internal/

directory
v0.161.1 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 23, 2026 License: Apache-2.0

Directories

Path Synopsis
Package agentguard refuses agent tool calls that would write into a canonical clone.
Package agentguard refuses agent tool calls that would write into a canonical clone.
Package agents dispatches one bounded coding task to one configured agent harness running inside an isolated WB worktree, and reports the execution facts of that run to whoever asks later.
Package agents dispatches one bounded coding task to one configured agent harness running inside an isolated WB worktree, and reports the execution facts of that run to whoever asks later.
Package archiveprune audits and, only under explicit apply, deletes local clones of repositories confirmed archived on GitHub.
Package archiveprune audits and, only under explicit apply, deletes local clones of repositories confirmed archived on GitHub.
Package buildinfo resolves the running WB binary's version so that any package can record it, not just the command layer.
Package buildinfo resolves the running WB binary's version so that any package can record it, not just the command layer.
Package canonicalrescue moves uncommitted work out of a canonical clone onto a branch, without discarding anything and without disturbing the clone.
Package canonicalrescue moves uncommitted work out of a canonical clone onto a branch, without discarding anything and without disturbing the clone.
Package checkoutmarker writes one `.worktree.md` into every checkout, stating what that checkout is and whether it may be written to.
Package checkoutmarker writes one `.worktree.md` into every checkout, stating what that checkout is and whether it may be written to.
Package ciaudit checks repository CI/CD files for explicit coverage gates and build-once artifact promotion.
Package ciaudit checks repository CI/CD files for explicit coverage gates and build-once artifact promotion.
Package console reports whether wb is attached to a human terminal.
Package console reports whether wb is attached to a human terminal.
Package daemon owns the durable local lifecycle record for the WB daemon.
Package daemon owns the durable local lifecycle record for the WB daemon.
Package dashboard serves WB's local read-only operations dashboard and API.
Package dashboard serves WB's local read-only operations dashboard and API.
Package deps coordinates exact dependency updates across isolated repository worktrees.
Package deps coordinates exact dependency updates across isolated repository worktrees.
Package discover finds the repositories to operate on by reconciling the local ~/projects/{org}/{repo} tree with the non-archived repositories GitHub reports for the relevant orgs.
Package discover finds the repositories to operate on by reconciling the local ~/projects/{org}/{repo} tree with the non-archived repositories GitHub reports for the relevant orgs.
Package disk reports where the bytes WB causes to exist actually are, and how much room is left for the next one.
Package disk reports where the bytes WB causes to exist actually are, and how much room is left for the next one.
Package diskusage measures a directory tree twice: the size it appears to occupy, and the size deleting it would actually reclaim.
Package diskusage measures a directory tree twice: the size it appears to occupy, and the size deleting it would actually reclaim.
Package encode renders wb's report types as JSON.
Package encode renders wb's report types as JSON.
Package envguard isolates a validation subprocess's environment from ambient machine state that has no lifecycle owner: a go.work file left above the process's TMPDIR or the repository being validated, an inherited GOWORK override, and WB_AGENT_* identity variables exported by whichever agent happens to be operating the shell that launched wb.
Package envguard isolates a validation subprocess's environment from ambient machine state that has no lifecycle owner: a go.work file left above the process's TMPDIR or the repository being validated, an inherited GOWORK override, and WB_AGENT_* identity variables exported by whichever agent happens to be operating the shell that launched wb.
Package fleetsync decides and performs the sync action for a single repo: clone or pull an active repo, or — only when the caller explicitly opts in — remove an archived one's local clone.
Package fleetsync decides and performs the sync action for a single repo: clone or pull an active repo, or — only when the caller explicitly opts in — remove an archived one's local clone.
gen
Package gitops wraps the git and gh commands needed to read the default branch of a repo and to land a change on it — pushing directly when allowed, or opening an auto-merge PR when the branch is protected.
Package gitops wraps the git and gh commands needed to read the default branch of a repo and to land a change on it — pushing directly when allowed, or opening an auto-merge PR when the branch is protected.
Package gitremote validates the portable, credential-free identity of Git remotes carried across WB session-move boundaries.
Package gitremote validates the portable, credential-free identity of Git remotes carried across WB session-move boundaries.
Package graduation composes independently produced WB and deployment evidence into one strict, reviewable graduation receipt.
Package graduation composes independently produced WB and deployment evidence into one strict, reviewable graduation receipt.
Package herdr is a thin, mechanical adapter over the herdr CLI (https://herdr.dev), the terminal workspace manager that hosts the founder's live agent panes.
Package herdr is a thin, mechanical adapter over the herdr CLI (https://herdr.dev), the terminal workspace manager that hosts the founder's live agent panes.
Package hooks manages declarative, user-owned Git hook templates.
Package hooks manages declarative, user-owned Git hook templates.
Package hostload refuses to admit more CPU-heavy WB work when the host is already saturated.
Package hostload refuses to admit more CPU-heavy WB work when the host is already saturated.
Package hubconfig reads the optional `hub:` section of ~/.config/wb/wb.yaml, which turns `wb daemon serve` into the self-hosting unit for bench.
Package hubconfig reads the optional `hub:` section of ~/.config/wb/wb.yaml, which turns `wb daemon serve` into the self-hosting unit for bench.
Package hubstore opens the DALgo engine a self-hosted bench hub runs on and wraps it in the githubapp.DocumentStore seam every hub-owned store writes through.
Package hubstore opens the DALgo engine a self-hosted bench hub runs on and wraps it in the githubapp.DocumentStore seam every hub-owned store writes through.
Package landinglane records exclusive ownership of one (repository, target) landing lane so two live sessions never drive `wb pr land` or `wb worktree merge` toward the same target branch at once.
Package landinglane records exclusive ownership of one (repository, target) landing lane so two live sessions never drive `wb pr land` or `wb worktree merge` toward the same target branch at once.
Package layout audits and safely cleans local clone placement under a projects root.
Package layout audits and safely cleans local clone placement under a projects root.
Package lifecyclehooks runs trusted user-configured commands after WB changes a repository checkout.
Package lifecyclehooks runs trusted user-configured commands after WB changes a repository checkout.
Package locallink builds a consumer against a library's *working tree* instead of a published version, so a change is proven across every affected repository before anything is published.
Package locallink builds a consumer against a library's *working tree* instead of a published version, so a change is proven across every affected repository before anything is published.
Package mergeack owns the on-disk shape, identity hash, and full validation of a worktree-merge absorbed-conflict acknowledgement -- the sidecar `wb worktree merge acknowledge-absorbed-conflict` writes next to a worktree-merge receipt whose every receipted source worktree is gone, once each source's content is proved already reachable from the current remote target.
Package mergeack owns the on-disk shape, identity hash, and full validation of a worktree-merge absorbed-conflict acknowledgement -- the sidecar `wb worktree merge acknowledge-absorbed-conflict` writes next to a worktree-merge receipt whose every receipted source worktree is gone, once each source's content is proved already reachable from the current remote target.
Package migrate plans and applies declarative source migrations.
Package migrate plans and applies declarative source migrations.
Package nodeidentity resolves the stable node ID every WB daemon carries, per spec/features/peer-connectivity#req:node-identity.
Package nodeidentity resolves the stable node ID every WB daemon carries, per spec/features/peer-connectivity#req:node-identity.
Package npmrelease coordinates an approved npm publication workflow without ever handling npm credentials.
Package npmrelease coordinates an approved npm publication workflow without ever handling npm credentials.
Package orchestrate runs typed repository mutations through isolated worktrees, local verification, and optional GitHub publication stages.
Package orchestrate runs typed repository mutations through isolated worktrees, local verification, and optional GitHub publication stages.
Package pathguard declares the paths a WB command needs to write to and turns a denial into an actionable diagnostic.
Package pathguard declares the paths a WB command needs to write to and turns a denial into an actionable diagnostic.
Package peers serves the one versioned peers read model peer-connectivity#req:peers-api requires, mounted identically in three places: the local daemon API (`GET /api/v1/peers`), the hub dashboard reads (`GET /v0/workbench/peers`), and — later, behind admin-requires-owner-credential — the admin write routes.
Package peers serves the one versioned peers read model peer-connectivity#req:peers-api requires, mounted identically in three places: the local daemon API (`GET /api/v1/peers`), the hub dashboard reads (`GET /v0/workbench/peers`), and — later, behind admin-requires-owner-credential — the admin write routes.
Package prinventory owns the remote pull-request inventory.
Package prinventory owns the remote pull-request inventory.
Package process starts bounded subprocesses with a lifecycle that owns their descendants as well as their direct child.
Package process starts bounded subprocesses with a lifecycle that owns their descendants as well as their direct child.
Package progress defines the transport-neutral event contract used by long-running WB operations.
Package progress defines the transport-neutral event contract used by long-running WB operations.
Package provenance reads the harness identity a WB record can safely carry, at zero cost: environment variables and the already-resolved wb build version, nothing else.
Package provenance reads the harness identity a WB record can safely carry, at zero cost: environment variables and the already-resolved wb build version, nothing else.
Package prsnapshot is one bounded, single-observation read of a pull request's current state and check verdict: no poll loop, no confirming reread, no target-branch strict-freshness fence.
Package prsnapshot is one bounded, single-observation read of a pull request's current state and check verdict: no poll loop, no confirming reread, no target-branch strict-freshness fence.
Package prwatch is the daemon's watcher for herdr-session-transport (spec/plans/herdr-session-transport.md, Task 6): it discovers pull requests worth watching only through worktrees.ListRegisteredPullRequestBindings — the first reader of the binding `wb pr create` already records via worktrees.RecordClaimPullRequestBinding — and evaluates each one's current state through prsnapshot.Observe, the same renamed-required-check-aware logic `wb wait pr` and `wb ci wait` already use.
Package prwatch is the daemon's watcher for herdr-session-transport (spec/plans/herdr-session-transport.md, Task 6): it discovers pull requests worth watching only through worktrees.ListRegisteredPullRequestBindings — the first reader of the binding `wb pr create` already records via worktrees.RecordClaimPullRequestBinding — and evaluates each one's current state through prsnapshot.Observe, the same renamed-required-check-aware logic `wb wait pr` and `wb ci wait` already use.
Package quality runs read-only coverage and verification checks for a local repository fleet.
Package quality runs read-only coverage and verification checks for a local repository fleet.
Package recipe implements wb's config-driven fleet operations: a Recipe describes how to detect and mutate matching repos, and how to land the result via the same worktree/commit/push-or-PR flow used everywhere else in wb.
Package recipe implements wb's config-driven fleet operations: a Recipe describes how to detect and mutate matching repos, and how to land the result via the same worktree/commit/push-or-PR flow used everywhere else in wb.
Package remotessh is WB's single remote-call boundary: it builds the OpenSSH invocation, resolves the local ssh executable, and bounds what a remote response can make WB hold in memory.
Package remotessh is WB's single remote-call boundary: it builds the OpenSSH invocation, resolves the local ssh executable, and bounds what a remote response can make WB hold in memory.
Package remotestate publishes one machine's WB fleet state to a shared store and reads every machine's state back.
Package remotestate publishes one machine's WB fleet state to a shared store and reads every machine's state back.
gitrepo
Package gitrepo stores machine snapshots in a git repository: one file per machine, history for free, no server.
Package gitrepo stores machine snapshots in a git repository: one file per machine, history for free, no server.
hub
Package repopath models the canonical clone layout below a projects root: <root>/<host>/<org>/<repository>.
Package repopath models the canonical clone layout below a projects root: <root>/<host>/<org>/<repository>.
Package repositoryevents receives provider-owned repository events and turns them into durable local sync jobs.
Package repositoryevents receives provider-owned repository events and turns them into durable local sync jobs.
Package retiredcandidateack owns the candidate-only acknowledgement used to retire an unpublished integration candidate after its recorded target was deleted.
Package retiredcandidateack owns the candidate-only acknowledgement used to retire an unpublished integration candidate after its recorded target was deleted.
Package runlog records privacy-safe telemetry for commands launched through `wb run --`.
Package runlog records privacy-safe telemetry for commands launched through `wb run --`.
Package runqueue coordinates CPU-heavy commands across WB processes.
Package runqueue coordinates CPU-heavy commands across WB processes.
Package scan inspects a repository working tree.
Package scan inspects a repository working tree.
Package secretscan is WB's deterministic secret-shape gate for agent-authored continuation text (wb session move's handover and wb session park's continuation).
Package secretscan is WB's deterministic secret-shape gate for agent-authored continuation text (wb session move's handover and wb session park's continuation).
Package session records which agent sessions are running on this machine.
Package session records which agent sessions are running on this machine.
Package sessionauthority defines the transport-neutral authority consumed by the shared pinned-worktree and successor-launch primitives.
Package sessionauthority defines the transport-neutral authority consumed by the shared pinned-worktree and successor-launch primitives.
Package sessioncourier delivers WB-owned session handoff protocol values.
Package sessioncourier delivers WB-owned session handoff protocol values.
Package sessioncustody owns source-side receipt acknowledgement.
Package sessioncustody owns source-side receipt acknowledgement.
Package sessionlaunch owns the fixed target-side harness launch boundary.
Package sessionlaunch owns the fixed target-side harness launch boundary.
Package sessionmessage owns durable follow-up delivery to a completed session-move successor.
Package sessionmessage owns durable follow-up delivery to a completed session-move successor.
Package sessionmessenger owns source-side durable session-message delivery.
Package sessionmessenger owns source-side durable session-message delivery.
Package sessionmove defines WB's portable agent-session handoff protocol and the local durable aggregate used by both source and target machines.
Package sessionmove defines WB's portable agent-session handoff protocol and the local durable aggregate used by both source and target machines.
Package sessionpark stores a complete, durable checkpoint for a parked WB session.
Package sessionpark stores a complete, durable checkpoint for a parked WB session.
Package sessionparkcourier transports canonical parked-session envelopes.
Package sessionparkcourier transports canonical parked-session envelopes.
Package sessionparkreceive owns target-side admission and atomic execution of one parked multi-worktree bundle.
Package sessionparkreceive owns target-side admission and atomic execution of one parked multi-worktree bundle.
Package sessionreceive owns target-side request admission, pinned-worktree recovery, successor launch, and completed-receipt publication.
Package sessionreceive owns target-side request admission, pinned-worktree recovery, successor launch, and completed-receipt publication.
Package sessiontransport defines the one Go transport interface WB's session layer addresses a terminal through (REQ:single-transport-interface), the typed capability matrix each implementation declares (REQ:transport-capability-matrix), and the capability-driven guard that decides record-only vs.
Package sessiontransport defines the one Go transport interface WB's session layer addresses a terminal through (REQ:single-transport-interface), the typed capability matrix each implementation declares (REQ:transport-capability-matrix), and the capability-driven guard that decides record-only vs.
transporttest
Package transporttest is the shared contract test suite REQ:two-transport-implementations requires: Task 3's tmux transport and Task 4's herdr transport must both pass it, and neither needs a distinct suite of its own to prove it satisfies sessiontransport.Transport (AC:two-implementations-satisfy-the-same-interface).
Package transporttest is the shared contract test suite REQ:two-transport-implementations requires: Task 3's tmux transport and Task 4's herdr transport must both pass it, and neither needs a distinct suite of its own to prove it satisfies sessiontransport.Transport (AC:two-implementations-satisfy-the-same-interface).
Package streambranch names the branch namespace a dependency stream owns.
Package streambranch names the branch namespace a dependency stream owns.
Package streams owns the identity of a dependency stream: one named cross-repository unit of work spanning a library and the consumers that must change with it.
Package streams owns the identity of a dependency stream: one named cross-repository unit of work spanning a library and the consumers that must change with it.
Package streamsync keeps a stream branch current and verifies its batch.
Package streamsync keeps a stream branch current and verifies its batch.
Package syncreport defines the agent-authored, InGitDB-backed sync analysis records that WB validates and publishes to a user's workbench repository.
Package syncreport defines the agent-authored, InGitDB-backed sync analysis records that WB validates and publishes to a user's workbench repository.
Package testenv isolates a test process from the ambient machine state documented in internal/envguard: WB_AGENT_* variables inherited from whichever agent is operating the shell that launched `go test`, and an ambient GOWORK the test process would otherwise carry into every `go` invocation it makes.
Package testenv isolates a test process from the ambient machine state documented in internal/envguard: WB_AGENT_* variables inherited from whichever agent is operating the shell that launched `go test`, and an ambient GOWORK the test process would otherwise carry into every `go` invocation it makes.
Package tui holds the bubbletea models for `wb sync`'s progress display.
Package tui holds the bubbletea models for `wb sync`'s progress display.
Package waitregistry records outstanding delegated waits so that someone other than the waiting process can see them.
Package waitregistry records outstanding delegated waits so that someone other than the waiting process can see them.
Package wbconfig resolves the user-level WB configuration file that several commands share (recipes for wb run, the remote section for wb remote).
Package wbconfig resolves the user-level WB configuration file that several commands share (recipes for wb run, the remote section for wb remote).
Package wbhome resolves the directories WB uses to coordinate work across agents and sessions: task worktrees, operation locks, and reports.
Package wbhome resolves the directories WB uses to coordinate work across agents and sessions: task worktrees, operation locks, and reports.
Package worktreeend closes one task's worktrees: the verb every lane contract already tells an agent to finish with.
Package worktreeend closes one task's worktrees: the verb every lane contract already tells an agent to finish with.
Package worktrees creates and validates the isolated Git worktrees used for human and agent development.
Package worktrees creates and validates the isolated Git worktrees used for human and agent development.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL