1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
# Default `kkernel code-audit` policy for the khive workspace itself
# (ADR-Q1/Q2 phase 1 — see docs/adr/ADR-114-code-audit-derived-report.md).
#
# `crate_ranks` is the versioned, total layer mapping the audit's layering
# signal evaluates `depends_on` project edges against: a source crate may only
# depend on a target crate at the same or a lower rank. Crates absent from
# this table degrade their layering signal to `unavailable`
# (`POLICY_INCOMPLETE`) rather than being silently treated as rank 0 — this
# now applies to every in-scope crate regardless of whether it appears in any
# evaluated edge.
#
# Ranks below are the longest-path depth of each crate's PRODUCTION
# `[dependencies]` graph (dev-dependencies excluded — several packs carry
# deliberate cyclic dev-only test deps, e.g. khive-pack-kg/khive-pack-gtd and
# khive-pack-brain/khive-pack-memory; production dependencies among them do
# not cycle). Every ingested `project` in the code map must appear here — the
# Rust crates under `crates/` and every other manifest `code.ingest` resolves
# (the npm distribution packages, the Python contract/workspace projects).
# Those non-crate projects form a dependency island disconnected from the Rust
# crate graph (no cross edges), so their ranks are evaluated in isolation and
# never interact with the crate ranks above.
= 1
= 0.0
# Same-band pairs that are structurally allowed to depend on each other even
# though `rank(target) == rank(source)` (e.g. sibling packs). Empty by
# default: the khive workspace's pack layer has no approved lateral edges
# today; add pairs here only with a recorded rationale. Must be declared
# before the `[crate_ranks]` table below — TOML would otherwise fold it into
# that table instead of the document root.
= []
[]
= 0
= 0
= 0
= 0
= 1
= 1
= 1
= 1
= 1
= 1
= 1
= 1
= 1
= 2
= 2
= 2
= 2
= 2
= 3
= 3
= 4
= 4
= 5
= 5
= 5
= 5
= 5
= 5
= 5
= 5
= 5
= 5
= 5
= 5
= 5
= 5
= 5
= 6
= 6
= 6
= 7
= 8
# Non-crate projects the workspace also ships and `code.ingest` resolves. The
# npm distribution graph is a real DAG evaluated in isolation: the six
# platform-native kernel binaries are leaves, the `khive` npm root bundles them
# as optional platform deps (rank 1), and `@khive-ai/cli` aliases `khive`
# (rank 2). `khive-contract` (Python contract-test harness) and
# `khive-workspace` have no in-map project dependencies (their specifiers
# resolve outside the code map), so they are leaves in the project graph
# (rank 0).
= 0
= 0
= 0
= 0
= 0
= 0
= 1
= 2
= 0
= 0