Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
75 commits
Select commit Hold shift + click to select a range
ffe9b85
chore(ai): make codebase-memory primary MCP
dporkka Oct 3, 2026
ba867fd
chore(ai): prefer codebase-memory in Codex
dporkka Oct 3, 2026
368fe18
docs(ai): add layered code-intelligence routing policy
dporkka Oct 3, 2026
d427a59
docs(ai): add layered code-intelligence routing policy
dporkka Oct 3, 2026
6055433
feat(ai): add shared Zoekt code-search profile
dporkka Oct 3, 2026
26992f9
docs(ai): document layered code-intelligence stack
dporkka Oct 3, 2026
9f37cea
test(repo-intel): define context routing behavior
dporkka Oct 3, 2026
266cefe
test(repo-intel): define backend bake-off scoring
dporkka Oct 3, 2026
3e8947c
feat(repo-intel): add vendor-neutral context router
dporkka Oct 3, 2026
5b9d996
feat(repo-intel): add backend bake-off scorer
dporkka Oct 3, 2026
56201e2
bench(repo-intel): seed cross-project code-intelligence scenarios
dporkka Oct 3, 2026
cf446fc
feat(repo-intel): add bake-off scoring CLI
dporkka Oct 3, 2026
51c3e7a
docs(repo-intel): document routing contract and bake-off workflow
dporkka Oct 3, 2026
0e367d7
test(repo-intel): require stable bake-off JSON output
dporkka Oct 3, 2026
c4c65f4
fix(repo-intel): emit stable bake-off JSON metrics
dporkka Oct 3, 2026
5ac07de
docs(repo-intel): describe context routing responsibilities
dporkka Oct 3, 2026
f3d7ccd
test(codeintel): specify executable bakeoff harness
dporkka Oct 3, 2026
f7c459f
feat(codeintel): add executable MCP bakeoff harness
dporkka Oct 3, 2026
1c8dd98
test(codeintel): make benchmark scenarios executable
dporkka Oct 3, 2026
0b05f4a
fix(codeintel): make harness tests import-safe
dporkka Oct 3, 2026
af83efd
chore(codeintel): add portable verification lane
dporkka Oct 3, 2026
29fc59c
docs(codeintel): document executable bakeoff and portable validation
dporkka Oct 3, 2026
9630a21
fix(codeintel): measure MCP tool latency without startup
dporkka Oct 3, 2026
1aa4097
test(codeintel): specify backend promotion gate
dporkka Oct 3, 2026
5bc2ad5
test(codeintel): keep promotion tests self-contained
dporkka Oct 3, 2026
6395155
feat(codeintel): add quality-first backend promotion gate
dporkka Oct 3, 2026
65bf41f
feat(codeintel): add suite promotion verdict CLI
dporkka Oct 3, 2026
e4ca2a6
ci(codeintel): add Woodpecker verification workflow
dporkka Oct 3, 2026
dd75f78
docs(codeintel): document Woodpecker lane and promotion gate
dporkka Oct 3, 2026
0a9e5fa
chore(codeintel): emit promotion verdict after live bakeoff
dporkka Oct 3, 2026
dc40c98
test(codeintel): require unsafe promotion verdict to fail
dporkka Oct 3, 2026
a7d49ff
feat(codeintel): fail unsafe promotion verdicts
dporkka Oct 3, 2026
f794c53
fix(codeintel): always emit and enforce live promotion verdict
dporkka Oct 3, 2026
e7f3a53
build(codeintel): add pinned benchmark worker image
dporkka Oct 3, 2026
53cf130
build(codeintel): add reproducible benchmark compose runner
dporkka Oct 3, 2026
0103e08
test(codeintel): specify benchmark provenance metadata
dporkka Oct 3, 2026
03d9817
test(codeintel): keep harness tests focused
dporkka Oct 3, 2026
bc37a6b
test(codeintel): specify benchmark provenance capture
dporkka Oct 3, 2026
e5b727a
feat(codeintel): capture benchmark source and tool provenance
dporkka Oct 3, 2026
5be7166
feat(codeintel): attach provenance before promotion verdict
dporkka Oct 3, 2026
0a23c9c
ci(codeintel): verify provenance and benchmark worker changes
dporkka Oct 3, 2026
77e1c36
ci(codeintel): add manual trusted live bakeoff workflow
dporkka Oct 3, 2026
aaf7411
fix(codeintel): keep benchmark runtime cache consistent
dporkka Oct 3, 2026
1a0c31f
ci(codeintel): pin live bakeoff to amd64 agent pool
dporkka Oct 3, 2026
f4fced5
docs(codeintel): add benchmark migration runbook
dporkka Oct 3, 2026
b47ebce
test(codeintel): require per-repository codebase-memory scope
dporkka Oct 3, 2026
2ef8bff
test(codeintel): keep harness generic across repository roots
dporkka Oct 3, 2026
0ab8ff1
fix(codeintel): scope benchmark calls and match pinned CBM schema
dporkka Oct 3, 2026
80b41ee
fix(codeintel): use deterministic BM25 discovery in benchmark corpus
dporkka Oct 4, 2026
6f6dbf3
test(codeintel): validate benchmark corpus contracts
dporkka Oct 4, 2026
2769bdf
test(codeintel): include corpus contract in portable verification
dporkka Oct 4, 2026
031649f
ci(codeintel): enforce corpus contract in Woodpecker lane
dporkka Oct 4, 2026
1a6502e
test(codeintel): strengthen Adacavo lifecycle impact corpus
dporkka Oct 4, 2026
536299c
test(codeintel): refresh Nulang production callsite ground truth
dporkka Oct 4, 2026
c690408
test(codeintel): refresh Dev Plane admission impact ground truth
dporkka Oct 4, 2026
03dd48e
test(codeintel): ground Nulang Cloud runtime benchmark in production …
dporkka Oct 4, 2026
6eac790
fix(codeintel): run pinned benchmark binaries without npx fallback
dporkka Oct 4, 2026
e61d6d0
build(codeintel): isolate persistent benchmark caches
dporkka Oct 4, 2026
f6a9a61
build(codeintel): pin CBM cache root in compose worker
dporkka Oct 4, 2026
a895d9d
ci(codeintel): isolate CBM cache in manual bakeoff
dporkka Oct 4, 2026
098e0cb
test(codeintel): specify immutable corpus provenance
dporkka Oct 4, 2026
6d7f05a
feat(codeintel): bind benchmark results to exact corpus revision
dporkka Oct 4, 2026
a4e2a33
test(codeintel): update provenance fixtures for corpus binding
dporkka Oct 4, 2026
ff33fbc
test(codeintel): require recall-first backend ranking
dporkka Oct 4, 2026
b9ec228
fix(codeintel): rank required recall before F1
dporkka Oct 4, 2026
942f5c7
test(codeintel): make promotion gate required-recall first
dporkka Oct 4, 2026
104fb9c
fix(codeintel): gate backend promotion on complete core-path recall
dporkka Oct 4, 2026
9021fdf
docs(codeintel): align runbook with complete-recall promotion gate
dporkka Oct 4, 2026
777873e
docs(codeintel): align architecture docs with recall-first benchmark
dporkka Oct 4, 2026
f8f334d
chore(codeintel): retain F1 as diagnostic promotion output
dporkka Oct 4, 2026
fd647e4
test(codeintel): keep graph corpus focused on executable runtime paths
dporkka Oct 4, 2026
1b70580
test(codeintel): require successful comparison baseline
dporkka Oct 4, 2026
1599f9f
fix(codeintel): require successful baseline for promotion
dporkka Oct 4, 2026
3b123a6
test(codeintel): require provenance-bound promotion inputs
dporkka Oct 4, 2026
874372e
feat(codeintel): require provenance-bound promotion verdicts
dporkka Oct 4, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
12 changes: 12 additions & 0 deletions .codex/config.toml
Original file line number Diff line number Diff line change
@@ -1,3 +1,15 @@
# Dev Plane code-intelligence policy:
# - codebase-memory-mcp is the primary structural/impact-analysis backend.
# - GitNexus remains configured but disabled during the migration bake-off.
# - Use rg/Zoekt for exact text, ast-grep for structural rewrites, and LSP/SCIP
# for definition/reference/type truth before escalating to graph analysis.

[mcp_servers.codebase-memory-mcp]
command = "codebase-memory-mcp"
args = []
enabled = true

[mcp_servers.gitnexus]
command = "npx"
args = ["-y", "gitnexus@1.6.12", "mcp"]
enabled = false
6 changes: 3 additions & 3 deletions .mcp.json
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
{
"mcpServers": {
"gitnexus": {
"command": "npx",
"args": ["-y", "gitnexus@1.6.12", "mcp"]
"codebase-memory-mcp": {
"command": "codebase-memory-mcp",
"args": []
}
}
}
55 changes: 55 additions & 0 deletions .woodpecker/code-intelligence-bakeoff.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,55 @@
labels:
platform: linux/amd64

when:
- event: manual

steps:
- name: live-bakeoff
image: node:24-bookworm
environment:
CODEINTEL_GITHUB_TOKEN:
from_secret: codeintel_github_token
CI: "1"
GITNEXUS_NO_UPDATE_NOTIFIER: "1"
GITNEXUS_SKIP_OPTIONAL_GRAMMARS: "1"
CODEINTEL_GITNEXUS_MCP_CMD: "gitnexus mcp"
CODEINTEL_GITNEXUS_ANALYZE_CMD: "gitnexus analyze --index-only"
CODEINTEL_GITNEXUS_VERSION_CMD: "gitnexus --version"
CODEINTEL_CODEBASE_MEMORY_CMD: "codebase-memory-mcp"
CODEINTEL_CODEBASE_MEMORY_VERSION_CMD: "codebase-memory-mcp --version"
commands:
- apt-get update && apt-get install -y --no-install-recommends ca-certificates curl git python3 && rm -rf /var/lib/apt/lists/*
- |
curl -fsSLo /tmp/go.tgz "https://go.dev/dl/go1.26.8.linux-amd64.tar.gz"
rm -rf /usr/local/go
tar -C /usr/local -xzf /tmp/go.tgz
export PATH="/usr/local/go/bin:$${PATH}"
go version
- npm install --global codebase-memory-mcp@0.11.0 gitnexus@1.6.12
- codebase-memory-mcp --version
- gitnexus --version
- |
export PATH="/usr/local/go/bin:$${PATH}"
export CBM_CACHE_DIR="$${PWD}/.codeintel-cbm"
export GITNEXUS_STORAGE_ROOT="$${PWD}/.codeintel-gitnexus"
export CODEINTEL_REPOS_ROOT="$${PWD}/.codeintel-repos"
mkdir -p "$${CBM_CACHE_DIR}" "$${GITNEXUS_STORAGE_ROOT}" "$${CODEINTEL_REPOS_ROOT}"
chmod 700 "$${CBM_CACHE_DIR}" "$${GITNEXUS_STORAGE_ROOT}"

git config --global credential.helper store
printf 'https://x-access-token:%s@github.com\n' "$${CODEINTEL_GITHUB_TOKEN}" > "$${HOME}/.git-credentials"
chmod 600 "$${HOME}/.git-credentials"

git clone --depth 1 https://github.com/dporkka/adacavo.git "$${CODEINTEL_REPOS_ROOT}/adacavo"
git clone --depth 1 https://github.com/nulang-org/nulang.git "$${CODEINTEL_REPOS_ROOT}/nulang"
git clone --depth 1 https://github.com/dporkka/nulang-cloud.git "$${CODEINTEL_REPOS_ROOT}/nulang-cloud"
git clone --depth 1 https://github.com/dporkka/dev-plane.git "$${CODEINTEL_REPOS_ROOT}/dev-plane"

rm -f "$${HOME}/.git-credentials"
git config --global --unset credential.helper || true
unset CODEINTEL_GITHUB_TOKEN

export CODEINTEL_RUN_LIVE=1
bash scripts/verify-codeintel.sh
- cat data/codeintel-bakeoff/suite.json
53 changes: 53 additions & 0 deletions .woodpecker/code-intelligence.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,53 @@
labels:
platform: linux/amd64

when:
- event: pull_request
path:
include:
- packages/repo-intel/**
- scripts/codeintel_bakeoff.py
- scripts/test_codeintel_bakeoff.py
- scripts/test_codeintel_corpus.py
- scripts/codeintel_provenance.py
- scripts/test_codeintel_provenance.py
- scripts/verify-codeintel.sh
- benchmarks/code-intelligence/**
- docs/code-intelligence.md
- docs/code-intelligence-bakeoff-runbook.md
- tools/codeintel-benchmark/**
- docker-compose.code-intelligence-benchmark.yml
- .woodpecker/code-intelligence.yaml
- .woodpecker/code-intelligence-bakeoff.yaml
- event: push
branch: main
path:
include:
- packages/repo-intel/**
- scripts/codeintel_bakeoff.py
- scripts/test_codeintel_bakeoff.py
- scripts/test_codeintel_corpus.py
- scripts/codeintel_provenance.py
- scripts/test_codeintel_provenance.py
- scripts/verify-codeintel.sh
- benchmarks/code-intelligence/**
- docs/code-intelligence.md
- docs/code-intelligence-bakeoff-runbook.md
- tools/codeintel-benchmark/**
- docker-compose.code-intelligence-benchmark.yml
- .woodpecker/code-intelligence.yaml
- .woodpecker/code-intelligence-bakeoff.yaml

steps:
- name: harness-tests
image: python:3.13-slim
commands:
- python3 scripts/test_codeintel_bakeoff.py
- python3 scripts/test_codeintel_corpus.py
- python3 scripts/test_codeintel_provenance.py

- name: repo-intel-tests
image: golang:1.26.8
commands:
- cd packages/repo-intel
- go test ./...
52 changes: 16 additions & 36 deletions AGENTS.md
Original file line number Diff line number Diff line change
@@ -1,44 +1,24 @@
<!-- gitnexus:start -->
# GitNexus — Code Intelligence
# Code Intelligence

This project is indexed by GitNexus as **dev-plane** (5801 symbols, 16255 relationships, 300 execution flows). Use the GitNexus MCP tools to understand code, assess impact, and navigate safely.
Use `codebase-memory-mcp` as the primary structural code-intelligence backend for Dev Plane. On a fresh checkout, index the repository before relying on graph results. Prefer the cheapest precise tool for each question instead of routing every task through the graph.

> Index stale? Run `node .gitnexus/run.cjs analyze` from the project root — it auto-selects an available runner. No `.gitnexus/run.cjs` yet? `npx gitnexus analyze` (npm 11 crash → `npm i -g gitnexus`; #1939).
## Tool routing

## Always Do
- Exact identifier, string, filename, or regex lookup: use `rg` or Zoekt when available.
- Structural syntax pattern or repeatable codemod: use `ast-grep`.
- Definition, reference, implementation, rename, or type-resolution questions: prefer the language server / SCIP-quality semantic tooling.
- Architecture, dependency, call-path, cross-file impact, or blast-radius questions: use `codebase-memory-mcp` (`get_architecture`, `search_graph`, `trace_path`, `detect_changes`, and `query_graph` as appropriate).
- Conceptual search when names are unknown: use semantic graph search only after cheaper lexical/structural search is insufficient.
- Security/data-flow analysis requiring source-to-sink reasoning: use Joern when available; do not use it for routine navigation.
- Historical intent or ownership: use Git history.
- Correctness: verify with the repository's tests, type checks, linters, and CI; static code intelligence is not proof that a change works.

- **MUST run impact analysis before editing any symbol.** Before modifying a function, class, or method, run `impact({target: "symbolName", direction: "upstream"})` and report the blast radius (direct callers, affected processes, risk level) to the user.
- **MUST run `detect_changes()` before committing** to verify your changes only affect expected symbols and execution flows. For regression review, compare against the default branch: `detect_changes({scope: "compare", base_ref: "main"})`.
- **MUST warn the user** if impact analysis returns HIGH or CRITICAL risk before proceeding with edits.
- When exploring unfamiliar code, use `query({search_query: "concept"})` to find execution flows instead of grepping. It returns process-grouped results ranked by relevance.
- When you need full context on a specific symbol — callers, callees, which execution flows it participates in — use `context({name: "symbolName"})`.
- For security review, `explain({target: "fileOrSymbol"})` lists taint findings (source→sink flows; needs `analyze --pdg`).
## Change safety

## Never Do
Before changing a high-fan-in symbol, public API, persistence contract, scheduler path, capability boundary, or execution protocol, inspect upstream/downstream impact with the graph and semantic tooling. Before committing a non-trivial change, run `detect_changes` against the working tree or `main` and confirm the affected scope matches the intended change.

- NEVER edit a function, class, or method without first running `impact` on it.
- NEVER ignore HIGH or CRITICAL risk warnings from impact analysis.
- NEVER rename symbols with find-and-replace — use `rename` which understands the call graph.
- NEVER commit changes without running `detect_changes()` to check affected scope.
If graph results conflict with compiler/LSP output or executable tests, treat compiler/LSP and runtime evidence as authoritative and refresh/re-index the graph.

## Resources
## Migration note

| Resource | Use for |
|----------|---------|
| `gitnexus://repo/dev-plane/context` | Codebase overview, check index freshness |
| `gitnexus://repo/dev-plane/clusters` | All functional areas |
| `gitnexus://repo/dev-plane/processes` | All execution flows |
| `gitnexus://repo/dev-plane/process/{name}` | Step-by-step execution trace |

## CLI

| Task | Read this skill file |
|------|---------------------|
| Understand architecture / "How does X work?" | `.claude/skills/gitnexus/gitnexus-exploring/SKILL.md` |
| Blast radius / "What breaks if I change X?" | `.claude/skills/gitnexus/gitnexus-impact-analysis/SKILL.md` |
| Trace bugs / "Why is X failing?" | `.claude/skills/gitnexus/gitnexus-debugging/SKILL.md` |
| Rename / extract / split / refactor | `.claude/skills/gitnexus/gitnexus-refactoring/SKILL.md` |
| Tools, resources, schema reference | `.claude/skills/gitnexus/gitnexus-guide/SKILL.md` |
| Index, status, clean, wiki CLI commands | `.claude/skills/gitnexus/gitnexus-cli/SKILL.md` |

<!-- gitnexus:end -->
GitNexus remains a temporary fallback during the bake-off but is not the default code-intelligence path. Do not add new GitNexus-specific workflow dependencies unless a measured gap in codebase-memory requires it.
52 changes: 16 additions & 36 deletions CLAUDE.md
Original file line number Diff line number Diff line change
@@ -1,44 +1,24 @@
<!-- gitnexus:start -->
# GitNexus — Code Intelligence
# Code Intelligence

This project is indexed by GitNexus as **dev-plane** (5801 symbols, 16255 relationships, 300 execution flows). Use the GitNexus MCP tools to understand code, assess impact, and navigate safely.
Use `codebase-memory-mcp` as the primary structural code-intelligence backend for Dev Plane. On a fresh checkout, index the repository before relying on graph results. Prefer the cheapest precise tool for each question instead of routing every task through the graph.

> Index stale? Run `node .gitnexus/run.cjs analyze` from the project root — it auto-selects an available runner. No `.gitnexus/run.cjs` yet? `npx gitnexus analyze` (npm 11 crash → `npm i -g gitnexus`; #1939).
## Tool routing

## Always Do
- Exact identifier, string, filename, or regex lookup: use `rg` or Zoekt when available.
- Structural syntax pattern or repeatable codemod: use `ast-grep`.
- Definition, reference, implementation, rename, or type-resolution questions: prefer the language server / SCIP-quality semantic tooling.
- Architecture, dependency, call-path, cross-file impact, or blast-radius questions: use `codebase-memory-mcp` (`get_architecture`, `search_graph`, `trace_path`, `detect_changes`, and `query_graph` as appropriate).
- Conceptual search when names are unknown: use semantic graph search only after cheaper lexical/structural search is insufficient.
- Security/data-flow analysis requiring source-to-sink reasoning: use Joern when available; do not use it for routine navigation.
- Historical intent or ownership: use Git history.
- Correctness: verify with the repository's tests, type checks, linters, and CI; static code intelligence is not proof that a change works.

- **MUST run impact analysis before editing any symbol.** Before modifying a function, class, or method, run `impact({target: "symbolName", direction: "upstream"})` and report the blast radius (direct callers, affected processes, risk level) to the user.
- **MUST run `detect_changes()` before committing** to verify your changes only affect expected symbols and execution flows. For regression review, compare against the default branch: `detect_changes({scope: "compare", base_ref: "main"})`.
- **MUST warn the user** if impact analysis returns HIGH or CRITICAL risk before proceeding with edits.
- When exploring unfamiliar code, use `query({search_query: "concept"})` to find execution flows instead of grepping. It returns process-grouped results ranked by relevance.
- When you need full context on a specific symbol — callers, callees, which execution flows it participates in — use `context({name: "symbolName"})`.
- For security review, `explain({target: "fileOrSymbol"})` lists taint findings (source→sink flows; needs `analyze --pdg`).
## Change safety

## Never Do
Before changing a high-fan-in symbol, public API, persistence contract, scheduler path, capability boundary, or execution protocol, inspect upstream/downstream impact with the graph and semantic tooling. Before committing a non-trivial change, run `detect_changes` against the working tree or `main` and confirm the affected scope matches the intended change.

- NEVER edit a function, class, or method without first running `impact` on it.
- NEVER ignore HIGH or CRITICAL risk warnings from impact analysis.
- NEVER rename symbols with find-and-replace — use `rename` which understands the call graph.
- NEVER commit changes without running `detect_changes()` to check affected scope.
If graph results conflict with compiler/LSP output or executable tests, treat compiler/LSP and runtime evidence as authoritative and refresh/re-index the graph.

## Resources
## Migration note

| Resource | Use for |
|----------|---------|
| `gitnexus://repo/dev-plane/context` | Codebase overview, check index freshness |
| `gitnexus://repo/dev-plane/clusters` | All functional areas |
| `gitnexus://repo/dev-plane/processes` | All execution flows |
| `gitnexus://repo/dev-plane/process/{name}` | Step-by-step execution trace |

## CLI

| Task | Read this skill file |
|------|---------------------|
| Understand architecture / "How does X work?" | `.claude/skills/gitnexus/gitnexus-exploring/SKILL.md` |
| Blast radius / "What breaks if I change X?" | `.claude/skills/gitnexus/gitnexus-impact-analysis/SKILL.md` |
| Trace bugs / "Why is X failing?" | `.claude/skills/gitnexus/gitnexus-debugging/SKILL.md` |
| Rename / extract / split / refactor | `.claude/skills/gitnexus/gitnexus-refactoring/SKILL.md` |
| Tools, resources, schema reference | `.claude/skills/gitnexus/gitnexus-guide/SKILL.md` |
| Index, status, clean, wiki CLI commands | `.claude/skills/gitnexus/gitnexus-cli/SKILL.md` |

<!-- gitnexus:end -->
GitNexus remains a temporary fallback during the bake-off but is not the default code-intelligence path. Do not add new GitNexus-specific workflow dependencies unless a measured gap in codebase-memory requires it.
Loading
Loading