Skip to main content

rto_graph/
lib.rs

1//! Provenance-tagged knowledge graph store.
2//!
3//! Every edge in a Roteiro graph carries a [`Provenance`] tag recording how it
4//! was produced: deterministically derived from source ASTs, authored by a
5//! human or agent in an ADR/blueprint, or inferred heuristically from docs and
6//! other artifacts. See ADR-0001.
7//!
8//! The graph is a set of [`Node`]s addressed by a deterministic natural
9//! [`Node::key`], connected by [`Edge`]s. Facts extracted from one source blob
10//! are grouped into a [`FactSet`] and applied atomically to a [`Store`].
11//!
12//! @rto:0001
13
14mod artifact;
15// Who wrote the change under review, from its `Co-Authored-By` trailers (#649).
16// In *this* crate for the reason `model_choice` and `review_corpus` are: the
17// comparison is against the model this crate resolves, and keeping the rule pure
18// is what lets "would this reviewer be reviewing its own work" be answered with
19// no engine, no git and no network.
20pub mod authorship;
21// Audio metadata (ADR-0016): codec, rate, bit depth, channels, duration and tags,
22// read from the container without decoding and without a model. Unlike the media
23// module below, these *are* `derived` facts and do live in `nodes`/`edges` — the
24// complement of ADR-0015 rather than an exception to it.
25#[cfg(feature = "audio-metadata")]
26pub mod audio;
27mod cache;
28// RFC 3339 UTC formatting for evidence timestamps (#667). Here rather than in
29// `rto-exec` because `rto-exec` is optional and the render paths, which are
30// gated on nothing, need the same formatter — twice now, in two different
31// renderers. `rto-exec` re-exports it; see the module for the history.
32mod clock;
33mod codegraph;
34mod config_keys;
35mod context;
36// The holder for the media extractors' process-wide native engines — and the
37// deterministic release that keeps a Metal build from aborting at exit (#291) —
38// now lives one level down, next to the llama.cpp backend that shares the same
39// mechanism: `rto_llama::EngineSlot` (#296).
40mod extract;
41// Analyzer findings (ADR-0012): a *separate* artifact store, deliberately not a
42// provenance class and deliberately not in `nodes`/`edges`.
43mod findings;
44mod git;
45#[cfg(feature = "inference")]
46mod infer;
47pub mod layering;
48mod links;
49mod markers;
50// Generated media content (ADR-0015): ASR transcripts and VLM descriptions. Like
51// findings, a *separate* artifact store — generated text is not a deterministic
52// function of the bytes, so it is not a `derived` fact and never enters
53// `nodes`/`edges`.
54pub mod media;
55// Episodic agent memory (ADR-0013): what a session learned, which has no
56// generating function at all — so it is neither `derived` nor `authored`, and it
57// gets a *separate* artifact store on the same terms as findings and media.
58mod memory;
59mod migrations;
60mod model;
61// Which model serves which task, and **why** (Stage 33). Deliberately in *this*
62// crate: `gix` is pinned here without transports, so a resolver that decides
63// which model runs structurally cannot grow a "check for a newer one" call.
64#[cfg(feature = "models")]
65pub mod model_choice;
66#[cfg(feature = "models")]
67mod models;
68mod provenance;
69mod query;
70// A citable external work (issue #801). In *this* crate for the reason
71// `model_choice` and `review_corpus` are, and with more at stake: `gix` is
72// pinned here without transports, so a record whose every field — author, year,
73// publisher, DOI — invites a lookup structurally cannot grow one. It is also the
74// crate the eventual extraction layer lives in, and the one `rto-render` depends
75// on, so both ends can name the type. What a *citation style* requires of such a
76// record is a different question and lives with the renderer.
77// Which repository paths the scan reads, and how much of each it mines
78// (ADR-0007 `[paths]`, ADR-0026 step 1, issue #840). In *this* crate because it
79// is the one crate both readers of repository bytes depend on: derived
80// extraction is here, and `rto_spec`'s authored classifier depends on this
81// crate. A rule that lived beside one of them would be a rule the other could
82// not consult, which is exactly the two-scan gap it exists to close.
83pub mod paths;
84pub mod reference;
85// Stage 35 — the adjudicated review corpus, and the two pure decisions made over
86// it. In *this* crate for the same reason `model_choice` is: `gix` is pinned here
87// without transports, and both a historical record that must not be "refreshed
88// from the GitHub API" and a suppression rule that must not "just ask CI" are
89// precisely the code that would otherwise acquire such a call.
90pub mod compile_claim;
91pub mod review_corpus;
92pub mod review_score;
93// Stage 35b — the reviewer's judgement, which is likewise pure: prompt assembly,
94// response parsing and the compile-claim site derivation are functions of bytes,
95// so what the reviewer *decides* is testable with no model and no network. The
96// loop that calls an engine is in the binary, where the engine already is.
97pub mod okf_consent;
98pub mod reviewer;
99pub mod screen;
100mod store;
101mod sync;
102mod text;
103pub mod topology;
104// Whether a producer's identity is measured or asserted (ADR-0019 §5). In *this*
105// crate rather than in `rto-remote` because `rto-remote` depends on this one, so
106// `ModelSource::Remote` cannot name a type that lives there — and because the
107// grade qualifies `Producer`, which is here. Two variants and a sentence: it
108// brings no transport with it.
109pub mod trust;
110mod workspace;
111
112pub use artifact::{ARTIFACT_SCHEMA, GraphArtifact};
113#[cfg(feature = "audio-metadata")]
114pub use audio::{AUDIO_STREAM_KIND, AudioDuration, AudioFacts, AudioTag, Exactness};
115pub use cache::{CacheError, ObjectCache, ObjectSweep};
116pub use clock::{age_in_days, rfc3339_from_unix, rfc3339_utc, unix_from_rfc3339};
117pub use codegraph::{ORACLE_SCHEMA, OracleError, OracleReport, compare as compare_codegraph};
118pub use config_keys::{
119    ConfigKey, canonicalize as canonicalize_config_key, flatten as flatten_config, is_config_path,
120    is_secret_key, is_tooling_config_path, normalize as normalize_config_key,
121};
122pub use context::{
123    BoundedEdges, ContextEdge, ContextNode, ContextRefresh, NodeContext, OmittedEdges,
124    TOOL_CONTEXT_EDGE_CAP, ToolContext, build_context, context, dependents, refresh_contexts,
125    tool_context,
126};
127pub use extract::{
128    Extractor, FileNodeExtractor, IngestConfig, MediaEngineGuard, Registry, RustExtractor,
129    cap_content, is_prose, release_media_engines,
130};
131pub use findings::{
132    AdvisoryDb, AnalysisRun, CommandPolicy, EnvironmentPolicy, FINDING_KEY_PREFIX, Finding,
133    FindingKey, FindingsApplied, FindingsError, FindingsLayer, Isolation, MAX_ANALYZER_ID,
134    MAX_IDENTITY_PART, NetworkPolicy, RunnerKind, SECURITY_LAYER_PREFIX, Severity, SourceIdentity,
135    WorktreeAccess, WorktreeId, analyzer_id_error, is_valid_analyzer_id, layer_key,
136};
137pub use git::{
138    BaseResolution, BlobRef, ChangeStatus, ChangedFile, GitError, GraphSource, PathAuthor, Repo,
139    Submodule, Upstream,
140};
141#[cfg(feature = "inference")]
142pub use infer::{
143    DuplicateConfig, DuplicatePair, DuplicateReport, EMBED_REF, Embedder, HashEmbedder,
144    InferenceConfig, duplicates, duplicates_with, embed, infer_edges, infer_edges_with, similarity,
145};
146pub use links::{
147    EXTERNAL_REF_KIND, LINKS_AUTHORED_REF, LINKS_REF, external_ref_key, external_ref_node,
148    external_ref_node_with, external_ref_target,
149};
150/// The whole-file scan opt-out (`roteiro:ignore-file`), so every scanner that
151/// reads sources honours one directive rather than each defining its own.
152pub use markers::is_scan_exempt;
153pub use media::{
154    CandidateCount, GateReason, GateThresholds, GeneratedContent, MAX_MODEL_ID, MAX_PROMPT,
155    MEDIA_PRODUCER_PREFIX, MEDIA_SCHEMA, MediaBlob, MediaBuildOptions, MediaBuildReport,
156    MediaError, MediaFilter, MediaKind, MediaOutcome, MediaProducer, MediaRecord, MediaSkip,
157    MediaStatus, MediaWrite, Producer, ProducerId, ProducerSummary, ProducerSummaryAvailable,
158    SkipEntry, build_media, is_valid_model_id, media_blobs, status as media_status,
159};
160pub use memory::{
161    AnchorState, CACHE_BUDGET_ENV, CACHE_SCHEMA, CacheEntry, CacheStats, CacheSweep, CacheWrite,
162    DEFAULT_BASE_CONFIDENCE, DEFAULT_CACHE_BUDGET_BYTES, DEFAULT_DECAY_SPAN, DEFAULT_HALF_LIFE,
163    DEFAULT_MEMORY_SCOPE, Decay, MAX_MEMORY_BODY, MAX_MEMORY_SCOPE, MEMORY_SCHEMA, MemoryAnchor,
164    MemoryError, MemoryFilter, MemoryForgotten, MemoryKind, MemoryListing, MemoryRecord,
165    MemoryWrite, RECALL_SCHEMA, Recall, RecallOptions, Recalled, anchor_penalty,
166    cache_budget_bytes,
167};
168pub use model::{Direction, Edge, EdgeKind, FactSet, Node, NodeKind, Span};
169#[cfg(feature = "models")]
170pub use model_choice::{
171    DEFAULT_GENERATIVE, DEFAULT_OCR, ModelChoice, ModelChoiceError, ModelPins, ModelSource,
172    ModelTask, RemoteTier, TASKS as MODEL_TASKS, resolve as resolve_model,
173    resolve_all_with as resolve_models, resolve_with as resolve_model_with,
174    resolve_with_remote as resolve_model_with_remote, set_model_pins,
175};
176#[cfg(feature = "models")]
177pub use models::{
178    DownloadError, DownloadEvent, ModelFile, ModelKind, ModelRole, ModelSpec, ModelVariant,
179    Platform, REGISTRY, RangeKind, RangeReply, Removal, ResourceTier, discard_partial,
180    download_resumable, download_verified, ensure_model_dir, find as find_model, installed_size,
181    interpret_range_response, is_installed, model_dir, partial_meta_path, partial_path,
182    remove_model, set_model_store, sha256_hex, store_root, verify_sha256,
183};
184pub use okf_consent::{
185    ConsentState, OkfConsent, OkfDecision, screen_fingerprint, screen_regressed,
186};
187pub use paths::{PathClass, PathPolicy, glob_match};
188pub use provenance::Provenance;
189pub use query::{
190    ConfigSecretItem, ConfigSecretReport, CouplingItem, CouplingOrder, CouplingReport,
191    DEFAULT_MIN_LINES, DebtDensityReport, DebtItem, DebtReport, DensityItem, DensityOrder, EdgeRef,
192    Explanation, GeneratedHit, Listing, MemoryHit, NodeSummary, Path, PathHop, RedactionState,
193    SCHEMA, SearchHit, SearchOptions, SearchResults, config_secrets, coupling, debt, debt_density,
194    explain, list_kind, path, search, search_channels, window,
195};
196pub use reference::{
197    AccessDate, Attested, Author, Day, Doi, GivenName, Locator, Month, NotADay, NotADoi,
198    NotAGivenName, NotAYear, PublicationDate, Reference, Stability, WorkKind, Year,
199    is_printable_identifier,
200};
201pub use store::{ImportApplied, SchemaAhead, Store, StoreError};
202pub use sync::{
203    DEFAULT_KEEP_GENERATIONS, ReclaimReport, SyncError, SyncReport, extraction_identity,
204    sweep_superseded, sync, sync_index, sync_tree, sync_worktree,
205};
206pub use text::{
207    Heading, LinkKind, LinkScope, MarkdownLink, code_spans, first_h1, heading_id, heading_id_from,
208    heading_text, headings, is_code_fence, link_scope, markdown_dialect, markdown_links, slugify,
209    strip_code_spans, wiki_link_targets,
210};
211pub use trust::ProducerTrust;
212pub use workspace::{
213    Follow, OKF_BUNDLE_DIR, OkfBundle, OnOpen, ReloadPlan, ResolvedWorkspace, RootScan,
214    SetReloadPlan, Workspace, WorkspaceError, WorkspaceSet, Worktrees, discover_okf_bundles,
215    discover_repos_under, is_linked_worktree, okf_bundle_in, parse_qualified, scan_root,
216};