Documentation contents

Configuration reference

Every field OpenHarnX 0.1.1 reads from ohx.toml and contract files, with its default. Nothing else is read.

OpenHarnX 0.1.1

ohx.toml at the repository root holds project defaults. ohx contract new copies them into each contract, ohx init --lock-tests and ohx gate read them, and in CI only the base branch's ohx.toml counts. Commit it. A change to ohx.toml is a weakening finding.

Project settings#

FieldTypeDefaultMeaning
pythonpath.venv or venv, else the active virtual environmentThe interpreter checks run with. {python} and {bindir} in commands point to it
environment"uv" or "npm"none"uv": checks run from an environment OpenHarnX builds from the accepted uv.lock, locked wheels only. "npm" (experimental): installs from the base's package-lock.json with install scripts off. A changed lockfile runs nothing
pytest_argslist of strings[]Added to the locked run and the default tests run, for example ["-n", "auto"] for pytest-xdist
suite_timeout_spositive number300Seconds each whole suite OpenHarnX adds may run
approverslist of stringsnoneWho may sign test-change approvals: "name ssh-ed25519 AAAA…". Read from the base only
js_runner"vitest", "jest" or "node"from package.jsonExperimental. Vitest or Jest when package.json lists it, else Node's own runner
mutation_budget_spositive number120Experimental. Seconds the advisory mutation check may take

Checks: [[obligations]]#

Each table adds one check.

FieldTypeDefaultMeaning
idstringrequiredUnique name, shown in reports
kind"acceptance", "regression" or "check"requiredAcceptance tests prove the task; regression suites get a per-test baseline; checks are commands such as linters
mandatorytrue or falserequiredOnly mandatory checks decide the verdict
commandlist of stringsrequiredThe command, without a shell
timeout_spositive integer300Seconds before the check is stopped and reported unknown
envtable of strings{}Extra environment variables for the check
protectedpathnoneA file or folder copied into the store at acceptance. Relative to the contract file
toml
python = ".venv/bin/python"
environment = "uv"
pytest_args = ["-n", "auto"]
suite_timeout_s = 1200

[[obligations]]
id = "lint"
kind = "check"
mandatory = true
command = ["{python}", "-m", "ruff", "check", "--no-cache", "."]

[[obligations]]
id = "types"
kind = "check"
mandatory = true
command = ["{python}", "-m", "mypy", "--cache-dir", "{tmp}/mypy"]

This is a shortened version of OpenHarnX's own ohx.toml. Keep caches in {tmp} or turn them off, so verification never writes into the candidate and can run sandboxed.

Placeholders in commands#

PlaceholderExpands to
{python}The checker interpreter
{bindir}The folder of the checker interpreter, for console scripts such as {bindir}/lint-imports
{tmp}The run's own temporary folder, the only place a sandboxed check may write
{protected}The locked copy of the check's protected path
{candidate}The candidate being judged
{junit}Where a JUnit-writing runner should put per-test results

{python} -m <module> checkers start through a launcher, so a file in the candidate cannot replace the module. Other commands are not covered by that protection.

Contract files only#

FieldMeaning
titleRequired
modebugfix or task for contracts you write. suite and gate are made by ohx init --lock-tests and ohx gate
change_summaryRequired. One line; becomes the report's changelog entry

A bugfix or task contract needs at least one mandatory acceptance check.

Environment variables#

VariableMeaning
OHX_HOMEThe evidence store. Default ~/.openharnx
OHX_SIGNING_KEYThe SSH key to sign evidence with, or none to turn signing off. Default: git's SSH signing key, else ~/.ssh/id_ed25519, id_ecdsa or id_rsa
OHX_SRTPath to srt, when it is not on PATH
Esc
Try verify, STALE, approve-tests or GitLab. Common pages: