Modules
BEAM-native runtime for bounded PTC-Lisp workflows.
Loads environment variables from an explicitly named dotenv file.
Public execution boundary for bounded PTC-Lisp workflows.
Shared assembler and attestation recipe for code-owned analysis profiles.
Closed registry of code-owned analysis-session authority recipes.
Owner of one bounded code-owned analysis mission continuation.
Host boundary for closed local analysis profiles.
Immutable, path-free application semantics and captured source closure.
Bounded, caching document source shared by application acquisition adapters.
Internal in-VM construction attestation for sealed Kernel values.
Shared bound for projecting a raw println list into a caller-facing form.
Internal one-shot worker for heap- and time-bounded host computation.
Internal implementation of PtcRunner.Kernel.compile_bundle/1.
Publishes one model-authored candidate as {candidate.clj, descriptor.json}.
Decides whether a verified candidate is fit to be promoted by a human.
A host-owned route from PTC-Lisp to trusted extension code.
Parsed standalone command arguments.
Generated-in-source JSON Schema for the V3 command envelope.
Sealed behavior and path scope for a classified contract failure.
Closed per-command grammar and help declarations.
Closed privacy-safe command diagnostic.
Shared command parser and dispatch router.
Closed result of the frontend-owned command entry step.
Bounded, no-replace publication of the stable application scaffold, or of one embedded example tree.
Sealed command result returned to frontends.
Shared strict parser for the stable standalone argv contract.
Schema-authorized diagnostic path.
Sealed continuation state for a prepared validate or run command.
Closed phase-1 parser rejection.
Deterministic, privacy-preserving human projection of sealed command outcomes.
Generates the fixed V1 command reference from 128 bits of entropy.
Sealed frontend-owned choices for shared command dispatch.
Closed, path-free provenance for command diagnostics.
Closed provider locator used by command diagnostics.
Closed projection policy for structured bundle-derived diagnostic messages.
A source-bearing, component-ID-addressed bundle input.
Replaces one already-selected component with trusted candidate source.
Closed messages for a refused component-override descriptor.
Reads one bounded UTF-8 file from a trusted root.
Closed projection policy for rejected value-contract schema documents.
Absolute monotonic deadline shared by bounded Kernel operations.
Internal deterministic encoder for frozen Kernel metadata and hashes.
Authoritative closed V1 command diagnostic catalog.
Internal bounded capability invocation boundary.
Documentation pages embedded at compile time and served by ptc docs.
Exact behavior identity for one fully normalized application declaration.
Internal shared validator for workflow and mission environment constructors.
A bounded failed Kernel outcome.
Internal subordinate PTC-Lisp evaluation boundary.
Builds bounded, non-authoritative observations for an agent turn.
Bounded in-memory owner for canonical Kernel events.
Internal canonical event helpers.
Runnable example projects embedded at compile time and materialized by
ptc init DIRECTORY --example NAME.
Sealed selected application input and its authority class.
Sealed, filesystem-path-free evidence captured at the one-shot execution boundary.
Destination-free event, inspection, and result policy for one execution.
An immutable, deterministically ordered component compilation result.
Strict loader for host-installed provider authority.
Turns one strict host document into an inert installation catalog.
Internal sealed transport for credential-bearing host runtime configuration.
Persists and loads one immutable private inspection JSONL artifact.
Pure, source-bound queries over validated private inspection records.
The closed private inspection record vocabulary.
Required, bounded in-memory owner for sensitive developer inspection records.
Owner-bound immutable capture of private inspection artifacts.
Inert provider declarations paired with trusted implementations.
Configuration identity for one decoded host installation.
Internal compiler for the bounded capability JSON Schema profile.
Internal validator for values that may cross JSON-shaped Kernel boundaries.
Constructs the provider-neutral llm-request workflow capability.
Serves language-model responses from a frozen fixture file.
Shipped PTC-Lisp libraries as explicit Kernel components.
Closed metadata authority for Kernel limits.
Normalized positive hard ceilings for one Kernel run.
Bounded, non-pooling HTTP transport for MCP and MCP OAuth traffic.
Validated host authority for one OAuth-protected Streamable HTTP MCP server.
Callback-agnostic explicit MCP OAuth authorization operations.
Bounded RFC 9110 challenge parser specialized for MCP Bearer challenges.
Principal-scoped host authorization context.
Just-in-time confidential-client secret resolution.
Bounded final-profile discovery for one installed MCP OAuth authority.
Opaque, epoch-fenced identity for one principal's OAuth grant.
Runtime-shared fail-closed fences for OAuth response transitions.
Single-shot, dependency-free OAuth loopback callback interaction.
Bounded cleanup owner for token managers left by failed provider acquisition.
Pure candidate construction and semantic validation for MCP OAuth metadata.
Resolve-and-pin egress policy for MCP OAuth HTTP requests.
Opaque handle for one explicit authorization interaction.
Small, auditable OAuth authorization-code primitives owned by PtcRunner.
Shared strict parser for every OAuth scope-bearing boundary.
Atomic authorization-store boundary for MCP OAuth state.
Owner-process, process-local implementation of the MCP OAuth store.
One-shot authorization-code and refresh token endpoint client.
Principal-scoped bearer-token owner for one installed MCP authority.
Strict, bounded projection of OAuth token endpoint responses.
Pure validation and normalization for the pinned MCP protocol contract.
Builds one host-installed MCP capability source with operator-owned effects.
Strict, path-confined version 1 JSON manifest loader.
Shared manifest-backed REPL acquisition and lifecycle boundary.
Frozen authority for confined subordinate programs.
Builds the frozen prompt-facing inventory for one mission environment.
Projects compiled prelude contracts and normalized capability JSON Schema into one deterministic, renderer-neutral model contract.
The single rule deciding which configured model selectors a command may print.
Sealed provider-inert output of phases 4 and 5.
Diagnostic projection policy for analysis sessions whose results are private.
Fixed private authority recipe for correlated run-evidence navigation.
Internal opaque representation of a static subordinate PTC-Lisp program.
Strict operator-owned launch configuration for a PTC project.
Acquires one prepared run's selected providers through its active session.
Opens the active provider boundary through selection validation.
Owner-backed monotonic active-lifecycle marker.
Admits selected optional provider applications after the active lifecycle begins.
Sealed, declarative metadata for one installed provider implementation.
A bounded host-constructed failure returned by a capability provider.
Host-owned mapping from manifest provider names to trusted builders.
Sealed services supplied only when active provider runtime is opened.
One owner-backed cleanup stack for a command's active provider work.
Builds the closed selector-safe public identity for an acquired provider.
Fixed public authority recipe for bounded run-evidence navigation.
Sealed, anchored artifact destinations authorized before execution.
Direct bounded PTC-Lisp continuation used by the Kernel REPL frontend.
Scoped acquisition handle for one provider session.
A bounded successful Kernel outcome.
Persists one run result as a standalone JSON artifact.
Small bounded navigation API over one immutable run-evidence capture.
The single capability builder for bounded run-evidence navigation.
Shared path-free request construction and execution path.
The complete host-constructed configuration for one Kernel run.
Path-free preparation and one-shot execution.
Sealed, path-free application package, input, and execution-policy tuple.
Internal single owner of mutable per-run resource state.
Internal implementation of PtcRunner.Kernel.run/2.
Internal construction of reserved runtime capabilities.
Validates the closed, payload-free metadata vocabulary used by canonical events.
Schema-explained prefix of an untrusted document path.
Bounded, value-free projection of a JSON Schema validation failure.
Closed messages for hand-authored document schema violations.
Sealed, non-executable provider-selection normalization rules.
Closed messages for provider-selection rule failures.
Conservative code-owned PTC execution-semantics revision.
Owner of one code-owned analysis session's canonical event batch and publication.
Bounded, duplicate-rejecting JSON admission for authority boundaries.
Builds the capability callbacks handed to a sandboxed evaluation.
Bounded canonical trace loading, validation, filtering, and pagination.
Type-preserving canonical JSON bytes for stable application identity.
Compiled manifest-local contract for application input and Result.value.
Internal sealed evidence for one value-contract classification.
Internal read-only viewer adapter over the shared TraceLog query layer.
Closed ptc viewer listener vocabulary.
Project details for the Viewer's Live tab (#1444).
Local connected backend for the standalone Viewer's run-analysis REPL.
Frozen authority for the trusted outer workflow.
Provider-neutral LLM adapter boundary used by trusted Kernel provider builders.
Immutable result of preparing a configured LLM selector.
Built-in LLM adapter using req_llm.
Prepared request target owned by PtcRunner.LLM.ReqLLMAdapter.
Execute PTC programs written in Lisp DSL (Clojure subset).
AST node types for PTC-Lisp
Validates and desugars RawAST into CoreAST.
Conditional analysis for if, if-not, when, when-not, if-let,
when-let, if-some, when-some, when-first, cond, case, and condp forms.
Definition analysis for def, defonce, and defn forms.
Iteration analysis for doseq and for comprehensions.
Pattern analysis and destructuring for let bindings and function parameters.
Process-local scope for the compiled prelude consulted during a single analysis pass.
Analyzer for short function syntax (#()).
Leaf source of env-dispatched builtin names and binding kinds, loaded from
priv/functions.exs at compile time. It also projects the bounded source
vocabulary from the validated Java surface manifest.
Validates PTC-Lisp programs against Babashka/Clojure.
Scope-aware helpers for determining which names a closure body references.
Manages context, memory, and tools for program execution.
Core, validated AST for PTC-Lisp.
Convert Core AST (the analyzed/desugared representation) back to PTC-Lisp source strings.
Static analysis to extract data keys accessed by a PTC-Lisp program.
Builds the initial environment with builtins for PTC-Lisp.
Metadata wrapper for callable environment builtins.
Evaluates CoreAST into values.
Function application dispatch for Lisp evaluation.
The evaluator's single nestable effect-capture stack.
Evaluation context for the Lisp interpreter.
Canonical evaluator audit effects and their ordering algebra.
Shared helper functions for Lisp evaluation.
Adapts plain host callbacks to evaluator context and effect semantics.
Evaluator-owned semantics for pmap and pcalls.
A shared, lock-free slot semaphore bounding the number of parallel
pmap/pcalls worker processes alive at once across a whole
PtcRunner.Lisp.run/2.
Dispatches indirect pmap and pcalls calls to the parallel evaluator.
Heap-capped, slot-bounded parallel execution of untrusted PTC-Lisp
work (pmap/pcalls).
One indexed result returned by PtcRunner.Lisp.Eval.ParallelRunner.
Pattern matching for let bindings in Lisp evaluation.
Public-safe renderer for catalogued PTC-Lisp evaluator failures.
Closed public catalog of PTC-Lisp evaluator error kinds.
Format PTC-Lisp values for human/LLM display.
Serialize PTC-Lisp AST to source code string.
Read-only introspection over the callable PTC-Lisp surface.
Native, closed reference to one admitted Java member.
Bounded recoverable failure produced by closed Java dispatch.
Closed selector and postcondition boundary for admitted Java operations.
Closed implementation of the admitted java.lang.Boolean surface.
Closed implementation of the admitted java.lang.Double surface.
Closed implementation of the admitted java.lang.Float surface.
Closed implementation of the admitted java.lang.Integer surface.
Closed implementation of the admitted java.lang.Long surface.
Closed implementations for the admitted java.lang.Math overloads.
Bounded UTF-16 semantics for the admitted java.lang.String methods.
Closed implementation of the admitted java.lang.System surface.
Pinned executable-oracle versions and deterministic process settings.
Validates structured Java oracle cases and their checked-in typed baseline.
Executes bounded Java behavior cases through pinned JVM Clojure, Babashka, or the PTC runtime for explicit compatibility-only operations.
Native Java numeric value whose primitive overload identity is observable.
Total, recursive projection for native Java values at bounded host edges.
Compile-time authority for the bounded PTC-Lisp Java compatibility surface.
Native, bounded representation of java.time.Duration.
Native, bounded representation of java.time.Instant.
Native, bounded representation of java.time.LocalDate.
Native, bounded representation of legacy java.util.Date.
Normalizes map keys at the tool boundary.
Runtime representation for PTC-Lisp keywords that are not in the bounded atom vocabulary.
Parser entry point for PTC-Lisp.
Compiled, stateless deployment prelude artifact.
Resolves a compiled or source deployment prelude and validates every
tool:<name> requirement against the host-granted tools map before user
code is analyzed. Unknown requirement shapes fail closed.
Host tool grants used to validate a prelude's requires at attach time.
Deterministic source-level composition for selected capability preludes.
Compiles deployment prelude SOURCE into a %PtcRunner.Lisp.Prelude{}
artifact.
Resolves a %PtcRunner.Lisp.Prelude.ValidationError{} to the byte span of
the top-level form it blames.
Per-export public projection consulted by the analyzer, evaluator, bundle validation and prompt rendering.
Byte-exact top-level form span scanner for raw PTC-Lisp prelude source TEXT.
Internal raw-definition spec gathered by
PtcRunner.Lisp.Prelude.Compiler during its AST walk, before
host-boundary %PtcRunner.Lisp.Prelude.Export{} records are built and
before the callable private env is captured.
Compile-time validation failure for a deployment prelude.
Single consult point for namespace protection for deployment preludes.
Single source of truth for PTC-Lisp function metadata.
Native continuation result returned by the neutral PTC-Lisp evaluator.
Built-in functions for PTC-Lisp.
Shared runtime argument validation for Env builtin calls.
The manifest of PTC-Lisp builtin bindings exposed by the Runtime subsystem.
Dispatch helper for calling Lisp functions from Collection operations.
Collection operations for PTC-Lisp runtime.
Predicate and collection normalization helpers for collection operations.
Selection operations for PTC-Lisp collections: filter, remove, find, some, every?, not_any?, not_every?, take_while, drop_while.
Transformation operations for PTC-Lisp collections: map, mapv, mapcat, keep, map_indexed, keep_indexed.
Bounded data-shape summaries for PTC-Lisp values.
Flexible key access helpers for PTC-Lisp runtime.
Pure numeric semantics shared by Java Math dispatch and the bare PTC
pow/sqrt helpers.
JSON parsing and generation for PTC-Lisp.
Map operations for PTC-Lisp runtime.
Arithmetic operations for PTC-Lisp runtime.
Type predicates, numeric predicates, and logic operations for PTC-Lisp runtime.
Minimal, safe Regex support for PTC-Lisp. Uses Erlang's :re directly with match limits for ReDoS protection.
Unified handling for IEEE 754 special values (Infinity, NaN) in PTC-Lisp.
String manipulation and parsing operations for PTC-Lisp runtime.
Runtime callable for effectful qualified Lisp symbols.
Signature parsing and validation for PTC-Lisp component exports.
Coerce values to expected types with warning generation.
NimbleParsec-based parser for signature strings.
Helper functions for signature parser AST building.
Renders signatures back to string representation.
Resolve paths against parsed signature types.
Validates data against signature type specifications.
Bounded vocabulary — the set of names the parser is allowed to intern as atoms.
Validates PTC-Lisp specification against implementation.
Markdown-extraction half of PtcRunner.Lisp.SpecValidator.
Metadata for context-dispatched builtin values.
Counts unique user-defined symbols and keywords in a parsed Lisp AST.
Extract signature and description from Elixir function @spec and @doc.
Converts Elixir values to human-readable type labels.
Wraps untrusted content in data-only envelopes for LLM feedback.
Heap-proportional structural previews for human and model observations.
Bounded, non-authoritative presentation of a PTC-Lisp value.
Opt-in live status reporting for one Kernel run.
An explicit destination for one run's live-status frames.
Starts a direct workflow PTC-Lisp REPL or a fixed code-owned analysis profile.
Executes programs in isolated BEAM processes with resource limits.
Renders the bounded Markdown subset the guides use into HTML for the static site.
One-shot private conversation retrieval for an immutable run capture.
Byte-bounded UTF-8 helpers shared by diagnostics and public metadata.
Serves one project's captured traces through the local PTC Viewer.
Mix Tasks
Checks deterministic PTC-Lisp eval metrics against a committed baseline.
Measures the heap cost of the PtcRunner embedding units and compares them
against bench/baselines/heap.json.
Runs any stable PTC command through the shared parser and frontend
Checks that conformance audit rows point at symbols/members that exist in local upstream runtimes.
Generates markdown reports comparing PTC-Lisp builtins against Clojure and Java namespaces.
Prints a coverage report for explicit PTC-Lisp conformance cases.
Generates documentation from priv/functions.exs (ordinary implemented
functions), priv/function_audit.exs (Clojure parity triage notes), and
priv/java_interop.exs (bounded Java surface and presentation metadata)
Generates the checked-in build half of the Kernel semantic revision.
Renders the published documentation groups into committed pages under
site/guides/, site/installation/, and site/reference/, plus the
directory page at site/guides/index.html, and rewrites the shared
sidebar between the generated markers in site/index.html.
Installs Babashka for Clojure validation.
Installs the checksum-pinned Clojure jars used by Java interop fixtures.
Runs structured typed Java interop cases against an executable oracle.
Runs the authoritative pinned JVM Clojure oracle and verifies its typed checked-in fixture baseline.
Turns model-authored source into {candidate.clj, descriptor.json} and
reports whether it is fit to promote.
Consumes one structured propose-change result and materializes its complete
replacement source through the normal G1-G4 candidate gate.
Runs .clj files through both PTC-Lisp and Babashka/Clojure, comparing results.
Regenerates the spec checksums file for drift detection.
Validates PTC-Lisp specification against implementation.
Rejects relative Markdown links that ExDoc would silently resolve to a different extra with the same basename, then verifies that local links and assets inside rendered page content remain under the documentation root, exist, and name real anchors.