frontier

package
v1.0.0-rc.2 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 6, 2026 License: AGPL-3.0, AGPL-3.0-or-later Imports: 13 Imported by: 0

Documentation

Overview

Package frontier implements Change Frontier V0 (`frontier/0`), the deterministic composition of canonical CEM 0.2, OCM 0.1, Lexical Relevance Floor V0, and Test Claim Qualification V0 specified in docs/specs/change-frontier-v0.md.

V0 is a local frontier preview and review queue. Per CF-V0-004 it has no stop-decision field and no hook authority, and per CF-V0-027 harness integration waits for a separately accepted harness-authority relation under a NEW profile identifier. Nothing in this package may be wired into the agent harness.

Index

Constants

View Source
const (
	CodeInvalidInput       = "invalid-frontier-input"
	CodeUnsupportedContext = "unsupported-frontier-context"
	CodeNoncanonical       = "noncanonical-frontier"
	CodeResourceExhausted  = "frontier-resource-exhausted"
	CodeInterrupted        = "frontier-interrupted"
	CodeInternalError      = "frontier-internal-error"
)

Frontier-owned operational codes (CF-V0-022).

View Source
const (
	Profile      = "frontier/0"
	ErrorProfile = "frontier-error/0"
	Policy       = "strict-v0"

	// ExcludedPath is the frozen CEM 0.2 sidecar exclusion. It is a literal in
	// both the universe preimage (CF-V0-006) and the emitted scope
	// (CF-V0-018), never copied from caller input.
	ExcludedPath = ".corvint/change.cem.json"
)

Profile identifiers and the single admitted policy (CF-V0-005, CF-V0-018).

View Source
const (
	AdmittedCEMSpec = "cem/0.2"
	AdmittedOCMSpec = "ocm/0.1-experimental"
)

Admitted upstream profiles (CF-V0-001). CEM 0.1, or OCM bound to CEM 0.1, is `unsupported-frontier-context`.

View Source
const (
	StateEmpty = "EMPTY"
	StateOpen  = "OPEN"
)

FrontierState is the CF-V0-004 global state. There is no third state, and deliberately no stop-decision field: V0 has no hook authority (CF-V0-027).

View Source
const (
	KindHunkBasis    = "HUNK_BASIS"
	KindIntentChange = "INTENT_CHANGE"
	KindIntentTest   = "INTENT_TEST"
)

Item kinds (CF-V0-007).

View Source
const (
	AuthorityNone             = "NONE"
	AuthorityProducerDeclared = "PRODUCER_DECLARED"
	AuthorityCallerReported   = "CALLER_REPORTED"
)

Authority classes (CF-V0-017). `CALLER_REPORTED` is integrity-bound caller input with no independent execution authority root, which is exactly why CF-V0-014 forbids it from closing anything.

View Source
const (
	ResolutionActionable        = "ACTIONABLE"
	ResolutionAuthorityRequired = "AUTHORITY_REQUIRED"
	ResolutionProfileRequired   = "PROFILE_REQUIRED"
)

Resolution classes (CF-V0-017).

View Source
const (
	ReasonHunkNoEvidence           = "HUNK_NO_EVIDENCE"
	ReasonHunkInsufficientEvidence = "HUNK_INSUFFICIENT_EVIDENCE"
	ReasonHunkConflictingEvidence  = "HUNK_CONFLICTING_EVIDENCE"

	ReasonDeletionRelationRequired   = "DELETION_RELATION_REQUIRED"
	ReasonSubjectTermBoundExceeded   = "SUBJECT_TERM_BOUND_EXCEEDED"
	ReasonEvidenceSpanTooBroad       = "EVIDENCE_SPAN_TOO_BROAD"
	ReasonSelfReferentialBasis       = "SELF_REFERENTIAL_BASIS"
	ReasonInsufficientLexicalSupport = "INSUFFICIENT_LEXICAL_SUPPORT"

	ReasonObligationUnassessed           = "OBLIGATION_UNASSESSED"
	ReasonObligationNoTestClaim          = "OBLIGATION_NO_TEST_CLAIM"
	ReasonObligationInsufficientEvidence = "OBLIGATION_INSUFFICIENT_EVIDENCE"
	ReasonObligationConflictingEvidence  = "OBLIGATION_CONFLICTING_EVIDENCE"

	ReasonLexicalCandidateNonclosing = "LEXICAL_CANDIDATE_NONCLOSING"
	ReasonNoMaterialChangeWitness    = "NO_MATERIAL_CHANGE_WITNESS"

	ReasonCallerReportedNonclosing     = "CALLER_REPORTED_NONCLOSING"
	ReasonTargetCleanlinessNotAttested = "TARGET_CLEANLINESS_NOT_ATTESTED"
	ReasonCommandFailed                = "COMMAND_FAILED"
	ReasonTestError                    = "TEST_ERROR"
	ReasonTestFailed                   = "TEST_FAILED"
	ReasonTestSkipped                  = "TEST_SKIPPED"
	ReasonTestIdentityAmbiguous        = "TEST_IDENTITY_AMBIGUOUS"
	ReasonTestRowIdentityUnavailable   = "TEST_ROW_IDENTITY_UNAVAILABLE"
	ReasonTestNotMatched               = "TEST_NOT_MATCHED"
	ReasonTestClaimEmpty               = "TEST_CLAIM_EMPTY"
	ReasonTestClaimUnconditionalSkip   = "TEST_CLAIM_UNCONDITIONAL_SKIP"
	ReasonTestClaimUnassociated        = "TEST_CLAIM_UNASSOCIATED"
	ReasonTestClaimUnsupported         = "TEST_CLAIM_UNSUPPORTED"
)

Reasons. HUNK_BASIS reasons come from CF-V0-009 and CF-V0-010, INTENT_CHANGE from CF-V0-011 and CF-V0-012, INTENT_TEST from the frozen CF-V0-016 table.

View Source
const (
	ActionSupplyHunkBasis           = "SUPPLY_HUNK_BASIS"
	ActionNarrowOrReplaceBasis      = "NARROW_OR_REPLACE_BASIS"
	ActionDefineSupportedProfile    = "DEFINE_SUPPORTED_PROFILE"
	ActionLinkObligation            = "LINK_OBLIGATION"
	ActionLinkMaterialHunk          = "LINK_MATERIAL_HUNK"
	ActionEstablishChangeWitness    = "ESTABLISH_CHANGE_WITNESS"
	ActionEstablishHarnessAuthority = "ESTABLISH_HARNESS_AUTHORITY"
	ActionRerunTestCommand          = "RERUN_TEST_COMMAND"
	ActionFixOrRerunTest            = "FIX_OR_RERUN_TEST"
	ActionDisambiguateTestIdentity  = "DISAMBIGUATE_TEST_IDENTITY"
	ActionSupplyTestObservation     = "SUPPLY_TEST_OBSERVATION"
	ActionRepairTestClaim           = "REPAIR_TEST_CLAIM"
)

Next actions (CF-V0-009..012, CF-V0-016).

View Source
const (
	MaxHunkItems         = 2048
	MaxIntentChangeItems = 256
	MaxIntentTestItems   = 256
	MaxTotalItems        = 2560
	MaxRelatedIDsPerItem = 64
	MaxReasonsPerItem    = 32
	MaxOutputBytes       = 4194304
)

Frontier-owned limits (CF-V0-023). Counts are checked before append and byte arithmetic before output allocation, so exhaustion never leaves a partial result behind.

View Source
const (
	OCMLinked  = "linked"
	OCMUnknown = "unknown"
)

OCM dispositions (OCM-V0-004).

View Source
const (
	CEMSupported  = "supported"
	CEMUnknown    = "unknown"
	CEMMechanical = "mechanical"
)

CEM dispositions consumed by CF-V0-008 and CF-V0-009.

View Source
const ErrorExitCode = 2

ErrorExitCode is the CF-V0-004 operational-failure exit: 2, with no Frontier JSON on stdout.

Variables

This section is empty.

Functions

func CanonicalBytes

func CanonicalBytes(document Document) ([]byte, error)

CanonicalBytes returns the complete Frontier document: codec(document) plus exactly one LF (CF-V0-019).

func CodeOf

func CodeOf(err error) string

CodeOf extracts a Frontier code from an error chain, or "" when the error is not a Frontier failure.

func ItemID

func ItemID(kind, subjectID, universeID string) (string, error)

ItemID derives the CF-V0-007 identity from exactly (kind, subjectId, universeId). Evidence repair may remove an item but cannot change the identity of an unresolved obligation in the same universe, which is what makes the queue diffable across runs.

func RenderError

func RenderError(err error) []byte

RenderError returns the one bounded stderr envelope CF-V0-022 allows: exactly `{"code":"CODE","profile":"frontier-error/0"}` plus one LF, carrying a code and nothing else. Nothing about the input reaches it, which is how CF-V0-024's no-echo rule is enforced structurally rather than by review.

func RenderErrorHuman

func RenderErrorHuman(err error) string

RenderErrorHuman renders one operational failure for a person. An inherited upstream code has no Frontier-owned message, so it is rendered as itself rather than as an invented sentence.

func RenderHuman

func RenderHuman(document Document) string

RenderHuman renders the same computation as RenderJSON for a person. It emits only the verified fields of the valid result, and it states the CF-V0-025 assertion boundary in full so the queue cannot be read as proof that evidence does not exist, that code is wrong, that a test lacks behavioral coverage, or that the repository was exhaustively searched.

func RenderJSON

func RenderJSON(document Document) ([]byte, error)

RenderJSON returns the exact canonical document bytes. CF-V0-026 makes JSON and human two renderings of ONE computation, so both take a sealed Document and neither recomputes anything.

func UniverseID

func UniverseID(scope Scope) (string, error)

UniverseID derives the CF-V0-006 identity. Identical Git content across clones intentionally yields an identical universe ID.

Types

type Document

type Document struct {
	FrontierState string
	ID            string
	Inputs        Inputs
	Items         []Item
	Scope         Scope
	UniverseID    string
}

Document is one complete Frontier result. It has no stop-decision field by construction (CF-V0-004).

func Compute

func Compute(ctx context.Context, request Request) (Document, []byte, error)

Compute runs the CF-V0-021 validation cascade and returns one complete Frontier document plus its exact canonical bytes. Every failure is operational: it emits no frontier result, never an open item.

func (Document) ExitCode

func (d Document) ExitCode() int

ExitCode is the CF-V0-004 exit law: 0 valid empty, 1 valid open. Operational failure exits 2 and is signalled by an error, never by a Document.

type Error

type Error struct {
	Code string
	// contains filtered or unexported fields
}

Error is one operational Frontier failure. It carries a code and nothing else on purpose: CF-V0-024 forbids echoing an unverified path, OID, digest, ID, count, XML value, argv element, sibling canary, or exception, and a message field is the usual way all of those leak. The unexported detail is for a Go caller's debugger, is never rendered, and never reaches Error().

func VerifyDocument

func VerifyDocument(data []byte) *Error

VerifyDocument checks candidate Frontier bytes against the whole wire contract: the CF-V0-019 codec round trip, the closed CF-V0-017/018 shapes, the CF-V0-004 state law, the CF-V0-020 orders, the CF-V0-023 bounds, and the recomputed CF-V0-019 identity. Every violation is `noncanonical-frontier`, which is what makes an independent consumer able to refuse an almost-right document instead of half-reading it (CF-V0-028).

func (*Error) Error

func (e *Error) Error() string

Error returns the code alone, so that even an accidental %v in a caller's log cannot widen the privacy surface.

type Inputs

type Inputs struct {
	CEMSHA256 string
	LRFSHA256 string
	OCMSHA256 string
	TCQID     string
	TestMode  TestMode
}

Inputs is the CF-V0-018 `inputs` block. Each digest binds exactly the bytes CF-V0-019 names: CEM and OCM hash their verified bounded raw copies, LRF hashes its complete canonical result bytes.

type IntentScope

type IntentScope struct {
	BlobOID    string
	Path       string
	Span       Span
	SpanSHA256 string
}

IntentScope is the one exact pinned OCM intent scope (CF-V0-001).

type Item

type Item struct {
	AuthorityClass  string
	ID              string
	Kind            string
	NextAction      string
	Reasons         []string
	RelatedIDs      []string
	ResolutionClass string
	SubjectID       string
}

Item is the closed CF-V0-017 shape. No field is optional and no field may be added under this profile; a stop-decision field in particular is refused by VerifyDocument as `noncanonical-frontier`.

type Obligation

type Obligation struct {
	ID          string
	Disposition string
	Reason      string
	HunkIDs     []string
	ClaimIDs    []string
}

Obligation is one verified OCM 0.1 obligation row projected into Frontier. Fields mirror the OCM wire exactly (`ocm-v0-dogfood.md` OCM-V0-004): a linked obligation carries non-empty hunk and claim references, an unknown one carries empty references and one bounded reason.

type Request

type Request struct {
	// CEMBytes and OCMBytes are the exact bounded raw copies that will be
	// verified and then digested into `inputs` (CF-V0-002, CF-V0-019).
	CEMBytes []byte
	OCMBytes []byte
	// ExpectedBase and Target are the two independent revision inputs. Neither
	// may be inferred: CF-V0-001 fails inferred revision authority.
	ExpectedBase string
	Target       string

	// The optional dynamic test bundle is the all-or-none CF-V0-003 tuple.
	Command     []byte
	Observation []byte
	JUnitReport []byte

	// Verifier is the shared OCM-consuming CEM 0.2 verifier whose native
	// precedence CF-V0-021 puts ahead of every later Frontier check.
	Verifier Verifier
	// TCQ recomputes Test Claim Qualification from the verified inputs. A
	// caller-supplied TCQ result is never accepted as authority or as a
	// shortcut (CF-V0-002), which is why this is a recomputer, not a document.
	TCQ TCQRecomputer
}

Request is one Frontier invocation (CF-V0-001). It carries immutable byte copies rather than paths: CF-V0-026 keeps path acquisition outside the wire and the verifier, so a command wrapper reads files through its own hardened reader and hands the bytes here.

type Scope

type Scope struct {
	BaseRevision     string
	IntentBlobOID    string
	IntentPath       string
	IntentSpan       Span
	IntentSpanSHA256 string
	ObjectFormat     string
	PatchSHA256      string
	TargetRevision   string
}

Scope is the CF-V0-018 `scope` block: the declared universe, restated in the result so a reader can rebind the identity without the original request.

type Span

type Span struct {
	Start int64
	End   int64
}

Span is an intent byte span. Both offsets are emitted as canonical decimal strings (CF-V0-006, CF-V0-018), never as JSON numbers.

type TCQClaimResult

type TCQClaimResult struct {
	ObligationID string
	ClaimID      string
	// Reasons are the TCQ diagnostics Frontier maps to `INTENT_TEST` reasons under
	// the exact CF-V0-016 table. The consumed vocabulary is closed:
	// target-cleanliness-not-attested, command-failed, test-error, test-failed,
	// test-skipped, execution-identity-ambiguous, repeated-test-rows,
	// row-identity-unavailable, test-not-matched, empty-body, unconditional-skip,
	// claim-association-missing, claim-association-ambiguous, python-offset-mismatch,
	// unparseable-test-unit, unsupported-anchor-profile, unsupported-python-grammar.
	// An unrecognised diagnostic is a closed-allowlist failure (CF-V0-022), never a
	// silently dropped reason.
	Reasons []string
	// Relation is the TCQ relation when one was emitted (`test-report-matched-v0`).
	// CF-V0-014 freezes it as non-closing: it maps to CALLER_REPORTED_NONCLOSING and
	// never removes an INTENT_TEST item, whatever the rows or exit status say.
	Relation string
	// AuthorityClass is `CALLER_REPORTED` for every TCQ V0 edge (CF-V0-015). It is
	// carried rather than assumed so a future producer cannot silently upgrade it.
	AuthorityClass string
}

TCQClaimResult is one selected claim edge, per the reference vector at docs/specs/test-claim-qualification-v0.md:391.

type TCQRecomputer

type TCQRecomputer interface {
	Recompute(request TCQRequest) (TCQResult, error)
}

TCQRecomputer recomputes TCQ from verified inputs and target Git objects. CF-V0-002 forbids accepting a caller-supplied TCQ result as authority or as a shortcut, so Frontier holds this seam rather than a decoded document.

type TCQRequest

type TCQRequest struct {
	// CEMBytes is the canonical `cem/0.2` artifact the OCM binds. TCQ-V0-001
	// requires it alongside the OCM, and TCQ-V0-002 refuses `cem/0.1`
	// operationally, so the producer cannot source it for itself: an artifact it
	// fetched independently would not be the one this invocation verified.
	CEMBytes       []byte
	OCMBytes       []byte
	BaseRevision   string
	TargetRevision string
	Mode           TestMode
	Command        []byte
	Observation    []byte
	JUnitReport    []byte
}

TCQRequest carries the verified bytes and revisions TCQ recomputes from. The dynamic tuple is all-or-none (CF-V0-003); a partial combination is `invalid-frontier-input` and is rejected before this call.

type TCQResult

type TCQResult struct {
	// ID is the `tcq:sha256:` identity recorded in the Frontier `inputs` block
	// (CF-V0-018) and bound in both static and dynamic modes (CF-V0-003).
	ID string
	// Claims holds exactly one result per selected `(obligationId, claimId)` edge
	// (TCQ-V0-003). CF-V0-015 requires every selected edge to be evaluated.
	Claims []TCQClaimResult
}

TCQResult is the `tcq/0` document Frontier recomputes under CF-V0-002. Its shape is the reference vector in docs/specs/test-claim-qualification-v0.md:375. Frontier reads only the fields declared here; the remaining document fields are bound by TCQID and never re-derived.

type TestMode

type TestMode string

TestMode is the CF-V0-003 all-or-none dynamic-input discipline.

const (
	// TestModeStatic is recorded when the (command, observation, report) tuple is
	// entirely absent.
	TestModeStatic TestMode = "STATIC"
	// TestModeDynamicCallerReported is recorded when all three are present. It does
	// not upgrade authority: CF-V0-015 keeps every edge CALLER_REPORTED in both modes.
	TestModeDynamicCallerReported TestMode = "DYNAMIC_CALLER_REPORTED"
)

type VerifiedUniverse

type VerifiedUniverse struct {
	CEM *wire.Map
	// Obligations retain the frozen intent requirement order, which is the
	// CF-V0-020 sort order for both intent item kinds.
	Obligations    []Obligation
	BaseRevision   string
	TargetRevision string
	// ObjectFormat is exactly `sha1` or `sha256` (CF-V0-006).
	ObjectFormat string
	PatchSHA256  string
	Intent       IntentScope
	// LRFRequest is the pure post-structural projection the verifier derived
	// from the same verified inputs and target Git objects. Frontier evaluates
	// it itself so the LRF result is recomputed, never accepted (CF-V0-002).
	LRFRequest lrf.Request
}

VerifiedUniverse is the declared universe after one shared OCM-consuming verification call. Frontier never interleaves or reimplements the steps inside that call (CF-V0-021 step 5); it consumes the accepted result.

type Verifier

type Verifier interface {
	Verify(ctx context.Context, request VerifyRequest) (VerifiedUniverse, error)
}

Verifier is the seam onto the shared OCM-consuming CEM 0.2 verifier. It is an interface so the cascade's ordering and translation are testable without a repository, and so the Git-backed adapter can land separately without changing this package's contract.

type VerifyRequest

type VerifyRequest struct {
	CEMBytes     []byte
	OCMBytes     []byte
	ExpectedBase string
	Target       string
}

VerifyRequest is what Frontier hands the shared verifier: the same bounded immutable byte copies and both independent revisions (CF-V0-002).

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL