Directories
¶
| Path | Synopsis |
|---|---|
|
cmd
|
|
|
nova-bus
command
nova-bus is the message bus between AIs over Redis streams (docs/SPEC-BUS.md; the delivery machine is tla/Bus2.tla).
|
nova-bus is the message bus between AIs over Redis streams (docs/SPEC-BUS.md; the delivery machine is tla/Bus2.tla). |
|
nova-cairn
command
nova-cairn keeps a session's words as plain files: it opens a session record, appends the caller's exact words with a clock stamp, a stable id and a source pointer, and reads them back as an index and receipts.
|
nova-cairn keeps a session's words as plain files: it opens a session record, appends the caller's exact words with a clock stamp, a stable id and a source pointer, and reads them back as an index and receipts. |
|
nova-check
command
nova-check runs checks over markdown records and repositories (SPEC-CHECK.md): quickstart (links, then nocode), boot attestation, link integrity, the kernel size budget, the self/machinery separation (nocode, and nocode --staged over the git index), the floor-set parity of a derived door and its source, the protected corpus, branch hygiene, the dogfood ledger (record, ledger, gate), convergence and spelling.
|
nova-check runs checks over markdown records and repositories (SPEC-CHECK.md): quickstart (links, then nocode), boot attestation, link integrity, the kernel size budget, the self/machinery separation (nocode, and nocode --staged over the git index), the floor-set parity of a derived door and its source, the protected corpus, branch hygiene, the dogfood ledger (record, ledger, gate), convergence and spelling. |
|
nova-ci
command
nova-ci runs the checks this repository's CI path makes on its own output.
|
nova-ci runs the checks this repository's CI path makes on its own output. |
|
nova-config
command
Command nova-config is the one tool for the fleet's permanent, non-ephemeral configuration: it owns Postgres (schema `config`, its migrations, its history) and every registry of the fleet, and it applies that configuration into Redis so Redis is always a rebuildable copy.
|
Command nova-config is the one tool for the fleet's permanent, non-ephemeral configuration: it owns Postgres (schema `config`, its migrations, its history) and every registry of the fleet, and it applies that configuration into Redis so Redis is always a rebuildable copy. |
|
nova-decide
command
nova-decide is a decision system trained from its own record (docs/SPEC-NOVA-DECIDE.md).
|
nova-decide is a decision system trained from its own record (docs/SPEC-NOVA-DECIDE.md). |
|
nova-doctor
command
Command nova-doctor says what is missing for the nova tools to work and the one line that fixes each.
|
Command nova-doctor says what is missing for the nova tools to work and the one line that fixes each. |
|
nova-friend
command
The daemon's reading of every harness's credit and quota refusal, from the places a lane leaves it: the lane's stdout, its stderr, the harness log it writes and the REPORT.md it leaves (docs/SPEC-FRIEND.md, a harness out of credits).
|
The daemon's reading of every harness's credit and quota refusal, from the places a lane leaves it: the lane's stdout, its stderr, the harness log it writes and the REPORT.md it leaves (docs/SPEC-FRIEND.md, a harness out of credits). |
|
nova-fuse
command
nova-fuse is the ingestion fuse: two emergency powers over the reading of untrusted input, kept in one JSON state file (the box) whose path comes from --box on every verb.
|
nova-fuse is the ingestion fuse: two emergency powers over the reading of untrusted input, kept in one JSON state file (the box) whose path comes from --box on every verb. |
|
nova-local
command
nova-local makes a local model engine usable (docs/SPEC-LOCAL.md): what is here (status), one model served at a context the caller chose (serve), and a worker description nova-swarm accepts (worker).
|
nova-local makes a local model engine usable (docs/SPEC-LOCAL.md): what is here (status), one model served at a context the caller chose (serve), and a worker description nova-swarm accepts (worker). |
|
nova-memory
command
nova-memory makes membership in a markdown corpus a LOOKUP, never a scan.
|
nova-memory makes membership in a markdown corpus a LOOKUP, never a scan. |
|
nova-redis
command
Command nova-redis is the Layer 2 binary of docs/SPEC-REDIS.md, the owner of the local instance: `serve` launches it bound to loopback and the tailnet, with auth from nova-secrets and the fleet store's rules: AOF on, no eviction, no TTL policy, the store in --dir (serve.go).
|
Command nova-redis is the Layer 2 binary of docs/SPEC-REDIS.md, the owner of the local instance: `serve` launches it bound to loopback and the tailnet, with auth from nova-secrets and the fleet store's rules: AOF on, no eviction, no TTL policy, the store in --dir (serve.go). |
|
nova-sandbox
command
What the wall denied, said out loud.
|
What the wall denied, said out loud. |
|
nova-secrets
command
Command nova-secrets keeps a team's secrets sops-encrypted in a git repository (the store) and hands the values one command needs to that command alone, in its environment; no verb prints a value.
|
Command nova-secrets keeps a team's secrets sops-encrypted in a git repository (the store) and hands the values one command needs to that command alone, in its environment; no verb prints a value. |
|
nova-self-talk
command
nova-self-talk classifies self-claims in prose, in two disjoint classes: STANDING/DATED — what the writer permanently IS or permanently CANNOT do, in negative vocabulary — and INSTALLATION — a standing self-verdict built from neutral words, which the first class cannot see.
|
nova-self-talk classifies self-claims in prose, in two disjoint classes: STANDING/DATED — what the writer permanently IS or permanently CANNOT do, in negative vocabulary — and INSTALLATION — a standing self-verdict built from neutral words, which the first class cannot see. |
|
nova-swarm
command
nova-swarm doctor: refuse to launch under a shadowed or unreadable binary.
|
nova-swarm doctor: refuse to launch under a shadowed or unreadable binary. |
|
nova-table
command
nova-table: work tables of ordered sets, text and formulas over Redis (pkg/ntable).
|
nova-table: work tables of ordered sets, text and formulas over Redis (pkg/ntable). |
|
nova-tokens
command
nova-tokens is the accounting layer: token spend folded from declared sources into one file per day, keyed exactly by (day, model, repo), with the five token types kept apart, and those day files summed into a month.
|
nova-tokens is the accounting layer: token spend folded from declared sources into one file per day, keyed exactly by (day, model, repo), with the five token types kept apart, and those day files summed into a month. |
|
nova-up
command
Command nova-up sets up nova on one machine, from nothing to a first sprint: it plans every step, prints one line per step, and applies the steps that are not ok (docs/SPEC-UP.md).
|
Command nova-up sets up nova on one machine, from nothing to a first sprint: it plans every step, prints one line per step, and applies the steps that are not ok (docs/SPEC-UP.md). |
|
nova-update
command
|
|
|
nova-version
command
Command nova-version reports installed tool identities and shares the update reader: local stdout by default, optional prepared bus delivery.
|
Command nova-version reports installed tool identities and shares the update reader: local stdout by default, optional prepared bus delivery. |
|
Package fleet holds the child rules files this repository's members inject into every card at stage time (nova-tools#5174 rule 6, rules by reference): fleet/child-rules.txt, and fleet/child-rules.<repo>.txt for a repository with rules of its own.
|
Package fleet holds the child rules files this repository's members inject into every card at stage time (nova-tools#5174 rule 6, rules by reference): fleet/child-rules.txt, and fleet/child-rules.<repo>.txt for a repository with rules of its own. |
|
internal
|
|
|
cairn
Package cairn is the store behind nova-cairn: session records holding a caller's exact words, each with a clock stamp, a stable identifier and a source pointer, and a bounded index and coverage count read back from them.
|
Package cairn is the store behind nova-cairn: session records holding a caller's exact words, each with a clock stamp, a stable identifier and a source pointer, and a bounded index and coverage count read back from them. |
|
check
Package check implements seven of the ten record-layer checks behind nova-check; the other three live elsewhere because none is about one self repo.
|
Package check implements seven of the ten record-layer checks behind nova-check; the other three live elsewhere because none is about one self repo. |
|
ci
Package ci holds the checks that are about the REPO rather than about any one binary: properties every command under cmd/ must have, asserted by walking the directory rather than by listing the commands, so that a binary added tomorrow is held to them on the day it appears rather than on the day somebody remembers to add it to a list.
|
Package ci holds the checks that are about the REPO rather than about any one binary: properties every command under cmd/ must have, asserted by walking the directory rather than by listing the commands, so that a binary added tomorrow is held to them on the day it appears rather than on the day somebody remembers to add it to a list. |
|
ci/allowlist
Package allowlist is the one reader and the one writer of the exception lists the class tests in internal/ci keep under internal/ci/testdata.
|
Package allowlist is the one reader and the one writer of the exception lists the class tests in internal/ci keep under internal/ci/testdata. |
|
ci/functional
Package functional is the machine behind cmd/nova-ci's `functional` verb: which of a change's packages carry functional tests, and which tests those are.
|
Package functional is the machine behind cmd/nova-ci's `functional` verb: which of a change's packages carry functional tests, and which tests those are. |
|
ci/slowtests
Package slowtests is the machine behind cmd/nova-ci's `slowtests` verb in docs/SPEC-CI.md, "The per-package test time budget".
|
Package slowtests is the machine behind cmd/nova-ci's `slowtests` verb in docs/SPEC-CI.md, "The per-package test time budget". |
|
ci/timing
Package timing is the machine behind the committed script cmd/nova-ci/timing.go, which prints one pull request's time from open to all-green split into queue, setup and test per job, for the last 200 pull requests of the project's own repositories.
|
Package timing is the machine behind the committed script cmd/nova-ci/timing.go, which prints one pull request's time from open to all-green split into queue, setup and test per job, for the last 200 pull requests of the project's own repositories. |
|
cireceipt
Package cireceipt is the run receipt the ci-ok job of .github/workflows/ci.yml writes at the end of every run: one ev:github row of the workflow_run shape, sender "runner", appended through internal/ghevent.
|
Package cireceipt is the run receipt the ci-ok job of .github/workflows/ci.yml writes at the end of every run: one ev:github row of the workflow_run shape, sender "runner", appended through internal/ghevent. |
|
converge
Package converge answers one question mechanically: are we converging?
|
Package converge answers one question mechanically: are we converging? |
|
doctor
Package doctor is nova-doctor's frame: a registry of checks, each one a name, the dependency it covers, a Run over an Env, and a result of ok, warn or fail with evidence and, when not ok, the one fix line.
|
Package doctor is nova-doctor's frame: a registry of checks, each one a name, the dependency it covers, a Run over an Env, and a result of ok, warn or fail with evidence and, when not ok, the one fix line. |
|
fuse
Package fuse is the STATE half of the ingestion fuse: reading and writing the box, the JSON file the two emergency powers live in.
|
Package fuse is the STATE half of the ingestion fuse: reading and writing the box, the JSON file the two emergency powers live in. |
|
ghevent
Package ghevent appends entries to the Redis stream ev:github and reads them back.
|
Package ghevent appends entries to the Redis stream ev:github and reads them back. |
|
ghevent/wire
Package wire holds the stream identity shared by GitHub event writers and readers.
|
Package wire holds the stream identity shared by GitHub event writers and readers. |
|
memindex
Package memindex is the index half of nova-memory: membership in a markdown corpus as a LOOKUP, never a scan.
|
Package memindex is the index half of nova-memory: membership in a markdown corpus as a LOOKUP, never a scan. |
|
nogh
Package nogh installs a refusing gh command first on a child shell's PATH.
|
Package nogh installs a refusing gh command first on a child shell's PATH. |
|
nsprint/store
Package store provides the Redis client shared by nova-sprint verbs.
|
Package store provides the Redis client shared by nova-sprint verbs. |
|
record
Package record holds the token ledger: the index of nova-tokens' day TSVs in the fleet Redis, one hash per day: a month query reads the day hashes in one pipelined trip, so the ledger keeps one store and no second copy.
|
Package record holds the token ledger: the index of nova-tokens' day TSVs in the fleet Redis, one hash per day: a month query reads the day hashes in one pipelined trip, so the ledger keeps one store and no second copy. |
|
roadmap
Package roadmap reads docs/roadmap.sexp and renders ROADMAP.md from it.
|
Package roadmap reads docs/roadmap.sexp and renders ROADMAP.md from it. |
|
roadmap/sexp
Package sexp is the bounded reader for docs/roadmap.sexp, a restricted-Lisp file.
|
Package sexp is the bounded reader for docs/roadmap.sexp, a restricted-Lisp file. |
|
scaffold
Package scaffold provides the shared write-confinement and template engine for scaffolding verbs across this repository.
|
Package scaffold provides the shared write-confinement and template engine for scaffolding verbs across this repository. |
|
selftalk
Package selftalk finds sentences in which a writer passes a standing verdict on themselves, in two disjoint classes, each finding with the source line it starts on.
|
Package selftalk finds sentences in which a writer passes a standing verdict on themselves, in two disjoint classes, each finding with the source line it starts on. |
|
shippedsmoke
Package shippedsmoke holds the smoke test of a SHIPPED nova-check binary: the executable a release puts in a user's hands, not one built from the tree under test.
|
Package shippedsmoke holds the smoke test of a SHIPPED nova-check binary: the executable a release puts in a user's hands, not one built from the tree under test. |
|
tablemodel
Package tablemodel checks nova-table against its TLA+ models.
|
Package tablemodel checks nova-table against its TLA+ models. |
|
testverbhelp
Package testverbhelp is the per-tool check of the verb-help rule (the CLI style's rule (b), #4505; pkg/nsprint/verbflag is the one seam that implements it): `<tool> <verb> -h` and `--help` print that verb's help on stdout and exit 0, with nothing on stderr, no file written and no dial.
|
Package testverbhelp is the per-tool check of the verb-help rule (the CLI style's rule (b), #4505; pkg/nsprint/verbflag is the one seam that implements it): `<tool> <verb> -h` and `--help` print that verb's help on stdout and exit 0, with nothing on stderr, no file written and no dial. |
|
textbody
Package textbody filters line-oriented message bodies without transport, storage, parsing of typed records, or decision policy.
|
Package textbody filters line-oriented message bodies without transport, storage, parsing of typed records, or decision policy. |
|
tokens
Package tokens is the accounting layer: the one message shape every source produces, the one fold over a stream of them, the day file, and the readers for the five declared source kinds.
|
Package tokens is the accounting layer: the one message shape every source produces, the one fold over a stream of them, the day file, and the readers for the five declared source kinds. |
|
up
Package up is nova-up: it takes one machine from nothing to a first sprint (docs/SPEC-UP.md).
|
Package up is nova-up: it takes one machine from nothing to a first sprint (docs/SPEC-UP.md). |
|
update
Package update implements the shared, explicit version inventory behind nova-update and nova-version.
|
Package update implements the shared, explicit version inventory behind nova-update and nova-version. |
|
yield
Package yield is the one place a process steps behind CI: CI over work is a permanent setting, because work creates more CI, and without the ordering the system is unstable.
|
Package yield is the one place a process steps behind CI: CI over work is a permanent setting, because work creates more CI, and without the ordering the system is unstable. |
|
pkg
|
|
|
atomicfile
Package atomicfile writes a file atomically: a reader opening or reading the file sees either the old content or the new content in full, never a part of either.
|
Package atomicfile writes a file atomically: a reader opening or reading the file sees either the old content or the new content in full, never a part of either. |
|
bench
Package bench runs one command on a Linux bench against a copy of a local tree: `nova-ci bench run`.
|
Package bench runs one command on a Linux bench against a copy of a local tree: `nova-ci bench run`. |
|
binstamp
Package binstamp names the state of a binary's file: a loop that runs for days (nova-sprint run, nova-swarm member) stamps its own file when it begins and again before each tick, and stops when the stamp changed, so its supervisor starts the build installed under it.
|
Package binstamp names the state of a binary's file: a loop that runs for days (nova-sprint run, nova-swarm member) stamps its own file when it begins and again before each tick, and stops when the stamp changed, so its supervisor starts the build installed under it. |
|
bounded
Package bounded is the one shape every listing in this repo prints, and the reason it exists is an incident: a line running on a 260K-context model died reading a single 674-line return from a verb that lists its state.
|
Package bounded is the one shape every listing in this repo prints, and the reason it exists is an incident: a line running on a 260K-context model died reading a single 674-line return from a verb that lists its state. |
|
buildinfo
Package buildinfo answers one question in one place: WHICH BUILD IS THIS.
|
Package buildinfo answers one question in one place: WHICH BUILD IS THIS. |
|
bus
Package bus is the message bus between AIs over Redis streams (docs/SPEC-BUS.md; the delivery machine is tla/Bus2.tla).
|
Package bus is the message bus between AIs over Redis streams (docs/SPEC-BUS.md; the delivery machine is tla/Bus2.tla). |
|
cardcontract
Package cardcontract is the frame around a card's task (docs/SPEC-CARD-CONTRACT.md): the frame the member hands native (Frame), the result shape a child ends with (Result), and the profiles, keyed by model family, that write JOB.md and the shims first on the child's PATH so the child meets the frame through the commands it already knows.
|
Package cardcontract is the frame around a card's task (docs/SPEC-CARD-CONTRACT.md): the frame the member hands native (Frame), the result shape a child ends with (Result), and the profiles, keyed by model family, that write JOB.md and the shims first on the child's PATH so the child meets the frame through the commands it already knows. |
|
cardcost
Package cardcost is what a card cost: a route's price sheet as nova-config holds it (the route kind's price fields, docs/SPEC-CONFIG.md, "route"), the tokens one run spent by class, the predicted cost of the one priced by the other, and the usage record a consumer card keeps (docs/SPEC-SPRINT.md, "What a card cost"), in exact decimal arithmetic.
|
Package cardcost is what a card cost: a route's price sheet as nova-config holds it (the route kind's price fields, docs/SPEC-CONFIG.md, "route"), the tokens one run spent by class, the predicted cost of the one priced by the other, and the usage record a consumer card keeps (docs/SPEC-SPRINT.md, "What a card cost"), in exact decimal arithmetic. |
|
cardhdr
Package cardhdr is the card header's vocabulary: the kinds and routes a card's KIND and ROUTE lines may carry, and the one reader of a `KEY: value` header line.
|
Package cardhdr is the card header's vocabulary: the kinds and routes a card's KIND and ROUTE lines may carry, and the one reader of a `KEY: value` header line. |
|
cardlimits
Package cardlimits holds the two sizes a card's brief is held to, in one place that nothing is behind: no redis client, no table layer, no store.
|
Package cardlimits holds the two sizes a card's brief is held to, in one place that nothing is behind: no redis client, no table layer, no store. |
|
cardtree
Package cardtree is a card as a tree of steps (docs/SPEC-SPRINT.md, "A card is a tree of steps"; nova-tools#5174 rule 7): the grammar of numbered step blocks, the lint of a tree, the script step the member runs with no model, the verdict per step, and the remainder a failed step leaves.
|
Package cardtree is a card as a tree of steps (docs/SPEC-SPRINT.md, "A card is a tree of steps"; nova-tools#5174 rule 7): the grammar of numbered step blocks, the lint of a tree, the script step the member runs with no model, the verdict per step, and the remainder a failed step leaves. |
|
config
Package config is nova-config's library: the permanent, non-ephemeral configuration of the fleet, kept in Postgres (schema `config`) and applied into Redis so Redis is always a rebuildable copy of the configuration.
|
Package config is nova-config's library: the permanent, non-ephemeral configuration of the fleet, kept in Postgres (schema `config`) and applied into Redis so Redis is always a rebuildable copy of the configuration. |
|
decide
Package decide is a decision system that is trained from its own record (docs/SPEC-NOVA-DECIDE.md).
|
Package decide is a decision system that is trained from its own record (docs/SPEC-NOVA-DECIDE.md). |
|
delayproxy
Package delayproxy is a TCP proxy that holds every write of its clients back by a fixed time before it forwards it: a store that stands far away, made on the loopback.
|
Package delayproxy is a TCP proxy that holds every write of its clients back by a fixed time before it forwards it: a store that stands far away, made on the loopback. |
|
diffcheck
Package diffcheck is the lander's mechanical checks of one card's diff, the two the calibration of the decide read found a model read does not make (docs/SPEC-SPRINT.md section 7, the lander's checks): every file the diff changes is one the card's PATHS names (E12), and no changed line leaves a stranded sentence fragment or an unmatched backquote beside it (E4).
|
Package diffcheck is the lander's mechanical checks of one card's diff, the two the calibration of the decide read found a model read does not make (docs/SPEC-SPRINT.md section 7, the lander's checks): every file the diff changes is one the card's PATHS names (E12), and no changed line leaves a stranded sentence fragment or an unmatched backquote beside it (E4). |
|
dogfood
Package dogfood answers one question about a tool that its own tests cannot: has somebody who did not write it actually run it?
|
Package dogfood answers one question about a tool that its own tests cannot: has somebody who did not write it actually run it? |
|
filelock
Package filelock is the one lock on a file across processes: the kernel's lock (flock on unix, LockFileEx on Windows), released by the kernel when its holder dies, with the holder's stamp written inside the file for a refusal to name.
|
Package filelock is the one lock on a file across processes: the kernel's lock (flock on unix, LockFileEx on Windows), released by the kernel when its holder dies, with the holder's stamp written inside the file for a refusal to name. |
|
fleet
Package fleet holds the machines registry: the one file that says what each machine in the fleet IS, and therefore what may be placed on it.
|
Package fleet holds the machines registry: the one file that says what each machine in the fleet IS, and therefore what may be placed on it. |
|
friend
Package friend is what a friend's machinery runs to be part of the team (docs/SPEC-FRIEND.md; the model is tla/Friend.tla).
|
Package friend is what a friend's machinery runs to be part of the team (docs/SPEC-FRIEND.md; the model is tla/Friend.tla). |
|
friend/friendtest
Package friendtest holds the test doubles of pkg/friend that tests in other packages share.
|
Package friendtest holds the test doubles of pkg/friend that tests in other packages share. |
|
gitrun
Package gitrun is the one runner for a one-shot git child.
|
Package gitrun is the one runner for a one-shot git child. |
|
gocache
Package gocache holds a Go build cache under a size: least recently used entries go first, never one used in the last Recent, never anything that is not a cache entry.
|
Package gocache holds a Go build cache under a size: least recently used entries go first, never one used in the last Recent, never anything that is not a cache entry. |
|
goenv
Package goenv builds the environment a tool hands to a child `go` command.
|
Package goenv builds the environment a tool hands to a child `go` command. |
|
harness
Package harness is the vocabulary of the harnesses a card's child runs under: the one word a route row, a packet and a launch name a harness by.
|
Package harness is the vocabulary of the harnesses a card's child runs under: the one word a route row, a packet and a launch name a harness by. |
|
hostload
Package hostload measures how busy a machine is, as a percent of all its cores: the CPU busy percent over an interval (the number Activity Monitor and top print), or, where that cannot be measured, the one-minute load average over the logical cores.
|
Package hostload measures how busy a machine is, as a percent of all its cores: the CPU busy percent over an interval (the number Activity Monitor and top print), or, where that cannot be measured, the one-minute load average over the logical cores. |
|
hygiene
Package hygiene is the one place that answers "is this diff clean", for the accept gate, for the merge lane and for a hand.
|
Package hygiene is the one place that answers "is this diff clean", for the accept gate, for the merge lane and for a hand. |
|
keyshape
Package keyshape holds the one predicate that says whether an environment NAME carries a secret: the env var value is never inspected, only the name.
|
Package keyshape holds the one predicate that says whether an environment NAME carries a secret: the env var value is never inspected, only the name. |
|
log
Package log is the one structured event line every part writes BESIDE the one human line it already writes.
|
Package log is the one structured event line every part writes BESIDE the one human line it already writes. |
|
member
Package member is a fleet member of a sprint: the loop a fleet machine runs against the sprint's fleet table (the machine's queue) and the sprint's verbs, with each card run as one child through a runner.
|
Package member is a fleet member of a sprint: the loop a fleet machine runs against the sprint's fleet table (the machine's queue) and the sprint's verbs, with each card run as one child through a runner. |
|
nsprint/fn
Package fn assembles and installs the nova-sprint Redis Function library.
|
Package fn assembles and installs the nova-sprint Redis Function library. |
|
nsprint/redisauth
Package redisauth is the one fleet Redis seat every tool dials with from the environment: the ACL user and the variable holding its password.
|
Package redisauth is the one fleet Redis seat every tool dials with from the environment: the ACL user and the variable holding its password. |
|
nsprint/testutil
Package testutil starts the throwaway Redis the nova-sprint controls share.
|
Package testutil starts the throwaway Redis the nova-sprint controls share. |
|
nsprint/testutil/pg
Package pg starts the throwaway Postgres the nova-config functional tests share, the way pkg/nsprint/testutil starts a throwaway Redis: initdb and pg_ctl from the binaries on PATH (or the well-known install directories, or NOVA_PG_BIN), a free loopback port, everything under the test's temporary directory, trust authentication, and the cleanup stops it.
|
Package pg starts the throwaway Postgres the nova-config functional tests share, the way pkg/nsprint/testutil starts a throwaway Redis: initdb and pg_ctl from the binaries on PATH (or the well-known install directories, or NOVA_PG_BIN), a free loopback port, everything under the test's temporary directory, trust authentication, and the cleanup stops it. |
|
nsprint/verbflag
Package verbflag is the one seam every living tool's verbs parse their flags through, so help and the CLI standard hold the same way for every verb.
|
Package verbflag is the one seam every living tool's verbs parse their flags through, so help and the CLI standard hold the same way for every verb. |
|
ntable
Package ntable is a general, Redis-backed table built from one primitive: the ordered set.
|
Package ntable is a general, Redis-backed table built from one primitive: the ordered set. |
|
onboarding
Package onboarding reads the two things docs/ONBOARDING.md makes every command in this repo carry — the `example:` block at the foot of its usage banner, and its `### First run` section in docs/TESTS.md — and reduces an output line to the part that document promises.
|
Package onboarding reads the two things docs/ONBOARDING.md makes every command in this repo carry — the `example:` block at the foot of its usage banner, and its `### First run` section in docs/TESTS.md — and reduces an output line to the part that document promises. |
|
oneline
Package oneline is the one escape every binary in this repo renders caller-supplied or stored text through before it reaches an event line.
|
Package oneline is the one escape every binary in this repo renders caller-supplied or stored text through before it reaches an event line. |
|
oneline/audit
Package audit is the source-level tripwire behind the one-line guarantee, shared by every binary in this repo.
|
Package audit is the source-level tripwire behind the one-line guarantee, shared by every binary in this repo. |
|
pkgselect
Package pkgselect chooses the Go packages a CI run tests and deals them to the legs that test them.
|
Package pkgselect chooses the Go packages a CI run tests and deals them to the legs that test them. |
|
provbalance
Package provbalance reads a model provider's balance through the seat's key: the transport of the sprint's balance poll (internal/sprint balance.go; nova-tools#5199).
|
Package provbalance reads a model provider's balance through the seat's key: the transport of the sprint's balance poll (internal/sprint balance.go; nova-tools#5199). |
|
readregular
Package readregular provides bounds-checked and type-checked file reads for regular files, rejecting non-regular files (such as FIFOs, devices, and sockets) and files that exceed an explicit size cap.
|
Package readregular provides bounds-checked and type-checked file reads for regular files, rejecting non-regular files (such as FIFOs, devices, and sockets) and files that exceed an explicit size cap. |
|
redisacl
Package redisacl renders the fleet store's ACL users from the function library a build embeds and the key families its tools use, and compares a rendering with a store's live ACL.
|
Package redisacl renders the fleet store's ACL users from the function library a build embeds and the key families its tools use, and compares a rendering with a store's live ACL. |
|
redisconn
Package redisconn is the one way a nova tool opens its Redis connection.
|
Package redisconn is the one way a nova tool opens its Redis connection. |
|
redisfn
Package redisfn builds, loads and checks a Redis function library from Lua source held in a file system, which for a tool is the Lua it embeds.
|
Package redisfn builds, loads and checks a Redis function library from Lua source held in a file system, which for a tool is the Lua it embeds. |
|
release
Package release is the last mile: a green commit on main becomes a version, a set of binaries, and the same binaries answering for themselves on every bench in the fleet.
|
Package release is the last mile: a green commit on main becomes a version, a set of binaries, and the same binaries answering for themselves on every bench in the fleet. |
|
safepath
Package safepath is the one way a path this tool COMPUTED is removed.
|
Package safepath is the one way a path this tool COMPUTED is removed. |
|
sandbox
The egress wall is the card's OUTBOUND half: the filesystem wall this package builds everywhere else says what a card may read and write, and this file says what it may talk to.
|
The egress wall is the card's OUTBOUND half: the filesystem wall this package builds everywhere else says what a card may read and write, and this file says what it may talk to. |
|
sandbox/darwincheck
Package darwincheck is the darwin profile check: it fills profiles/darwin.sb.tmpl for a scratch write set, then runs, INSIDE the wall and by ABSOLUTE path, the things a swarm worker does in its first second (cd, mkdir -p, git init, git clone --shared, a config write under HOME, cat /etc/hosts, /bin/sh -c true, killing its own child, stdout to a pipe and to a file in the write set), and asserts that a write outside, a read of the named secret, a listing of an ancestor, a connect to a socket outside the write set and a nested sandbox all FAIL, each with a control run OUTSIDE the wall so that a check cannot pass by being impossible.
|
Package darwincheck is the darwin profile check: it fills profiles/darwin.sb.tmpl for a scratch write set, then runs, INSIDE the wall and by ABSOLUTE path, the things a swarm worker does in its first second (cd, mkdir -p, git init, git clone --shared, a config write under HOME, cat /etc/hosts, /bin/sh -c true, killing its own child, stdout to a pipe and to a file in the write set), and asserts that a write outside, a read of the named secret, a listing of an ancestor, a connect to a socket outside the write set and a nested sandbox all FAIL, each with a control run OUTSIDE the wall so that a check cannot pass by being impossible. |
|
seatcred
Package seatcred resolves a seat's fleet Redis user and password in the process that needs them (nova-tools#4052).
|
Package seatcred resolves a seat's fleet Redis user and password in the process that needs them (nova-tools#4052). |
|
seatcred/seattest
Package seattest builds a real nova-secrets store for a test: a git working copy with an upstream, recovery.pub, .sops.yaml and one seat's file sealed by sops to a fresh age key, laid out where pkg/seatcred looks by default under a temporary HOME.
|
Package seattest builds a real nova-secrets store for a test: a git working copy with an upstream, recovery.pub, .sops.yaml and one seat's file sealed by sops to a fresh age key, laid out where pkg/seatcred looks by default under a temporary HOME. |
|
secretcheck
Package secretcheck is the harness of the class rule "no secret reaches an error" (docs/SPEC-CI.md, `secrets-never-in-errors`): secret-shaped inputs, a driver that hands them to a function by reflection and reads what came back, and the two-way comparisons of a reviewed table and allowlist with what a walk of the tree finds.
|
Package secretcheck is the harness of the class rule "no secret reaches an error" (docs/SPEC-CI.md, `secrets-never-in-errors`): secret-shaped inputs, a driver that hands them to a function by reflection and reads what came back, and the two-way comparisons of a reviewed table and allowlist with what a walk of the tree finds. |
|
secrets
Package secrets implements the credential-layer machinery described in docs/SPEC-SECRETS.md.
|
Package secrets implements the credential-layer machinery described in docs/SPEC-SECRETS.md. |
|
sprintwire
Package sprintwire is how a worker talks to the sprint's server: the run loop on the coordinator's machine, the one writer of the sprint, which runs a worker's verbs for it, one at a time, beside the store.
|
Package sprintwire is how a worker talks to the sprint's server: the run loop on the coordinator's machine, the one writer of the sprint, which runs a worker's verbs for it, one at a time, beside the store. |
|
subproc
Package subproc is the one place a child process gets its bound.
|
Package subproc is the one place a child process gets its bound. |
|
swarm
Package swarm is nova-swarm's machinery: a pool of one-task workers, each with its own working directory, its own data home, its own job directory and its own deadline held by the machinery rather than by the worker.
|
Package swarm is nova-swarm's machinery: a pool of one-task workers, each with its own working directory, its own data home, its own job directory and its own deadline held by the machinery rather than by the worker. |
|
testbin
Package testbin places a built program into a test's directory.
|
Package testbin places a built program into a test's directory. |
|
testgit
Package testgit is the one identity a test's git commit runs under.
|
Package testgit is the one identity a test's git commit runs under. |
|
testguard
Package testguard refuses to let a unit test reach a real host.
|
Package testguard refuses to let a unit test reach a real host. |
|
testkit
Package testkit holds the test rigs that were copied from package to package: running a tool's entry point in process with both streams captured and checked (verb.go), writing and reading the files a test sets up (here and tree.go), a recording wait for code a synctest bubble cannot hold (waits.go) and a skip by platform (skip.go).
|
Package testkit holds the test rigs that were copied from package to package: running a tool's entry point in process with both streams captured and checked (verb.go), writing and reading the files a test sets up (here and tree.go), a recording wait for code a synctest bubble cannot hold (waits.go) and a skip by platform (skip.go). |
|
testredis
Package testredis is a throwaway redis-server for one test.
|
Package testredis is a throwaway redis-server for one test. |
|
tlc
Package tlc runs TLC over the declared cases of tla/CASES.tsv and reads what it says.
|
Package tlc runs TLC over the declared cases of tla/CASES.tsv and reads what it says. |
|
tool
Package tool is the one shape of a nova command.
|
Package tool is the one shape of a nova command. |
|
tty
Package tty says whether a file is a terminal and how large its screen is, on the systems that have a terminal to ask (the unix family and Windows); elsewhere a file is never a terminal and its size is not known.
|
Package tty says whether a file is a terminal and how large its screen is, on the systems that have a terminal to ask (the unix family and Windows); elsewhere a file is never a terminal and its size is not known. |
|
typedrec
Package typedrec is the one typed parser: the home of every typed line a nova tool reads, the RESULT v2 record and DISPOSITION line first, and the Lua replies (the PATHS gate's refusal) and any other typed line with them.
|
Package typedrec is the one typed parser: the home of every typed line a nova tool reads, the RESULT v2 record and DISPOSITION line first, and the Lua replies (the PATHS gate's refusal) and any other typed line with them. |
|
units
Package units is the text and install of every unit a running sprint needs.
|
Package units is the text and install of every unit a running sprint needs. |
|
Package profiles holds the generated-policy TEMPLATES this repository ships, and it exists so that the tool and tools/sandboxcheck fill ONE text rather than two (SPEC-SANDBOX rule 15, and the work list's "the file is embedded with go:embed").
|
Package profiles holds the generated-policy TEMPLATES this repository ships, and it exists so that the tool and tools/sandboxcheck fill ONE text rather than two (SPEC-SANDBOX rule 15, and the work list's "the file is embedded with go:embed"). |
|
tools
|
|
|
agentsmap
command
Command agentsmap regenerates the repository's AGENTS.md map: one root page carrying docs/STANDARD.md whole, plus a page per big tree, each a table of directory → purpose → guarding test → one command.
|
Command agentsmap regenerates the repository's AGENTS.md map: one root page carrying docs/STANDARD.md whole, plus a page per big tree, each a table of directory → purpose → guarding test → one command. |
|
analyzers/cmd/vetlaw
command
|
|
|
benchstandard
command
Command benchstandard is the acceptance WITNESS for a Linux bench: it checks the bench it runs on against the standard and prints one DRIFT line per finding.
|
Command benchstandard is the acceptance WITNESS for a Linux bench: it checks the bench it runs on against the standard and prints one DRIFT line per finding. |
|
ci
command
Command ci holds the verbs this repository's own CI and Makefile call: the programs that were shell steps and scripts, in Go, each with a test that pins what it does.
|
Command ci holds the verbs this repository's own CI and Makefile call: the programs that were shell steps and scripts, in Go, each with a test that pins what it does. |
|
clidoc
command
clidoc rewrites the reference blocks between docs/CLI.md's clidoc markers from the built tools' own help, so the reference cannot drift from the binaries it documents.
|
clidoc rewrites the reference blocks between docs/CLI.md's clidoc markers from the built tools' own help, so the reference cannot drift from the binaries it documents. |
|
fardelay
command
Command fardelay makes a TCP server, usually a store, look far away, as a process: a TCP proxy that listens on the loopback, forwards every connection to a target, and holds each write of the client back by a fixed delay before it forwards it.
|
Command fardelay makes a TCP server, usually a store, look far away, as a process: a TCP proxy that listens on the loopback, forwards every connection to a target, and holds each write of the client back by a fixed delay before it forwards it. |
|
functionalrun
command
Command functionalrun runs the functional tier (the tests behind `//go:build functional`) inside ONE container per run, so every dependency a test starts (redis-server, postgres, a built binary) lives and dies with the container.
|
Command functionalrun runs the functional tier (the tests behind `//go:build functional`) inside ONE container per run, so every dependency a test starts (redis-server, postgres, a built binary) lives and dies with the container. |
|
ghrelease
command
Command ghrelease holds the verbs a GitHub release runs: the ldflags a build is stamped with, the build of every shipped tool for one platform, the checksums over the whole shipped set, the assertion that every binary reports the tag it was built from, the gate that asks whether a green certification run vouches for a commit, and the upload that attaches the set to a release draft and never to a published release.
|
Command ghrelease holds the verbs a GitHub release runs: the ldflags a build is stamped with, the build of every shipped tool for one platform, the checksums over the whole shipped set, the assertion that every binary reports the tag it was built from, the gate that asks whether a green certification run vouches for a commit, and the upload that attaches the set to a release draft and never to a published release. |
|
newrule
command
|
|
|
newverb
command
|
|
|
notes20261002
command
Command notes20261002 writes the notes of 2026-10-02 into nova-config: the reason each route the first real sprint disabled was disabled, and why one machine is held, as the `note` of the row (pkg/config, migration 0015; docs/SPEC-CONFIG.md, "The note").
|
Command notes20261002 writes the notes of 2026-10-02 into nova-config: the reason each route the first real sprint disabled was disabled, and why one machine is held, as the `note` of the row (pkg/config, migration 0015; docs/SPEC-CONFIG.md, "The note"). |
|
preflight
command
Command preflight is the standard check before a card is submitted or a pull request is opened: gofmt, go vet, and the unit tests through `make test-full`, in that order, stopping at the first that fails.
|
Command preflight is the standard check before a card is submitted or a pull request is opened: gofmt, go vet, and the unit tests through `make test-full`, in that order, stopping at the first that fails. |
|
roadmap
command
roadmap writes ROADMAP.md from docs/roadmap.sexp (and, with --kind fixes, FIXES.md from docs/fixes.sexp), so neither page is ever written by hand: the sexp is the data, internal/roadmap decodes it through internal/roadmap/sexp (nothing is evaluated) and renders the page, and internal/docs's TestRoadmapIsGeneratedFromTheSexp and TestFixesIsGeneratedFromTheSexp hold the committed pages to what this writes.
|
roadmap writes ROADMAP.md from docs/roadmap.sexp (and, with --kind fixes, FIXES.md from docs/fixes.sexp), so neither page is ever written by hand: the sexp is the data, internal/roadmap decodes it through internal/roadmap/sexp (nothing is evaluated) and renders the page, and internal/docs's TestRoadmapIsGeneratedFromTheSexp and TestFixesIsGeneratedFromTheSexp hold the committed pages to what this writes. |
|
sandboxcheck
command
Command sandboxcheck is the darwin profile check of nova-sandbox: it fills profiles/darwin.sb.tmpl for a scratch write set, then runs, INSIDE the wall and by ABSOLUTE path, the things a swarm worker does in its first second, and asserts that a write outside, a read of the named secret, a listing of an ancestor, a connect to a socket outside the write set and a nested sandbox all FAIL, each with a control run outside the wall so that a check cannot pass by being impossible.
|
Command sandboxcheck is the darwin profile check of nova-sandbox: it fills profiles/darwin.sb.tmpl for a scratch write set, then runs, INSIDE the wall and by ABSOLUTE path, the things a swarm worker does in its first second, and asserts that a write outside, a read of the named secret, a listing of an ancestor, a connect to a socket outside the write set and a nested sandbox all FAIL, each with a control run outside the wall so that a check cannot pass by being impossible. |
|
sessiontrace
command
Command sessiontrace captures bounded shell executions and validates them against TableSession with an installed TLC jar.
|
Command sessiontrace captures bounded shell executions and validates them against TableSession with an installed TLC jar. |
|
testmanifest
command
Command testmanifest runs an exact list of Go tests and refuses missing, duplicate, skipped, or failed results.
|
Command testmanifest runs an exact list of Go tests and refuses missing, duplicate, skipped, or failed results. |
|
tlacheck
command
Command tlacheck runs the TLA+ model checks of this repository: the declared cases of tla/CASES.tsv with their run records, the table model's suites, the replay of the table model's findings against a table.lua, and the execution replay of table.lua receipts against EpochMemberTable.
|
Command tlacheck runs the TLA+ model checks of this repository: the declared cases of tla/CASES.tsv with their run records, the table model's suites, the replay of the table model's findings against a table.lua, and the execution replay of table.lua receipts against EpochMemberTable. |
Click to show internal directories.
Click to hide internal directories.
