Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
30 commits
Select commit Hold shift + click to select a range
53dbf5e
docs: approve CodeGraph MCP proxy boundaries
GraphZLL Aug 18, 2026
6a25ace
docs: plan CodeGraph MCP proxy implementation
GraphZLL Aug 18, 2026
376ae95
feat: add bounded CodeGraph query primitives
GraphZLL Aug 18, 2026
cf6501d
feat: bind CodeGraph queries to freshness windows
GraphZLL Aug 18, 2026
8c8a644
feat: expose the Polaris CodeGraph MCP proxy
GraphZLL Aug 18, 2026
ce3d175
feat: record auditable CodeGraph proxy evidence
GraphZLL Aug 18, 2026
9400561
feat: register the project CodeGraph proxy
GraphZLL Aug 18, 2026
1fe3243
feat: migrate CodeGraph evidence to protocol 0.1.21
GraphZLL Aug 18, 2026
66a1061
test: verify the CodeGraph proxy end to end
GraphZLL Aug 18, 2026
91e4c2d
fix: preserve failed CodeGraph proxy evidence
GraphZLL Aug 18, 2026
76de90d
fix: support MCP registration on Python 3.10
GraphZLL Aug 18, 2026
62a9970
fix: validate TOML consistently on Python 3.10
GraphZLL Aug 18, 2026
e35d4f4
fix: protect unrelated TOML from managed markers
GraphZLL Aug 18, 2026
e3db8e6
fix: compare TOML NaN values semantically
GraphZLL Aug 18, 2026
5cf3057
test: run CodeGraph proxy fixture cross-platform
GraphZLL Aug 18, 2026
f58d159
Merge pull request #4 from CoronaEngine/codex/codegraph-mcp-proxy
FaithZL Aug 19, 2026
5e7eba1
docs: design CodeGraph freshness hardening
GraphZLL Aug 19, 2026
ab27796
docs: translate CodeGraph freshness design
GraphZLL Aug 19, 2026
c731e4a
docs: plan CodeGraph freshness hardening
GraphZLL Aug 19, 2026
0ec7541
fix: classify current CodeGraph freshness framing
GraphZLL Aug 19, 2026
b6c1c7a
feat: enforce automatic CodeGraph freshness windows
GraphZLL Aug 19, 2026
b3eda95
fix: preserve CodeGraph identity failures
GraphZLL Aug 19, 2026
6a9ef4f
docs: define automatic CodeGraph freshness behavior
GraphZLL Aug 19, 2026
76c87b0
docs: clarify CodeGraph unknown-status queries
GraphZLL Aug 19, 2026
854a880
test: bind CodeGraph unknown-status query contract
GraphZLL Aug 19, 2026
bcd2653
chore: advance Polaris protocol to 0.1.22
GraphZLL Aug 19, 2026
03b88ba
test: verify CodeGraph freshness hardening end to end
GraphZLL Aug 19, 2026
befb54c
fix: close CodeGraph freshness safety gaps
GraphZLL Aug 19, 2026
b823f1d
fix: preserve misplaced worktree mismatch evidence
GraphZLL Aug 19, 2026
655449d
Merge pull request #5 from CoronaEngine/codex/codegraph-freshness-har…
FaithZL Aug 19, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
12 changes: 9 additions & 3 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@

English | [简体中文](README.zh-CN.md)

> Current protocol version: `0.1.20` (in development); workflow version: `0.1.3`
> Current protocol version: `0.1.22` (in development); workflow version: `0.1.3`

Polaris is a repo-native engineering workflow for coding agent hosts. It stores requirements, plans, implementation results, independent reviews, validation evidence, and task state in Git, then uses deterministic gates to prevent requirement drift, stale evidence, and agents declaring their own work complete.

Expand Down Expand Up @@ -89,9 +89,15 @@ codegraph init
polaris code-intelligence add codegraph --repo .
```

Run these commands from the target repository as appropriate. `codegraph init` creates the `.codegraph/` marker; without it Polaris uses source and Git directly and creates no stage record. Polaris writes a Code Intelligence record only when it actually performs a Provider status, sync, or explore operation. Polaris can only read CodeGraph status, explore indexed relationships, and perform one bounded `codegraph sync` at a declared stage boundary. It never installs, initializes, starts, configures, reconfigures, waits for, or manages CodeGraph or its watcher/daemon/MCP configuration.
Run these commands from the target repository as appropriate. `codegraph init` creates the `.codegraph/` marker; without it Polaris uses source and Git directly and creates no stage record. Vendoring registers the project-scoped `polaris-codegraph` proxy in `.codex/config.toml` and `.mcp.json` without replacing unrelated settings. The host may require project trust or first-use approval; that approval remains the user's decision.

CodeGraph's watcher and connection reconciliation are the primary freshness mechanisms. Polaris records a limited conclusion at the time it checks: `CURRENT_AT_CHECK`, `PARTIAL_STALE`, `INDEX_STALE`, `NOT_VERIFIED`, or `UNAVAILABLE`; it never claims commit-exact graph freshness. A `PARTIAL_STALE` response names specific files: read each current file directly (`READ_SOURCE`), or inspect the registered Git diff if it was deleted (`INSPECT_GIT_DIFF`). For `INDEX_STALE` or `NOT_VERIFIED`, treat the graph only as a lead and search the repository plus Git (`SEARCH_SOURCE`). Validation remains graph-free and relies on source, Git, builds, tests, static checks, and Human Checks.
Polaris stages call only `polaris_codegraph_explore`. The proxy checks status and automatically runs at most one bounded incremental `codegraph sync` when pending changes exist, then runs one explore, rechecks status, and returns a freshness envelope before graph content. There is no separate stage status/sync MCP call. `CURRENT` means `NON_AUTHORITATIVE_CONTEXT`; `STALE` and `UNKNOWN`/`TREAT_AS_STALE` mean `NAVIGATION_ONLY` and require the exact source/Git fallback before a conclusion is used; `UNAVAILABLE` means no graph. A current named file uses `READ_SOURCE`, a deleted file uses `INSPECT_GIT_DIFF`, and an index-wide or unsafe result uses `SEARCH_SOURCE`. Validation remains graph-free and relies on source, Git, builds, tests, static checks, and Human Checks.

When status cannot be verified but the project has a safe repository identity, the proxy still calls `polaris_codegraph_explore` and returns `UNKNOWN`/`TREAT_AS_STALE`. The graph remains navigation-only: use the exact source/Git fallback before any conclusion.

The repository owner, not Polaris, owns CodeGraph installation, initialization, configuration, raw MCP registration, watcher, daemon, and every full `codegraph index` rebuild. Polaris never starts, configures, reconfigures, waits for, or manages them. Raw `codegraph_explore` or `codegraph explore` remains available out-of-band but cannot back `CURRENT` Polaris evidence. New records are v3 projections of the retained proxy bundle and completed fallbacks; v1/v2 are historical only. CodeGraph remains optional and never becomes a workflow gate.

Protocol `0.1.22` keeps Workflow at `0.1.3` and adds an explicit version-only migration from `0.1.21` that neither inventories nor rewrites Code Intelligence record v3 evidence. Protocol `0.1.21` introduced the project-scoped Polaris CodeGraph proxy, host adapter v3 registration, and auditable record v3; record v1 and v2 remain immutable historical evidence only.

## v0.1 scope

Expand Down
12 changes: 9 additions & 3 deletions README.zh-CN.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@

[English](README.md) | 简体中文

> 当前协议版本:`0.1.20`(开发中);Workflow 版本:`0.1.3`
> 当前协议版本:`0.1.22`(开发中);Workflow 版本:`0.1.3`

Polaris 是运行在 Coding Agent 宿主上的仓库原生工程工作流。它把需求、计划、实现、独立审查、验证和任务状态保存在 Git 仓库中,并通过确定性门禁防止需求漂移、证据过期和 Agent 自行宣布完成。

Expand Down Expand Up @@ -89,9 +89,15 @@ codegraph init
polaris code-intelligence add codegraph --repo .
```

`codegraph init` 创建 `.codegraph/` marker。只有目标仓库已经有这个 marker 且项目策略允许时,Polaris 才会使用 CodeGraph;没有 marker 时直接使用源码和 Git,不生成阶段 record。只有实际执行 Provider `status`、`sync` 或 `explore` 操作时才写 Code Intelligence record。Polaris 只会读取 `status`、查询 `explore`,以及只在声明的阶段边界至多执行一次有界 `codegraph sync`;它绝不安装、初始化、启动、配置、重新配置、等待或管理 CodeGraph、watcher、daemon 或 MCP 配置。
`codegraph init` 创建 `.codegraph/` marker;没有 marker 时 Polaris 直接使用源码和 Git,不生成阶段 record。Vendoring 会在 `.codex/config.toml` 与 `.mcp.json` 中非破坏地注册项目级 `polaris-codegraph` 代理,并保留其他设置。宿主可能要求信任项目或首次使用确认;是否批准仍由用户决定。

CodeGraph 的 watcher 和连接时 reconciliation 是正常情况下的实时更新机制。Polaris 只记录检查时的有限结论:`CURRENT_AT_CHECK`、`PARTIAL_STALE`、`INDEX_STALE`、`NOT_VERIFIED` 或 `UNAVAILABLE`,不会宣称与 Git commit 精确一致。`PARTIAL_STALE` 会精确列出待同步文件:当前普通文件必须直接读取并记录 `READ_SOURCE`;已删除文件必须检查注册 subject 的 Git diff 并记录 `INSPECT_GIT_DIFF`。`INDEX_STALE` 或 `NOT_VERIFIED` 时,图只能作为导航线索,Agent 必须通过仓库搜索和 Git 证据记录 `SEARCH_SOURCE`。Provider 不可用、status 不可读或 sync 失败都不阻断阶段;Validation 不调用 CodeGraph,仍以源码、Git、构建、测试、静态检查和 Human Check 为准。
Polaris 阶段只调用 `polaris_codegraph_explore`。代理先检查 status,存在 pending changes 时自动且至多执行一次有界增量 `codegraph sync`,再执行一次 explore、复查 status,并保证 freshness envelope 位于图内容之前;阶段没有独立的 status/sync MCP 调用。`CURRENT` 表示 `NON_AUTHORITATIVE_CONTEXT`;`STALE` 与 `UNKNOWN`/`TREAT_AS_STALE` 表示 `NAVIGATION_ONLY`,在使用任何结论前必须完成 envelope 指定的精确源码/Git 回退;`UNAVAILABLE` 表示没有图内容。当前具名文件使用 `READ_SOURCE`,已删除文件使用 `INSPECT_GIT_DIFF`,索引级或不安全结果使用 `SEARCH_SOURCE`。Validation 不调用 CodeGraph,仍以源码、Git、构建、测试、静态检查和 Human Check 为准。

当 status 无法验证但仓库身份安全时,代理仍执行 `polaris_codegraph_explore`,并返回 `UNKNOWN`/`TREAT_AS_STALE`。图只用于导航;在使用任何结论前,必须完成精确源码/Git 回退。

CodeGraph 的安装、初始化、配置、raw MCP 注册、watcher、daemon 与每次全量 `codegraph index` 重建都归仓库所有者,而不是 Polaris;全量重建始终由用户主动执行。Polaris 绝不启动、配置、重新配置、等待或管理这些能力。raw `codegraph_explore` 或 `codegraph explore` 仍可作为带外工具使用,但不能支持 Polaris 的 `CURRENT` 证据。新 record 必须由保留的代理 bundle 与已完成回退投影为 v3;v1/v2 仅供历史读取。CodeGraph 始终可选,永远不是 Workflow 门禁。

协议 `0.1.22` 保持 Workflow `0.1.3`,并新增从 `0.1.21` 出发的显式纯版本迁移;该迁移不清点也不重写 Code Intelligence record v3 证据。协议 `0.1.21` 引入项目级 Polaris CodeGraph 代理、Host Adapter v3 注册和可审计的 record v3;record v1/v2 仍仅作为不可变历史证据读取。

## v0.1 边界

Expand Down
2 changes: 1 addition & 1 deletion VERSION
Original file line number Diff line number Diff line change
@@ -1 +1 @@
0.1.20
0.1.22
Loading