Directories
¶
| Path | Synopsis |
|---|---|
|
Package atomicfile writes a file atomically: a reader opening or reading the file sees either the old content or the new content in full, never a part of either.
|
Package atomicfile writes a file atomically: a reader opening or reading the file sees either the old content or the new content in full, never a part of either. |
|
Package bench runs one command on a Linux bench against a copy of a local tree: `nova-ci bench run`.
|
Package bench runs one command on a Linux bench against a copy of a local tree: `nova-ci bench run`. |
|
Package binstamp names the state of a binary's file: a loop that runs for days (nova-sprint run, nova-swarm member) stamps its own file when it begins and again before each tick, and stops when the stamp changed, so its supervisor starts the build installed under it.
|
Package binstamp names the state of a binary's file: a loop that runs for days (nova-sprint run, nova-swarm member) stamps its own file when it begins and again before each tick, and stops when the stamp changed, so its supervisor starts the build installed under it. |
|
Package bounded is the one shape every listing in this repo prints, and the reason it exists is an incident: a line running on a 260K-context model died reading a single 674-line return from a verb that lists its state.
|
Package bounded is the one shape every listing in this repo prints, and the reason it exists is an incident: a line running on a 260K-context model died reading a single 674-line return from a verb that lists its state. |
|
Package buildinfo answers one question in one place: WHICH BUILD IS THIS.
|
Package buildinfo answers one question in one place: WHICH BUILD IS THIS. |
|
Package bus is the message bus between AIs over Redis streams (docs/SPEC-BUS.md; the delivery machine is tla/Bus2.tla).
|
Package bus is the message bus between AIs over Redis streams (docs/SPEC-BUS.md; the delivery machine is tla/Bus2.tla). |
|
Package cardcontract is the frame around a card's task (docs/SPEC-CARD-CONTRACT.md): the frame the member hands native (Frame), the result shape a child ends with (Result), and the profiles, keyed by model family, that write JOB.md and the shims first on the child's PATH so the child meets the frame through the commands it already knows.
|
Package cardcontract is the frame around a card's task (docs/SPEC-CARD-CONTRACT.md): the frame the member hands native (Frame), the result shape a child ends with (Result), and the profiles, keyed by model family, that write JOB.md and the shims first on the child's PATH so the child meets the frame through the commands it already knows. |
|
Package cardcost is what a card cost: a route's price sheet as nova-config holds it (the route kind's price fields, docs/SPEC-CONFIG.md, "route"), the tokens one run spent by class, the predicted cost of the one priced by the other, and the usage record a consumer card keeps (docs/SPEC-SPRINT.md, "What a card cost"), in exact decimal arithmetic.
|
Package cardcost is what a card cost: a route's price sheet as nova-config holds it (the route kind's price fields, docs/SPEC-CONFIG.md, "route"), the tokens one run spent by class, the predicted cost of the one priced by the other, and the usage record a consumer card keeps (docs/SPEC-SPRINT.md, "What a card cost"), in exact decimal arithmetic. |
|
Package cardhdr is the card header's vocabulary: the kinds and routes a card's KIND and ROUTE lines may carry, and the one reader of a `KEY: value` header line.
|
Package cardhdr is the card header's vocabulary: the kinds and routes a card's KIND and ROUTE lines may carry, and the one reader of a `KEY: value` header line. |
|
Package cardlimits holds the two sizes a card's brief is held to, in one place that nothing is behind: no redis client, no table layer, no store.
|
Package cardlimits holds the two sizes a card's brief is held to, in one place that nothing is behind: no redis client, no table layer, no store. |
|
Package cardtree is a card as a tree of steps (docs/SPEC-SPRINT.md, "A card is a tree of steps"; nova-tools#5174 rule 7): the grammar of numbered step blocks, the lint of a tree, the script step the member runs with no model, the verdict per step, and the remainder a failed step leaves.
|
Package cardtree is a card as a tree of steps (docs/SPEC-SPRINT.md, "A card is a tree of steps"; nova-tools#5174 rule 7): the grammar of numbered step blocks, the lint of a tree, the script step the member runs with no model, the verdict per step, and the remainder a failed step leaves. |
|
ci
|
|
|
Package config is nova-config's library: the permanent, non-ephemeral configuration of the fleet, kept in Postgres (schema `config`) and applied into Redis so Redis is always a rebuildable copy of the configuration.
|
Package config is nova-config's library: the permanent, non-ephemeral configuration of the fleet, kept in Postgres (schema `config`) and applied into Redis so Redis is always a rebuildable copy of the configuration. |
|
Package decide is a decision system that is trained from its own record (docs/SPEC-NOVA-DECIDE.md).
|
Package decide is a decision system that is trained from its own record (docs/SPEC-NOVA-DECIDE.md). |
|
Package delayproxy is a TCP proxy that holds every write of its clients back by a fixed time before it forwards it: a store that stands far away, made on the loopback.
|
Package delayproxy is a TCP proxy that holds every write of its clients back by a fixed time before it forwards it: a store that stands far away, made on the loopback. |
|
Package diffcheck is the lander's mechanical checks of one card's diff, the two the calibration of the decide read found a model read does not make (docs/SPEC-SPRINT.md section 7, the lander's checks): every file the diff changes is one the card's PATHS names (E12), and no changed line leaves a stranded sentence fragment or an unmatched backquote beside it (E4).
|
Package diffcheck is the lander's mechanical checks of one card's diff, the two the calibration of the decide read found a model read does not make (docs/SPEC-SPRINT.md section 7, the lander's checks): every file the diff changes is one the card's PATHS names (E12), and no changed line leaves a stranded sentence fragment or an unmatched backquote beside it (E4). |
|
Package dogfood answers one question about a tool that its own tests cannot: has somebody who did not write it actually run it?
|
Package dogfood answers one question about a tool that its own tests cannot: has somebody who did not write it actually run it? |
|
Package filelock is the one lock on a file across processes: the kernel's lock (flock on unix, LockFileEx on Windows), released by the kernel when its holder dies, with the holder's stamp written inside the file for a refusal to name.
|
Package filelock is the one lock on a file across processes: the kernel's lock (flock on unix, LockFileEx on Windows), released by the kernel when its holder dies, with the holder's stamp written inside the file for a refusal to name. |
|
Package fleet holds the machines registry: the one file that says what each machine in the fleet IS, and therefore what may be placed on it.
|
Package fleet holds the machines registry: the one file that says what each machine in the fleet IS, and therefore what may be placed on it. |
|
Package friend is what a friend's machinery runs to be part of the team (docs/SPEC-FRIEND.md; the model is tla/Friend.tla).
|
Package friend is what a friend's machinery runs to be part of the team (docs/SPEC-FRIEND.md; the model is tla/Friend.tla). |
|
friendtest
Package friendtest holds the test doubles of pkg/friend that tests in other packages share.
|
Package friendtest holds the test doubles of pkg/friend that tests in other packages share. |
|
Package gitrun is the one runner for a one-shot git child.
|
Package gitrun is the one runner for a one-shot git child. |
|
Package gocache holds a Go build cache under a size: least recently used entries go first, never one used in the last Recent, never anything that is not a cache entry.
|
Package gocache holds a Go build cache under a size: least recently used entries go first, never one used in the last Recent, never anything that is not a cache entry. |
|
Package goenv builds the environment a tool hands to a child `go` command.
|
Package goenv builds the environment a tool hands to a child `go` command. |
|
Package harness is the vocabulary of the harnesses a card's child runs under: the one word a route row, a packet and a launch name a harness by.
|
Package harness is the vocabulary of the harnesses a card's child runs under: the one word a route row, a packet and a launch name a harness by. |
|
Package hostload measures how busy a machine is, as a percent of all its cores: the CPU busy percent over an interval (the number Activity Monitor and top print), or, where that cannot be measured, the one-minute load average over the logical cores.
|
Package hostload measures how busy a machine is, as a percent of all its cores: the CPU busy percent over an interval (the number Activity Monitor and top print), or, where that cannot be measured, the one-minute load average over the logical cores. |
|
Package hygiene is the one place that answers "is this diff clean", for the accept gate, for the merge lane and for a hand.
|
Package hygiene is the one place that answers "is this diff clean", for the accept gate, for the merge lane and for a hand. |
|
Package keyshape holds the one predicate that says whether an environment NAME carries a secret: the env var value is never inspected, only the name.
|
Package keyshape holds the one predicate that says whether an environment NAME carries a secret: the env var value is never inspected, only the name. |
|
Package log is the one structured event line every part writes BESIDE the one human line it already writes.
|
Package log is the one structured event line every part writes BESIDE the one human line it already writes. |
|
Package member is a fleet member of a sprint: the loop a fleet machine runs against the sprint's fleet table (the machine's queue) and the sprint's verbs, with each card run as one child through a runner.
|
Package member is a fleet member of a sprint: the loop a fleet machine runs against the sprint's fleet table (the machine's queue) and the sprint's verbs, with each card run as one child through a runner. |
|
nsprint
|
|
|
fn
Package fn assembles and installs the nova-sprint Redis Function library.
|
Package fn assembles and installs the nova-sprint Redis Function library. |
|
redisauth
Package redisauth is the one fleet Redis seat every tool dials with from the environment: the ACL user and the variable holding its password.
|
Package redisauth is the one fleet Redis seat every tool dials with from the environment: the ACL user and the variable holding its password. |
|
testutil
Package testutil starts the throwaway Redis the nova-sprint controls share.
|
Package testutil starts the throwaway Redis the nova-sprint controls share. |
|
testutil/pg
Package pg starts the throwaway Postgres the nova-config functional tests share, the way pkg/nsprint/testutil starts a throwaway Redis: initdb and pg_ctl from the binaries on PATH (or the well-known install directories, or NOVA_PG_BIN), a free loopback port, everything under the test's temporary directory, trust authentication, and the cleanup stops it.
|
Package pg starts the throwaway Postgres the nova-config functional tests share, the way pkg/nsprint/testutil starts a throwaway Redis: initdb and pg_ctl from the binaries on PATH (or the well-known install directories, or NOVA_PG_BIN), a free loopback port, everything under the test's temporary directory, trust authentication, and the cleanup stops it. |
|
verbflag
Package verbflag is the one seam every living tool's verbs parse their flags through, so help and the CLI standard hold the same way for every verb.
|
Package verbflag is the one seam every living tool's verbs parse their flags through, so help and the CLI standard hold the same way for every verb. |
|
Package ntable is a general, Redis-backed table built from one primitive: the ordered set.
|
Package ntable is a general, Redis-backed table built from one primitive: the ordered set. |
|
Package onboarding reads the two things docs/ONBOARDING.md makes every command in this repo carry — the `example:` block at the foot of its usage banner, and its `### First run` section in docs/TESTS.md — and reduces an output line to the part that document promises.
|
Package onboarding reads the two things docs/ONBOARDING.md makes every command in this repo carry — the `example:` block at the foot of its usage banner, and its `### First run` section in docs/TESTS.md — and reduces an output line to the part that document promises. |
|
Package oneline is the one escape every binary in this repo renders caller-supplied or stored text through before it reaches an event line.
|
Package oneline is the one escape every binary in this repo renders caller-supplied or stored text through before it reaches an event line. |
|
audit
Package audit is the source-level tripwire behind the one-line guarantee, shared by every binary in this repo.
|
Package audit is the source-level tripwire behind the one-line guarantee, shared by every binary in this repo. |
|
Package pkgselect chooses the Go packages a CI run tests and deals them to the legs that test them.
|
Package pkgselect chooses the Go packages a CI run tests and deals them to the legs that test them. |
|
Package provbalance reads a model provider's balance through the seat's key: the transport of the sprint's balance poll (internal/sprint balance.go; nova-tools#5199).
|
Package provbalance reads a model provider's balance through the seat's key: the transport of the sprint's balance poll (internal/sprint balance.go; nova-tools#5199). |
|
Package readregular provides bounds-checked and type-checked file reads for regular files, rejecting non-regular files (such as FIFOs, devices, and sockets) and files that exceed an explicit size cap.
|
Package readregular provides bounds-checked and type-checked file reads for regular files, rejecting non-regular files (such as FIFOs, devices, and sockets) and files that exceed an explicit size cap. |
|
Package redisacl renders the fleet store's ACL users from the function library a build embeds and the key families its tools use, and compares a rendering with a store's live ACL.
|
Package redisacl renders the fleet store's ACL users from the function library a build embeds and the key families its tools use, and compares a rendering with a store's live ACL. |
|
Package redisconn is the one way a nova tool opens its Redis connection.
|
Package redisconn is the one way a nova tool opens its Redis connection. |
|
Package redisfn builds, loads and checks a Redis function library from Lua source held in a file system, which for a tool is the Lua it embeds.
|
Package redisfn builds, loads and checks a Redis function library from Lua source held in a file system, which for a tool is the Lua it embeds. |
|
Package release is the last mile: a green commit on main becomes a version, a set of binaries, and the same binaries answering for themselves on every bench in the fleet.
|
Package release is the last mile: a green commit on main becomes a version, a set of binaries, and the same binaries answering for themselves on every bench in the fleet. |
|
Package safepath is the one way a path this tool COMPUTED is removed.
|
Package safepath is the one way a path this tool COMPUTED is removed. |
|
The egress wall is the card's OUTBOUND half: the filesystem wall this package builds everywhere else says what a card may read and write, and this file says what it may talk to.
|
The egress wall is the card's OUTBOUND half: the filesystem wall this package builds everywhere else says what a card may read and write, and this file says what it may talk to. |
|
darwincheck
Package darwincheck is the darwin profile check: it fills profiles/darwin.sb.tmpl for a scratch write set, then runs, INSIDE the wall and by ABSOLUTE path, the things a swarm worker does in its first second (cd, mkdir -p, git init, git clone --shared, a config write under HOME, cat /etc/hosts, /bin/sh -c true, killing its own child, stdout to a pipe and to a file in the write set), and asserts that a write outside, a read of the named secret, a listing of an ancestor, a connect to a socket outside the write set and a nested sandbox all FAIL, each with a control run OUTSIDE the wall so that a check cannot pass by being impossible.
|
Package darwincheck is the darwin profile check: it fills profiles/darwin.sb.tmpl for a scratch write set, then runs, INSIDE the wall and by ABSOLUTE path, the things a swarm worker does in its first second (cd, mkdir -p, git init, git clone --shared, a config write under HOME, cat /etc/hosts, /bin/sh -c true, killing its own child, stdout to a pipe and to a file in the write set), and asserts that a write outside, a read of the named secret, a listing of an ancestor, a connect to a socket outside the write set and a nested sandbox all FAIL, each with a control run OUTSIDE the wall so that a check cannot pass by being impossible. |
|
Package seatcred resolves a seat's fleet Redis user and password in the process that needs them (nova-tools#4052).
|
Package seatcred resolves a seat's fleet Redis user and password in the process that needs them (nova-tools#4052). |
|
seattest
Package seattest builds a real nova-secrets store for a test: a git working copy with an upstream, recovery.pub, .sops.yaml and one seat's file sealed by sops to a fresh age key, laid out where pkg/seatcred looks by default under a temporary HOME.
|
Package seattest builds a real nova-secrets store for a test: a git working copy with an upstream, recovery.pub, .sops.yaml and one seat's file sealed by sops to a fresh age key, laid out where pkg/seatcred looks by default under a temporary HOME. |
|
Package secretcheck is the harness of the class rule "no secret reaches an error" (docs/SPEC-CI.md, `secrets-never-in-errors`): secret-shaped inputs, a driver that hands them to a function by reflection and reads what came back, and the two-way comparisons of a reviewed table and allowlist with what a walk of the tree finds.
|
Package secretcheck is the harness of the class rule "no secret reaches an error" (docs/SPEC-CI.md, `secrets-never-in-errors`): secret-shaped inputs, a driver that hands them to a function by reflection and reads what came back, and the two-way comparisons of a reviewed table and allowlist with what a walk of the tree finds. |
|
Package secrets implements the credential-layer machinery described in docs/SPEC-SECRETS.md.
|
Package secrets implements the credential-layer machinery described in docs/SPEC-SECRETS.md. |
|
Package sprintwire is how a worker talks to the sprint's server: the run loop on the coordinator's machine, the one writer of the sprint, which runs a worker's verbs for it, one at a time, beside the store.
|
Package sprintwire is how a worker talks to the sprint's server: the run loop on the coordinator's machine, the one writer of the sprint, which runs a worker's verbs for it, one at a time, beside the store. |
|
Package subproc is the one place a child process gets its bound.
|
Package subproc is the one place a child process gets its bound. |
|
Package swarm is nova-swarm's machinery: a pool of one-task workers, each with its own working directory, its own data home, its own job directory and its own deadline held by the machinery rather than by the worker.
|
Package swarm is nova-swarm's machinery: a pool of one-task workers, each with its own working directory, its own data home, its own job directory and its own deadline held by the machinery rather than by the worker. |
|
Package testbin places a built program into a test's directory.
|
Package testbin places a built program into a test's directory. |
|
Package testgit is the one identity a test's git commit runs under.
|
Package testgit is the one identity a test's git commit runs under. |
|
Package testguard refuses to let a unit test reach a real host.
|
Package testguard refuses to let a unit test reach a real host. |
|
Package testkit holds the test rigs that were copied from package to package: running a tool's entry point in process with both streams captured and checked (verb.go), writing and reading the files a test sets up (here and tree.go), a recording wait for code a synctest bubble cannot hold (waits.go) and a skip by platform (skip.go).
|
Package testkit holds the test rigs that were copied from package to package: running a tool's entry point in process with both streams captured and checked (verb.go), writing and reading the files a test sets up (here and tree.go), a recording wait for code a synctest bubble cannot hold (waits.go) and a skip by platform (skip.go). |
|
Package testredis is a throwaway redis-server for one test.
|
Package testredis is a throwaway redis-server for one test. |
|
Package tlc runs TLC over the declared cases of tla/CASES.tsv and reads what it says.
|
Package tlc runs TLC over the declared cases of tla/CASES.tsv and reads what it says. |
|
Package tool is the one shape of a nova command.
|
Package tool is the one shape of a nova command. |
|
Package tty says whether a file is a terminal and how large its screen is, on the systems that have a terminal to ask (the unix family and Windows); elsewhere a file is never a terminal and its size is not known.
|
Package tty says whether a file is a terminal and how large its screen is, on the systems that have a terminal to ask (the unix family and Windows); elsewhere a file is never a terminal and its size is not known. |
|
Package typedrec is the one typed parser: the home of every typed line a nova tool reads, the RESULT v2 record and DISPOSITION line first, and the Lua replies (the PATHS gate's refusal) and any other typed line with them.
|
Package typedrec is the one typed parser: the home of every typed line a nova tool reads, the RESULT v2 record and DISPOSITION line first, and the Lua replies (the PATHS gate's refusal) and any other typed line with them. |
|
Package units is the text and install of every unit a running sprint needs.
|
Package units is the text and install of every unit a running sprint needs. |
Click to show internal directories.
Click to hide internal directories.