Expand description
Trust-boundary compiler (SCC-148): derives crosses_boundary
relationships from deployment units, component dependencies, and calls
to external APIs.
Model:
- Deployment units (entities kind
deployment_unit) with abuild_contextattribute map to that directory; units with only animageattribute map to their own name (no directory is recorded, so the unit name is the best deterministic stand-in). Units with neither attribute (e.g. pure Dockerfile units) are ignored. - A component (from
store.components()) belongs to the unit whose directory is the longest prefix match against any of the component’simplementation.paths. Components matching no unit belong to the synthetic unitlocal. - Every RESOLVED
depends_onedge between components in different units, and everycallsedge into anexternal_api, becomes acrosses_boundaryrelationship carrying the evidence of the underlying fact. Ids are content-derived (blake3,rel:boundary:prefix) and the derived set is replaced wholesale on each compile, so the output is deterministic and idempotent.
Constants§
Functions§
- boundary_
crossings - Human-readable, sorted list of boundary crossings in the form
"unitA/compA -> unitB/compB"(external crossings read"unit/comp -> external/name"), forverify/CLI/Atlas display. - boundary_
crossings_ from_ rels boundary_crossingsover an already-loaded relationship slice (C6): same predicate filter and render path as [crossing_lines], without the extra full-tableall_relationships()+components()store reads. Callers that already hold the trusted edge set (e.g.verify) use this.- compile_
boundaries - Compile the full set of trust-boundary crossings for the current reality
graph. Returns
(relationship, source_path)pairs ready forstore.insert_relationship; the source path is empty (derived facts). Replaces any previously compiled crossings (stale edges from removed dependencies or calls do not survive a rebuild). - production_
crossings boundary_crossingsrestricted to production-side crossings: a crossing whose subject (component or calling symbol) lives under a test/fixture/benchmark/example tree is fixture chatter, not architecture. Used by atlas scope filtering;verify/CLI keep the unfiltered diagnostic view.