csf

module
v0.2.3 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 3, 2026 License: Apache-2.0

README

One Go runtime for agent work, typed tools, shared knowledge and observable experiments.

Take the tour · What is CSF · North star · Why CSF · Proofs · Architecture · Quick start · CSF guide · Agent instructions · Citation


What is CSF

Most robots run two kinds of software side by side: a slow, best-effort layer that decides what to do (planning, perception, learned policies) and a fast, real-time layer that does it (the control loop that must never miss a deadline). LITHE (Lim and Clites, 2026) turns that split into an architecture on one ordinary computer. A best-effort Brain proposes, a real-time Spine executes, and each gets its own CPU core. On LITHE's quad-core board, CPU 1 runs the Spine's control loop alone, CPU 2 runs the Brain, CPU 3 handles the motor bus, and CPU 0 is the housekeeping core: it takes the operating system's chores, absorbs timing jitter so the other cores never feel it, and prepares the next controller before it is swapped in. LITHE demonstrates this on one robot, but deciding versus doing is the shape of most robot software stacks, so we expect the architecture to carry over to most robots.

CSF is the LITHE philosophy applied to CPU 0. It is the housekeeping layer: the tools, records, schedules and experiments around an agent system's decisions, composed into one Go process so they talk through function calls instead of inter-process communication. In CSF the architecture is a checked artifact and the engineers are agents working under rules. It ships with working implementations (gotth-live, Warden, xetcas, pgmem, liquidproto) that prove the loop works.

New here? Take the tour of CSF: nine stops from the idea to the running pieces, each with one command to run and what you should see.

It has four parts, and together they form one loop:

  1. A language. architecture.csf declares what the system is: its terms (124 today), how they contain and depend on each other, and the paper each borrowed word comes from. For example: term widget "Widget" "A component of gotth-live ...".
  2. A compiler, csfc. It checks the code against that declaration and generates what used to be hand-written: the glossary, the dictionary, the architecture diagrams below, and this README's north star. For example, tools/merge-pr.sh refuses a pull request whose ontology alignment score regresses against main.
  3. A harness. One process per machine runs coding-agent sessions with a gate on every shell command and every commit. For example, harness submit -recipe agent.json starts an agent that cannot run a polling loop and whose first commit opens a draft pull request.
  4. Miners (ouroboros). They read the operator–agent record and the repository, find where intent and code diverge, and turn each divergence into the next gate or change. For example, on 2026-10-02 the finding that 64 of the 124 terms own no directory became a ticket that states the gate's predicate; the gate itself is not built yet.

What it can be used as

An agent-operated deployment system: propose and approve changes, reconcile applications, approve infrastructure updates, and watch the fleet. An agent harness with gates on every command and commit. A server-driven live UI that syncs state with a browser. A self-hosted build and evidence cache. Fast tests with real SQL and no server.

What you get, grouped by what it is for:

  • CSF — The Cerebrospinal Fluid, the core: a Go library and runtime for the coordination around an agent system, covering typed tools, sessions and worktrees, schedules, knowledge ingestion and search, traces and retained evidence. Its services are libraries mounted into one Go process through functional options, and each operation is generated once and served as HTTP, CLI and MCP. Start with the consumer example.
  • Deploy, an agent-operated deployment system: an agent harness proposes, the deploy service approves and fences every change, the node executor reconciles Compose applications, and the operator UI watches.
  • Libraries you can use on their own:
    • gotth-live: server-driven live user interfaces from Go. Widgets, event handlers and state are synced from the application layer, and the browser renders each change as the app commits it. State and rendering stay in your process; one WebSocket per tab carries events up and re-rendered fragments down. No npm, no CDN.
    • xetcas: a self-hosted Xet [6] content-addressable storage server with a Git LFS [7] front door, used for build caches, snapshots and evidence archival. Re-pushing a 48 MiB model after editing 2% of it costs about 1 MiB.
    • pkg/: domain-neutral Go primitives: pgmem, a process-local PostgreSQL [8] emulator for fast tests (real PostgreSQL AST, no server); liquidproto, the runtime for Liquid Proto, protobuf with refinement types [9] compiled into the generated Go; cron, config, redact, telemetry, mailbox, and more.

The north star is a robot software stack whose correctness is proven end to end; today that is a goal, not a capability: the generated table below reports no completed milestone, and the csfc verifier does not yet issue certificates. It ships as one Go monorepo with a CLI.

1. Introduction

The name comes from the architecture that shaped it. In LITHE (Lim and Clites, 2026), a best-effort Brain proposes and a real-time Spine executes, on one partitioned computer. CSF is the fluid around them: the housekeeping layer that carries tools, records and experiments between decisions.

LITHE, Figure 2 (Lim and Clites, 2026).

New to the words used here? The glossary explains every CSF term in plain language, plus the words CSF borrows from papers, with citations.

First-party source is Apache-2.0. Dependencies, vendor simulator images and paper figures retain their own licenses.

North star

Generated from architecture.csf; change that file, not this section.

Goal. End-to-end correctness of a robot software stack, proven relative to stated assumptions and checked against them at runtime. The physical world and the models in it are not proven; the envelope around them is: check before execute, contracts at every io boundary, and runtime monitors with a safe fallback.

Milestones. 0 done, 6 in progress, 1 planned. A done milestone names a path in this repository that the generator checks exists; PR and issue numbers refer to the source monorepo.

# Milestone Status Terms Evidence Builds on
1 Every io boundary is a typed capability: a service crosses only what its constructor was granted, and the io tree is sorted by crossing tier. Process launch and PostgreSQL are capabilities today; the move into the tier-sorted io directories is planned. in progress I/O crossing, Crossing tier, Capability ipc/proc, ipc/db/csfpg, PR #290, PR #301, PR #321, issue #264 —
2 Each crossing's tier is resolved from runtime and placement state instead of being declared by hand. planned Crossing tier, Placement rules, Runtime issue #264 —
3 The low-level controller is reached only through the ros seam, whose contract is proven ROS-side and monitored CSF-side with a safe fallback. The stub that answers every call with a typed not-connected error ships; the transport, proof and monitor are planned. in progress ROS spine capability, Low-level spine controller, Check ipc/ros, PR #299 KeYmaera X (glossary), VeriPhy (glossary)
4 Turn executors are interchangeable behind one contract while CSF owns the session, its context and its tools. Claude Code runs as the first turn executor; CSF does not yet own the session's context. in progress Turn executor, Workbench conversation session, Claude Code provider ipc/model/claudecode, examples/claudecode, PR #322 —
5 Every unit of the system climbs the compilability ladder from prose to structured, typed, checked and finally discharged, where a checker discharges a stated proof obligation. csfc checks the declared architecture against its Go source on every change, and its check-generated command states lifetime and cleanup obligations that it does not yet discharge. in progress Compiler, Compile, Shared typed contracts csf/compiler/architecture, issue #329 CompCert (glossary), seL4 (glossary)
6 The system improves itself through Ouroboros, under gates it may not change: mined evidence proposes each change and every accepted change is an operator-approved pull request. Session mining exists in the source monorepo, outside this repository; the CSF service is planned. in progress Ouroboros, Evaluate, Save evidence PR #237 —
7 No hand-written documentation: every claim is typed data in architecture.csf and its prose is generated, this section included. in progress Compiler, Compile csf/compiler/language/architecture.csf, docs/GLOSSARY.md, PR #333 —

2. Why CSF: no IPC inside CPU 0

LITHE runs a whole robot control hierarchy on one quad-core single-board computer by partitioning its cores (LITHE §III-B):

LITHE core Role in LITHE
CPU 0 (Housekeeping) Linux housekeeping, SSH sessions and non-critical interrupts. It absorbs system jitter, and LITHE's loader thread prepares new controllers here (LITHE §III-E1).
CPU 1 (Spine) The C++ control loop, alone on an isolated core.
CPU 2 (Brain) The high-level Python runtime.
CPU 3 (Transport) Blocking SPI/CAN bus I/O, kept off the control core.

LITHE treats inter-process communication as architecture (LITHE §III-C): the Brain and Spine exchange state through lock-free, zero-copy POSIX shared memory whose layout a build-time generator owns. Its abstract names complex middleware as one cost of the conventional alternatives.

The coordination an agent system needs — tools, sessions, schedules, knowledge and observation — lands on the housekeeping side of that partition. Built the usual way, each capability is its own daemon, and every handoff inside CPU 0 becomes a socket, a serialization format and another process lifecycle to supervise.

CSF prevents that IPC problem inside CPU 0 by composing those capabilities in one Go process. Services are Go libraries selected with functional options. They exchange typed values through function calls and coordinate concurrent work with goroutines and channels; contexts and explicit ownership give each operation a cancellation and cleanup path. An internal handoff needs no socket, no wire serialization and no separate daemon. Separate architecture checks inspect selected Go ownership and process boundaries in source; they establish those source constraints, not runtime timing.

The diagram at the top of this page is our architectural mapping onto LITHE [1], drawn by hand; it is not generated from the architecture model. Its boundaries are exact:

  • PostgreSQL, OpenSearch, Langfuse and external model or simulator processes keep their protocol boundaries. CSF removes IPC between its own capabilities, not IPC with systems that genuinely live elsewhere.
  • LITHE's Brain–Spine shared-memory IPC remains a separate integration boundary.
  • CPU affinity and isolation are deployment configuration. CSF does not implement LITHE's loader, CPU isolation or real-time controller hot swap.

examples/csf-consumer shows the composition: CSF, its generated routes, its MCP server and the consumer's own endpoint in one router owned by the consumer's process.

3. Proofs, not just hardware: CSF and LITHE's safety problem

LITHE is explicit about where its guarantee stops. Its user-space real-time approach "provides a functional margin of safety, even if it lacks the formal mathematical guarantees of a verified real-time operating system" (LITHE §V-A). For model-written controllers, "it remains an area of active research to implement appropriate safety and verification bounds on the model's output" (LITHE §V-B); "theoretical stability guarantees remain an open challenge", so safety "must be enforced via strict hardware-level limits on torque and velocity" (LITHE §V-C).

A hardware limit is enforced per device. A proof about a language holds for every program written in it. CSF's direction is to narrow what a model may author to a typed, bounded language, and to prove what that language's compiled code computes. The model then chooses among checked options instead of emitting arbitrary code. That is how we think LITHE's idea scales past one robot on one bench.

What is proved today. csf/examples/proof/BrainSpine.lean models the arithmetic slice of brainspine.proto: a typed expression language with constants, four observation slots, addition, integer scaling and clamping over saturating integers, compiled to a postfix stack machine. Lean machine-checks four theorems:

Theorem Guarantee
compile_correct For every expression, inputs and existing stack, the compiled instructions push exactly the evaluated value and preserve the stack.
evaluate_bounds Every expression evaluates within the saturation bound [-1000000000, 1000000000].
compiled_actuator_correct Compiled code run from an empty stack, then through the actuator clamp, agrees exactly with the clamped source evaluator.
compiled_actuator_bounds Every compiled expression produces an actuator value in [-1000, 1000].

bash csf/examples/proof/check.sh downloads the pinned Lean release, verifies its SHA-256, runs Lean with --trust=0, and audits the axioms of all four theorems: only Lean's standard propext, Classical.choice and Quot.sound are admitted, and sorryAx or custom axioms fail the check. CI runs it in its own job.

What is not proved. Be precise about the gap:

  • Agreement between the Lean model and the canonical wire semantics is a reviewed translation boundary. CSF ships no controller implementation: the low-level spine is external and ROS-side, reached through ipc/ros.
  • The csfc compiler verifier is a stub: CSFC.Verification.verify returns notImplemented for every input and issues no certificate.
  • The actuator clamp proves a numeric range only. Timing, stability, collision avoidance, safe controller switching and physical safety are outside every theorem here. A hardware watchdog remains necessary.
  • The Lean kernel, its official release build, the standard library, the operating system and the hardware remain trusted.

The improvement loop below is generated from the same architecture model as every CSF diagram. Choose and controller selection are planned: the low-level controller is external and ROS-side, and an agent choosing among proved options is the next step, not a shipped one.

%% Generated from csf/compiler/language/architecture.csf; do not edit.
%% Documentation model only; status labels do not establish runtime verification.
flowchart LR
  classDef csf_existing fill:#0F766E,stroke:#115E59,stroke-width:2px,color:#FFFFFF;
  classDef csf_planned fill:#FEF3C7,stroke:#B45309,stroke-width:2px,color:#78350F;
  n_observe["Observe (existing)"]:::csf_existing
  n_retrieve["Retrieve (existing)"]:::csf_existing
  n_choose["Choose (planned)"]:::csf_planned
  n_check["Check (existing)"]:::csf_existing
  n_execute["Execute (existing)"]:::csf_existing
  n_evaluate["Evaluate (existing)"]:::csf_existing
  n_save_evidence["Save evidence (existing)"]:::csf_existing
  n_ouroboros["Ouroboros (planned)"]:::csf_planned
  n_select_controller["Select a controller between episodes (planned)"]:::csf_planned
  n_observe -.-> n_retrieve
  n_retrieve -.-> n_choose
  n_choose -.-> n_check
  n_check --> n_execute
  n_execute --> n_evaluate
  n_evaluate --> n_save_evidence
  n_evaluate -.-> n_select_controller
  n_select_controller -.->|"next agent iteration"| n_choose
  n_save_evidence -.-> n_ouroboros
  n_ouroboros -.->|"next iteration"| n_observe
  linkStyle 0 stroke:#B45309,stroke-width:2px,stroke-dasharray:5 5
  linkStyle 1 stroke:#B45309,stroke-width:2px,stroke-dasharray:5 5
  linkStyle 2 stroke:#B45309,stroke-width:2px,stroke-dasharray:5 5
  linkStyle 3 stroke:#0F766E,stroke-width:2px
  linkStyle 4 stroke:#0F766E,stroke-width:2px
  linkStyle 5 stroke:#0F766E,stroke-width:2px
  linkStyle 6 stroke:#B45309,stroke-width:2px,stroke-dasharray:5 5
  linkStyle 7 stroke:#B45309,stroke-width:2px,stroke-dasharray:5 5
  linkStyle 8 stroke:#B45309,stroke-width:2px,stroke-dasharray:5 5
  linkStyle 9 stroke:#B45309,stroke-width:2px,stroke-dasharray:5 5

4. Architecture

The diagram is generated from csf/compiler/language/architecture.csf by the CSF documentation compiler, which also produces the shared vocabulary and the plain-language glossary. Solid connections are existing components or configurable integrations; dotted connections are planned. An integration shown here still needs its dependencies and configuration; it is not automatically running when you import CSF.

%% Generated from csf/compiler/language/architecture.csf; do not edit.
%% Documentation model only; status labels do not establish runtime verification.
flowchart TB
  classDef csf_existing fill:#0F766E,stroke:#115E59,stroke-width:2px,color:#FFFFFF;
  classDef csf_planned fill:#FEF3C7,stroke:#B45309,stroke-width:2px,color:#78350F;
  n_human["Human or agent client (existing)"]:::csf_existing
  n_brain["Brain (existing)"]:::csf_existing
  n_contracts["Shared typed contracts (existing)"]:::csf_existing
  n_stores["Store (existing)"]:::csf_existing
  n_jobs["Job ledger (existing)"]:::csf_existing
  n_views["Prometheus#44; Grafana and Langfuse (existing)"]:::csf_existing
  n_experiments["Training results and optional MLflow (existing)"]:::csf_existing
  n_vendor["Copilot brain provider (existing)"]:::csf_existing
  n_spine["Low#45;level spine controller (planned)"]:::csf_planned
  n_hardware["Consumer sensors and actuators (planned)"]:::csf_planned
  subgraph g_host["CSF#58; one Go application process"]
    n_bench["Workbench (existing)"]:::csf_existing
    n_api["Generated HTTP#44; CLI and MCP operations (existing)"]:::csf_existing
    n_knowledge["Knowledge and retrieval (existing)"]:::csf_existing
    n_ros["ROS spine capability (existing)"]:::csf_existing
    n_workers["Configured worker goroutines (existing)"]:::csf_existing
    n_inspect["Inspection (existing)"]:::csf_existing
    n_widgets["Widget SDK and gotth#45;live (existing)"]:::csf_existing
  end
  style g_host fill:#EEF2FF,stroke:#4338CA,stroke-width:2px,color:#1E1B4B
  n_human --> n_bench
  n_brain --> n_api
  n_contracts --> n_api
  n_bench --> n_api
  n_bench --> n_vendor
  n_api --> n_knowledge
  n_api -->|"spine status"| n_ros
  n_api --> n_workers
  n_api --> n_inspect
  n_knowledge --> n_stores
  n_workers --> n_jobs
  n_jobs --> n_stores
  n_inspect --> n_views
  n_brain --> n_experiments
  n_widgets -->|"keyed Kanban cards"| n_bench
  n_ros -.->|"planned ROS transport"| n_spine
  n_spine -.-> n_hardware
  linkStyle 0 stroke:#0F766E,stroke-width:2px
  linkStyle 1 stroke:#0F766E,stroke-width:2px
  linkStyle 2 stroke:#0F766E,stroke-width:2px
  linkStyle 3 stroke:#0F766E,stroke-width:2px
  linkStyle 4 stroke:#0F766E,stroke-width:2px
  linkStyle 5 stroke:#0F766E,stroke-width:2px
  linkStyle 6 stroke:#0F766E,stroke-width:2px
  linkStyle 7 stroke:#0F766E,stroke-width:2px
  linkStyle 8 stroke:#0F766E,stroke-width:2px
  linkStyle 9 stroke:#0F766E,stroke-width:2px
  linkStyle 10 stroke:#0F766E,stroke-width:2px
  linkStyle 11 stroke:#0F766E,stroke-width:2px
  linkStyle 12 stroke:#0F766E,stroke-width:2px
  linkStyle 13 stroke:#0F766E,stroke-width:2px
  linkStyle 14 stroke:#0F766E,stroke-width:2px
  linkStyle 15 stroke:#B45309,stroke-width:2px,stroke-dasharray:5 5
  linkStyle 16 stroke:#B45309,stroke-width:2px,stroke-dasharray:5 5

Stores and data structures

CSF separates what data is from where it lives, following the ANSI/SPARC three-level architecture [2] and Codd's physical data independence [3]:

CSF ANSI/SPARC Meaning
data structure (pkg/graph, Cell, Map, Queue) conceptual level the data and its operations, with no placement, locks or I/O
store (pkg/store.Store[D]) internal level the physical placement of a data structure: memory (RAM), a file, or PostgreSQL; its crossing tier is derived from that backend
store places data_structure conceptual/internal mapping changing a store's backend never changes code written against the data structure (physical data independence)
view, dashboard external level (specializes) generated projections of typed records, not per-user schemas

Status: operator ruling recorded 2026-10-02; pkg/graph, pkg/store and the ontology terms are planned (source monorepo issue #366). The in-process Queue exists today in io/inproc.

Aspects: hooks on service actions

Anything that does something is a service, and cross-cutting behavior attaches to a service's actions the way aspect-oriented programming attaches advice to join points [4]:

CSF AOP Meaning
action join point a service operation (an RPC method); the only thing a hook attaches to
hook advice (before/after) pre or post code on one action, supplied as a generated functional option such as WithPreSubmit, typed by that action's request and response
pointcut pointcut a typed selector of actions
aspect aspect one cross-cutting concern: a pointcut plus its hooks, e.g. the session gate, telemetry, admission, the merge gate
weaving (specializes) weaving applying aspects when the host app composes its services; no source or bytecode rewriting

An action CSF does not execute itself, such as git commit, enters through an adapter service whose operation is the join point.

Status: operator ruling recorded 2026-10-02; the generated options and ontology terms are planned (source monorepo issue #374).

What is in here

.
├── csf/          typed coordination library, contracts, examples and consumer guide
├── pkg/          domain-neutral primitives — nothing in them knows about any service
├── services/     composable business logic — deploy, warden, the agent harness, cron, ops view and more
├── app/          runnable compositions — csf, harness, deploy, node executor, warden, intake
├── runtime/      the process runtime: the lifetimes every goroutine starts under
├── ipc/          boundary crossings, each a capability granted through a constructor
├── io/           the in-process io tier (io/inproc)
├── web/          the deploy service's and node executor's web layers
├── proto/        .proto sources and their committed Go bindings
├── infra/        deploy-kit/ (Compose stack, installer, fleet driver, updater) and local dev services
├── tools/        build wrapper, house gates, the CSF kit installer and the csf operator CLI
├── xetcas/       a Rust workspace (xetcasd) plus its generated Go bindings
├── examples/     one worked consumer per extension seam, each with its own suite
├── extensions/   copilot-pair, a GitHub Copilot CLI extension
├── docs/         extending.md (the four compile-time seams) and GLOSSARY.md (for humans)
└── bazel/        the legacy WORKSPACE shim

The three Go trees are separated by one rule, about who may import whom:

Imports Allowed direction
Runnable compositions (app/) Services, CSF and shared packages
Domain services and CSF Shared packages
Domain-neutral packages (pkg/) No import of services or application compositions

Nothing in pkg/ imports services/ or app/, which is what makes the primitives usable on their own:

Package What it is
gotth Server-driven live UI. Large enough to have its own documentation set. And it does.
pgmem A process-local PostgreSQL emulator for fast tests — real PostgreSQL AST, no server.
cron The schedule grammar: human-readable trigger declarations and their canonical five-field form. The scheduler that fires them is services/cron.
liquidproto The runtime for Liquid Proto: protobuf with refinement predicates compiled into the generated Go.
telemetry Trace propagation and structured JSONL over the candace.telemetry.v1 contracts, with no observability SDK.
config Configuration-boundary parsing: environment lookup, private-origin validation, provider/model strings.
mailbox Serializes ownership of a mutable value onto one goroutine — commands run in turn, so no field needs a lock.
boundedbuffer An io.Writer that retains at most a fixed number of bytes while still reporting the true write lengths.
redact Removes caller-declared sensitive values, and their URL-userinfo spellings, from log-bound text.
labels Canonicalizes case-insensitive label lists so services compare and deduplicate them one way.
core The zerolog logger the Go trees log through, plus the few formatters operator pages share.
eventually The one typed await for tests: poll a value, judge it with a predicate, get the value that satisfied it back.
widget The widget dialect and its toolchain: interpreter, validator, generator, and the typed SDK that mounts generated cards into a gotth-live host.

pkg/proto and pkg/scripts hold tooling rather than a package.

5. Quick start

To put CSF into a repository of yours, run csf init at its root. It writes a sample assignment under .csf/ and registers the repository with this machine's agent harness, starting it if none is running. Then:

csf submit -recipe .csf/assignments/sample/agent.json   # an agent session starts
csf events -assignment <id>                              # ends with a draft pull request
csf chat -assignment <id>                                # the session's chat address

csf comes from this repository, once per machine, with only Docker on the machine: tools/kit/install.sh from a clone. The CSF kit guide walks every step, its success check and how to undo it.

Use Go 1.26. The smallest CSF example needs no database, GPU, model account or extra process:

go run ./examples/csf-theme --listen 127.0.0.1:8089 --theme-dir ./examples/csf-theme

That mounts the generated HTTP API and MCP at http://127.0.0.1:8089/mcp. The caller owns the process; CSF only registers routes and hands back a handler. From examples/csf-consumer/main.go:

service, err := csf.New(options...)
if err != nil {
	return nil, fmt.Errorf("create CSF: %w", err)
}
router := httpserver.NewEngine(applicationName)
service.Register(router)
router.Any(mcpPath, gin.WrapH(service.MCPHandler()))
registerConsumerSummary(router, service)

Agent-native onboarding. The intended first instruction to your agent is “Learn about CSF.” The LearnAboutCSF MCP operation explains the pinned version's capabilities and extension points and, when knowledge is configured, submits the embedded guidance plus selected consumer files for indexing. Your own tools join the same MCP server with typed inputs and outputs; the pinned MCP SDK derives and validates their schemas, and CSF rejects name collisions with its own operations. The signature, from csf/service.go:

func WithMCPTool[In, Out any](tool mcp.Tool, handler mcp.ToolHandlerFor[In, Out]) Option

The host still owns listener startup, authentication, repository authorization and consumer checks. The CSF guide covers the Workbench, onboarding and every example with its boundary.

gotth-live, the web layer CSF's Workbench uses, runs with no npm or code generation:

go run ./examples/gotth/counter
counter: http://127.0.0.1:8080
counter: allowed origins [http://127.0.0.1:8080 http://localhost:8080]

Open that URL in two browser tabs. The number lives in the Go process and neither tab holds a copy of it: click in one and the other repaints, reload either and the count survives, and the client script that carried the patch was compiled into the binary and served by the same handler that serves the WebSocket. examples/gotth/counter/README.md follows one click all the way through and names the file each step lives in. The optional CSF Workbench has a separate browser-asset build documented in its README.

6. Consume it

This repository is generated

It is a one-way snapshot of the canonical repository at one exact revision, published with no upstream history. The canonical repository is private CSF staging since 2026-10-02; v0.1.3 and earlier were exported from a private monorepo's candace/ folder. Snapshot updates arrive as ready pull requests from the candace-export branch against main, and releases from candace-release. Make source changes in the canonical repository; editing the generated destination directly would conflict with its next snapshot.

After its review PR is merged, the publisher verifies that tree and creates immutable v<version> and export-<sha12> tags. The GitHub Release uses the semantic-version tag; .candace-export.json records the exact source revision. Cite a tag, not a branch.

Consume it in 60 seconds

Releases are published on candacelabs/csf; the current one is v0.2.3. For a private staging release, download the release assets with authenticated access and use the verified local-archive consumer. The Go module path is github.com/candacelabs/csf in both cases.

New releases carry csf-<sha12>.tar.gz and its .sha256; historical releases retain their original archive names. The tarball is this tree re-rooted so MODULE.bazel is at the archive root, plus a deterministic .candace-source.json recording the source revision and selected tree, built twice and byte-compared before it is kept.

Download both files from the same Release. In their directory, replace <sha12> with the 12-character revision from its tag and verify the hexadecimal checksum, then compute the base64 SRI value required by Bazel (Bash, sha256sum and OpenSSL):

set -euo pipefail
archive='csf-<sha12>.tar.gz'
sha256sum --check "$archive.sha256"
printf 'sha256-'
openssl dgst -sha256 -binary "$archive" | openssl base64 -A
printf '\n'

Copy the complete sha256-... output line into integrity in your own MODULE.bazel; the .sha256 file's hexadecimal value is not an SRI value. The archive's module() still declares version 0.1.0, so bazel_dep keeps that version while the URL names the release tag:

bazel_dep(name = "csf", version = "0.1.0")

archive_override(
    module_name = "csf",
    integrity = "sha256-...",          # base64 SRI output from the command above
    strip_prefix = "csf-<sha12>",
    urls = ["https://github.com/candacelabs/csf/releases/download/v0.2.3/csf-<sha12>.tar.gz"],
)

Then depend on what you use — @csf//services/deploy/component, @csf//pkg/gotth/live, @csf//services/warden — and build. Since v0.2.0 the deploy service sits at services/deploy/ and its kit at infra/deploy-kit/; v0.1.3 and earlier used services/candaceos/ and candaceos/.

Not a Bazel repository? The module path is the repository path:

go get github.com/candacelabs/csf@v0.2.3

Use the published semantic version matching your archive, not @latest. The accompanying export-<sha12> tag identifies its exact source snapshot.

docs/extending.md covers both shapes in full, plus the http_archive fallback and the legacy WORKSPACE path.

7. Examples

Every extension seam has a worked example with its own test suite. They are the contract's executable half — the documentation says what is guaranteed, and these fail if it stops being true.

Example Shows
csf-consumer CSF mounted beside a consumer's own Go endpoint in one process, its generated client, MCP tool discovery and shutdown. Its archive acceptance script builds a fresh repository with networking disabled.
external-consumer A complete outside repository choosing every seam at once: its own identity and overlay, its own sidebar entry and page, three composed services, a custom agent harness, and the deploy service binary linked from them — built and tested both supported Bazel ways. This is also the acceptance test every release archive passes.
custom-brand The deploy service wearing another product's identity — name, agent, wordmark, palette, an overlay asset, an extra sidebar entry and page — with no edit to the deploy service.
custom-ui-page The smallest useful UI extension: stock identity, one sidebar entry, one page of your own.
gotth/counter gotth-live at its smallest: a number that lives in Go, four buttons, and every open tab kept in step by the server.
gotth/chat One room in Go, several browsers, and every message reaching every session over a server push.
gotth/dashboard A feed pushing twenty times a second, three live regions patched independently, and two plain-HTMX regions on the same page.

8. Build it

Bazel is the primary build and comes from a pinned container, so the command is the same on a laptop and on a runner. Docker is the only prerequisite:

tools/bazel.sh build -- //... -//xetcas/...   # everything but the Rust workspace
tools/bazel.sh test  -- //... -//xetcas/...
tools/bazel.sh build //xetcas/...             # the Rust workspace and its Go bindings
tools/bazel.sh test  //xetcas/...

The plain go command works on the same tree and needs no Bazel:

go build ./...
go test ./...

The Rust workspace builds with plain Cargo too — that is the path its demo, container images, and just targets take:

cd xetcas && cargo build --workspace && cargo test --workspace

.bazelversion (Bazel 9.2.0) and MODULE.bazel (rules_go 0.62.0, Gazelle 0.52.2, Go SDK 1.26.5, rules_rust 0.73.0) are the only version authority. BUILD files are generated by Gazelle (tools/bazel.sh run //:gazelle) and CI fails on drift.

Run the deploy stack

The deployment kit installs and runs the whole one-box stack (deploy service, node executor and operator UI) from this clone. The default install is deliberately harmless: a simulated harness, a dry-run executor, and no Docker socket bind-mounted anywhere.

./infra/deploy-kit/install.sh          # then open http://<host>:7780
./infra/deploy-kit/status.sh
./infra/deploy-kit/uninstall.sh

The deploy service publishes on all host IPv4 interfaces with no built-in authentication: put it behind your own authenticating proxy before exposing it beyond a trusted network. infra/deploy-kit/README.md is the operations manual, and infra/deploy-kit/AGENTS.md states the trust model as eight invariants with their enforcement points.

9. Where to go next

  • csf/README.md — the CSF guide: Workbench, onboarding, examples and release evidence.
  • AGENTS.md — the repository's own guide: taxonomy, seams, invariants, conventions.
  • docs/extending.md — the four compile-time seams and how to pin a snapshot.
  • docs/GLOSSARY.md — every CSF term and borrowed literature term in plain language, for human readers.
  • pkg/gotth/README.md, xetcas/README.md — each subsystem's own front page.
  • app/*/CLAUDE.md — what may not be changed casually in each binary.

10. Citation

[1] He Kai Lim and Tyler R. Clites. LITHE: Bridging Best-Effort Python and Real-Time C++ for Hot-Swapping Robotic Control Laws on Commodity Linux. arXiv:2603.07442 [cs.RO], 2026. Submitted to IROS 2026. https://doi.org/10.48550/arXiv.2603.07442

@misc{lim2026lithe,
  title         = {{LITHE}: Bridging Best-Effort {Python} and Real-Time {C++} for Hot-Swapping Robotic Control Laws on Commodity {Linux}},
  author        = {Lim, He Kai and Clites, Tyler R.},
  year          = {2026},
  eprint        = {2603.07442},
  archivePrefix = {arXiv},
  primaryClass  = {cs.RO},
  doi           = {10.48550/arXiv.2603.07442},
  url           = {https://arxiv.org/abs/2603.07442},
  note          = {Submitted to IROS 2026}
}

CSF's architecture is inspired by LITHE [1]. To cite CSF itself, name the exact release tag you used:

@software{csf2026,
  title   = {CSF — The Cerebrospinal Fluid},
  author  = {{Candace Labs}},
  version = {0.2.3},
  year    = {2026},
  url     = {https://github.com/candacelabs/csf}
}

The LITHE paper and its figures are distributed under arXiv's non-exclusive distribution license, not a Creative Commons license. © the authors; this repository's license does not cover them, and no figure file is copied into it.

[2] D. Tsichritzis and A. Klug. The ANSI/X3/SPARC DBMS framework report of the study group on database management systems. Information Systems 3(3):173–191, 1978. https://doi.org/10.1016/0306-4379(78)90001-7

[3] E. F. Codd. A relational model of data for large shared data banks. Communications of the ACM 13(6):377–387, 1970. https://doi.org/10.1145/362384.362685

[4] G. Kiczales, J. Lamping, A. Mendhekar, C. Maeda, C. Lopes, J.-M. Loingtier and J. Irwin. Aspect-oriented programming. ECOOP '97, LNCS 1241, pp. 220–242, 1997. https://doi.org/10.1007/BFb0053381

[5] D. Ongaro and J. Ousterhout. In search of an understandable consensus algorithm. 2014 USENIX Annual Technical Conference (USENIX ATC 14), pp. 305–319, 2014. https://www.usenix.org/conference/atc14/technical-sessions/presentation/ongaro

[6] Hugging Face. xet-core: the Xet storage protocol, client and content-addressed chunk format. https://github.com/huggingface/xet-core

[7] Git LFS contributors. Git Large File Storage. https://git-lfs.com/

[8] M. Stonebraker and L. A. Rowe. The design of POSTGRES. Proceedings of the 1986 ACM SIGMOD International Conference on Management of Data, pp. 340–355, 1986. https://doi.org/10.1145/16894.16888

[9] T. Freeman and F. Pfenning. Refinement types for ML. Proceedings of the ACM SIGPLAN 1991 Conference on Programming Language Design and Implementation (PLDI), pp. 268–277, 1991. https://doi.org/10.1145/113445.113468

[10] N. Fulton, S. Mitsch, J.-D. Quesel, M. Völp and A. Platzer. KeYmaera X: an axiomatic tactical theorem prover for hybrid systems. CADE-25, LNCS 9195, pp. 527–538, 2015. https://doi.org/10.1007/978-3-319-21401-6_36

[11] R. Bohrer, Y. K. Tan, S. Mitsch, M. O. Myreen and A. Platzer. VeriPhy: verified controller executables from verified cyber-physical system models. PLDI 2018, pp. 617–630, 2018. https://doi.org/10.1145/3192366.3192406

[12] X. Leroy. Formal verification of a realistic compiler. Communications of the ACM 52(7):107–115, 2009. https://doi.org/10.1145/1538788.1538814

[13] G. Klein, K. Elphinstone, G. Heiser, J. Andronick, D. Cock, P. Derrin, D. Elkaduwe, K. Engelhardt, R. Kolanski, M. Norrish, T. Sewell, H. Tuch and S. Winwood. seL4: formal verification of an OS kernel. SOSP 2009, pp. 207–220, 2009. https://doi.org/10.1145/1629575.1629596

The north star's "Builds on" column links KeYmaera X [10], VeriPhy [11], CompCert [12] and seL4 [13].

License

Apache License 2.0. See LICENSE.

AI systems assisted with work in this repository. Their output is not presumed correct, secure, reviewed, or production-ready.

Directories

Path Synopsis
app
csf/cmd command
The JSONL adapter is a disposable simulator boundary.
The JSONL adapter is a disposable simulator boundary.
deploy/bootstrap
Package bootstrap assembles and runs Deploy.
Package bootstrap assembles and runs Deploy.
deploy/cmd command
Command deploy is the single-operator deploy control plane.
Command deploy is the single-operator deploy control plane.
harness/cmd command
Command csf is the agent harness: one process per machine that runs every agent session, and the thin client that talks to it.
Command csf is the agent harness: one process per machine that runs every agent session, and the thin client that talks to it.
intake/cmd command
Command intake polls GitHub for actionable events on the configured pull requests and issues and delivers each to its owning agent through an in-process relay.
Command intake polls GitHub for actionable events on the configured pull requests and issues and delivers each to its owning agent through an in-process relay.
nodeexec/cmd command
Command nodeexec is the node-local Deploy Compose executor.
Command nodeexec is the node-local Deploy Compose executor.
nodeexec/internal/config
Package config loads and validates nodeexec process configuration.
Package config loads and validates nodeexec process configuration.
warden/cmd command
Command warden is the candacenet fleet watchdog daemon.
Command warden is the candacenet fleet watchdog daemon.
csf
Code generated by Candacegen (csf/compiler/api_codegen).
Code generated by Candacegen (csf/compiler/api_codegen).
internal/mocks
Package csfmocks is a generated GoMock package.
Package csfmocks is a generated GoMock package.
examples
claudecode command
Command claudecode runs one real turn through the Claude Code turn executor (ipc/model/claudecode) and prints the turn report: every event in and out, as one JSON log record per line, each carrying the turn trace, its own span, the session, the turn number, the event type and the elapsed time.
Command claudecode runs one real turn through the Claude Code turn executor (ipc/model/claudecode) and prints the turn report: every event in and out, as one JSON log record per line, each carrying the turn trace, its own span, the session, the turn number, the event type and the elapsed time.
csf-agent command
csf-consumer command
This consumer owns the process, listener and custom routes.
This consumer owns the process, listener and custom routes.
csf-theme command
csfpg-consumer
Package csfpgconsumer is a copyable example of an application's own migrations stacked on CSF's schema in one PostgreSQL database.
Package csfpgconsumer is a copyable example of an application's own migrations stacked on CSF's schema in one PostgreSQL database.
custom-brand command
Command custom-brand is deploy wearing another product's identity.
Command custom-brand is deploy wearing another product's identity.
custom-ui-page command
Command custom-ui-page is stock deploy with one page added.
Command custom-ui-page is stock deploy with one page added.
external-consumer/_workspace/cmd command
Command custom-deploy is this repository's own Core binary.
Command custom-deploy is this repository's own Core binary.
external-consumer/_workspace/composition
Package composition is this repository's composition root: the exact set of values handed to bootstrap.Run, assembled in one place so the binary and its suite cannot describe different products.
Package composition is this repository's composition root: the exact set of values handed to bootstrap.Run, assembled in one place so the binary and its suite cannot describe different products.
external-consumer/_workspace/customharness
Package customharness is a complete harness implementation compiled outside the deploy source tree.
Package customharness is a complete harness implementation compiled outside the deploy source tree.
external-consumer/_workspace/identity
Package identity is this repository's own product identity: the two brand-bearing names, the lockup rendered in the shell, the design tokens the operator stylesheet reads, and the one shipped template block its overlay redefines.
Package identity is this repository's own product identity: the two brand-bearing names, the lockup rendered in the shell, the design tokens the operator stylesheet reads, and the one shipped template block its overlay redefines.
external-consumer/_workspace/noteboard
Package noteboard is this repository's own service.
Package noteboard is this repository's own service.
external-consumer/_workspace/steering
Package steering composes an agent-steering service alongside deploy Core.
Package steering composes an agent-steering service alongside deploy Core.
gotth/chat command
Command chat is gotth-live's multi-user example: one room in Go, several browsers, and every message reaching every session over a server push.
Command chat is gotth-live's multi-user example: one room in Go, several browsers, and every message reaching every session over a server push.
gotth/counter command
Command counter is gotth-live's smallest end-to-end application: a number that lives in Go, four buttons that change it, and every open tab kept in step by the server.
Command counter is gotth-live's smallest end-to-end application: a number that lives in Go, four buttons that change it, and every open tab kept in step by the server.
gotth/dashboard command
Command dashboard is gotth-live's resilience example: a simulated metrics feed pushing from the server twenty times a second, three live regions that are patched independently, and two plain-HTMX regions on the same page.
Command dashboard is gotth-live's resilience example: a simulated metrics feed pushing from the server twenty times a second, three live regions that are patched independently, and two plain-HTMX regions on the same page.
widget command
Command widget is the widget SDK's smallest end-to-end host: two generated widgets, one registry, one page, one binary — and, behind one of them, a real consensus protocol.
Command widget is the widget SDK's smallest end-to-end host: two generated widgets, one registry, one page, one binary — and, behind one of them, a real consensus protocol.
widget/candaws command
Command candaws is the CandaWS fleet: five parody cloud services, five engines, five generated widgets, and one binary.
Command candaws is the CandaWS fleet: five parody cloud services, five engines, five generated widgets, and one binary.
widget/candaws/blobfish
Package blobfish is the generated Blobfish widget.
Package blobfish is the generated Blobfish widget.
widget/candaws/coldstart
Package coldstart is the generated Coldstart widget.
Package coldstart is the generated Coldstart widget.
widget/candaws/dashbored
Package dashbored is the generated Dashbored widget.
Package dashbored is the generated Dashbored widget.
widget/candaws/fleet
Package fleet is the part of every CandaWS engine that is the same part.
Package fleet is the part of every CandaWS engine that is the same part.
widget/candaws/queuecumber
Package queuecumber is the generated Queuecumber widget.
Package queuecumber is the generated Queuecumber widget.
widget/candaws/yakshave
Package yakshave is the generated Yakshave widget.
Package yakshave is the generated Yakshave widget.
widget/clusterheartbeats
Package clusterheartbeats is the generated ClusterHeartbeats widget.
Package clusterheartbeats is the generated ClusterHeartbeats widget.
widget/hosting
Package hosting is what both widget demo hosts do the same way.
Package hosting is what both widget demo hosts do the same way.
widget/nodestatus
Package nodestatus is the generated NodeStatus widget.
Package nodestatus is the generated NodeStatus widget.
widget/raftdemo
Package raftdemo runs a real leader election in one process, so that the raft widget beside it animates a protocol rather than a script.
Package raftdemo runs a real leader election in one process, so that the raft widget beside it animates a protocol rather than a script.
widget/relaypipeline
Package relaypipeline is the generated RelayPipeline widget.
Package relaypipeline is the generated RelayPipeline widget.
io
inproc
Package inproc is the home of the in-process io tier: communication between goroutines of one process.
Package inproc is the home of the in-process io tier: communication between goroutines of one process.
ipc
Package ipc is the umbrella for every boundary crossing a CSF process makes.
Package ipc is the umbrella for every boundary crossing a CSF process makes.
clock
Package clock is the clock capability: the kernel I/O tier's time source.
Package clock is the clock capability: the kernel I/O tier's time source.
clock/mocks
Package mocks is a generated GoMock package.
Package mocks is a generated GoMock package.
db/csfpg
Package csfpg is CSF's PostgreSQL backend: the one owner of database connection pools in a CSF process, CSF's schema and its migrations, and the queries sqlc generates against that schema.
Package csfpg is CSF's PostgreSQL backend: the one owner of database connection pools in a CSF process, CSF's schema and its migrations, and the queries sqlc generates against that schema.
db/csfpg/mocks
Package mocks is a generated GoMock package.
Package mocks is a generated GoMock package.
docker
Package docker is the container capability: the Docker Engine reached over its API socket, granted to the code that runs containers.
Package docker is the container capability: the Docker Engine reached over its API socket, granted to the code that runs containers.
fs
Package fs is the file capability: the kernel I/O tier's file boundary.
Package fs is the file capability: the kernel I/O tier's file boundary.
model
Package model is CSF's contract with a brain: an agent loop over a large model behind an inference provider or API.
Package model is CSF's contract with a brain: an agent loop over a large model behind an inference provider or API.
model/claudecode
Package claudecode is the Claude Code provider: a Claude Code session is an agent loop in its own process on the operator's machine.
Package claudecode is the Claude Code provider: a Claude Code session is an agent loop in its own process on the operator's machine.
model/copilot
Package copilot is the first inference provider behind CSF's brain contract: the GitHub Copilot agent loop, reached through the existing Copilot adapter's generated Workbench client (services/copilot-adapter/gen/api).
Package copilot is the first inference provider behind CSF's brain contract: the GitHub Copilot agent loop, reached through the existing Copilot adapter's generated Workbench client (services/copilot-adapter/gen/api).
model/stub
Package stub is the brain that needs no model: it answers every decision with the same canned proposal, so the harness runs and its specs pass with no inference provider, network or credential at all.
Package stub is the brain that needs no model: it answers every decision with the same canned proposal, so the harness runs and its specs pass with no inference provider, network or credential at all.
net
Package net is the socket capability: the kernel I/O tier's network boundary.
Package net is the socket capability: the kernel I/O tier's network boundary.
net/grpc
Package grpc is the gRPC client-connection capability.
Package grpc is the gRPC client-connection capability.
net/http
Package http is the HTTP capability: one server bound to one address, mounted into the process runtime as a service, and the outbound client (NewHTTPClient) whose every connection is dialed through a granted socket capability.
Package http is the HTTP capability: one server bound to one address, mounted into the process runtime as a service, and the outbound client (NewHTTPClient) whose every connection is dialed through a granted socket capability.
proc
Package proc is the process boundary: the one subprocess gateway in CSF.
Package proc is the process boundary: the one subprocess gateway in CSF.
ros
Package ros is CSF's boundary to the low-level spine controller.
Package ros is CSF's boundary to the low-level spine controller.
pkg
argv
Package argv reads another program's argument vector without knowing that program's option table: whether a POSIX short flag or a GNU long option is present, the way getopt and getopt_long would see it.
Package argv reads another program's argument vector without knowing that program's option table: whether a POSIX short flag or a GNU long option is present, the way getopt and getopt_long would see it.
boundedbuffer
Package boundedbuffer provides an io.Writer that retains at most a fixed number of bytes while reporting the original write lengths to its producer.
Package boundedbuffer provides an io.Writer that retains at most a fixed number of bytes while reporting the original write lengths to its producer.
config
Package config provides small, domain-neutral parsers and validators for configuration values.
Package config provides small, domain-neutral parsers and validators for configuration values.
cron
Package cron is the schedule grammar: human-readable trigger declarations, their canonical five-field form, and the pure value model of triggers and occurrences that the scheduler, its store and the Liquid Proto contract share.
Package cron is the schedule grammar: human-readable trigger declarations, their canonical five-field form, and the pure value model of triggers and occurrences that the scheduler, its store and the Liquid Proto contract share.
cron/contract
Package contract maps the cron domain model to validated Liquid Proto messages at HTTP and messaging boundaries.
Package contract maps the cron domain model to validated Liquid Proto messages at HTTP and messaging boundaries.
eventually
Package eventually is the one way a test in this repository waits for something to become true.
Package eventually is the one way a test in this repository waits for something to become true.
gotth/bench/apps/chat/gotth command
The gotth-live side of equivalence-spec §2.3's chat room.
The gotth-live side of equivalence-spec §2.3's chat room.
gotth/bench/apps/counter/gotth command
The gotth-live side of equivalence-spec §2.1's counter — app C-B, and only C-B.
The gotth-live side of equivalence-spec §2.1's counter — app C-B, and only C-B.
gotth/bench/apps/dashboard/gotth command
The gotth-live side of equivalence-spec §2.4's live dashboard.
The gotth-live side of equivalence-spec §2.4's live dashboard.
gotth/docs/guide/_samples
Package samples is the compiled twin of the gotth-live documentation.
Package samples is the compiled twin of the gotth-live documentation.
gotth/docs/guide/_samples/apptest
Package apptest is the compiled source for docs/guide/testing-your-app.md: a small application, and the specs that hold it to the library's contracts.
Package apptest is the compiled source for docs/guide/testing-your-app.md: a small application, and the specs that hold it to the library's contracts.
gotth/docs/guide/_samples/architecture
Package architecture is the compiled source for docs/guide/architecture.md.
Package architecture is the compiled source for docs/guide/architecture.md.
gotth/docs/guide/_samples/deploying
Package deploying is the compiled source for docs/guide/deploying.md.
Package deploying is the compiled source for docs/guide/deploying.md.
gotth/docs/guide/_samples/effects
Package effects is the compiled source for docs/guide/effects-and-server-push.md.
Package effects is the compiled source for docs/guide/effects-and-server-push.md.
gotth/docs/guide/_samples/errorhandling
Package errorhandling is the compiled source for docs/guide/error-handling.md.
Package errorhandling is the compiled source for docs/guide/error-handling.md.
gotth/docs/guide/_samples/events
Package events is the compiled source for docs/guide/events-and-forms.md.
Package events is the compiled source for docs/guide/events-and-forms.md.
gotth/docs/guide/_samples/fragments
Package fragments is the compiled source for docs/guide/fragments-and-dirty-tracking.md.
Package fragments is the compiled source for docs/guide/fragments-and-dirty-tracking.md.
gotth/docs/guide/_samples/htmxinterop
Package htmxinterop is the compiled source for docs/guide/htmx-interop.md.
Package htmxinterop is the compiled source for docs/guide/htmx-interop.md.
gotth/docs/guide/_samples/keychords
Package keychords is the compiled source for the two modifier-aware options on docs/guide/events-and-forms.md: live.Bind.NoModifiers and live.Bind.PreventDefault.
Package keychords is the compiled source for the two modifier-aware options on docs/guide/events-and-forms.md: live.Bind.NoModifiers and live.Bind.PreventDefault.
gotth/docs/guide/_samples/lifecycle
Package lifecycle is the compiled source for docs/guide/lifecycle-hooks.md.
Package lifecycle is the compiled source for docs/guide/lifecycle-hooks.md.
gotth/docs/guide/_samples/mounting
Package mounting is the compiled source for the two things docs/quickstart.md §2 explains beside its router: where the live handler is mounted, and where the first paint's state comes from.
Package mounting is the compiled source for the two things docs/quickstart.md §2 explains beside its router: where the live handler is mounted, and where the first paint's state comes from.
gotth/docs/guide/_samples/observability
Package observability is the compiled source for docs/guide/observability.md.
Package observability is the compiled source for docs/guide/observability.md.
gotth/docs/guide/_samples/payments
Package payments is the compiled source for the idempotency section of docs/guide/effects-and-server-push.md.
Package payments is the compiled source for the idempotency section of docs/guide/effects-and-server-push.md.
gotth/docs/guide/_samples/quickstart command
Command quickstart is the application docs/quickstart.md builds: a number that lives in Go, and a button that changes it.
Command quickstart is the application docs/quickstart.md builds: a number that lives in Go, and a button that changes it.
gotth/docs/guide/_samples/security
Package security is the compiled source for docs/guide/security.md.
Package security is the compiled source for docs/guide/security.md.
gotth/internal/arch
Package arch holds this module's architecture tests.
Package arch holds this module's architecture tests.
gotth/internal/clientcodec
Package clientcodec generates the browser runtime's protobuf codec, its predicate manifest, and the cross-runtime golden vectors, from the same FileDescriptorSet that drives the Go refinement generator.
Package clientcodec generates the browser runtime's protobuf codec, its predicate manifest, and the cross-runtime golden vectors, from the same FileDescriptorSet that drives the Go refinement generator.
gotth/internal/cmd/gen-clientcodec command
Command gen-clientcodec generates the browser runtime's protobuf codec.
Command gen-clientcodec generates the browser runtime's protobuf codec.
gotth/internal/cmd/gotth-live-dev command
Command gotth-live-dev is the server half of FR-57: it watches a gotth-live application's source, rebuilds it when a Go or templ file changes, and restarts it.
Command gotth-live-dev is the server half of FR-57: it watches a gotth-live application's source, rebuilds it when a Go or templ file changes, and restarts it.
gotth/internal/livebridge
Package livebridge lets live/livetest construct a value only live can build.
Package livebridge lets live/livetest construct a value only live can build.
gotth/internal/obs
Package obs is the library's instrumentation: metrics, traces and the provenance log.
Package obs is the library's instrumentation: metrics, traces and the provenance log.
gotth/internal/obstest
Package obstest records what the library actually emits, so that a spec can assert on a signal rather than on a method having been called.
Package obstest records what the library actually emits, so that a spec can assert on a signal rather than on a method having been called.
gotth/internal/protocol
Package protocol is the boundary every byte crosses in either direction.
Package protocol is the boundary every byte crosses in either direction.
gotth/internal/render
Package render turns state into whole HTML fragments.
Package render turns state into whole HTML fragments.
gotth/internal/session
Package session implements the service that maintains one WebSocket connection's widget state.
Package session implements the service that maintains one WebSocket connection's widget state.
gotth/internal/wsx
Package wsx is the WebSocket transport, and the only place it exists.
Package wsx is the WebSocket transport, and the only place it exists.
gotth/live
Package live serves server-driven live user interfaces from Go.
Package live serves server-driven live user interfaces from Go.
gotth/live/livetest
Package livetest provides testing helpers for live applications.
Package livetest provides testing helpers for live applications.
gotth/test/internal/chaos/cmd/chaossrv command
Command chaossrv is a live server in its own process, for the one chaos case that cannot be expressed inside the test binary.
Command chaossrv is a live server in its own process, for the one chaos case that cannot be expressed inside the test binary.
gotth/test/memory
Package memory is the G2 idle-connection memory harness: the arithmetic half of equivalence-spec §3.6, with the three commands beside it supplying the server under test, the synthetic session driver, and the report.
Package memory is the G2 idle-connection memory harness: the arithmetic half of equivalence-spec §3.6, with the three commands beside it supplying the server under test, the synthetic session driver, and the report.
gotth/test/memory/cmd/memdiag command
Command memdiag reports the G2 remediation diagnostic that diag.sh collects.
Command memdiag reports the G2 remediation diagnostic that diag.sh collects.
gotth/test/memory/cmd/memdrv command
Command memdrv is equivalence-spec §3.6's synthetic session driver for gotth-live: it opens N real sessions against a memsrv, holds them IDLE, and keeps them alive for as long as the harness needs them.
Command memdrv is equivalence-spec §3.6's synthetic session driver for gotth-live: it opens N real sessions against a memsrv, holds them IDLE, and keeps them alive for as long as the harness needs them.
gotth/test/memory/cmd/memsrv command
Command memsrv is the server under test for the G2 idle-connection memory baseline (RFC-0001 §6.1/§6.2, equivalence-spec §3.6).
Command memsrv is the server under test for the G2 idle-connection memory baseline (RFC-0001 §6.1/§6.2, equivalence-spec §3.6).
gotth/test/memory/cmd/memstat command
Command memstat turns the sample files measure.sh collects into the figure equivalence-spec §3.6 defines, and refuses to produce one from a window that is not §3.6's window.
Command memstat turns the sample files measure.sh collects into the figure equivalence-spec §3.6 defines, and refuses to produce one from a window that is not §3.6's window.
gotth/test/routers
Package routers holds the FR-33 three-router mount suite and nothing else.
Package routers holds the FR-33 three-router mount suite and nothing else.
gotth/test/sampling
Package sampling holds FR-36 clause 4's falsifier and nothing else.
Package sampling holds FR-36 clause 4's falsifier and nothing else.
gotth/tools/apisurface command
Command apisurface counts the library's exported surface and holds it against the ledger.
Command apisurface counts the library's exported surface and holds it against the ledger.
gotth/tools/doccheck command
Command doccheck holds every exported symbol in the tree to a doc comment, and every godoc example to an output the test runner actually checks.
Command doccheck holds every exported symbol in the tree to a doc comment, and every godoc example to an output the test runner actually checks.
gotth/tools/minify command
Command minify builds the files the library serves, and measures them.
Command minify builds the files the library serves, and measures them.
httpserver
Package httpserver provides the shared Gin HTTP surface used by Candace services.
Package httpserver provides the shared Gin HTTP surface used by Candace services.
labels
Package labels canonicalizes case-insensitive label lists, such as CI runner labels, so services compare, deduplicate, and match them with one set of semantics.
Package labels canonicalizes case-insensitive label lists, such as CI runner labels, so services compare, deduplicate, and match them with one set of semantics.
liquidproto
Package liquidproto provides the small runtime used by Liquid Proto generated code and deterministic, validating protobuf serialization.
Package liquidproto provides the small runtime used by Liquid Proto generated code and deterministic, validating protobuf serialization.
liquidproto/cmd/protoc-gen-liquidproto command
protoc-gen-liquidproto compiles Liquid Proto field refinements into native Go validation boundaries.
protoc-gen-liquidproto compiles Liquid Proto field refinements into native Go validation boundaries.
liquidproto/cmd/protoc-gen-liquidproto/internal/expr
Package expr compiles the small Liquid Proto predicate grammar to Go.
Package expr compiles the small Liquid Proto predicate grammar to Go.
liquidproto/cmd/protoc-gen-liquidproto/internal/gen
Package gen turns Liquid Proto field refinements into Go validators.
Package gen turns Liquid Proto field refinements into Go validators.
listsched
Package listsched is list scheduling (Graham, 1969): whenever a machine is free, start the highest-priority ready task that may run beside what is running.
Package listsched is list scheduling (Graham, 1969): whenever a machine is free, start the highest-priority ready task that may run beside what is running.
mailbox
Package mailbox serializes ownership of a mutable value onto one goroutine.
Package mailbox serializes ownership of a mutable value onto one goroutine.
pgmem
Package pgmem provides a fast, process-local PostgreSQL emulator for Go tests.
Package pgmem provides a fast, process-local PostgreSQL emulator for Go tests.
privatefile
Package privatefile reads bounded, owner-only configuration and secret files.
Package privatefile reads bounded, owner-only configuration and secret files.
redact
Package redact removes caller-declared sensitive values from text destined for logs or operator diagnostics.
Package redact removes caller-declared sensitive values from text destined for logs or operator diagnostics.
sqlmigrate
Package sqlmigrate applies a service's embedded migration files to a database/sql handle, so a service's store directory holds its .sql files and nothing else: the files are the only schema source, and this is the one runner that reads them.
Package sqlmigrate applies a service's embedded migration files to a database/sql handle, so a service's store directory holds its .sql files and nothing else: the files are the only schema source, and this is the one runner that reads them.
telemetry
Package telemetry provides dependency-light distributed trace propagation and structured JSONL logging over the candace.telemetry.v1 protobuf contracts.
Package telemetry provides dependency-light distributed trace propagation and structured JSONL logging over the candace.telemetry.v1 protobuf contracts.
widget
Package widget is the widget SDK: the contract a widget implements, the registry a host binary mounts them through, and the interpreter for the small Mermaid dialect widgets are declared in.
Package widget is the widget SDK: the contract a widget implements, the registry a host binary mounts them through, and the interpreter for the small Mermaid dialect widgets are declared in.
widget/internal/cmd/widgetc command
Command widgetc validates widget documents and prints their findings.
Command widgetc validates widget documents and prints their findings.
widget/internal/diag
Package diag carries the widget validator's location-anchored findings and the identifiers of the error catalogue every finding belongs to.
Package diag carries the widget validator's location-anchored findings and the identifiers of the error catalogue every finding belongs to.
widget/internal/ir
Package ir holds the widget interpreter's typed intermediate representation: one resolved, ordered, total record per document.
Package ir holds the widget interpreter's typed intermediate representation: one resolved, ordered, total record per document.
widget/internal/lex
Package lex turns widget source into positioned tokens, one slice per significant line.
Package lex turns widget source into positioned tokens, one slice per significant line.
widget/internal/mocks
Package mocks is a generated GoMock package.
Package mocks is a generated GoMock package.
widget/internal/parse
Package parse turns positioned tokens into a widget document's block structure, and reports every structural finding of the catalogue's W0 group.
Package parse turns positioned tokens into a widget document's block structure, and reports every structural finding of the catalogue's W0 group.
widget/internal/uigen
Package uigen turns one resolved widget document into the files that make it a running widget: a templ view and a Go scaffold implementing the SDK's widget contract.
Package uigen turns one resolved widget document into the files that make it a running widget: a templ view and a Go scaffold implementing the SDK's widget contract.
widget/internal/validate
Package validate resolves a parsed widget document into the typed IR and reports every finding of the error catalogue.
Package validate resolves a parsed widget document into the typed IR and reports every finding of the error catalogue.
widget/widgettest
Package widgettest renders a registered widget's own live region, so a specification can assert on what a viewer receives rather than on how the markup was produced.
Package widgettest renders a registered widget's own live region, so a specification can assert on what a viewer receives rather than on how the markup was produced.
proto
candace/deploy/v1
Package deployv1 contains the stable protobuf contracts used to configure Deploy and to fence and reconcile desired-state assignments on node-local agents.
Package deployv1 contains the stable protobuf contracts used to configure Deploy and to fence and reconcile desired-state assignments on node-local agents.
candace/telemetry/v1
Package telemetryv1 contains the stable protobuf contracts for distributed trace propagation and structured JSONL logging.
Package telemetryv1 contains the stable protobuf contracts for distributed trace propagation and structured JSONL logging.
Package runtime is the process runtime: it owns the lifetimes every goroutine in a CSF process starts under.
Package runtime is the process runtime: it owns the lifetimes every goroutine in a CSF process starts under.
config
Package config is the config capability: the one place in a CSF process that reads the process environment.
Package config is the config capability: the one place in a CSF process that reads the process environment.
services
copilot-adapter
Package copilotadapter is the HTTP adapter that fronts a Copilot CLI session with the contract in openapi.yaml.
Package copilotadapter is the HTTP adapter that fronts a Copilot CLI session with the contract in openapi.yaml.
copilot-adapter/adaptertest
Package adaptertest is a generated GoMock package.
Package adaptertest is a generated GoMock package.
copilot-adapter/copilotbridge
Package copilotbridge is the concrete ICopilotBridge over the Copilot Go SDK.
Package copilotbridge is the concrete ICopilotBridge over the Copilot Go SDK.
copilot-adapter/gen/api
Package api provides primitives to interact with the openapi HTTP API.
Package api provides primitives to interact with the openapi HTTP API.
copilot-adapter/kanban
Package kanban mounts shared task planning into an existing HTTP server.
Package kanban mounts shared task planning into an existing HTTP server.
copilot-adapter/kanban/card
Package card is the generated KanbanCard widget.
Package card is the generated KanbanCard widget.
copilot-adapter/store
Package store carries the adapter's schema.
Package store carries the adapter's schema.
copilot-adapter/terminaladapter
Package terminaladapter owns interactive PTYs for the Copilot workbench.
Package terminaladapter owns interactive PTYs for the Copilot workbench.
copilot-adapter/workbench
Package workbench composes the existing Copilot service for caller-owned hosts.
Package workbench composes the existing Copilot service for caller-owned hosts.
copilot-adapter/worktreeadapter
Package worktreeadapter implements configured git repository and worktree operations for the Copilot adapter.
Package worktreeadapter implements configured git repository and worktree operations for the Copilot adapter.
cron
Package cron is the cron service: the durable in-process scheduler that mounts into a host runtime, fires each declared trigger on its schedule and records every occurrence through csfpg.
Package cron is the cron service: the durable in-process scheduler that mounts into a host runtime, fires each declared trigger on its schedule and records every occurrence through csfpg.
cron/crontest
Package crontest opens the cron store on pgmem, CSF's in-process substitute for PostgreSQL, with CSF's real schema applied: the store a spec grants when it needs cron state without a database.
Package crontest opens the cron store on pgmem, CSF's in-process substitute for PostgreSQL, with CSF's real schema applied: the store a spec grants when it needs cron state without a database.
cron/mocks
Package mocks is a generated GoMock package.
Package mocks is a generated GoMock package.
deploy
Package deploy contains the small, durable domain model shared by Deploy controllers and user-facing applications.
Package deploy contains the small, durable domain model shared by Deploy controllers and user-facing applications.
deploy/component
Package component defines the public bring-up contract for services an embedding repository composes alongside deploy.
Package component defines the public bring-up contract for services an embedding repository composes alongside deploy.
deploy/config
Package config resolves deploy's environment into its canonical Liquid Proto contract.
Package config resolves deploy's environment into its canonical Liquid Proto contract.
deploy/control
Package control is deploy's control-plane composition root beneath main.
Package control is deploy's control-plane composition root beneath main.
deploy/fleet
Package fleet is deploy's read-only view of Warden's cluster membership.
Package fleet is deploy's read-only view of Warden's cluster membership.
deploy/internal/storedb
Package storedb is the sqlc-generated query layer over the deploy control schema.
Package storedb is the sqlc-generated query layer over the deploy control schema.
deploy/operator
Package operator owns deploy's agent turn: policy, approvals, and run state.
Package operator owns deploy's agent turn: policy, approvals, and run state.
deploy/reconcile
Package reconcile turns approved desired state into fenced node-agent calls.
Package reconcile turns approved desired state into fenced node-agent calls.
deploy/store
Package store is Deploy's durable control-plane state.
Package store is Deploy's durable control-plane state.
dispatch
Package dispatch is the intent-ranked work queue of one harness process: a slice graph, its frontier, and the list scheduling that dispatches the frontier onto agent sessions.
Package dispatch is the intent-ranked work queue of one harness process: a slice graph, its frontier, and the list scheduling that dispatches the frontier onto agent sessions.
dispatch/mocks
Package mocks is a generated GoMock package.
Package mocks is a generated GoMock package.
email
Package email provides a composable, host-configured email capability.
Package email provides a composable, host-configured email capability.
harness
Package harness defines the public behavior boundary between deploy and a compiled-in agent runtime implementation.
Package harness defines the public behavior boundary between deploy and a compiled-in agent runtime implementation.
harness/chat
Package chat is the Workbench chat for harness sessions: a gotth-live page that shows one session's transcript as its event log grows and sends the operator's messages into the open session through the harness service, in process.
Package chat is the Workbench chat for harness sessions: a gotth-live page that shows one session's transcript as its event log grows and sends the operator's messages into the open session through the harness service, in process.
harness/mocks
Package mocks is a generated GoMock package.
Package mocks is a generated GoMock package.
harness/opencode
Package opencode implements the built-in OpenCode agent runtime behind the public deploy harness seam.
Package opencode implements the built-in OpenCode agent runtime behind the public deploy harness seam.
harness/routing
Package routing maps virtual sessions onto real sessions.
Package routing maps virtual sessions onto real sessions.
harness/session
Package session is the agent harness's session runner: it runs an agent's session for an assignment on a turn executor, in a git worktree of its own, with the session gates installed and every event logged under the run's trace.
Package session is the agent harness's session runner: it runs an agent's session for an assignment on a turn executor, in a git worktree of its own, with the session gates installed and every event logged under the run's trace.
harness/session/mocks
Package mocks is a generated GoMock package.
Package mocks is a generated GoMock package.
harness/sessiongate
Package sessiongate holds the session gates the agent harness installs into every session it runs: structural checks Claude Code calls as hooks around a tool call.
Package sessiongate holds the session gates the agent harness installs into every session it runs: structural checks Claude Code calls as hooks around a tool call.
housekeeping
Package housekeeping is the housekeeping service: the default cron triggers that keep a harness host's disk healthy.
Package housekeeping is the housekeeping service: the default cron triggers that keep a harness host's disk healthy.
housekeeping/mocks
Package mocks is a generated GoMock package.
Package mocks is a generated GoMock package.
intake
Package intake wakes the agent that owns a pull request or issue when something actionable happens to it: a comment, a review, an inline review comment, or a failed CI run.
Package intake wakes the agent that owns a pull request or issue when something actionable happens to it: a comment, a review, an inline review comment, or a failed CI run.
jobs
Package jobs is the harness job ledger: the durable record of requests admitted to external executors, kept in the tables csf_jobs, csf_job_budgets, csf_job_metric_definitions, csf_job_measurements and csf_job_trace_deliveries.
Package jobs is the harness job ledger: the durable record of requests admitted to external executors, kept in the tables csf_jobs, csf_job_budgets, csf_job_metric_definitions, csf_job_measurements and csf_job_trace_deliveries.
jobs/jobsmock
Package jobsmock is a generated GoMock package.
Package jobsmock is a generated GoMock package.
nodeexec/client
Package client is deploy's transport to one node agent.
Package client is deploy's transport to one node agent.
opsview
Package opsview is the ops view: a gotth-live page that shows every harness session on this machine as a live card, read from the run directories under the harness state directory.
Package opsview is the ops view: a gotth-live page that shows every harness session on this machine as a live card, read from the run directories under the harness state directory.
relay
Package relay delivers messages between agents.
Package relay delivers messages between agents.
relay/relaytest
Package relaytest holds the conformance specs every relay.IRegistry implementation must pass, and the messaging specs every relay.Relay[Body] must pass over such a registry.
Package relaytest holds the conformance specs every relay.IRegistry implementation must pass, and the messaging specs every relay.Relay[Body] must pass over such a registry.
warden
Package warden defines the shared contracts for the candacenet warden service: core types, the wire protocol, and the interfaces that the election, watchdog, notification, dashboard, and configuration packages implement or consume.
Package warden defines the shared contracts for the candacenet warden service: core types, the wire protocol, and the interfaces that the election, watchdog, notification, dashboard, and configuration packages implement or consume.
warden/config
Package config loads warden node configuration from built-in defaults, an optional YAML file, and environment overrides, in that precedence order (env beats file beats defaults).
Package config loads warden node configuration from built-in defaults, an optional YAML file, and environment overrides, in that precedence order (env beats file beats defaults).
warden/dashboard
Package dashboard renders the operator-facing observability surface of a warden node: a server-side-rendered, HTMX-refreshed dashboard, an HTMX partial for live cluster refresh, and a JSON status API.
Package dashboard renders the operator-facing observability surface of a warden node: a server-side-rendered, HTMX-refreshed dashboard, an HTMX partial for live cluster refresh, and a JSON status API.
warden/discovery
Package discovery implements warden.IPeerDiscoverer: the sources that report which nodes are candidate members of the cluster.
Package discovery implements warden.IPeerDiscoverer: the sources that report which nodes are candidate members of the cluster.
warden/election
Package election implements Raft-style leader election (terms and votes, no log replication) over a static peer set, plus the peer-liveness tracking that feeds the cluster ClusterView.
Package election implements Raft-style leader election (terms and votes, no log replication) over a static peer set, plus the peer-liveness tracking that feeds the cluster ClusterView.
warden/grpcmux
Package grpcmux multiplexes the warden gRPC plane and the existing HTTP surface onto a SINGLE bound port using soheilhy/cmux.
Package grpcmux multiplexes the warden gRPC plane and the existing HTTP surface onto a SINGLE bound port using soheilhy/cmux.
warden/grpcserver
Package grpcserver implements the candacenet.warden.v1 WardenService: the three unary cluster RPCs (Vote/Heartbeat/Identify) delegating to the existing warden.IRPCHandler through the wireconv boundary, and the server-streaming WatchCluster that pushes full ClusterView snapshots from a warden.IViewSource.
Package grpcserver implements the candacenet.warden.v1 WardenService: the three unary cluster RPCs (Vote/Heartbeat/Identify) delegating to the existing warden.IRPCHandler through the wireconv boundary, and the server-streaming WatchCluster that pushes full ClusterView snapshots from a warden.IViewSource.
warden/grpctransport
Package grpctransport is the gRPC client side of the warden cluster wire protocol: it implements warden.ITransport (RequestVote/SendHeartbeat/Identify) over the candacenet.warden.v1 WardenService, replacing the retired HTTP/JSON HTTPTransport.
Package grpctransport is the gRPC client side of the warden cluster wire protocol: it implements warden.ITransport (RequestVote/SendHeartbeat/Identify) over the candacenet.warden.v1 WardenService, replacing the retired HTTP/JSON HTTPTransport.
warden/httpserver
Package httpserver builds the single gin.Engine every warden node serves its HTTP surface from (dashboard + /api/status + /metrics).
Package httpserver builds the single gin.Engine every warden node serves its HTTP surface from (dashboard + /api/status + /metrics).
warden/internal/mocks
Package mocks is a generated GoMock package.
Package mocks is a generated GoMock package.
warden/internal/transportidentity
Package transportidentity carries transport-observed peer identity between Warden's gRPC adapter and election state machine.
Package transportidentity carries transport-observed peer identity between Warden's gRPC adapter and election state machine.
warden/metrics
Package metrics exposes a warden node's cluster state as Prometheus metrics.
Package metrics exposes a warden node's cluster state as Prometheus metrics.
warden/notify
Package notify implements the warden.INotifier delivery backends used by the watchdog:
Package notify implements the warden.INotifier delivery backends used by the watchdog:
warden/proto/warden/v1
Package wardenv1 holds the generated Go bindings for the candacenet warden wire contracts (candacenet.warden.v1).
Package wardenv1 holds the generated Go bindings for the candacenet warden wire contracts (candacenet.warden.v1).
warden/store
Package store provides persistence for warden.PersistentState (the Raft current term and vote).
Package store provides persistence for warden.PersistentState (the Raft current term and vote).
warden/testclock
Package testclock provides a deterministic, manually-advanced implementation of warden.IClock for tests.
Package testclock provides a deterministic, manually-advanced implementation of warden.IClock for tests.
warden/watchdog
Package watchdog turns cluster views into operator alerts.
Package watchdog turns cluster views into operator alerts.
warden/wireconv
Package wireconv provides total, composable conversions between the frozen warden domain types (services/warden) and the generated candacenet.warden.v1 protobuf messages (services/warden/proto/warden/v1).
Package wireconv provides total, composable conversions between the frozen warden domain types (services/warden) and the generated candacenet.warden.v1 protobuf messages (services/warden/proto/warden/v1).
workcontinuity
Package workcontinuity validates and records task checkpoints so work can resume across agents and sessions.
Package workcontinuity validates and records task checkpoints so work can resume across agents and sessions.
tools
generateopensearch command
Command generateopensearch derives one consumer client from the upstream spec-generated SDK, then delegates its test double to MockGen.
Command generateopensearch derives one consumer client from the upstream spec-generated SDK, then delegates its test double to MockGen.
ifacereturn
Package ifacereturn reports handwritten function and method declarations through whose results an interface reaches a caller.
Package ifacereturn reports handwritten function and method declarations through whose results an interface reaches a caller.
ifacereturn/cmd/ifacereturn command
Command ifacereturn reports every function and method result in a Go module through which an interface reaches a caller — the result's own type, or an interface-typed field of a struct it hands back.
Command ifacereturn reports every function and method result in a Go module through which an interface reaches a caller — the result's own type, or an interface-typed field of a struct it hands back.
web
deploy/browserroutes
Package browserroutes is the single source of truth for deploy's browser-facing URL space.
Package browserroutes is the single source of truth for deploy's browser-facing URL space.
deploy/httpapi
Package httpapi is deploy's operator-facing HTTP transport.
Package httpapi is deploy's operator-facing HTTP transport.
deploy/httpserver
Package httpserver owns deploy's single configured Gin engine.
Package httpserver owns deploy's single configured Gin engine.
deploy/webui
Package webui serves deploy's local-first operator interface and is the seam where an embedding product supplies its own branding.
Package webui serves deploy's local-first operator interface and is the seam where an embedding product supplies its own branding.
nodeexec/httpapi
Package httpapi exposes the node-local JSON control API.
Package httpapi exposes the node-local JSON control API.
xetcas

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL