Documentation
¶
Index ¶
- Constants
- Variables
- func AnnotateRuntimeCompatibilityEquivalence(primary, compatibility *cobra.Command, review RuntimeCompatibilityEquivalence)
- func AuditSchemaAssembly(assemble func() error) (err error)
- func AwaitSchemaCachePrewarmForTest()
- func BuildAgentSelectionEvalFixture(bound BoundCommandRegistry) (AgentSelectionFixture, AgentSelectionReport, error)
- func CaptureSchemaAssemblyEnviron()
- func ClearBuildTimeAgentMetadata()
- func CollectIdentitySpecs(root *cobra.Command) ([]CommandSpec, IdentityCollectionReport, error)
- func CompareCommandSpecEquivalence(collected, reviewed []CommandSpec) []string
- func DeliverySchemaAllPayloadForTest() (map[string]any, error)
- func DeliverySchemaOverviewPayloadForTest() (map[string]any, error)
- func DeliverySchemaQueryPayloadForTest(path string) (map[string]any, error)
- func DiagnoseMissingPrimaries(root *cobra.Command, missing []CommandSpec) []string
- func EncodeSchemaMetaIndex(index SchemaMetaIndexSnapshot) ([]byte, error)
- func EncodeSchemaMetaIndexJSON(index SchemaMetaIndexSnapshot) ([]byte, error)
- func InstallBuildTimeAgentMetadataJSON(data []byte) error
- func InstallProductionSchemaAssemblyForTest(factory func() *cobra.Command)
- func InvalidatePersistedSchemaCacheIdentities()
- func LoadSchemaParameterBindings() (map[string]map[string]string, error)
- func LocalSchemaCacheIdentityFileName() string
- func MarkSchemaCacheRuntimeUncertain()
- func NewMCPCommand() *cobra.Command
- func NewSchemaCommand() *cobra.Command
- func OverridePriority(cmd *cobra.Command) int
- func ParseAgentExampleArgv(input string) ([]string, error)
- func PrewarmSchemaCache()
- func ReadFileArg(value string) (string, bool, error)
- func ReadStdin() (string, error)
- func ReadStdinIfPiped() (string, error)
- func RegisterRuntimeSchemaConstraints(canonicalPath string, constraints RuntimeSchemaConstraints)
- func RegisterRuntimeSchemaParameterMetadata(canonicalPath string, metadata RuntimeSchemaParameterMetadata)
- func RegisterSchemaCacheIsolatedBuilder(builder SchemaCacheIsolatedBuilder)
- func RegisterSchemaCacheOptions(options SchemaCacheOptions) error
- func RegisterSchemaSourceRoot(factory func() *cobra.Command)
- func RenderHelpAffordances(cmd *cobra.Command)
- func RenderSafetyAnnotation(cmd *cobra.Command)
- func ResetSchemaCacheRuntimeUncertaintyForTest()
- func ResolveInputSource(value string, flagName string, guard *StdinGuard) (string, error)
- func RestorePackageCLISchemaDeliveryForTest()
- func ReviewedDryRunCapabilities() (map[string]contract.DryRunSpec, error)
- func RuntimeSchemaParameterMetadataDefinitions() map[string]RuntimeSchemaParameterMetadata
- func SchemaAssemblyEnvironmentSnapshot() []string
- func SchemaAssemblyWorkingDirectory() string
- func SchemaCachePrewarmPayloadsHandleForTest() *schemacache.Registry
- func SchemaSourceRootRegistered() bool
- func SetOverridePriority(cmd *cobra.Command, priority int)
- func StdinIsPipe() bool
- func ValidateCatalogStructure(data []byte) error
- func ValidateInputSchema(params map[string]any, schema map[string]any) error
- func ValidateJSONSchemaValue(value any, schema map[string]any) error
- func ValidateReviewedDryRunCapabilityDelivery(registry SchemaRegistry) error
- func ValidateRuntimeSchemaCompleteness(root *cobra.Command) error
- func ValidateSchemaDeliveryInvariants(source SchemaRegistry, snapshot SchemaCatalogSnapshot) error
- func ValidateSchemaMetaIndexAgainstCatalog(index SchemaMetaIndexSnapshot, registry SchemaRegistry) error
- func ValidateSchemaMetaIndexAgainstSnapshot(index SchemaMetaIndexSnapshot, snapshot SchemaCatalogSnapshot) error
- func ValidateSchemaParameterBindingDelivery(bound BoundCommandRegistry, registry SchemaRegistry) error
- func ValidateSchemaParameterBindings() error
- func WriteSchemaCacheBuildResult(w io.Writer, result SchemaCacheBuildResult) error
- type AgentExampleDisposition
- type AgentExampleDispositionSource
- type AgentExampleExecution
- type AgentExampleExecutionPlan
- type AgentExampleMode
- type AgentExampleReasonCode
- type AgentSelectionCase
- type AgentSelectionFixture
- type AgentSelectionReport
- type AgentToolSelection
- type AliasKind
- type BoundAlias
- type BoundCommandRegistry
- type BoundCommandSpec
- type CommandIdentity
- type CommandMeta
- type CommandOverride
- type CommandPathFallback
- type CommandPathFallbackMode
- type CommandRegistry
- type CommandSafety
- type CommandSelection
- type CommandSpec
- type Concept
- type EffectiveCommandRegistry
- type FixtureAgentProductSelection
- type FixtureAgentSelectionRevision
- type FixtureAgentSelectionSet
- type IdentityCollectionReport
- type InterfaceRefKey
- type InterfaceRegistry
- type InterfaceRegistryEntry
- type ParamAliasEntry
- type ParamConcepts
- type ParamFixtureCase
- type ParamMorphRule
- type ParameterSpec
- type ProductSpec
- type ResolvedSchemaBuild
- type RuntimeCompatibilityEquivalence
- type RuntimeSchemaCompletenessReport
- type RuntimeSchemaConstraints
- type RuntimeSchemaExclusion
- type RuntimeSchemaParameterMetadata
- type RuntimeToolSpecInput
- type SchemaCacheArtifacts
- func (a SchemaCacheArtifacts) LocatorPaths() []string
- func (a SchemaCacheArtifacts) MetaArtifact() schemacache.Artifact
- func (a SchemaCacheArtifacts) PayloadArtifact() schemacache.Artifact
- func (a SchemaCacheArtifacts) PayloadIndexPins() (uint64, [sha256.Size]byte, error)
- func (a SchemaCacheArtifacts) RegistryArtifact() schemacache.Artifact
- func (a SchemaCacheArtifacts) RenderAll() (map[string]any, error)
- func (a SchemaCacheArtifacts) RenderOverview() (map[string]any, error)
- func (a SchemaCacheArtifacts) RenderQuery(path string) (map[string]any, error)
- func (a SchemaCacheArtifacts) ValidateRoundTrip() error
- type SchemaCacheBuildResult
- type SchemaCacheIdentity
- func IdentityFromArtifacts(edition string, artifacts SchemaCacheArtifacts) (SchemaCacheIdentity, error)
- func SchemaCacheFastPathIdentity() (SchemaCacheIdentity, bool)
- func SchemaCacheReadableIdentityForTest() (SchemaCacheIdentity, bool)
- func TryLoadLocalSchemaCacheIdentity(edition string) (SchemaCacheIdentity, bool)
- type SchemaCacheIsolatedBuilder
- type SchemaCacheOptions
- type SchemaCatalogBuildOptions
- type SchemaCatalogSnapshot
- type SchemaIndex
- type SchemaMetaIndexEntry
- type SchemaMetaIndexSnapshot
- type SchemaMetadataLoadCounts
- type SchemaRegistry
- type SchemaSnapshotPayload
- type SchemaVisibility
- type StdinGuard
- type ToolSpec
Constants ¶
const ( AgentExampleModeContract = contract.ExampleDispositionModeContract AgentExampleModeDryRun = contract.ExampleDispositionModeDryRun AgentExampleModeContractOnly = contract.ExampleDispositionModeContractOnly )
const ( AgentExampleReasonLocalState = contract.ExampleDispositionReasonLocalState AgentExampleReasonStatefulPreflight = contract.ExampleDispositionReasonStatefulPreflight )
const ( ProvenanceEmbeddedSkillMetadata = "embedded-skill-metadata" ProvenanceReviewedManual = "reviewed_manual" )
Wire provenance / metadata_source labels (#602 Catalog contract). Const identifiers may be renamed; the string values must not change.
const CommandSourceContractIdentity = "contract_identity"
CommandSourceContractIdentity is the delivery source label for command identity collected from ContractFinal.Identity declarations. The collector (CollectIdentitySpecs) is the single identity source since the reviewed schema_command_registry retirement.
const ( // DefaultSchemaCacheBuilderTimeout defines the maximum duration allowed for // isolated schema cache generation before timing out. DefaultSchemaCacheBuilderTimeout = 30 * time.Second )
const SchemaCatalogSnapshotVersion = schemareader.CatalogSnapshotVersion
const SchemaMetaIndexVersion = 1
SchemaMetaIndexVersion is the CommandMeta summary index format used by CI dumps (cmd_schema_catalog) and unit-test encode/decode fixtures. Production ResolveMeta projects from the runtime-assembled SchemaRegistry — there is no committed schema_meta_index.gob embed.
const SchemaSourceRuntimeAssembled = "runtime-assembled"
SchemaSourceRuntimeAssembled is stamped on SchemaRegistry.Source for declare→ResolveSchemaBuild delivery.
Variables ¶
var ( AttachRuntimeSchema = runtimeannotate.AttachRuntimeSchema AnnotateRuntimeFlag = runtimeannotate.AnnotateRuntimeFlag AnnotateRuntimeFlagProperty = runtimeannotate.AnnotateRuntimeFlagProperty AnnotateRuntimeRequiredFlags = runtimeannotate.AnnotateRuntimeRequiredFlags AnnotateRuntimeFlagRequiredValue = runtimeannotate.AnnotateRuntimeFlagRequiredValue AnnotateRuntimeFlagRequiredWhen = runtimeannotate.AnnotateRuntimeFlagRequiredWhen AnnotateRuntimeFlagFormat = runtimeannotate.AnnotateRuntimeFlagFormat AnnotateRuntimeFlagInterfaceType = runtimeannotate.AnnotateRuntimeFlagInterfaceType AnnotateRuntimeFlagEnum = runtimeannotate.AnnotateRuntimeFlagEnum AnnotateRuntimeFlagExample = runtimeannotate.AnnotateRuntimeFlagExample RuntimeContractRisk = runtimeannotate.RuntimeContractRisk RuntimeContractGate = runtimeannotate.RuntimeContractGate AnnotateRuntimeConstraints = runtimeannotate.AnnotateRuntimeConstraints AnnotateRuntimePositionals = runtimeannotate.AnnotateRuntimePositionals HasDeclaredOrAnnotatedConfirmation = contractfinal.HasDeclaredOrAnnotatedConfirmation RuntimeContractFinal = contractfinal.RuntimeContractFinal HasRuntimeContractFinal = contractfinal.HasRuntimeContractFinal ClearRuntimeContractFinalForTest = contractfinal.ClearRuntimeContractFinalForTest ApplyParamDecls = contractfinal.ApplyParamDecls )
var ( SchemaRegistryFromRuntime = schemaruntime.SchemaRegistryFromRuntime ToolSpecFromRuntime = schemaruntime.ToolSpecFromRuntime )
var ErrSchemaAssemblyConsumedDelivery = errors.New("Schema declaration assembly consumed runtime delivery")
Functions ¶
func AnnotateRuntimeCompatibilityEquivalence ¶ added in v1.0.52
func AnnotateRuntimeCompatibilityEquivalence(primary, compatibility *cobra.Command, review RuntimeCompatibilityEquivalence)
AnnotateRuntimeCompatibilityEquivalence records the same typed review on both sides of one independently executable compatibility pair. Invalid review data panics during command construction so production cannot silently accept an unreviewed handler mismatch.
func AuditSchemaAssembly ¶ added in v1.0.63
AuditSchemaAssembly is an exclusive build-time audit, not a runtime lock. The identity generator uses it around the entire declaration/projection path. Any delivery access, including an already cached lookup, aborts immediately before it can enter a loader Once. Do not run alongside runtime consumers. Normal production readers do not install an audit and retain concurrency.
func AwaitSchemaCachePrewarmForTest ¶ added in v1.0.63
func AwaitSchemaCachePrewarmForTest()
AwaitSchemaCachePrewarmForTest blocks until the registered runtime's speculative prewarm (if any) settles, so counter and filesystem assertions are deterministic.
func BuildAgentSelectionEvalFixture ¶ added in v1.0.57
func BuildAgentSelectionEvalFixture(bound BoundCommandRegistry) (AgentSelectionFixture, AgentSelectionReport, error)
BuildAgentSelectionEvalFixture turns every ContractFinal use_when and avoid_when entry into a typed, reproducible evaluation case and validates it against the exact BoundCommandRegistry.
func CaptureSchemaAssemblyEnviron ¶ added in v1.0.63
func CaptureSchemaAssemblyEnviron()
CaptureSchemaAssemblyEnviron snapshots the environment before runtime plugin discovery. The snapshot is used as a child-process environment only.
func ClearBuildTimeAgentMetadata ¶ added in v1.0.57
func ClearBuildTimeAgentMetadata()
ClearBuildTimeAgentMetadata removes a cmd_schema_catalog dump-helper injection.
func CollectIdentitySpecs ¶ added in v1.0.57
func CollectIdentitySpecs(root *cobra.Command) ([]CommandSpec, IdentityCollectionReport, error)
CollectIdentitySpecs walks the runnable leaves under root and synthesises a CommandSpec from each leaf's ContractFinal.Identity (public visibility; SourceProductID defaulting is handled by the shared indexer). It is the single identity source consumed by BuildEffectiveCommandRegistry.
func CompareCommandSpecEquivalence ¶ added in v1.0.57
func CompareCommandSpecEquivalence(collected, reviewed []CommandSpec) []string
CompareCommandSpecEquivalence returns a human-readable, deterministic diff between two CommandSpec sets keyed by canonical path. An empty slice means the two sets agree on every compared field.
func DeliverySchemaAllPayloadForTest ¶ added in v1.0.57
DeliverySchemaAllPayloadForTest returns schema --all through the installed delivery loader (catalog_hash comes from Snapshot.SourceHash).
func DeliverySchemaOverviewPayloadForTest ¶ added in v1.0.63
DeliverySchemaOverviewPayloadForTest exercises the production route split.
func DeliverySchemaQueryPayloadForTest ¶ added in v1.0.63
DeliverySchemaQueryPayloadForTest exercises one production path query.
func DiagnoseMissingPrimaries ¶ added in v1.0.57
func DiagnoseMissingPrimaries(root *cobra.Command, missing []CommandSpec) []string
DiagnoseMissingPrimaries resolves each spec that has no collected primary and reports why: the primary CLI path may not exist as a Cobra leaf, the leaf may lack ContractFinal, or its declared canonical may drift from the expected one.
func EncodeSchemaMetaIndex ¶ added in v1.0.57
func EncodeSchemaMetaIndex(index SchemaMetaIndexSnapshot) ([]byte, error)
EncodeSchemaMetaIndex marshals a CI/test SchemaMetaIndex dump (gob). Production ResolveMeta does not embed or load this artifact.
func EncodeSchemaMetaIndexJSON ¶ added in v1.0.57
func EncodeSchemaMetaIndexJSON(index SchemaMetaIndexSnapshot) ([]byte, error)
EncodeSchemaMetaIndexJSON is retained for diagnostics / fixtures that need a human-readable projection of the same snapshot struct.
func InstallBuildTimeAgentMetadataJSON ¶ added in v1.0.57
InstallBuildTimeAgentMetadataJSON installs generator-produced Agent metadata for cmd_schema_catalog CI/local dump assembly only. Production binaries never call this; production authority remains leaf ContractFinal / ProductDecl. The dump helper injects an in-memory snapshot so schema_agent_metadata/ is neither committed nor embedded.
func InstallProductionSchemaAssemblyForTest ¶ added in v1.0.57
InstallProductionSchemaAssemblyForTest installs the production assembleSchemaCatalogFromRoot delivery path with factory and clears lazy caches. Tests must Cleanup via RegisterSchemaSourceRoot(nil) or a restore helper that reinstalls their prior delivery stub.
func InvalidatePersistedSchemaCacheIdentities ¶ added in v1.0.63
func InvalidatePersistedSchemaCacheIdentities()
InvalidatePersistedSchemaCacheIdentities deletes identity.json and legacy identity.*.json files under every candidate .../dws/schema tree. It never recurses a wide cache base (LOCALAPPDATA, ProgramData root, /var/cache) so unrelated apps' identity files stay untouched. dws upgrade calls this after replacing the executable so binary B cannot keep serving binary A's Schema.
func LoadSchemaParameterBindings ¶ added in v1.0.57
LoadSchemaParameterBindings returns a defensive copy of the reviewed active public flag-to-interface bindings. Active bindings are empty; property delivery comes from ParamDecl.Property. Mapping exclusions and removals remain on the Go mapping ledger (not returned here).
func LocalSchemaCacheIdentityFileName ¶ added in v1.0.63
func LocalSchemaCacheIdentityFileName() string
LocalSchemaCacheIdentityFileName is the stable per-edition identity sidecar stored next to protobuf shards. Cache identity is the content hashes inside the record (source/surface/build_id and artifact digests) plus binary_build_id, which must match the running binary's buildversion.Digest. Sidecars are not keyed by a per-fingerprint filename.
func MarkSchemaCacheRuntimeUncertain ¶ added in v1.0.63
func MarkSchemaCacheRuntimeUncertain()
MarkSchemaCacheRuntimeUncertain disables persistent cache publication for a process whose runtime state changed after registration. The process may still read an authenticated existing cache; cache repair is delegated to the isolated declaration builder.
func NewMCPCommand ¶
NewMCPCommand registers the mcp product declaration and returns its root command. The app layer attaches reviewed static MCP helpers as subcommands; live discovery surfaces are retired.
func NewSchemaCommand ¶
NewSchemaCommand serves the typed Schema contract. Production assembles from declarations via ResolveSchemaBuild (factory registered by internal/app). A malformed assembly fails closed; the command takes no discovery loader because queries never run service discovery.
func OverridePriority ¶
OverridePriority delegates to cobracmd.OverridePriority.
func ParseAgentExampleArgv ¶ added in v1.0.57
ParseAgentExampleArgv exposes the shell-free argv parser used by example validation and dry-run tests.
func PrewarmSchemaCache ¶ added in v1.0.63
func PrewarmSchemaCache()
PrewarmSchemaCache starts the speculative payload read for the registered runtime. It is a no-op unless an enabled, eligible runtime is registered. The probe opens noCreate: a missing cache is left for the synchronous path.
func ReadFileArg ¶
ReadFileArg reads the contents of a file referenced by the @filename syntax. Returns the original value unchanged if it does not start with "@" or is otherwise not a file-path-shaped value (e.g. "@所有人" is treated as plain text, not a path). Returns an error if the file cannot be read or exceeds the size limit.
Note: @- (stdin) is NOT handled here; use ResolveInputSource instead.
func ReadStdin ¶
ReadStdin reads all data from stdin unconditionally (up to maxStdinSize). Use this when the caller has explicitly requested stdin via @-.
func ReadStdinIfPiped ¶
ReadStdinIfPiped reads all data from stdin if it is a pipe (not a terminal). Returns empty string if stdin is a terminal or has no data.
func RegisterRuntimeSchemaConstraints ¶ added in v1.0.52
func RegisterRuntimeSchemaConstraints(canonicalPath string, constraints RuntimeSchemaConstraints)
RegisterRuntimeSchemaConstraints records reviewed cross-parameter CLI rules independently from the delivered Catalog so reviewed constraints always apply, regardless of which snapshot is shipped.
func RegisterRuntimeSchemaParameterMetadata ¶ added in v1.0.52
func RegisterRuntimeSchemaParameterMetadata(canonicalPath string, metadata RuntimeSchemaParameterMetadata)
RegisterRuntimeSchemaParameterMetadata records strong, code-owned parameter semantics for one canonical command path.
func RegisterSchemaCacheIsolatedBuilder ¶ added in v1.0.63
func RegisterSchemaCacheIsolatedBuilder(builder SchemaCacheIsolatedBuilder)
RegisterSchemaCacheIsolatedBuilder installs the production child-process builder. Passing nil is intended for tests only.
func RegisterSchemaCacheOptions ¶ added in v1.0.63
func RegisterSchemaCacheOptions(options SchemaCacheOptions) error
RegisterSchemaCacheOptions replaces the cache registration. Invalid options fail closed to disabled before schemacache.Open or any filesystem operation.
func RegisterSchemaSourceRoot ¶ added in v1.0.57
RegisterSchemaSourceRoot installs the root factory used by runtime Schema delivery (dws schema / ResolveMeta). Production registers from internal/app before runtime plugin discovery, so each registration also captures the pristine child-process environment. Passing nil clears the factory (tests only) and resets lazy delivery / Meta state.
func RenderHelpAffordances ¶ added in v1.0.61
RenderHelpAffordances appends the Agent-facing metadata that Cobra cannot express in its native command template. Leaf guidance and Safety come from ResolveMeta (the assembled Schema source); references come from the owning ProductDecl. Direct product/service Help renders references only.
func RenderSafetyAnnotation ¶ added in v1.0.55
RenderSafetyAnnotation writes the reviewed Safety tuple to the command's stdout. Prefer RenderHelpAffordances for production Help; this focused entry point remains for compatibility and direct safety tests.
func ResetSchemaCacheRuntimeUncertaintyForTest ¶ added in v1.0.63
func ResetSchemaCacheRuntimeUncertaintyForTest()
ResetSchemaCacheRuntimeUncertaintyForTest resets process state between tests.
func ResolveInputSource ¶
func ResolveInputSource(value string, flagName string, guard *StdinGuard) (string, error)
ResolveInputSource resolves a flag value that may reference an external input source. It supports three forms:
- "@-" reads from stdin (requires StdinGuard claim)
- "@<path>" reads from the named file
- anything else returned unchanged
The flagName parameter is used only for error messages and StdinGuard tracking.
func RestorePackageCLISchemaDeliveryForTest ¶ added in v1.0.57
func RestorePackageCLISchemaDeliveryForTest()
RestorePackageCLISchemaDeliveryForTest reinstalls the package-cli TestMain assembled-delivery stub after a production-assembly exercise. Outside package cli TestMain it clears the factory and resets lazy delivery state.
func ReviewedDryRunCapabilities ¶ added in v1.0.52
func ReviewedDryRunCapabilities() (map[string]contract.DryRunSpec, error)
ReviewedDryRunCapabilities returns a defensive copy of the positive, reviewed capability registry for delivery gates.
func RuntimeSchemaParameterMetadataDefinitions ¶ added in v1.0.52
func RuntimeSchemaParameterMetadataDefinitions() map[string]RuntimeSchemaParameterMetadata
RuntimeSchemaParameterMetadataDefinitions returns a defensive copy for build-time contract validation.
func SchemaAssemblyEnvironmentSnapshot ¶ added in v1.0.63
func SchemaAssemblyEnvironmentSnapshot() []string
SchemaAssemblyEnvironmentSnapshot returns an immutable copy for child process setup. It never changes the caller's environment.
func SchemaAssemblyWorkingDirectory ¶ added in v1.0.63
func SchemaAssemblyWorkingDirectory() string
SchemaAssemblyWorkingDirectory returns the registration-time working directory for isolated child-process assembly.
func SchemaCachePrewarmPayloadsHandleForTest ¶ added in v1.0.63
func SchemaCachePrewarmPayloadsHandleForTest() *schemacache.Registry
SchemaCachePrewarmPayloadsHandleForTest returns the never-adopted prewarm payloads handle after it settles, so tests can assert repair reset closes it.
func SchemaSourceRootRegistered ¶ added in v1.0.57
func SchemaSourceRootRegistered() bool
SchemaSourceRootRegistered reports whether runtime assembly has a root factory.
func SetOverridePriority ¶
SetOverridePriority delegates to cobracmd.SetOverridePriority.
func StdinIsPipe ¶
func StdinIsPipe() bool
StdinIsPipe reports whether stdin is a pipe (not a terminal). This is a non-consuming check — it only inspects file mode via stat.
func ValidateCatalogStructure ¶ added in v1.0.55
ValidateCatalogStructure checks that every tool entry in a schema_catalog snapshot conforms to the unified command data structure. It returns an error aggregating up to schemaCatalogStructureMaxViolations violations.
func ValidateInputSchema ¶
ValidateInputSchema performs strict local validation for reviewed tool inputs. It enforces required/type/enum checks and rejects unknown properties by default.
func ValidateJSONSchemaValue ¶ added in v1.0.60
ValidateJSONSchemaValue validates one decoded JSON value against the required/type/enum/properties/items subset used by reviewed CLI contracts.
func ValidateReviewedDryRunCapabilityDelivery ¶ added in v1.0.52
func ValidateReviewedDryRunCapabilityDelivery(registry SchemaRegistry) error
ValidateReviewedDryRunCapabilityDelivery proves that every positive source entry reaches the final typed registry and no serializer invents one. It deliberately imposes no minimum capability count or all-command coverage.
func ValidateRuntimeSchemaCompleteness ¶ added in v1.0.57
ValidateRuntimeSchemaCompleteness enforces the reviewed reverse command-tree contract used by generation and CI.
func ValidateSchemaDeliveryInvariants ¶ added in v1.0.52
func ValidateSchemaDeliveryInvariants(source SchemaRegistry, snapshot SchemaCatalogSnapshot) error
ValidateSchemaDeliveryInvariants proves that the serialized snapshot which will be embedded in the release binary is an exact delivery of source and has one content-identical ToolSpec behind every public Schema view. The snapshot is deliberately encoded and decoded through the production loader before any comparison is made.
This is a content gate, not a count gate: replacing one tool with another, consistently dropping a source field from every snapshot view, drifting a summary, or changing an alias payload while preserving all aggregate counts still fails.
func ValidateSchemaMetaIndexAgainstCatalog ¶ added in v1.0.57
func ValidateSchemaMetaIndexAgainstCatalog(index SchemaMetaIndexSnapshot, registry SchemaRegistry) error
ValidateSchemaMetaIndexAgainstCatalog proves the summary index matches the Identity / Safety / Selection projection of every delivered ToolSpec.
func ValidateSchemaMetaIndexAgainstSnapshot ¶ added in v1.0.57
func ValidateSchemaMetaIndexAgainstSnapshot(index SchemaMetaIndexSnapshot, snapshot SchemaCatalogSnapshot) error
ValidateSchemaMetaIndexAgainstSnapshot proves the summary index matches the Identity / Safety / Selection projection of every ToolSpec in a Catalog snapshot (generation-time gate before writing the index).
func ValidateSchemaParameterBindingDelivery ¶ added in v1.0.52
func ValidateSchemaParameterBindingDelivery(bound BoundCommandRegistry, registry SchemaRegistry) error
ValidateSchemaParameterBindingDelivery proves that every reviewed mapping ledger entry reaches the final public typed registry it was written for.
func ValidateSchemaParameterBindings ¶ added in v1.0.57
func ValidateSchemaParameterBindings() error
ValidateSchemaParameterBindings is the production validation gate for the reviewed mapping ledger (exclusions + removals). Build and generator entrypoints call this before any candidate resolution.
func WriteSchemaCacheBuildResult ¶ added in v1.0.63
func WriteSchemaCacheBuildResult(w io.Writer, result SchemaCacheBuildResult) error
WriteSchemaCacheBuildResult writes a bounded, versioned private response.
Types ¶
type AgentExampleDisposition ¶ added in v1.0.57
type AgentExampleDisposition = contract.ExampleDisposition
AgentExampleDisposition narrows one exact example with an explicit typed dry-run capability to contract-only. Index is a pointer so a missing field cannot silently select example zero.
Dispositions are authored on the owning ContractFinal Selection.
type AgentExampleDispositionSource ¶ added in v1.0.57
type AgentExampleDispositionSource string
AgentExampleDispositionSource distinguishes the normal typed-contract classification from narrow reviewed exceptions.
const ( AgentExampleDispositionDefault AgentExampleDispositionSource = "default" AgentExampleDispositionReviewed AgentExampleDispositionSource = ProvenanceReviewedManual )
type AgentExampleExecution ¶ added in v1.0.57
type AgentExampleExecution struct {
CanonicalPath string
Index int
Example string
Mode AgentExampleMode
DryRun *contract.DryRunSpec
ReasonCode AgentExampleReasonCode
Reason string
Source AgentExampleDispositionSource
}
AgentExampleExecution is one resolved example and its effective test mode.
type AgentExampleExecutionPlan ¶ added in v1.0.57
type AgentExampleExecutionPlan struct {
Examples []AgentExampleExecution
Total int
Contract int
DryRun int
ContractOnly int
ReviewedContractOnly int
ContractOnlyByReason map[AgentExampleReasonCode]int
}
AgentExampleExecutionPlan is a stable, typed report used by the exhaustive real-Cobra dry-run test.
func BuildAgentExampleExecutionPlan ¶ added in v1.0.57
func BuildAgentExampleExecutionPlan(bound BoundCommandRegistry, registry SchemaRegistry) (AgentExampleExecutionPlan, error)
BuildAgentExampleExecutionPlan validates every ContractFinal example against its real BoundCommand/Cobra contract. Runtime dry-run execution is opt-in and comes only from the final typed ToolSpec.
func ValidateAgentExampleDelivery ¶ added in v1.0.57
func ValidateAgentExampleDelivery(bound BoundCommandRegistry, registry SchemaRegistry) (AgentExampleExecutionPlan, error)
ValidateAgentExampleDelivery is the final generation gate. It validates every bound tool's ContractFinal Selection.Examples against the assembled typed SchemaRegistry.
type AgentExampleMode ¶ added in v1.0.57
type AgentExampleMode = contract.ExampleDispositionMode
AgentExampleMode controls only how an already contract-validated example is exercised. Contract validation is the default. dry_run is used only when the final ToolSpec publishes an explicit reviewed capability; contract_only remains a precise reviewed exception for such a capability whose runtime preconditions cannot be exercised safely and deterministically in the isolated test process.
type AgentExampleReasonCode ¶ added in v1.0.57
type AgentExampleReasonCode = contract.ExampleDispositionReasonCode
AgentExampleReasonCode is a closed taxonomy for reviewed contract-only exceptions to an explicit dry-run capability.
type AgentSelectionCase ¶ added in v1.0.57
type AgentSelectionCase struct {
ID string `json:"id"`
ProductID string `json:"product_id"`
Scenario string `json:"scenario"`
ExpectedCanonical string `json:"expected_canonical,omitempty"`
ForbiddenCanonical string `json:"forbidden_canonical,omitempty"`
CandidateCanonicals []string `json:"candidate_canonicals"`
}
AgentSelectionCase is one reproducible model-evaluation assertion derived from ContractFinal Selection prose. Positive cases require one exact canonical result; negative cases only forbid the command that owns the avoid_when text. CandidateCanonicals contains every bound tool in the same product, in stable order.
type AgentSelectionFixture ¶ added in v1.0.57
type AgentSelectionFixture struct {
Version int `json:"version"`
Cases []AgentSelectionCase `json:"cases"`
}
AgentSelectionFixture is the stable input to an optional live Agent evaluation. It is built from contract.ProductDecl/ContractFinal selection prose and the real bound command tree; it is not a second authored hint source.
type AgentSelectionReport ¶ added in v1.0.57
type AgentSelectionReport struct {
Tools int
PositiveAssertions int
NegativeAssertions int
FixtureSHA256 string
}
AgentSelectionReport records deterministic coverage and the exact fixture digest. It proves that all reviewed assertions are well-formed and executable; it deliberately does not claim that a language model understood their natural-language meaning.
func ValidateAgentSelectionContract ¶ added in v1.0.57
func ValidateAgentSelectionContract(bound BoundCommandRegistry) (AgentSelectionReport, error)
ValidateAgentSelectionContract is the lightweight generator-facing gate.
type AgentToolSelection ¶ added in v1.0.57
type AgentToolSelection struct {
AgentSummary string `json:"agent_summary"`
UseWhen []string `json:"use_when"`
AvoidWhen []string `json:"avoid_when"`
Examples []string `json:"examples"`
ExampleDispositions []AgentExampleDisposition `json:"example_dispositions,omitempty"`
Reviewed bool `json:"reviewed"`
Revision string `json:"revision"`
Reason string `json:"reason"`
Evidence []string `json:"evidence"`
}
AgentToolSelection is the tool-level selection projection used by example planning and live-selection fixtures. Production authority remains ContractFinal Selection on the owning leaf.
type AliasKind ¶ added in v1.0.52
type AliasKind string
AliasKind records how a reviewed alias path is represented by Cobra. A Cobra alias resolves to the primary command pointer; a compatibility leaf is a separately registered (usually hidden) runnable command. Keeping the two forms explicit prevents downstream code from assuming that every alias has its own Cobra leaf.
type BoundAlias ¶ added in v1.0.52
type BoundAlias struct {
Path string
Command *cobra.Command
Kind AliasKind
Source string
ReviewReason string
}
BoundAlias is one reviewed alias path resolved against the live Cobra tree.
type BoundCommandRegistry ¶ added in v1.0.52
type BoundCommandRegistry struct {
Commands []BoundCommandSpec
ByCanonical map[string]BoundCommandSpec
ByCLIPath map[string]BoundCommandSpec
}
BoundCommandRegistry is the only command input the Schema assembler should consume. Every entry has passed exact path, executable-leaf, collision, and native-annotation consistency checks.
func BindEffectiveCommandRegistry ¶ added in v1.0.52
func BindEffectiveCommandRegistry(root *cobra.Command, effective EffectiveCommandRegistry) (BoundCommandRegistry, error)
BindEffectiveCommandRegistry resolves every registry path against the live Cobra tree. Registry entries may target hidden compatibility leaves when they are explicitly reviewed, but every target must be an actual runnable leaf. Native annotations are optional implementation evidence; when present they must exactly agree with the registry identity.
type BoundCommandSpec ¶ added in v1.0.52
type BoundCommandSpec struct {
CommandSpec
PrimaryCommand *cobra.Command
AliasCommands []BoundAlias
}
BoundCommandSpec joins one stable registry identity to its executable primary leaf and all executable alias paths.
type CommandIdentity ¶ added in v1.0.55
type CommandIdentity = schemaruntime.CommandIdentity
CommandIdentity is the stable identity of a command.
type CommandMeta ¶ added in v1.0.55
type CommandMeta = schemaruntime.CommandMeta
CommandMeta is the complete runtime metadata view for a single command. Consumers read this struct; they never touch the raw catalog maps.
func ResolveMeta ¶ added in v1.0.55
func ResolveMeta(cliPath string) (CommandMeta, bool)
ResolveMeta returns the complete metadata for a command identified by its CLI path (e.g. "dev app delete") or one of its compat aliases (e.g. "report list" for "report inbox list"). Returns ok=false for commands not in the Schema surface (utility commands, hidden commands, shortcuts).
A persistent hit authenticates the payload file's index and one product shard header — Meta and the registry are never read on this path. Misses and corruption use the shared authoritative repair path.
type CommandOverride ¶ added in v1.0.56
type CommandOverride struct {
CommandPath string
Bind map[string]string
ScopedAliases map[string]string
Block []string
Ambiguous []string
Confirm bool
ScopeStrict bool
Investigate bool
Note string
}
CommandOverride is one reviewed per-command adjustment: binding a generic real flag to a concept, command-scoped aliases, blocks, and the reviewed co-occurrence whitelist.
type CommandPathFallback ¶ added in v1.0.58
type CommandPathFallback struct {
From string `json:"from"`
Mode CommandPathFallbackMode `json:"mode"`
To string `json:"to,omitempty"`
Candidates []string `json:"candidates,omitempty"`
Reviewed bool `json:"reviewed"`
ReviewReason string `json:"review_reason"`
}
CommandPathFallback is one validated, generated runtime recovery record. From is never advertised as a stable alias. To and Candidates are canonical real Cobra paths validated at generation time.
func LoadCommandPathFallbacks ¶ added in v1.0.58
func LoadCommandPathFallbacks() ([]CommandPathFallback, error)
LoadCommandPathFallbacks decodes and validates the authored recovery table. Callers receive a clone so generation and tests cannot mutate shared data.
func LookupCommandPathFallback ¶ added in v1.0.58
func LookupCommandPathFallback(rawPath string) (CommandPathFallback, bool)
LookupCommandPathFallback performs an exact O(1) lookup of a reviewed recovery-only path. Normalization only removes a leading dws and folds whitespace; it does not apply prefix, typo, or semantic matching.
func ReduceCommandPathFallbacks ¶ added in v1.0.58
func ReduceCommandPathFallbacks(root *cobra.Command) ([]CommandPathFallback, error)
ReduceCommandPathFallbacks validates the reviewed recovery table against the live distribution-owned Cobra tree. It refuses to turn an existing command or stable alias into a hidden rewrite. The sole exception is an explicitly annotated hint-only compatibility node, which contains no business action.
type CommandPathFallbackMode ¶ added in v1.0.58
type CommandPathFallbackMode string
CommandPathFallbackMode determines whether an invalid reviewed path can be normalized exactly or must stop and surface reviewed candidates.
const ( CommandPathFallbackRewrite CommandPathFallbackMode = "rewrite" CommandPathFallbackAmbiguous CommandPathFallbackMode = "ambiguous" )
type CommandRegistry ¶ added in v1.0.52
type CommandRegistry struct {
Commands []CommandSpec
ByCLIPath map[string]CommandSpec
ByCanonical map[string]CommandSpec
}
CommandRegistry is an indexed command identity set.
func (CommandRegistry) SourceHash ¶ added in v1.0.52
func (registry CommandRegistry) SourceHash() string
SourceHash hashes only stable identity, navigation, and reviewed exposure. Formatting, product order, provenance labels, and omitted default source_product_id/visibility values do not affect it.
type CommandSafety ¶ added in v1.0.55
type CommandSafety = schemaruntime.CommandSafety
func SafetyForCLIPath
deprecated
added in
v1.0.55
func SafetyForCLIPath(cliPath string) (CommandSafety, bool)
SafetyForCLIPath returns the safety metadata for a command identified by its CLI path (e.g. "dev app delete"). Returns ok=false when the path is absent from the Schema surface (utility commands, hidden commands, shortcuts), or when no Schema source root is registered (synthetic help trees in unit tests). With a registered factory, assembly failure panics via ResolveMeta (fail-closed).
Deprecated: use ResolveMeta(cliPath).Safety for the complete metadata view. Kept for backward compatibility with existing callers.
type CommandSelection ¶ added in v1.0.55
type CommandSelection = schemaruntime.CommandSelection
CommandSelection is the agent-facing selection metadata.
type CommandSpec ¶ added in v1.0.52
type CommandSpec struct {
CanonicalPath string
SourceProductID string
PrimaryCLIPath string
Aliases []string
Visibility SchemaVisibility
Source string
ReviewReason string
}
CommandSpec is one command identity. Identity and navigation are deliberately kept together so no downstream renderer can independently invent a canonical name, primary path, or alias.
type Concept ¶ added in v1.0.56
type Concept struct {
ID string
Denotes string
CanonicalHint string
Members []string
Excludes []string
Commands []string
Risk string
}
Concept is one reviewed set of equivalent flag spellings that all denote a single entity. Members reduce onto the command's real flag; Excludes lists spellings that denote a different entity and must never be reduced in.
type EffectiveCommandRegistry ¶ added in v1.0.52
type EffectiveCommandRegistry struct {
Commands []CommandSpec
ByCLIPath map[string]CommandSpec
ByCanonical map[string]CommandSpec
}
EffectiveCommandRegistry is the collected command identity registry after indexing. It remains independent of Cobra; binding is a separate fail-closed step.
func BuildEffectiveCommandRegistry ¶ added in v1.0.52
func BuildEffectiveCommandRegistry(root *cobra.Command) (EffectiveCommandRegistry, error)
BuildEffectiveCommandRegistry assembles the effective command identity registry by collecting ContractFinal.Identity from the live Cobra leaves under root. The collector is the single identity source; there is no separate reviewed identity file to merge or overlay.
Parameter mapping ledger (schema_parameter_mapping_ledger.go — mapping_exclusions / removals; active bindings retired to ParamDecl.Property) is validated at BindEffectiveCommandRegistry and catalog assembly, not here. Identity registry construction must not hard-depend on active binding rows.
func BuildEffectiveFromSpecs ¶ added in v1.0.57
func BuildEffectiveFromSpecs(specs []CommandSpec) (EffectiveCommandRegistry, error)
BuildEffectiveFromSpecs wraps the shared indexing so collected specs are normalised by the exact same rules used for effective registry assembly.
func (EffectiveCommandRegistry) SourceHash ¶ added in v1.0.52
func (registry EffectiveCommandRegistry) SourceHash() string
SourceHash covers every effective command identity delivered to downstream consumers.
type FixtureAgentProductSelection ¶ added in v1.0.57
type FixtureAgentProductSelection struct {
AgentSummary string `json:"agent_summary"`
UseWhen []string `json:"use_when"`
AvoidWhen []string `json:"avoid_when"`
Reviewed bool `json:"reviewed"`
Revision string `json:"revision"`
Reason string `json:"reason"`
Evidence []string `json:"evidence"`
}
FixtureAgentProductSelection is retained for transitional fixtures only.
type FixtureAgentSelectionRevision ¶ added in v1.0.57
type FixtureAgentSelectionRevision struct {
GeneratedBy string `json:"generated_by"`
Model string `json:"model,omitempty"`
PromptVersion string `json:"prompt_version,omitempty"`
Reason string `json:"reason"`
}
FixtureAgentSelectionRevision is retained for transitional fixtures only.
type FixtureAgentSelectionSet ¶ added in v1.0.57
type FixtureAgentSelectionSet struct {
Revisions map[string]FixtureAgentSelectionRevision `json:"revisions,omitempty"`
Products map[string]FixtureAgentProductSelection `json:"products,omitempty"`
Tools map[string]AgentToolSelection `json:"tools,omitempty"`
}
FixtureAgentSelectionSet is a transitional Agent selection fixture type retained only so live-selection call sites can project candidate tables. Production paths must keep it empty; example planning reads ContractFinal.
type IdentityCollectionReport ¶ added in v1.0.57
type IdentityCollectionReport struct {
Leaves int // runnable leaves walked (hidden included)
WithIdentity int // primary leaves carrying a ContractFinal.Identity
HiddenPrimaries int // collected primaries that are Hidden deprecated/migration shims
Excluded int // leaves matched by reviewed exclusions
NoIdentity []string // leaves without Identity (alias / compatibility / deprecated; informational)
MissingPrimary []string // canonicals with no collected primary (populated by spec-set comparisons)
}
IdentityCollectionReport summarises a collection walk.
type InterfaceRefKey ¶ added in v1.0.52
InterfaceRefKey is the exact, typed identity of an embedded MCP operation. It is deliberately independent from a CLI canonical path: multiple commands may explicitly project the same operation.
type InterfaceRegistry ¶ added in v1.0.52
type InterfaceRegistry struct {
ByCanonical map[string]InterfaceRegistryEntry
ByInterfaceRef map[InterfaceRefKey][]string
}
InterfaceRegistry is the typed interface fact model for optional MCP-shaped fixtures. ByCanonical supports exact navigation; ByInterfaceRef answers whether an explicitly selected (product_id, rpc_name) exists.
type InterfaceRegistryEntry ¶ added in v1.0.52
type InterfaceRegistryEntry struct {
CanonicalPath string
Ref contract.InterfaceRefSpec
Metadata embeddedMCPToolMetadata
}
InterfaceRegistryEntry is one operation projection from an optional diagnostic MCP-shaped map (tests / fetch dumps). CanonicalPath is a lookup key, not command identity. Production assembly does not build this from a committed pin.
type ParamAliasEntry ¶ added in v1.0.56
type ParamAliasEntry struct {
CLIPath string `json:"cli_path"`
Aliases map[string]string `json:"aliases,omitempty"`
Blocked []string `json:"blocked,omitempty"`
Ambiguous []string `json:"ambiguous,omitempty"`
}
ParamAliasEntry is the reduced parameter-alias table for one runnable Cobra leaf. It is the typed value the build-time generator serializes into param_aliases_generated.go and that the runtime normalizer (P2) consumes.
Aliases maps an already-morphed emitted name to the command's canonical real flag; the runtime looks up Morph(emitted) here to resolve a synonym. Blocked lists morphed names that must never be reduced (they route to did-you-mean), and Ambiguous lists morphed names that a reviewed co-occurrence guard leaves unresolved on purpose.
func LookupParamAlias ¶ added in v1.0.56
func LookupParamAlias(rawCommandPath string) (ParamAliasEntry, bool)
LookupParamAlias resolves the reduced parameter-alias entry for a command.
rawCommandPath is Cobra's CommandPath() (it still carries the "dws" prefix). It is normalized through normalizeSchemaCLIPath — the exact function the build-time generator used to key each entry — so the runtime lookup key is byte-identical to the generation key and there is zero mapping drift.
func ReduceParamAliases ¶ added in v1.0.56
func ReduceParamAliases(root *cobra.Command) ([]ParamAliasEntry, error)
ReduceParamAliases resolves the reviewed concept dictionary against every runnable leaf's real flags and returns the per-command alias table. It is the single source of the reduction algorithm, shared by the generator and tests so the build-time (intersection) and generated views can never disagree.
The reduction is deliberately mechanical (no NLU): for each concept it morphs the concept members (plus any command-bound generic flag) and intersects them with the command's morphed real flags. An intersection of exactly one real flag yields aliases onto it; two or more real flags is a co-occurrence that must be an explicitly reviewed `ambiguous` entry or generation fails. Command scoped aliases override, blocks are removed and recorded, and every override path and target is validated against the live tree.
func (ParamAliasEntry) IsAmbiguous ¶ added in v1.0.56
func (e ParamAliasEntry) IsAmbiguous(morphed string) bool
IsAmbiguous reports whether a morphed emitted name is on this command's reviewed co-occurrence whitelist: it is intentionally left unresolved so the runtime asks instead of guessing between two real flags.
func (ParamAliasEntry) IsBlocked ¶ added in v1.0.56
func (e ParamAliasEntry) IsBlocked(morphed string) bool
IsBlocked reports whether a morphed emitted name is on this command's block list: it must never be auto-rewritten and instead routes to did-you-mean.
func (ParamAliasEntry) ResolveAlias ¶ added in v1.0.56
func (e ParamAliasEntry) ResolveAlias(morphed string) (string, bool)
ResolveAlias returns the canonical real flag a morphed emitted name reduces to, if this command aliases it. The caller is expected to pass an already-morphed name (cmdutil.Morph), matching how the table is keyed.
type ParamConcepts ¶ added in v1.0.56
type ParamConcepts struct {
Version int
Morph map[string]ParamMorphRule
Concepts []Concept
ByConcept map[string]Concept
Overrides []CommandOverride
Fixture []ParamFixtureCase
}
ParamConcepts is the decoded, validated reviewed concept dictionary.
func LoadParamConcepts ¶ added in v1.0.56
func LoadParamConcepts() (ParamConcepts, error)
LoadParamConcepts decodes and validates the embedded reviewed concept dictionary exactly once.
type ParamFixtureCase ¶ added in v1.0.56
ParamFixtureCase is one reviewed regression assertion derived from evaluation bad cases: the emitted name on Command must reduce to Expect (a real flag) or route to a did-you-mean sentinel.
type ParamMorphRule ¶ added in v1.0.56
type ParamMorphRule struct {
Desc string `json:"desc"`
Enabled bool `json:"enabled"`
Guard string `json:"guard,omitempty"`
Reason string `json:"reason,omitempty"`
}
ParamMorphRule documents one table-free name normalization behavior. It is evidence for the shared Morph function; it is not a per-command alias.
type ParameterSpec ¶ added in v1.0.52
type ParameterSpec = schemaruntime.ParameterSpec
type ProductSpec ¶ added in v1.0.52
type ProductSpec = schemaruntime.ProductSpec
type ResolvedSchemaBuild ¶ added in v1.0.52
type ResolvedSchemaBuild struct {
// contains filtered or unexported fields
}
ResolvedSchemaBuild is the single source-to-delivery hand-off used by the Catalog generator. Effective, Bound, and Registry are three views of one resolution pass: reviewed identity, executable Cobra binding, and the final typed Agent contract. Downstream gates and serializers must consume this value instead of rebuilding any view from the command tree.
The command root is intentionally private. It lets delivery completeness inspect the same executable tree without allowing callers to construct a seemingly resolved build by assembling the exported fields themselves.
func ResolveSchemaBuild ¶ added in v1.0.52
func ResolveSchemaBuild(root *cobra.Command) (ResolvedSchemaBuild, error)
ResolveSchemaBuild is the only assembly path from executable Cobra commands and reviewed metadata into the typed Agent contract. It resolves identity once, binds Cobra once, and assembles one SchemaRegistry from ContractFinal / contract.ProductDecl leaf declarations. Catalog gates and serialization consume the returned value directly; they never re-read overlays or merge sources.
func (ResolvedSchemaBuild) CommandCount ¶ added in v1.0.52
func (resolved ResolvedSchemaBuild) CommandCount() int
CommandCount reports the reviewed effective command count for generator diagnostics without exposing a mutable registry view.
func (ResolvedSchemaBuild) RegistryHash ¶ added in v1.0.52
func (resolved ResolvedSchemaBuild) RegistryHash() string
RegistryHash returns the semantic identity/navigation hash attached to this resolved build. It is an envelope value, not a second registry input.
type RuntimeCompatibilityEquivalence ¶ added in v1.0.52
type RuntimeCompatibilityEquivalence struct {
ID string `json:"id"`
Reason string `json:"reason"`
Reviewed bool `json:"reviewed"`
}
RuntimeCompatibilityEquivalence is an implementation-side review record for two separately registered Cobra leaves that intentionally share one Schema identity despite using different execution handlers. Registry alias review alone is not enough: different handlers may inject fixed arguments or route to different business operations while exposing identical flags.
type RuntimeSchemaCompletenessReport ¶ added in v1.0.52
type RuntimeSchemaCompletenessReport struct {
Covered []string
Excluded []string
Missing []string
InvalidExclusions []string
StaleExclusions []string
DeliveryErrors []string
}
RuntimeSchemaCompletenessReport compares the public executable Cobra leaves with a reviewed Schema command set, such as runtime annotations or the final generated Catalog.
func RuntimeSchemaCompleteness ¶ added in v1.0.52
func RuntimeSchemaCompleteness(root *cobra.Command, exclusions []RuntimeSchemaExclusion) RuntimeSchemaCompletenessReport
RuntimeSchemaCompleteness scans the real command tree in the reverse direction: every public executable leaf must either belong to the effective reviewed CommandRegistry or have a reviewed exclusion with a non-empty reason.
type RuntimeSchemaConstraints ¶ added in v1.0.52
type RuntimeSchemaConstraints = contract.RuntimeSchemaConstraints
type RuntimeSchemaExclusion ¶ added in v1.0.52
RuntimeSchemaExclusion records a reviewed reason why a public executable command is intentionally not advertised as an Agent tool.
func ReviewedRuntimeSchemaExclusions ¶ added in v1.0.57
func ReviewedRuntimeSchemaExclusions() ([]RuntimeSchemaExclusion, error)
ReviewedRuntimeSchemaExclusions returns the exact, reviewed list of public CLI leaves intentionally kept outside the stable Agent command contract. Authority is the reviewed Go registry in schema_command_exclusions.go (central groups + non-empty reason); there is no JSON completeness input.
type RuntimeSchemaParameterMetadata ¶ added in v1.0.52
type RuntimeSchemaParameterMetadata struct {
Inherited []string
Required []string
RequiredWhen map[string]string
Formats map[string]string
Enums map[string][]string
Examples map[string]string
}
RuntimeSchemaParameterMetadata contains reviewed CLI parameter semantics that Cobra cannot represent by itself. It is an independent generation input: generated Catalog data is never read back into this registry.
type RuntimeToolSpecInput ¶ added in v1.0.52
type RuntimeToolSpecInput = schemaruntime.RuntimeToolSpecInput
type SchemaCacheArtifacts ¶ added in v1.0.63
type SchemaCacheArtifacts struct {
Version int
SourceHash string
SurfaceHash string
Meta []byte
Registry []byte
Payload []byte
ProductCount int
MetaSHA256 [sha256.Size]byte
RegistrySHA256 [sha256.Size]byte
PayloadSHA256 [sha256.Size]byte
ProductDescriptors []schemaruntime.ProductDescriptor
// contains filtered or unexported fields
}
SchemaCacheArtifacts is the deterministic cache hand-off used by the identity generator. Payload slices are detached from assembly state.
func BuildSchemaCacheArtifacts ¶ added in v1.0.63
func BuildSchemaCacheArtifacts(resolved ResolvedSchemaBuild) (SchemaCacheArtifacts, error)
BuildSchemaCacheArtifacts validates and snapshots one ResolvedSchemaBuild, then derives Meta and product shards from that exact typed registry.
func DeliverySchemaCacheArtifactsForTest ¶ added in v1.0.63
func DeliverySchemaCacheArtifactsForTest() (SchemaCacheArtifacts, error)
DeliverySchemaCacheArtifactsForTest derives artifacts from an already assembled live result without invoking its source factory again.
func (SchemaCacheArtifacts) LocatorPaths ¶ added in v1.0.63
func (a SchemaCacheArtifacts) LocatorPaths() []string
LocatorPaths returns a detached, sorted list of every authenticated path in Meta. It is primarily useful for exhaustive generation and parity gates.
func (SchemaCacheArtifacts) MetaArtifact ¶ added in v1.0.63
func (a SchemaCacheArtifacts) MetaArtifact() schemacache.Artifact
func (SchemaCacheArtifacts) PayloadArtifact ¶ added in v1.0.63
func (a SchemaCacheArtifacts) PayloadArtifact() schemacache.Artifact
func (SchemaCacheArtifacts) PayloadIndexPins ¶ added in v1.0.63
PayloadIndexPins derives the pinned payload index region identity from the artifact's self-describing prefix: the region length including the 4-byte prefix, and the region digest.
func (SchemaCacheArtifacts) RegistryArtifact ¶ added in v1.0.63
func (a SchemaCacheArtifacts) RegistryArtifact() schemacache.Artifact
func (SchemaCacheArtifacts) RenderAll ¶ added in v1.0.63
func (a SchemaCacheArtifacts) RenderAll() (map[string]any, error)
RenderAll returns the public full-export projection represented by these exact artifacts without rebuilding the authoritative source tree.
func (SchemaCacheArtifacts) RenderOverview ¶ added in v1.0.63
func (a SchemaCacheArtifacts) RenderOverview() (map[string]any, error)
RenderOverview returns the public Meta-only overview projection.
func (SchemaCacheArtifacts) RenderQuery ¶ added in v1.0.63
func (a SchemaCacheArtifacts) RenderQuery(path string) (map[string]any, error)
RenderQuery returns a product/group/leaf projection from the exact registry used to create the cache artifacts.
func (SchemaCacheArtifacts) ValidateRoundTrip ¶ added in v1.0.63
func (a SchemaCacheArtifacts) ValidateRoundTrip() error
ValidateRoundTrip proves the release hand-off before its digests can become binary trust anchors. It is intentionally a build-time operation: a cache hit authenticates bytes and validates the selected DTO, without reconstructing the complete public Catalog.
type SchemaCacheBuildResult ¶ added in v1.0.63
type SchemaCacheBuildResult struct {
Artifacts SchemaCacheArtifacts
Identity SchemaCacheIdentity
}
SchemaCacheBuildResult is the detached result of a clean declaration-only Schema assembly. It contains no live Cobra or registry state.
func ReadSchemaCacheBuildResult ¶ added in v1.0.63
func ReadSchemaCacheBuildResult(r io.Reader) (SchemaCacheBuildResult, error)
ReadSchemaCacheBuildResult reads and validates a private builder response.
type SchemaCacheIdentity ¶ added in v1.0.63
type SchemaCacheIdentity = schemareader.Identity
SchemaCacheIdentity is the complete identity of one cache generation. No value is learned from an on-disk envelope. Production does not embed this at compile time; each supported machine generates it from live declarations.
func IdentityFromArtifacts ¶ added in v1.0.63
func IdentityFromArtifacts(edition string, artifacts SchemaCacheArtifacts) (SchemaCacheIdentity, error)
IdentityFromArtifacts derives the authenticated Schema cache identity of one live declaration assembly. Production never embeds this at compile time; each machine generates it from the running binary's declarations.
func SchemaCacheFastPathIdentity ¶ added in v1.0.63
func SchemaCacheFastPathIdentity() (SchemaCacheIdentity, bool)
SchemaCacheFastPathIdentity returns only the currently registered, eligible authority. Replacing the source factory or marking runtime uncertainty must disable early process delivery just as it disables ordinary cache loaders. This accessor never opens the cache or assembles declarations.
func SchemaCacheReadableIdentityForTest ¶ added in v1.0.63
func SchemaCacheReadableIdentityForTest() (SchemaCacheIdentity, bool)
SchemaCacheReadableIdentityForTest returns the registered identity even when the process is uncertain and therefore prohibited from direct publication.
func TryLoadLocalSchemaCacheIdentity ¶ added in v1.0.63
func TryLoadLocalSchemaCacheIdentity(edition string) (SchemaCacheIdentity, bool)
TryLoadLocalSchemaCacheIdentity reads the per-edition identity sidecar from the edition cache directory. Missing files are a miss, not an error. Leftover fingerprint-suffixed sidecars are ignored and never used as a lookup key. A sidecar whose binary_build_id does not match the running binary is a miss with no side effect: it is left in place for lock-holding repair/publish or explicit upgrade invalidation. A sidecar whose recorded edition does not match the requested one is also a miss: identity binds the (directory, record) edition pair, so a sidecar copied from another edition's directory must not substitute that edition's artifacts for the requested one.
type SchemaCacheIsolatedBuilder ¶ added in v1.0.63
type SchemaCacheIsolatedBuilder func(context.Context) (SchemaCacheBuildResult, error)
SchemaCacheIsolatedBuilder assembles a cache generation outside the caller's process state. Production installs this from internal/app.
type SchemaCacheOptions ¶ added in v1.0.63
type SchemaCacheOptions struct {
Enabled bool
AllowGenerate bool
Edition string
Identity SchemaCacheIdentity
GOOS string
GOARCH string
LockTimeout time.Duration
Counters *schemacache.Counters
RuntimeEligible func() bool
}
SchemaCacheOptions configures production cache delivery. Enabled options are accepted for darwin/linux/windows on amd64/arm64; tests may inject GOOS/GOARCH. AllowGenerate lets an empty identity be derived from the running binary's declarations on first schema use.
type SchemaCatalogBuildOptions ¶ added in v1.0.52
type SchemaCatalogBuildOptions struct {
RegistryHash string
}
SchemaCatalogBuildOptions carries release-envelope inputs which are checked against the effective reviewed CommandRegistry. The command set is not an option: visibility is resolved by EffectiveCommandRegistry before assembly, and every public command must be delivered.
type SchemaCatalogSnapshot ¶ added in v1.0.52
type SchemaCatalogSnapshot struct {
Version int `json:"version"`
SourceHash string `json:"source_hash"`
SurfaceHash string `json:"surface_hash,omitempty"`
Catalog map[string]any `json:"catalog"`
Tools map[string]map[string]any `json:"tools"`
}
SchemaCatalogSnapshot is the release-stable Agent contract. Catalog holds the progressive product/tool index; Tools holds full leaf parameter schemas. It intentionally contains no endpoint, credential, or runtime cache data.
func BuildSchemaCatalogSnapshot ¶ added in v1.0.52
func BuildSchemaCatalogSnapshot(resolved ResolvedSchemaBuild, options SchemaCatalogBuildOptions) (SchemaCatalogSnapshot, error)
BuildSchemaCatalogSnapshot renders a deterministic Catalog from one resolved source-to-delivery hand-off. It deliberately accepts no Cobra root: rebuilding SchemaRegistry or re-deriving identity at this boundary would allow generation gates to validate one candidate while publishing another.
type SchemaIndex ¶ added in v1.0.52
type SchemaIndex = schemaruntime.SchemaIndex
type SchemaMetaIndexEntry ¶ added in v1.0.57
type SchemaMetaIndexEntry struct {
CLIPath string `json:"cli_path"`
Canonical string `json:"canonical_path"`
Aliases []string `json:"aliases,omitempty"`
ProductID string `json:"product_id,omitempty"`
Title string `json:"title,omitempty"`
Effect string `json:"effect,omitempty"`
Risk string `json:"risk,omitempty"`
Confirmation string `json:"confirmation,omitempty"`
Idempotency string `json:"idempotency,omitempty"`
AgentSummary string `json:"agent_summary,omitempty"`
UseWhen []string `json:"use_when,omitempty"`
AvoidWhen []string `json:"avoid_when,omitempty"`
Examples []string `json:"examples,omitempty"`
}
SchemaMetaIndexEntry is one primary-path CommandMeta record. Aliases are expanded into the ResolveMeta lookup at decode time.
type SchemaMetaIndexSnapshot ¶ added in v1.0.57
type SchemaMetaIndexSnapshot struct {
Version int `json:"version"`
SourceHash string `json:"source_hash"`
SurfaceHash string `json:"surface_hash,omitempty"`
Entries []SchemaMetaIndexEntry `json:"entries"`
}
SchemaMetaIndexSnapshot is the CommandMeta summary shape written by CI Catalog dumps for determinism checks. Runtime delivery does not embed or decode this artifact.
func BuildSchemaMetaIndex ¶ added in v1.0.57
func BuildSchemaMetaIndex(snapshot SchemaCatalogSnapshot) (SchemaMetaIndexSnapshot, error)
BuildSchemaMetaIndex extracts the ResolveMeta summary from a full Catalog snapshot. Entries are sorted by cli_path for deterministic generation.
func DecodeSchemaMetaIndex ¶ added in v1.0.57
func DecodeSchemaMetaIndex(data []byte) (SchemaMetaIndexSnapshot, error)
DecodeSchemaMetaIndex parses a CI/test gob meta index dump.
func DecodeSchemaMetaIndexJSON ¶ added in v1.0.57
func DecodeSchemaMetaIndexJSON(data []byte) (SchemaMetaIndexSnapshot, error)
DecodeSchemaMetaIndexJSON parses a JSON meta index document. Kept for unit fixtures; runtime delivery uses gob via DecodeSchemaMetaIndex.
type SchemaMetadataLoadCounts ¶ added in v1.0.52
type SchemaMetadataLoadCounts struct {
Catalog uint64
MetaIndex uint64
AgentMetadata uint64
ParameterBinding uint64
}
SchemaMetadataLoadCounts exposes read-only diagnostics for startup tests and profiling. Counts are incremented only when a lazy delivery snapshot is assembled / projected for the first time.
func RuntimeSchemaMetadataLoadCounts ¶ added in v1.0.52
func RuntimeSchemaMetadataLoadCounts() SchemaMetadataLoadCounts
RuntimeSchemaMetadataLoadCounts reads the concurrency-safe lazy loader counters without triggering any loader.
type SchemaRegistry ¶ added in v1.0.52
type SchemaRegistry = schemaruntime.SchemaRegistry
Public aliases preserve the original cli API while ownership lives in the Cobra-free runtime package.
func AssembleSchemaRegistry ¶ added in v1.0.52
func AssembleSchemaRegistry(root *cobra.Command) (SchemaRegistry, error)
AssembleSchemaRegistry is a test/homology gate entry that only needs the typed registry. Catalog production must use ResolveSchemaBuild so the bound/effective views remain attached to the exact same resolution pass.
func AssembleSchemaRegistryFromBound ¶ added in v1.0.52
func AssembleSchemaRegistryFromBound(bound BoundCommandRegistry) (SchemaRegistry, error)
AssembleSchemaRegistryFromBound resolves non-identity sources into the single typed ToolSpec model. Command discovery is intentionally impossible below this boundary: callers must first provide a fail-closed bound registry.
type SchemaSnapshotPayload ¶ added in v1.0.52
type SchemaSnapshotPayload = schemaruntime.SchemaSnapshotPayload
type SchemaVisibility ¶ added in v1.0.52
type SchemaVisibility string
SchemaVisibility is the reviewed CommandRegistry visibility class for a command identity.
const ( SchemaVisibilityPublic SchemaVisibility = "public" SchemaVisibilityCompat SchemaVisibility = "compat" SchemaVisibilityInternal SchemaVisibility = "internal" )
type StdinGuard ¶
type StdinGuard struct {
// contains filtered or unexported fields
}
StdinGuard ensures stdin is consumed at most once per command invocation. Multiple flags using @- or implicit stdin fallback would race on the same reader; StdinGuard detects and rejects the second claim with a clear error.
func NewStdinGuard ¶
func NewStdinGuard() *StdinGuard
NewStdinGuard creates a fresh guard for one command invocation.
func (*StdinGuard) Claim ¶
func (g *StdinGuard) Claim(source string) error
Claim marks stdin as consumed by the named source (e.g. "--text @-"). Returns an error if stdin was already claimed.
func (*StdinGuard) Claimed ¶
func (g *StdinGuard) Claimed() bool
Claimed reports whether stdin has been consumed.
type ToolSpec ¶ added in v1.0.52
type ToolSpec = schemaruntime.ToolSpec
Source Files
¶
- canonical.go
- command_meta.go
- command_path_fallbacks.go
- command_path_fallbacks_generated.go
- command_path_fallbacks_lookup.go
- command_safety.go
- fortest.go
- gen.go
- help_affordance.go
- param_aliases.go
- param_aliases_generated.go
- param_aliases_lookup.go
- param_concepts.go
- priority.go
- runtime_schema.go
- runtime_schema_seam.go
- schema_agent_examples.go
- schema_agent_metadata.go
- schema_agent_selection.go
- schema_assembly_audit.go
- schema_assembly_environ.go
- schema_cache_builder.go
- schema_cache_delivery.go
- schema_cache_identity.go
- schema_cache_local.go
- schema_canonical_path.go
- schema_catalog.go
- schema_catalog_structure.go
- schema_cobra_binding.go
- schema_command_exclusions.go
- schema_command_registry.go
- schema_completeness.go
- schema_constraints_runtime.go
- schema_contract_model.go
- schema_delivery_invariants.go
- schema_dry_run_capabilities.go
- schema_identity_collect.go
- schema_interface_registry.go
- schema_lazy_metadata.go
- schema_meta_index.go
- schema_parameter_bindings.go
- schema_parameter_mapping_ledger.go
- schema_parameters_runtime.go
- schema_runtime_registry.go
- schema_snapshot_adapter.go
- schema_source_root.go
- schema_support.go
- schema_validate.go
- stdin.go
Directories
¶
| Path | Synopsis |
|---|---|
|
Package homology holds Schema/CLI homology and ContractFinal consistency gates that exercise the live command tree and delivered Catalog.
|
Package homology holds Schema/CLI homology and ContractFinal consistency gates that exercise the live command tree and delivered Catalog. |
|
Package schemacachepb contains the private generated Schema cache DTO.
|
Package schemacachepb contains the private generated Schema cache DTO. |