-nav-bench command
SPDX-License-Identifier: AGPL-3.0-or-later Experimental offline comparison; headings confer no authority.
SPDX-License-Identifier: AGPL-3.0-or-later Experimental offline comparison; headings confer no authority.
pi-tui-fixture command
Command pi-tui-fixture drives native Pi TUI prompts through a pseudo-terminal and reaps the complete owned PTY process group.
Command pi-tui-fixture drives native Pi TUI prompts through a pseudo-terminal and reaps the complete owned PTY process group.
retrieval-bench command
Command retrieval-bench runs Agent Retrieval Bench samples (arXiv 2607.24882) against `corvint query`, `corvint context`, `corvint impact`, and `corvint affected` beside a deterministic grep baseline and reports recall, MRR, file F1, and selective success with confidence intervals.
Command retrieval-bench runs Agent Retrieval Bench samples (arXiv 2607.24882) against `corvint query`, `corvint context`, `corvint impact`, and `corvint affected` beside a deterministic grep baseline and reports recall, MRR, file F1, and selective success with confidence intervals.
unbounded-readers command
SPDX-License-Identifier: AGPL-3.0-or-later unbounded-readers is the AFP-V0-025 ratchet: it fails when a test unit selected on every change (AFP-V0-012 rule (d)) is not in the repository's recorded set.
SPDX-License-Identifier: AGPL-3.0-or-later unbounded-readers is the AFP-V0-025 ratchet: it fails when a test unit selected on every change (AFP-V0-012 rule (d)) is not in the repository's recorded set.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL