Documentation
¶
Overview ¶
Package frontier implements Change Frontier V0 (`frontier/0`), the deterministic composition of canonical CEM 0.2, OCM 0.1, Lexical Relevance Floor V0, and Test Claim Qualification V0 specified in docs/specs/change-frontier-v0.md.
V0 is a local frontier preview and review queue. Per CF-V0-004 it has no stop-decision field and no hook authority, and per CF-V0-027 harness integration waits for a separately accepted harness-authority relation under a NEW profile identifier. Nothing in this package may be wired into the agent harness.
Index ¶
- Constants
- func CanonicalBytes(document Document) ([]byte, error)
- func CodeOf(err error) string
- func ItemID(kind, subjectID, universeID string) (string, error)
- func RenderError(err error) []byte
- func RenderErrorHuman(err error) string
- func RenderHuman(document Document) string
- func RenderJSON(document Document) ([]byte, error)
- func UniverseID(scope Scope) (string, error)
- type Document
- type Error
- type Inputs
- type IntentScope
- type Item
- type Obligation
- type Request
- type Scope
- type Span
- type TCQClaimResult
- type TCQRecomputer
- type TCQRequest
- type TCQResult
- type TestMode
- type VerifiedUniverse
- type Verifier
- type VerifyRequest
Constants ¶
const ( CodeInvalidInput = "invalid-frontier-input" CodeUnsupportedContext = "unsupported-frontier-context" CodeNoncanonical = "noncanonical-frontier" CodeResourceExhausted = "frontier-resource-exhausted" CodeInterrupted = "frontier-interrupted" CodeInternalError = "frontier-internal-error" )
Frontier-owned operational codes (CF-V0-022).
const ( Profile = "frontier/0" ErrorProfile = "frontier-error/0" Policy = "strict-v0" // ExcludedPath is the frozen CEM 0.2 sidecar exclusion. It is a literal in // both the universe preimage (CF-V0-006) and the emitted scope // (CF-V0-018), never copied from caller input. ExcludedPath = ".corvint/change.cem.json" )
Profile identifiers and the single admitted policy (CF-V0-005, CF-V0-018).
const ( AdmittedCEMSpec = "cem/0.2" AdmittedOCMSpec = "ocm/0.1-experimental" )
Admitted upstream profiles (CF-V0-001). CEM 0.1, or OCM bound to CEM 0.1, is `unsupported-frontier-context`.
const ( StateEmpty = "EMPTY" StateOpen = "OPEN" )
FrontierState is the CF-V0-004 global state. There is no third state, and deliberately no stop-decision field: V0 has no hook authority (CF-V0-027).
const ( KindHunkBasis = "HUNK_BASIS" KindIntentChange = "INTENT_CHANGE" KindIntentTest = "INTENT_TEST" )
Item kinds (CF-V0-007).
const ( AuthorityNone = "NONE" AuthorityProducerDeclared = "PRODUCER_DECLARED" AuthorityCallerReported = "CALLER_REPORTED" )
Authority classes (CF-V0-017). `CALLER_REPORTED` is integrity-bound caller input with no independent execution authority root, which is exactly why CF-V0-014 forbids it from closing anything.
const ( ResolutionActionable = "ACTIONABLE" ResolutionAuthorityRequired = "AUTHORITY_REQUIRED" ResolutionProfileRequired = "PROFILE_REQUIRED" )
Resolution classes (CF-V0-017).
const ( ReasonHunkNoEvidence = "HUNK_NO_EVIDENCE" ReasonHunkInsufficientEvidence = "HUNK_INSUFFICIENT_EVIDENCE" ReasonHunkConflictingEvidence = "HUNK_CONFLICTING_EVIDENCE" ReasonDeletionRelationRequired = "DELETION_RELATION_REQUIRED" ReasonSubjectTermBoundExceeded = "SUBJECT_TERM_BOUND_EXCEEDED" ReasonEvidenceSpanTooBroad = "EVIDENCE_SPAN_TOO_BROAD" ReasonSelfReferentialBasis = "SELF_REFERENTIAL_BASIS" ReasonInsufficientLexicalSupport = "INSUFFICIENT_LEXICAL_SUPPORT" ReasonObligationUnassessed = "OBLIGATION_UNASSESSED" ReasonObligationNoTestClaim = "OBLIGATION_NO_TEST_CLAIM" ReasonObligationInsufficientEvidence = "OBLIGATION_INSUFFICIENT_EVIDENCE" ReasonObligationConflictingEvidence = "OBLIGATION_CONFLICTING_EVIDENCE" ReasonLexicalCandidateNonclosing = "LEXICAL_CANDIDATE_NONCLOSING" ReasonNoMaterialChangeWitness = "NO_MATERIAL_CHANGE_WITNESS" ReasonCallerReportedNonclosing = "CALLER_REPORTED_NONCLOSING" ReasonTargetCleanlinessNotAttested = "TARGET_CLEANLINESS_NOT_ATTESTED" ReasonCommandFailed = "COMMAND_FAILED" ReasonTestError = "TEST_ERROR" ReasonTestFailed = "TEST_FAILED" ReasonTestSkipped = "TEST_SKIPPED" ReasonTestIdentityAmbiguous = "TEST_IDENTITY_AMBIGUOUS" ReasonTestNotMatched = "TEST_NOT_MATCHED" ReasonTestClaimEmpty = "TEST_CLAIM_EMPTY" ReasonTestClaimUnconditionalSkip = "TEST_CLAIM_UNCONDITIONAL_SKIP" ReasonTestClaimUnassociated = "TEST_CLAIM_UNASSOCIATED" ReasonTestClaimUnsupported = "TEST_CLAIM_UNSUPPORTED" )
Reasons. HUNK_BASIS reasons come from CF-V0-009 and CF-V0-010, INTENT_CHANGE from CF-V0-011 and CF-V0-012, INTENT_TEST from the frozen CF-V0-016 table.
const ( ActionSupplyHunkBasis = "SUPPLY_HUNK_BASIS" ActionNarrowOrReplaceBasis = "NARROW_OR_REPLACE_BASIS" ActionDefineSupportedProfile = "DEFINE_SUPPORTED_PROFILE" ActionLinkObligation = "LINK_OBLIGATION" ActionLinkMaterialHunk = "LINK_MATERIAL_HUNK" ActionEstablishChangeWitness = "ESTABLISH_CHANGE_WITNESS" ActionEstablishHarnessAuthority = "ESTABLISH_HARNESS_AUTHORITY" ActionRerunTestCommand = "RERUN_TEST_COMMAND" ActionFixOrRerunTest = "FIX_OR_RERUN_TEST" ActionDisambiguateTestIdentity = "DISAMBIGUATE_TEST_IDENTITY" ActionSupplyTestObservation = "SUPPLY_TEST_OBSERVATION" ActionRepairTestClaim = "REPAIR_TEST_CLAIM" )
Next actions (CF-V0-009..012, CF-V0-016).
const ( MaxHunkItems = 2048 MaxIntentChangeItems = 256 MaxIntentTestItems = 256 MaxTotalItems = 2560 MaxRelatedIDsPerItem = 64 MaxReasonsPerItem = 32 MaxOutputBytes = 4194304 )
Frontier-owned limits (CF-V0-023). Counts are checked before append and byte arithmetic before output allocation, so exhaustion never leaves a partial result behind.
const ( OCMLinked = "linked" OCMUnknown = "unknown" )
OCM dispositions (OCM-V0-004).
const ( CEMSupported = "supported" CEMUnknown = "unknown" CEMMechanical = "mechanical" )
CEM dispositions consumed by CF-V0-008 and CF-V0-009.
const ErrorExitCode = 2
ErrorExitCode is the CF-V0-004 operational-failure exit: 2, with no Frontier JSON on stdout.
Variables ¶
This section is empty.
Functions ¶
func CanonicalBytes ¶
CanonicalBytes returns the complete Frontier document: codec(document) plus exactly one LF (CF-V0-019).
func CodeOf ¶
CodeOf extracts a Frontier code from an error chain, or "" when the error is not a Frontier failure.
func ItemID ¶
ItemID derives the CF-V0-007 identity from exactly (kind, subjectId, universeId). Evidence repair may remove an item but cannot change the identity of an unresolved obligation in the same universe, which is what makes the queue diffable across runs.
func RenderError ¶
RenderError returns the one bounded stderr envelope CF-V0-022 allows: exactly `{"code":"CODE","profile":"frontier-error/0"}` plus one LF, carrying a code and nothing else. Nothing about the input reaches it, which is how CF-V0-024's no-echo rule is enforced structurally rather than by review.
func RenderErrorHuman ¶
RenderErrorHuman renders one operational failure for a person. An inherited upstream code has no Frontier-owned message, so it is rendered as itself rather than as an invented sentence.
func RenderHuman ¶
RenderHuman renders the same computation as RenderJSON for a person. It emits only the verified fields of the valid result, and it states the CF-V0-025 assertion boundary in full so the queue cannot be read as proof that evidence does not exist, that code is wrong, that a test lacks behavioral coverage, or that the repository was exhaustively searched.
func RenderJSON ¶
RenderJSON returns the exact canonical document bytes. CF-V0-026 makes JSON and human two renderings of ONE computation, so both take a sealed Document and neither recomputes anything.
func UniverseID ¶
UniverseID derives the CF-V0-006 identity. Identical Git content across clones intentionally yields an identical universe ID.
Types ¶
type Document ¶
type Document struct {
FrontierState string
ID string
Inputs Inputs
Items []Item
Scope Scope
UniverseID string
}
Document is one complete Frontier result. It has no stop-decision field by construction (CF-V0-004).
type Error ¶
type Error struct {
Code string
// contains filtered or unexported fields
}
Error is one operational Frontier failure. It carries a code and nothing else on purpose: CF-V0-024 forbids echoing an unverified path, OID, digest, ID, count, XML value, argv element, sibling canary, or exception, and a message field is the usual way all of those leak. The unexported detail is for a Go caller's debugger, is never rendered, and never reaches Error().
func VerifyDocument ¶
VerifyDocument checks candidate Frontier bytes against the whole wire contract: the CF-V0-019 codec round trip, the closed CF-V0-017/018 shapes, the CF-V0-004 state law, the CF-V0-020 orders, the CF-V0-023 bounds, and the recomputed CF-V0-019 identity. Every violation is `noncanonical-frontier`, which is what makes an independent consumer able to refuse an almost-right document instead of half-reading it (CF-V0-028).
type Inputs ¶
type Inputs struct {
CEMSHA256 string
LRFSHA256 string
OCMSHA256 string
TCQID string
TestMode TestMode
}
Inputs is the CF-V0-018 `inputs` block. Each digest binds exactly the bytes CF-V0-019 names: CEM and OCM hash their verified bounded raw copies, LRF hashes its complete canonical result bytes.
type IntentScope ¶
IntentScope is the one exact pinned OCM intent scope (CF-V0-001).
type Item ¶
type Item struct {
AuthorityClass string
ID string
Kind string
NextAction string
Reasons []string
RelatedIDs []string
ResolutionClass string
SubjectID string
}
Item is the closed CF-V0-017 shape. No field is optional and no field may be added under this profile; a stop-decision field in particular is refused by VerifyDocument as `noncanonical-frontier`.
type Obligation ¶
type Obligation struct {
ID string
Disposition string
Reason string
HunkIDs []string
ClaimIDs []string
}
Obligation is one verified OCM 0.1 obligation row projected into Frontier. Fields mirror the OCM wire exactly (`ocm-v0-dogfood.md` OCM-V0-004): a linked obligation carries non-empty hunk and claim references, an unknown one carries empty references and one bounded reason.
type Request ¶
type Request struct {
// CEMBytes and OCMBytes are the exact bounded raw copies that will be
// verified and then digested into `inputs` (CF-V0-002, CF-V0-019).
CEMBytes []byte
OCMBytes []byte
// ExpectedBase and Target are the two independent revision inputs. Neither
// may be inferred: CF-V0-001 fails inferred revision authority.
ExpectedBase string
Target string
// The optional dynamic test bundle is the all-or-none CF-V0-003 tuple.
Command []byte
Observation []byte
JUnitReport []byte
// Verifier is the shared OCM-consuming CEM 0.2 verifier whose native
// precedence CF-V0-021 puts ahead of every later Frontier check.
Verifier Verifier
// TCQ recomputes Test Claim Qualification from the verified inputs. A
// caller-supplied TCQ result is never accepted as authority or as a
// shortcut (CF-V0-002), which is why this is a recomputer, not a document.
TCQ TCQRecomputer
}
Request is one Frontier invocation (CF-V0-001). It carries immutable byte copies rather than paths: CF-V0-026 keeps path acquisition outside the wire and the verifier, so a command wrapper reads files through its own hardened reader and hands the bytes here.
type Scope ¶
type Scope struct {
BaseRevision string
IntentBlobOID string
IntentPath string
IntentSpan Span
IntentSpanSHA256 string
ObjectFormat string
PatchSHA256 string
TargetRevision string
}
Scope is the CF-V0-018 `scope` block: the declared universe, restated in the result so a reader can rebind the identity without the original request.
type Span ¶
Span is an intent byte span. Both offsets are emitted as canonical decimal strings (CF-V0-006, CF-V0-018), never as JSON numbers.
type TCQClaimResult ¶
type TCQClaimResult struct {
ObligationID string
ClaimID string
// Reasons are the TCQ diagnostics Frontier maps to `INTENT_TEST` reasons under
// the exact CF-V0-016 table. The consumed vocabulary is closed:
// target-cleanliness-not-attested, command-failed, test-error, test-failed,
// test-skipped, execution-identity-ambiguous, repeated-test-rows,
// row-identity-unavailable, test-not-matched, empty-body, unconditional-skip,
// claim-association-missing, claim-association-ambiguous, python-offset-mismatch,
// unparseable-test-unit, unsupported-anchor-profile, unsupported-python-grammar.
// An unrecognised diagnostic is a closed-allowlist failure (CF-V0-022), never a
// silently dropped reason.
Reasons []string
// Relation is the TCQ relation when one was emitted (`test-report-matched-v0`).
// CF-V0-014 freezes it as non-closing: it maps to CALLER_REPORTED_NONCLOSING and
// never removes an INTENT_TEST item, whatever the rows or exit status say.
Relation string
// AuthorityClass is `CALLER_REPORTED` for every TCQ V0 edge (CF-V0-015). It is
// carried rather than assumed so a future producer cannot silently upgrade it.
AuthorityClass string
}
TCQClaimResult is one selected claim edge, per the reference vector at docs/specs/test-claim-qualification-v0.md:391.
type TCQRecomputer ¶
type TCQRecomputer interface {
Recompute(request TCQRequest) (TCQResult, error)
}
TCQRecomputer recomputes TCQ from verified inputs and target Git objects. CF-V0-002 forbids accepting a caller-supplied TCQ result as authority or as a shortcut, so Frontier holds this seam rather than a decoded document.
type TCQRequest ¶
type TCQRequest struct {
// CEMBytes is the canonical `cem/0.2` artifact the OCM binds. TCQ-V0-001
// requires it alongside the OCM, and TCQ-V0-002 refuses `cem/0.1`
// operationally, so the producer cannot source it for itself: an artifact it
// fetched independently would not be the one this invocation verified.
CEMBytes []byte
OCMBytes []byte
BaseRevision string
TargetRevision string
Mode TestMode
Command []byte
Observation []byte
JUnitReport []byte
}
TCQRequest carries the verified bytes and revisions TCQ recomputes from. The dynamic tuple is all-or-none (CF-V0-003); a partial combination is `invalid-frontier-input` and is rejected before this call.
type TCQResult ¶
type TCQResult struct {
// ID is the `tcq:sha256:` identity recorded in the Frontier `inputs` block
// (CF-V0-018) and bound in both static and dynamic modes (CF-V0-003).
ID string
// Claims holds exactly one result per selected `(obligationId, claimId)` edge
// (TCQ-V0-003). CF-V0-015 requires every selected edge to be evaluated.
Claims []TCQClaimResult
}
TCQResult is the `tcq/0` document Frontier recomputes under CF-V0-002. Its shape is the reference vector in docs/specs/test-claim-qualification-v0.md:375. Frontier reads only the fields declared here; the remaining document fields are bound by TCQID and never re-derived.
type TestMode ¶
type TestMode string
TestMode is the CF-V0-003 all-or-none dynamic-input discipline.
const ( // TestModeStatic is recorded when the (command, observation, report) tuple is // entirely absent. TestModeStatic TestMode = "STATIC" // TestModeDynamicCallerReported is recorded when all three are present. It does // not upgrade authority: CF-V0-015 keeps every edge CALLER_REPORTED in both modes. TestModeDynamicCallerReported TestMode = "DYNAMIC_CALLER_REPORTED" )
type VerifiedUniverse ¶
type VerifiedUniverse struct {
CEM *wire.Map
// Obligations retain the frozen intent requirement order, which is the
// CF-V0-020 sort order for both intent item kinds.
Obligations []Obligation
BaseRevision string
TargetRevision string
// ObjectFormat is exactly `sha1` or `sha256` (CF-V0-006).
ObjectFormat string
PatchSHA256 string
Intent IntentScope
// LRFRequest is the pure post-structural projection the verifier derived
// from the same verified inputs and target Git objects. Frontier evaluates
// it itself so the LRF result is recomputed, never accepted (CF-V0-002).
LRFRequest lrf.Request
}
VerifiedUniverse is the declared universe after one shared OCM-consuming verification call. Frontier never interleaves or reimplements the steps inside that call (CF-V0-021 step 5); it consumes the accepted result.
type Verifier ¶
type Verifier interface {
Verify(ctx context.Context, request VerifyRequest) (VerifiedUniverse, error)
}
Verifier is the seam onto the shared OCM-consuming CEM 0.2 verifier. It is an interface so the cascade's ordering and translation are testable without a repository, and so the Git-backed adapter can land separately without changing this package's contract.