26382a7ac6
CI / Clippy (push) Failing after 15m13s
CI / Test (ubuntu-latest) (push) Failing after 16m1s
CI / Test (macos-latest) (push) Has been cancelled
CI / Test (windows-latest) (push) Has been cancelled
CI / Build (no embeddings / no ORT) (push) Has been cancelled
CI / Format (push) Has been cancelled
CI / Cookbook (Node) (push) Has been cancelled
CI / Pi Extension (Node) (push) Has been cancelled
CI / Rust SDK (lean-ctx-client) (push) Has been cancelled
CI / Embed SDK (lean-ctx-sdk) (push) Has been cancelled
CI / Python SDK (leanctx) (push) Has been cancelled
CI / Hermes Plugin (Python) (push) Has been cancelled
CI / SDK Conformance Matrix (push) Has been cancelled
CI / Coverage (push) Has been cancelled
CI / cargo-deny (push) Has been cancelled
CI / Adversarial Safety (push) Has been cancelled
CI / Benchmarks (push) Has been cancelled
CI / Output-Quality Gate (eval A/B) (push) Has been cancelled
CI / Documentation (push) Has been cancelled
CI / CI Green (push) Has been cancelled
JetBrains Plugin / Actionlint (push) Has been cancelled
CodeQL / Analyze (actions) (push) Has been cancelled
CodeQL / Analyze (javascript-typescript) (push) Has been cancelled
CodeQL / Analyze (rust) (push) Has been cancelled
JetBrains Plugin / Validation (push) Has been cancelled
JetBrains Plugin / Build (push) Has been cancelled
JetBrains Plugin / Test (push) Has been cancelled
Security Check / Security Scan (push) Has been cancelled
2.9 KiB
2.9 KiB
Graph Reproducibility Contract v1
GitLab: #2318
Goal
Make graph-driven tooling reproducible (CI/proofs), deterministic (stable ordering), bounded (output caps), and safe-by-default.
This contract covers:
- Property graph storage under
$LEAN_CTX_DATA_DIR/graphs/<project_hash>/graph.db - Graph build + freshness semantics (
ctx_impact action=build|status) - Deterministic exports from
ctx_impactandctx_architecture(incl.format=json) - Architecture proof artifacts exported via
ctx_proof
Version (SSOT)
leanctx.contract.graph_reproducibility_v1.schema_version=1- SSOT:
CONTRACTS.md - Runtime:
rust/src/core/contracts.rs
- SSOT:
Build triggers & freshness
Auto-build (zero-config)
- Tools may auto-build the property graph when it is missing/empty:
ctx_impact action=analyze(auto-build if empty)ctx_architecture action=overview|...(auto-build if empty)
Explicit rebuild
ctx_impact action=buildis the authoritative rebuild:- Clears and rebuilds
graph.db(in$LEAN_CTX_DATA_DIR/graphs/<project_hash>/) - Writes
graph.meta.jsonalongside the database
- Clears and rebuilds
Freshness check
ctx_impact action=statusreports whether the graph looks fresh or stale.- Staleness is determined by comparing build metadata (git head/dirty) to current repo state when available.
Determinism (MUST)
Same repo snapshot + same policies ⇒ same logical outputs (stable ordering + stable truncation).
Rules:
- File enumeration during
buildis sorted lexicographically (relative paths). - Resolved import targets are sorted + deduplicated before inserting edges.
- Traversal adjacency lists are sorted + deduplicated (BFS/DFS becomes deterministic).
- Output lists are stable-sorted, then truncated with explicit
truncatedmarkers.
Output format (tools)
Both tools accept:
format=text|json(default:text)
When format=json:
- Output is machine-readable JSON (no token-suffix lines).
- Payload includes:
schema_version(Graph Reproducibility Contract v1)tool,actionproject.project_root_hash+project.project_identity_hash(hash-only; never leak identity strings)graphsummary (exists, nodes, edges, db_path)- action-specific fields +
truncatedflags
Proof artifacts (architecture overview)
When exporting proofs with ctx_proof write=true, the runtime also exports:
architecture-overview-v1_<ts>.jsonarchitecture-overview-v1_<ts>.html
to .lean-ctx/proofs/ (redacted-by-default for CI attachment safety).
Boundedness (MUST)
Graph tool outputs are capped by hard budgets (see rust/src/core/budgets.rs) to prevent DoS/token-burn.
Security & privacy
- Graph DB + meta are written only under the project’s
.lean-ctx/directory. - Proof artifacts are redacted before writing (same safety policy as other proof exports).
- No secrets must appear in graph artifacts, logs, or exports.