Metadata-Version: 2.3
Name: context-loader
Version: 0.1.8
Summary: Render deterministic local Git context for Codex
License:                                  Apache License
                                    Version 2.0, January 2004
                                 http://www.apache.org/licenses/
         
            TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION
         
            1. Definitions.
         
               "License" shall mean the terms and conditions for use, reproduction,
               and distribution as defined by Sections 1 through 9 of this document.
         
               "Licensor" shall mean the copyright owner or entity authorized by
               the copyright owner that is granting the License.
         
               "Legal Entity" shall mean the union of the acting entity and all
               other entities that control, are controlled by, or are under common
               control with that entity. For the purposes of this definition,
               "control" means (i) the power, direct or indirect, to cause the
               direction or management of such entity, whether by contract or
               otherwise, or (ii) ownership of fifty percent (50%) or more of the
               outstanding shares, or (iii) beneficial ownership of such entity.
         
               "You" (or "Your") shall mean an individual or Legal Entity
               exercising permissions granted by this License.
         
               "Source" form shall mean the preferred form for making modifications,
               including but not limited to source code, documentation source, and
               configuration files.
         
               "Object" form shall mean any form resulting from mechanical
               transformation or translation of a Source form, including but
               not limited to compiled object code, generated documentation,
               and conversions to other media types.
         
               "Work" shall mean the work of authorship, whether in Source or
               Object form, made available under the License, as indicated by a
               copyright notice that is included in or attached to the work
               (an example is provided in the Appendix below).
         
               "Derivative Works" shall mean any work, whether in Source or Object
               form, that is based on (or derived from) the Work and for which the
               editorial revisions, annotations, elaborations, or other modifications
               represent, as a whole, an original work of authorship. For the
               purposes of this License, Derivative Works shall not include works
               that remain separable from, or merely link (or bind by name) to the
               interfaces of, the Work and Derivative Works thereof.
         
               "Contribution" shall mean any work of authorship, including
               the original version of the Work and any modifications or additions
               to that Work or Derivative Works thereof, that is intentionally
               submitted to Licensor for inclusion in the Work by the copyright
               owner or by an individual or Legal Entity authorized to submit on
               behalf of the copyright owner. For the purposes of this definition,
               "submitted" means any form of electronic, verbal, or written
               communication sent to the Licensor or its representatives, including
               but not limited to communication on electronic mailing lists, source
               code control systems, and issue tracking systems that are managed by,
               or on behalf of, the Licensor for the purpose of discussing and
               improving the Work, but excluding communication that is conspicuously
               marked or otherwise designated in writing by the copyright owner as
               "Not a Contribution."
         
               "Contributor" shall mean Licensor and any individual or Legal Entity
               on behalf of whom a Contribution has been received by Licensor and
               subsequently incorporated within the Work.
         
            2. Grant of Copyright License. Subject to the terms and conditions of
               this License, each Contributor hereby grants to You a perpetual,
               worldwide, non-exclusive, no-charge, royalty-free, irrevocable
               copyright license to reproduce, prepare Derivative Works of,
               publicly display, publicly perform, sublicense, and distribute the
               Work and such Derivative Works in Source or Object form.
         
            3. Grant of Patent License. Subject to the terms and conditions of
               this License, each Contributor hereby grants to You a perpetual,
               worldwide, non-exclusive, no-charge, royalty-free, irrevocable
               (except as stated in this section) patent license to make, have made,
               use, offer to sell, sell, import, and otherwise transfer the Work,
               where such license applies only to those patent claims licensable
               by such Contributor that are necessarily infringed by their
               Contribution(s) alone or by combination of their Contribution(s)
               with the Work to which such Contribution(s) was submitted. If You
               institute patent litigation against any entity (including a
               cross-claim or counterclaim in a lawsuit) alleging that the Work
               or a Contribution incorporated within the Work constitutes direct
               or contributory patent infringement, then any patent licenses
               granted to You under this License for that Work shall terminate
               as of the date such litigation is filed.
         
            4. Redistribution. You may reproduce and distribute copies of the
               Work or Derivative Works thereof in any medium, with or without
               modifications, and in Source or Object form, provided that You
               meet the following conditions:
         
               (a) You must give any other recipients of the Work or
                   Derivative Works a copy of this License; and
         
               (b) You must cause any modified files to carry prominent notices
                   stating that You changed the files; and
         
               (c) You must retain, in the Source form of any Derivative Works
                   that You distribute, all copyright, patent, trademark, and
                   attribution notices from the Source form of the Work,
                   excluding those notices that do not pertain to any part of
                   the Derivative Works; and
         
               (d) If the Work includes a "NOTICE" text file as part of its
                   distribution, then any Derivative Works that You distribute must
                   include a readable copy of the attribution notices contained
                   within such NOTICE file, excluding those notices that do not
                   pertain to any part of the Derivative Works, in at least one
                   of the following places: within a NOTICE text file distributed
                   as part of the Derivative Works; within the Source form or
                   documentation, if provided along with the Derivative Works; or,
                   within a display generated by the Derivative Works, if and
                   wherever such third-party notices normally appear. The contents
                   of the NOTICE file are for informational purposes only and do
                   not modify the License. You may add Your own attribution notices
                   within Derivative Works that you distribute, alongside or as an
                   addendum to the NOTICE text from the Work, provided that such
                   additional attribution notices cannot be construed as modifying
                   the License.
         
               You may add Your own copyright statement to Your modifications and
               may provide additional or different license terms and conditions
               for use, reproduction, or distribution of Your modifications, or
               for any such Derivative Works as a whole, provided Your use,
               reproduction, and distribution of the Work otherwise complies with
               the conditions stated in this License.
         
            5. Submission of Contributions. Unless You explicitly state otherwise,
               any Contribution intentionally submitted for inclusion in the Work
               by You to the Licensor shall be under the terms and conditions of
               this License, without any additional terms or conditions.
               Notwithstanding the above, nothing herein shall supersede or modify
               the terms of any separate license agreement you may have executed
               with Licensor regarding such Contributions.
         
            6. Trademarks. This License does not grant permission to use the trade
               names, trademarks, service marks, or product names of the Licensor,
               except as required for reasonable and customary use in describing the
               origin of the Work and reproducing the content of the NOTICE file.
         
            7. Disclaimer of Warranty. Unless required by applicable law or
               agreed to in writing, Licensor provides the Work (and each
               Contributor provides its Contributions) on an "AS IS" BASIS, WITHOUT
               WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied,
               including, without limitation, any warranties or conditions of
               TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A
               PARTICULAR PURPOSE. You are solely responsible for determining the
               appropriateness of using or redistributing the Work and assume any
               risks associated with Your exercise of permissions under this License.
         
            8. Limitation of Liability. In no event and under no legal theory,
               whether in tort (including negligence), contract, or otherwise,
               unless required by applicable law (such as deliberate and grossly
               negligent acts) or agreed to in writing, shall any Contributor be
               liable to You for damages, including any direct, indirect, special,
               incidental, or consequential damages of any character arising as a
               result of this License or out of the use or inability to use the
               Work (including but not limited to damages for loss of goodwill,
               work stoppage, computer failure or malfunction, or any and all
               other commercial damages or losses), even if such Contributor has
               been advised of the possibility of such damages.
         
            9. Accepting Warranty or Additional Liability. While redistributing
               the Work or Derivative Works thereof, You may choose to offer,
               and charge a fee for, acceptance of support, warranty, indemnity,
               or other liability obligations and/or rights consistent with this
               License. However, in accepting such obligations, You may act only
               on Your own behalf and on Your sole responsibility, not on behalf of
               any other Contributor, and only if You agree to indemnify, defend,
               and hold each Contributor harmless for any liability incurred by,
               or claims asserted against, such Contributor by reason of your
               accepting any such warranty or additional liability.
         
            END OF TERMS AND CONDITIONS
         
            APPENDIX: How to apply the Apache License to your work.
         
               To apply the Apache License to your work, attach the following
               boilerplate notice, with the fields enclosed by brackets "[]"
               replaced with your own identifying information. (Don't include
               the brackets!)  The text should be enclosed in the appropriate
               comment syntax for the file format. We also recommend that a file
               or class name and description of purpose be included on the same
               "printed page" as the copyright notice for easier identification.
         
            Copyright [yyyy] [name of copyright owner]
         
            Licensed under the Apache License, Version 2.0 (the "License");
            you may not use this file except in compliance with the License.
            You may obtain a copy of the License at
         
                http://www.apache.org/licenses/LICENSE-2.0
         
            Unless required by applicable law or agreed to in writing, software
            distributed under the License is distributed on an "AS IS" BASIS,
            WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
            See the License for the specific language governing permissions and
            limitations under the License.
         
Requires-Python: >=3.12, <3.13
Project-URL: Repository, https://github.com/xuanheng-tech/context-loader
Project-URL: Issues, https://github.com/xuanheng-tech/context-loader/issues
Description-Content-Type: text/markdown

# Context Loader

Context Loader renders deterministic, bounded context for one local Git working tree.
The default CLI output remains Markdown; a stable JSON interface is also available for machine
callers. The tool reads repository state and a fixed set of root files without fetching, executing
repository code, network access, or writes to the target repository. Runtime code uses only the
Python standard library.

## Open-source quick start

Context Loader is a local CLI that exports repository context deterministically for coding-agent workflows,
rendering stable Markdown or JSON output.

```bash
uv tool install context-loader
```

```bash
pip install context-loader
```

```bash
codex-project-context --repo /path/to/repo
```

```bash
codex-project-context --repo /path/to/repo --format json
```

## Install

Public stable release on PyPI: `0.1.8`.

Install via `uv`:

```bash
uv tool install context-loader
```

Install via `pip`:

```bash
pip install context-loader
```

For development or source-based installs tracking current repository (`0.1.8`):

```bash
uv tool install git+https://github.com/xuanheng-tech/context-loader.git
```

The repository also retains `./codex-project-context` as a direct development entry point.

### Distributions

From `0.1.8` the canonical PyPI distribution is **`context-loader`**. It carries the
`context_loader` runtime and installs the `codex-project-context` console script; the CLI name,
the JSON schema version and the public contract are unchanged by the rename.

**`codex-project-context-loader`** remains published as a compatibility distribution. From
`0.1.8` it contains no runtime and no console script and only depends on `context-loader==0.1.8`,
so installing either name yields exactly one implementation and one CLI. Existing pins keep
working, and releases `0.1.5`-`0.1.7` of the old name are unchanged. New integrations should
depend on `context-loader`.

The wheel installs the runtime package only. The source distribution additionally carries
`tool_cli_contract.json`, so a package-only consumer can pin the declared public CLI contract
without cloning. The test suite, `justfile` and lockfile stay in the Git repository and are not
part of either distribution; run them from a checkout of the matching tag.

## Platform and Runtime Requirements

- **Python**: Python 3.12 (`>=3.12,<3.13`). Runtime code uses only the Python standard library with zero runtime dependencies.
- **Git**: Requires the standard `git` CLI at the fixed absolute path `/usr/bin/git`. The
  executable is never resolved through `PATH`, so an installation elsewhere is not used and
  every invocation fails with exit `1`. Git runs with a sanitized environment that ignores
  system, global and per-command configuration, attributes, and hooks.
- **Operating System**: supported and locally tested on Ubuntu 24.04 LTS; CI also tests the
  GitHub-hosted Ubuntu runner. Other Linux/POSIX systems are unverified, not a portability promise.
  Windows is not supported.

Deterministic means byte-identical output for the same tool version, CLI arguments, canonical
repository path, readable file contents, directory entries, Git state/local refs, and relevant Git
configuration, with no concurrent changes. Different checkout paths, permissions, Git versions or
working-tree contents can change the output. The tool does not freeze a repository snapshot.

Output can contain sensitive information from the repository itself: README/instructions, declared
commands, paths, branch names and commit subjects. Fixed file selection and size limits are **not
automatic redaction**. Inspect the output before sharing it with a person or external service.

## Usage

```bash
codex-project-context --version
codex-project-context --repo /home/user/projects/example
codex-project-context --repo /home/user/projects/example --format markdown
codex-project-context --repo /home/user/projects/example --format json
codex-project-context --repo /home/user/projects/example \
  --focus "Authentication and session management" \
  --path auth/session.py
```

`--format` defaults to `markdown`. In Markdown mode, `--repo` retains the 0.1.1 contract: it must be
the absolute, canonical root of a non-bare Git working tree. In JSON mode, an absolute existing
directory inside the working tree is accepted; symlinks are normalized and the discovered root is
reported as `canonical_root`. Relative paths, non-Git directories, regular files, and bare
repositories are rejected in both modes.

`--focus` and `--path` are optional, bounded selection signals for the root `AGENTS.md`. `--path`
must be repository-relative. The collector does not retain either input in output or audit data.
Calls that omit both options remain valid and use the conservative fallback described below.

## Markdown Output

Successful repository collection uses schema `context-loader/v0.1` and emits these sections in
order:

1. `Git State`, including bounded working-tree changes
2. `Development Instructions`
3. `Project Overview`
4. `Declared Commands`
5. `Project Entry Files`
6. `Recent Commits`
7. `Directory Tree`

The output has no generated timestamp, AI summary, architecture inference, or diff body.

## JSON Output

`--format json` writes exactly one compact UTF-8 JSON document plus one trailing newline to stdout.
Keys are serialized in sorted order with `ensure_ascii=False`. The declared contract is:

```json
{
  "schema_version": 1,
  "tool": {
    "name": "context-loader",
    "version": "0.1.8"
  },
  "repository": {
    "requested_path": "/canonical/requested/path",
    "canonical_root": "/canonical/worktree/root"
  },
  "sources": [
    {
      "ordinal": 0,
      "kind": "agents",
      "scope": "repository",
      "path": "/canonical/worktree/root/AGENTS.md",
      "content_sha256": "sha256-hex",
      "content": "actual selected source text",
      "selection": {
        "source": "AGENTS.md",
        "selected_sections": [],
        "indexed_only_sections": [],
        "chars_selected": 0,
        "chars_omitted": 0,
        "truncated": false,
        "parse_fallback": false,
        "source_scan_truncated": false,
        "index_truncated": false
      }
    }
  ],
  "context": "the same assembled Markdown context",
  "context_sha256": "sha256-hex",
  "warnings": []
}
```

`context_sha256` hashes the UTF-8 bytes of `context`; each `content_sha256` does the same for that
source's `content`. `sources` contains only file bodies that actually enter the final context, in
assembly order, after the existing newline normalization and truncation rules. `scope` distinguishes
`repository` from `global`; version 0.1.8's fixed root-file selection currently emits only
`repository` sources and does not add any global-file discovery.

The optional `selection` object is present only on a rendered `AGENTS.md` source. Its section entries
contain heading, heading level, and fixed selection reasons; it never contains the original focus or
target path. Existing source fields and schema version 1 remain unchanged.

The JSON schema version and package version are independent: `schema_version` is currently the
integer `1`, while `tool.version` is `0.1.8`. Callers must depend only on fields declared above.
The document contains no generated time or random identifier, so unchanged input produces identical
JSON bytes. On failure, stdout remains empty and stderr contains only a short diagnostic.

## Authority Boundary

Context Loader is a bounded transport for repository-root context, not the authority for a
repository's instruction hierarchy. It reads the fixed root candidates listed below, renders them
under explicit limits, and stops there.

Resolving an instruction hierarchy stays with the calling agent harness. That includes any
shared or user-level instruction file outside the repository, nested or scoped `AGENTS.md` files
under subdirectories, and any include or import directive written inside an instruction file:
such a directive is transported as literal text and is never followed. `--path` selects sections
of the repository-root `AGENTS.md` only; it never changes which files are read.

A successful run therefore proves that the bounded root context was collected and rendered. It
does not prove that every instruction applicable to a task has been loaded.

## Supported Root Files

Only these exact files directly under the Git root are eligible:

- Development instructions: `AGENTS.md`
- Project overview: `README.md`
- Entry files, in fixed order: `pyproject.toml`, `justfile` or `Justfile`, `package.json`,
  `Makefile`, `Cargo.toml`, and `go.mod`

Lowercase `justfile` takes precedence over `Justfile`. Nested files, lockfiles, CI configuration,
`.env`, and glob-discovered files are not read.

A leading UTF-8 byte order mark is removed from the root `AGENTS.md` before parsing, so a
heading on the first line is still recognized as a heading.

The root `AGENTS.md` is split at Markdown headings outside fenced code blocks. The output always
starts with complete early sections fitting a 4-KiB head, then adds complete relevant sections in
source order using exact normalized focus/path tokens and their parent context. Remaining headings
appear in an explicit index whose body text is not loaded. With no selection signals, only the small
head and index are emitted. Unsafe heading parsing falls back to a bounded head and an explicit
manual-recovery notice. A head whose own headings would not fit the budget falls back to the same
bounded head without a section index; a single instruction file never fails the whole collection.

`Omitted source characters` is measured against the whole normalized source, so a bounded source
scan that ends before EOF still reports the characters it could not select.

## Limits

- Final stdout: 98,304 bytes
- `AGENTS.md`: 256-KiB bounded source scan; selected source plus selection audit remains at most
  16 KiB, including a 4-KiB maximum small head
- `README.md`: 16 KiB
- Each entry file: 8 KiB
- All entry-file bodies: 24 KiB
- Declared commands: 8 KiB
- Directory tree: 12 KiB, 300 entries, and depth 2
- Working-tree changes: 100 paths and 4 KiB
- Recent commits: 8

Truncation occurs only at complete UTF-8 and line boundaries and is marked explicitly.
These are output/capture limits. Eligible regular files are still streamed to EOF to validate UTF-8
and reject NUL bytes, including beyond the captured prefix; a large file can therefore take longer
to read. Symlinked candidate files are skipped, and directory symlinks are not traversed.

## Git State Semantics

Git state is derived only from the working tree and local refs. The command does not fetch or query
the remote.

- An unborn working tree reports its symbolic branch name, such as `Branch: main`, and
  `HEAD: unborn`.
- A detached HEAD reports `Branch: detached` and the resolved commit object ID.
- `Upstream` is the current branch's configured tracking target. Without one,
  `Upstream: not configured` is used.
- A configured target such as `origin/main` may be shown before its commit is resolvable locally;
  this is normal after cloning an empty remote.
- `Ahead / behind: not available` means the commit relationship cannot currently be computed.
  Counts are reported only when the configured upstream commit is available locally.

## Exit Codes

- `0`: context or version output completed successfully
- `1`: required Git collection or an internal operation failed
- `2`: command arguments or the repository path do not satisfy the contract

On nonzero exit, stdout is empty and a bounded diagnostic is written to stderr without a traceback
or candidate-file content.

## Not Included

Version 0.1.8 does not provide AI summaries, project-type detection, nested `AGENTS.md` handling,
Memory retrieval, semantic ranking, ignore-rule parsing, plugins, profiles, caches, databases,
network services, MCP, daemons, GUIs, CI/CD, telemetry, or automatic updates.

## Development

Run the complete local check:

```bash
just check
```

## Version maintenance

The versions in `pyproject.toml` and `context_loader/__init__.py`, the matching `CHANGELOG.md`
section, and required tests must change in the same release-preparation batch. `CHANGELOG.md` is the
authoritative version-change record. Merging to `master` is not a release; formal publication
still requires a separately created and pushed tag.

## Release closure and retries

GitHub `ci` and Gitea `quality` both use `just check`. GitHub `publish-pypi.yml` is the only
package build/upload authority, using the `pypi` environment and OIDC Trusted Publishing.
GitHub `release-record` closes the GitHub Release after package publication. Gitea `release`
only verifies the public release, mirrors its exact formal tag object if missing, and closes
the Gitea Release record. It builds no package and has no PyPI publishing credentials.
No private endpoint or credential is needed on GitHub.

Release checks use Python 3.12, Git, and the runner's existing OpenSSL CLI. They compare downloaded
PyPI file bytes, metadata and SHA-256, plus the publisher/tag/commit claims in PyPI's HTTPS-served
provenance. This is an identity check, not an independent cryptographic Sigstore verifier.

- Tag/version or expected-commit mismatch and `just check` failure stop before build/upload.
- The build refuses to run unless `dist/` is empty, and refuses any produced file set other than
  the current version's wheel and sdist. A leftover artifact can carry a release filename while
  holding different bytes, so it is never treated as the current release.
- A complete matching PyPI version skips both build and upload. Missing/conflicting provenance,
  unexpected files or differing hashes stop; existing files are never overwritten.
- Release closure runs right after publication, so `record`, `verify` and the Gitea sync poll the
  PyPI index and integrity endpoints for a bounded period before treating a version as missing.
  Build and upload selection never poll: there, an absent version still means "not yet published".
- A refused release API call reports the bounded server message alongside its status code. A
  GitHub Release is created against the release commit, so that commit must already be reachable
  from the public branch; pushing the release commit to the public branch precedes record closure.
- If an upload stopped after one file, rerun the **original failed publish job** while its original
  `dist` artifact is available. It compares the original bytes and selects only missing files.
  A full rebuild is refused for an incomplete PyPI file set. If the original artifact is gone,
  stop for recovery; do not substitute a fresh build.
- If PyPI succeeded but a Release failed, rerun `release-record` on GitHub (manual input: tag)
  and `release` on Gitea. Existing matching records pass; a missing record is created once;
  a draft, differing recorded identity or tag conflict stops without overwriting it.
- Gitea also retries the current project version on `master` pushes, only after that version has
  a public tag, verified PyPI files and GitHub Release. An unpublished version reports `SKIP`.
  Use the **built-in Actions job token** for exact missing-tag synchronization: Gitea suppresses
  recursive workflows for that actor, including old tag workflows. Never use a PAT for this step.
- Keep historical/private tags and archive refs private. Never mirror all refs or push all tags.

Release verification reads the public GitHub API with `PUBLIC_GITHUB_TOKEN` when it is set, as CI
does. A local caller without that variable falls back to the credential an authenticated
[GitHub CLI](https://cli.github.com/) already holds, keeping verification authenticated and clear
of the unauthenticated rate limit without this repository storing a token. With neither available
the calls stay unauthenticated and may be rate limited; the reported API message names that cause.

For each formal version, verify both platforms separately (the Gitea API URL and `RELEASE_TOKEN`
come from the caller's private environment):

```bash
python scripts/release.py verify vX.Y.Z
python scripts/release.py verify vX.Y.Z --platform gitea \
  --api-url "$GITEA_API_URL" --repository "$GITEA_REPOSITORY"
```

Each check reports tag commit, PyPI file identities and the selected Release ID. Git Finalizer's
`remote_verified` describes branch publication only; report package/release verification separately.
