Skip to main content

Module boundaries

Module boundaries 

Source
Expand description

Trust-boundary compiler (SCC-148): derives crosses_boundary relationships from deployment units, component dependencies, and calls to external APIs.

Model:

  • Deployment units (entities kind deployment_unit) with a build_context attribute map to that directory; units with only an image attribute map to their own name (no directory is recorded, so the unit name is the best deterministic stand-in). Units with neither attribute (e.g. pure Dockerfile units) are ignored.
  • A component (from store.components()) belongs to the unit whose directory is the longest prefix match against any of the component’s implementation.paths. Components matching no unit belong to the synthetic unit local.
  • Every RESOLVED depends_on edge between components in different units, and every calls edge into an external_api, becomes a crosses_boundary relationship carrying the evidence of the underlying fact. Ids are content-derived (blake3, rel:boundary: prefix) and the derived set is replaced wholesale on each compile, so the output is deterministic and idempotent.

Constants§

RELPREFIX

Functions§

boundary_crossings
Human-readable, sorted list of boundary crossings in the form "unitA/compA -> unitB/compB" (external crossings read "unit/comp -> external/name"), for verify/CLI/Atlas display.
boundary_crossings_from_rels
boundary_crossings over an already-loaded relationship slice (C6): same predicate filter and render path as [crossing_lines], without the extra full-table all_relationships() + components() store reads. Callers that already hold the trusted edge set (e.g. verify) use this.
compile_boundaries
Compile the full set of trust-boundary crossings for the current reality graph. Returns (relationship, source_path) pairs ready for store.insert_relationship; the source path is empty (derived facts). Replaces any previously compiled crossings (stale edges from removed dependencies or calls do not survive a rebuild).
production_crossings
boundary_crossings restricted to production-side crossings: a crossing whose subject (component or calling symbol) lives under a test/fixture/benchmark/example tree is fixture chatter, not architecture. Used by atlas scope filtering; verify/CLI keep the unfiltered diagnostic view.