{"_id":"@bpmsoftwaresolutions/sej-runtime-resolver","_rev":"3-eccbc2867b2da0696e6d0cd6ddff55ab","name":"@bpmsoftwaresolutions/sej-runtime-resolver","dist-tags":{"latest":"0.1.26"},"versions":{"0.1.24":{"name":"@bpmsoftwaresolutions/sej-runtime-resolver","version":"0.1.24","_id":"@bpmsoftwaresolutions/sej-runtime-resolver@0.1.24","maintainers":[{"name":"bpmsoftwaresolutions","email":"sjones@bpmsoftwaresolutions.com"}],"bin":{"sej-resolver":"packages/node/src/cli.cjs"},"dist":{"shasum":"e67738e63d6f5230fbcad70971c1a47993f625e0","tarball":"https://registry.npmjs.org/@bpmsoftwaresolutions/sej-runtime-resolver/-/sej-runtime-resolver-0.1.24.tgz","fileCount":25,"integrity":"sha512-cw4HeRzH2aq/B//wl6JkuSifoyyOqPyU96zYu8e7miHjavJw1avckv95ijcRY8INkRavGPXJ4OlvpRQIca8DPQ==","signatures":[{"sig":"MEQCIEOSVUQl1lG4xoJ46nJlF7CgXmADXTULYdnNKNOMRT7YAiA6Lmywa3WPYMh/KpmVabpqikzIkmdbqiwCXT75jR1K+w==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":663531},"main":"packages/node/src/resolver.cjs","type":"commonjs","_from":"file:D:\\a\\sej-runtime-resolver\\sej-runtime-resolver\\artifacts\\bpmsoftwaresolutions-sej-runtime-resolver-0.1.24.tgz","exports":{".":"./packages/node/src/resolver.cjs","./doorway":"./packages/node/src/doorway.cjs","./package.json":"./package.json"},"scripts":{"test":"powershell -NoProfile -ExecutionPolicy Bypass -File ./conformance/run-all.ps1","test:node":"npm test --prefix ./packages/node","sej:resolve":"node ./packages/node/src/cli.cjs resolve","facade:generate":"node ./packages/node/src/cli.cjs facade:generate"},"_npmUser":{"name":"bpmsoftwaresolutions","email":"sjones@bpmsoftwaresolutions.com"},"_resolved":"D:\\a\\sej-runtime-resolver\\sej-runtime-resolver\\artifacts\\bpmsoftwaresolutions-sej-runtime-resolver-0.1.24.tgz","_integrity":"sha512-cw4HeRzH2aq/B//wl6JkuSifoyyOqPyU96zYu8e7miHjavJw1avckv95ijcRY8INkRavGPXJ4OlvpRQIca8DPQ==","_npmVersion":"10.8.2","description":"Complete SEJ Runtime Resolver distribution for Node.js, Python, and .NET.","directories":{},"_nodeVersion":"20.20.2","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/sej-runtime-resolver_0.1.24_1784799275311_0.8576194639202104","host":"s3://npm-registry-packages-npm-production"}},"0.1.25":{"name":"@bpmsoftwaresolutions/sej-runtime-resolver","version":"0.1.25","_id":"@bpmsoftwaresolutions/sej-runtime-resolver@0.1.25","maintainers":[{"name":"bpmsoftwaresolutions","email":"sjones@bpmsoftwaresolutions.com"}],"bin":{"sej-resolver":"packages/node/src/cli.cjs"},"dist":{"shasum":"ac49512d343716fdea10fb032f4ea5710bfb15d2","tarball":"https://registry.npmjs.org/@bpmsoftwaresolutions/sej-runtime-resolver/-/sej-runtime-resolver-0.1.25.tgz","fileCount":23,"integrity":"sha512-Ec0HC7k3DqRFGybazSOf7aruXPx2n32v4JE2lQG5VJYIgM1AZ+QwJdShq53luFx50nlhvphZGFO+W9YI2WjOpQ==","signatures":[{"sig":"MEUCIQDrBk3ioVT4aLuM2tjAbqb8QXxbOtuesemfhfZYXKKS7AIgLcq/xy6hh6qV3pECUuhMrvb6tK05bmhiAcJX2IGiBTI=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":392051},"main":"packages/node/src/resolver.cjs","type":"commonjs","_from":"file:D:\\a\\sej-runtime-resolver\\sej-runtime-resolver\\artifacts\\bpmsoftwaresolutions-sej-runtime-resolver-0.1.25.tgz","exports":{".":"./packages/node/src/resolver.cjs","./doorway":"./packages/node/src/doorway.cjs","./package.json":"./package.json"},"scripts":{"test":"powershell -NoProfile -ExecutionPolicy Bypass -File ./conformance/run-all.ps1","test:node":"npm test --prefix ./packages/node","sej:resolve":"node ./packages/node/src/cli.cjs resolve","facade:generate":"node ./packages/node/src/cli.cjs facade:generate"},"_npmUser":{"name":"bpmsoftwaresolutions","email":"sjones@bpmsoftwaresolutions.com"},"_resolved":"D:\\a\\sej-runtime-resolver\\sej-runtime-resolver\\artifacts\\bpmsoftwaresolutions-sej-runtime-resolver-0.1.25.tgz","_integrity":"sha512-Ec0HC7k3DqRFGybazSOf7aruXPx2n32v4JE2lQG5VJYIgM1AZ+QwJdShq53luFx50nlhvphZGFO+W9YI2WjOpQ==","_npmVersion":"10.8.2","description":"Complete SEJ Runtime Resolver distribution for Node.js, Python, and .NET.","directories":{},"_nodeVersion":"20.20.2","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/sej-runtime-resolver_0.1.25_1784822518859_0.8413438471207773","host":"s3://npm-registry-packages-npm-production"}},"0.1.26":{"name":"@bpmsoftwaresolutions/sej-runtime-resolver","version":"0.1.26","description":"Complete SEJ Runtime Resolver distribution for Node.js, Python, and .NET.","main":"packages/node/src/resolver.cjs","type":"commonjs","exports":{".":"./packages/node/src/resolver.cjs","./doorway":"./packages/node/src/doorway.cjs","./package.json":"./package.json"},"bin":{"sej-resolver":"packages/node/src/cli.cjs"},"publishConfig":{"access":"public"},"scripts":{"prepack":"node ./conformance/generate-package-authority.cjs node && node ./conformance/generate-package-authority.cjs python && node ./conformance/generate-package-authority.cjs csharp","test":"powershell -NoProfile -ExecutionPolicy Bypass -File ./conformance/run-all.ps1","test:node":"npm test --prefix ./packages/node","sej:resolve":"node ./packages/node/src/cli.cjs resolve","facade:generate":"node ./packages/node/src/cli.cjs facade:generate"},"_id":"@bpmsoftwaresolutions/sej-runtime-resolver@0.1.26","_integrity":"sha512-eeTNrbnHSYVRrKNaivH8QWoNUsEgcf68JcxUw/zuiBMUVY/9b0f6k37vp2S0nn6MqlspyIj/fsmN2jwFYWgEaQ==","_resolved":"D:\\a\\sej-runtime-resolver\\sej-runtime-resolver\\artifacts\\bpmsoftwaresolutions-sej-runtime-resolver-0.1.26.tgz","_from":"file:D:\\a\\sej-runtime-resolver\\sej-runtime-resolver\\artifacts\\bpmsoftwaresolutions-sej-runtime-resolver-0.1.26.tgz","_nodeVersion":"20.20.2","_npmVersion":"10.8.2","dist":{"integrity":"sha512-eeTNrbnHSYVRrKNaivH8QWoNUsEgcf68JcxUw/zuiBMUVY/9b0f6k37vp2S0nn6MqlspyIj/fsmN2jwFYWgEaQ==","shasum":"4d1d456718adac1e2a4c22ede51ec7c145a47d80","tarball":"https://registry.npmjs.org/@bpmsoftwaresolutions/sej-runtime-resolver/-/sej-runtime-resolver-0.1.26.tgz","fileCount":26,"unpackedSize":673432,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIBJSz7F0v0G4dLUiEz9ckoC1+VK3lwRUL4RvrTm5+Zk0AiEA7RCrgeWmmsNhEYLL0pOgI3x1ZWObeWRAzHWNCpA2nD4="}]},"_npmUser":{"name":"bpmsoftwaresolutions","email":"sjones@bpmsoftwaresolutions.com"},"directories":{},"maintainers":[{"name":"bpmsoftwaresolutions","email":"sjones@bpmsoftwaresolutions.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/sej-runtime-resolver_0.1.26_1784824364068_0.1036235901975393"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-23T09:34:35.182Z","modified":"2026-07-23T16:32:44.373Z","0.1.24":"2026-07-23T09:34:35.451Z","0.1.25":"2026-07-23T16:01:59.070Z","0.1.26":"2026-07-23T16:32:44.228Z"},"description":"Complete SEJ Runtime Resolver distribution for Node.js, Python, and .NET.","maintainers":[{"name":"bpmsoftwaresolutions","email":"sjones@bpmsoftwaresolutions.com"}],"readme":"# SEJ Runtime Resolver\r\n\r\nResolved scenario graphs may carry `authorityProvenance` as defined by `contracts/schemas/authority-provenance.schema.v1.json`: the root scenario, exact authority set, and resolver policy hash. This provenance is immutable input lineage; local primitive `authority.scope` fields remain resource guards and do not grant scenario execution authority.\r\n\r\nThis repository owns the approved Resolver implementations for Semantic Executable JSON.\r\n\r\n## Core Rule\r\n\r\nSEJ is the source-truth path.\r\n\r\nDo not generate source truth inside authored code files. Do not add a product-specific generator brain to the resolver. Do not encode facade templates, SDK decisions, business workflows, adapter choreography, or package layout meaning inside runtime code.\r\n\r\nThe resolver exists to execute declared SEJ. If something must be generated, materialized, projected, hashed, or evidenced, the declaration belongs in SEJ and the resolver may only perform the approved primitive mechanics required by that declaration.\r\n\r\nThe architectural line is:\r\n\r\n```text\r\nSEJ declares meaning\r\nResolver executes generic primitives\r\nPrimitives perform bounded mechanics\r\nEvidence records the result\r\n```\r\n\r\nFor generated surfaces, the flow is:\r\n\r\n```text\r\nSEJ declares the facade projection\r\npackage.json exposes a resolver CLI doorway\r\nCLI invokes the resolver\r\nresolver executes SEJ stages\r\nartifact.materialize.v1 writes the declared artifact\r\nevidence.emit.v1 writes the declared receipt\r\n```\r\n\r\nThe CLI is not a generator. It is only a doorway into the resolver.\r\n\r\n## Boundary Rules\r\n\r\n- SEJ source truth lives under `contracts/`\r\n- Resolver implementations live under `packages/`\r\n- Generated facades belong in product SDK repos, not here\r\n- Primitive handlers live only inside approved Resolver packages\r\n- Product logic never belongs in primitive handlers\r\n- Generated/disposable artifacts must be declared by SEJ, not invented by code\r\n- Evidence must be declared and emitted through SEJ-backed resolver execution\r\n\r\n## Distribution Boundary\r\n\r\nThe repository root is the single holistic distribution boundary. The root\r\n`package.json` publishes one npm package containing the Node.js, Python, and\r\n.NET resolver implementations under `packages/`.\r\n\r\nThe manifests inside `packages/node`, `packages/python`, and `packages/csharp`\r\ndescribe and test their runtime implementations; they are not independent\r\npublication entrypoints. CI/CD packs and publishes only the repository root.\r\n\r\n## What SEJ Owns\r\n\r\nSEJ owns all product and artifact meaning, including:\r\n\r\n- contract keys\r\n- command keys\r\n- source-truth paths\r\n- output artifact paths\r\n- facade content\r\n- projection manifests\r\n- receipt content\r\n- evidence shape\r\n- blocked and allowed execution surfaces\r\n- primitive operation selection\r\n- primitive payload data\r\n\r\nIf a facade line appears in output, it must be traceable to SEJ data. If an evidence field appears in a receipt, it must be traceable to SEJ data or to the generic output of an approved primitive.\r\n\r\n## What Resolver Code Owns\r\n\r\nResolver code owns generic execution only:\r\n\r\n- resolve references\r\n- resolve values\r\n- evaluate predicates\r\n- project values\r\n- execute stages and nested contracts\r\n- dispatch approved primitive handlers\r\n- fail closed when a declaration cannot be executed safely\r\n\r\nResolver code must remain domain-neutral. It must not branch on customer domains, SDK names, command families, product workflows, or business policy. It must not know how to generate a specific facade. It may only materialize content that SEJ declares.\r\n\r\n## Materialization\r\n\r\nMaterialization is an approved effect tier, not a product generator.\r\n\r\nCurrent materialization primitives include:\r\n\r\n- `filesystem.ensure_directory.v1`\r\n- `artifact.materialize.v1`\r\n- `hash.compute.v1`\r\n- `evidence.emit.v1`\r\n\r\nThese primitives are data-driven through SEJ steps. A SEJ contract chooses the primitive operation and supplies the payload:\r\n\r\n```json\r\n{\r\n  \"id\": \"materializeFacade\",\r\n  \"type\": \"resolver\",\r\n  \"operation\": \"artifact.materialize.v1\",\r\n  \"payload\": {\r\n    \"authority\": {\r\n      \"scope\": \"tmp_workspace_only\"\r\n    },\r\n    \"artifact\": {\r\n      \"path\": \"$constants.facadePath\",\r\n      \"format\": \"text\",\r\n      \"joinWith\": \"\\n\",\r\n      \"content\": [\r\n        \"'use strict';\",\r\n        \"// GENERATED FILE. DO NOT EDIT.\",\r\n        \"module.exports = {};\"\r\n      ]\r\n    }\r\n  }\r\n}\r\n```\r\n\r\nThe handler does not decide that this is a facade. It only sees a declared artifact path, format, content, and authority metadata.\r\n\r\nThe current effect handlers enforce relative-path syntax and reject lexical parent traversal. They do not enforce allowed workspace roots, inspect symlinks, prove ownership, provide compare-and-swap protection, or make multi-file writes atomic. A governed host must enforce those workspace capabilities before invoking resolver effects. Resolver effects are mechanics, not a filesystem security boundary.\r\n\r\n## DTO Projection Handles\r\n\r\nThe resolver can expose declared DTO projection handles when a SEJ contract includes `resultProjection`.\r\n\r\nThe resolver owns only this generic work:\r\n\r\n- resolve the declared `dtoContractKey`\r\n- resolve the declared `projectionContractKey`\r\n- resolve the declared `projectionSource`\r\n- apply the declared projection to resolver operation state\r\n- return `projectedOutputShape`\r\n- emit `resolverProjectionEvidence`\r\n- fail closed with `unsupportedProjectionReason`\r\n\r\nThe resolver does not detect DTO stitching, inspect product source code, route host-tool candidates, or decide promotion status. Those decisions belong to the consuming host.\r\n\r\nMinimal shape:\r\n\r\n```json\r\n{\r\n  \"resultProjection\": {\r\n    \"dtoContractKey\": \"example.operation.result.dto.v1\",\r\n    \"projectionContractKey\": \"example.operation.result.projection.v1\",\r\n    \"projectionSource\": \"operationState\"\r\n  }\r\n}\r\n```\r\n\r\nSuccessful resolver output includes:\r\n\r\n```text\r\ndtoContractKey\r\nprojectionContractKey\r\nprojectionSource\r\nprojectedOutputShape\r\nresolverProjectionEvidence\r\nunsupportedProjectionReason\r\n```\r\n\r\nUnsupported or missing projection declarations fail closed with one of:\r\n\r\n```text\r\ndto_contract_missing\r\nprojection_contract_missing\r\nprojection_source_missing\r\nprojection_operation_unsupported\r\nprojection_contract_invalid\r\nprojected_output_shape_invalid\r\ncross_language_projection_mismatch\r\n```\r\n\r\n## Runtime Import Projection Handles\r\n\r\nThe resolver can also expose declared runtime import/dependency projection handles when a SEJ contract includes `runtimeImportProjection`.\r\n\r\nThis path is intentionally narrow:\r\n\r\n- host tools extract runtime dependency facts\r\n- SEJ declares the runtime import contract and projection contract\r\n- Resolver validates the declared fact shape\r\n- Resolver projects facts into `projectedRuntimeImports`\r\n- Resolver projects facts into `projectedRuntimeDependencyGraph`\r\n- Resolver emits `resolverRuntimeImportProjectionEvidence`\r\n- Resolver fails closed with `unsupportedRuntimeImportProjectionReason`\r\n\r\nThe resolver must not scan source text, regex import statements, inspect product file layout, decide whether `src/node` should relocate, label unmanaged binding debt, or make promotion decisions.\r\n\r\nMinimal shape:\r\n\r\n```json\r\n{\r\n  \"runtimeImportProjection\": {\r\n    \"runtimeSurfaceBindingKey\": \"example.runtime_surface.bindings.v1\",\r\n    \"runtimeImportContractKey\": \"example.runtime_imports.dto.v1\",\r\n    \"runtimeImportProjectionKey\": \"example.runtime_imports.projection.v1\",\r\n    \"runtimeDependencySource\": \"stageResult.runtimeDependencyFacts\"\r\n  }\r\n}\r\n```\r\n\r\nAccepted runtime dependency facts are already-extracted telemetry objects. They must include `kind` and `sourceLocation`. Import-like facts require `specifier`; path-like facts require `path`.\r\n\r\nSuccessful resolver output includes:\r\n\r\n```text\r\nruntimeImportContractKey\r\nruntimeSurfaceBindingKey\r\nruntimeImportProjectionKey\r\nruntimeDependencySource\r\nprojectedRuntimeImports\r\nprojectedRuntimeDependencyGraph\r\nresolverRuntimeImportProjectionEvidence\r\nunsupportedRuntimeImportProjectionReason\r\n```\r\n\r\nFor `tmp_runtime_scratch_path`, the resolver only projects neutral graph shape:\r\n\r\n```text\r\nnodeKey: tmp:<path>\r\nnodeType: tmp_runtime_scratch_path\r\ngraphRole: scratch_runtime_artifact\r\n```\r\n\r\nThe resolver does not assign promotion, maturity, source-truth, relocation, or runtime-surface authority to `.tmp` paths.\r\n\r\nUnsupported, missing, or invalid runtime import projection declarations fail closed with one of:\r\n\r\n```text\r\nruntime_import_contract_missing\r\nruntime_import_projection_contract_missing\r\nruntime_dependency_source_missing\r\nruntime_dependency_fact_shape_invalid\r\nruntime_import_projection_operation_unsupported\r\nruntime_import_projection_contract_invalid\r\nprojected_runtime_import_shape_invalid\r\nprojected_runtime_dependency_graph_invalid\r\ncross_language_runtime_import_projection_mismatch\r\n```\r\n\r\nThe operating contract is:\r\n\r\n```text\r\nHost tools extract facts.\r\nResolver projects facts.\r\nContracts own shape.\r\nGraph reveals relocation risk.\r\n```\r\n\r\n## Generated-Body Consumer Contract\r\n\r\nThe exact result-envelope contract relied on by generated language bodies (`resolveContract` entry points, guaranteed fields, fail-closed vs. throw conditions, and runtime-identity exposure) is documented in `Docs/consumer-contract.md`. The runtime posture for declared numeric bounds (projector `typeRegistry` minimum/maximum) is documented separately in `Docs/numeric-bound-posture.md`.\r\n\r\n## Adding Capability\r\n\r\nIf new capability is needed, add it through the primitive admission path:\r\n\r\n```text\r\nprimitive catalog entry\r\ninput schema\r\noutput schema\r\nreceipt shape\r\ngeneric resolver handler\r\nconformance fixture\r\nexpected result\r\nevidence\r\n```\r\n\r\nDo not bypass this path by hiding product behavior inside `cli.cjs`, a package script, a resolver helper, or a primitive handler.\r\n\r\nA valid primitive is small and generic. Examples of acceptable future primitive shapes:\r\n\r\n- `filesystem.read_text.v1`\r\n- `artifact.copy.v1`\r\n- `json.patch.v1`\r\n- `template.render.v1`\r\n- `process.invoke_governed.v1`\r\n\r\nAn invalid primitive is product-shaped. Examples of invalid primitive shapes:\r\n\r\n- `facade.generate.v1`\r\n- `sdk.generate_client.v1`\r\n- `customer_onboarding.workflow.v1`\r\n- `starter_workspace.create_product_layout.v1`\r\n\r\nIf the capability has product meaning, the meaning belongs in SEJ. The primitive should only provide the smallest governed mechanic needed to execute that meaning.\r\n\r\n## CLI Doorway\r\n\r\nThe Node package exposes a thin resolver CLI:\r\n\r\n```powershell\r\ncd packages/node\r\nnpm run facade:generate -- --sej ..\\..\\contracts\\conformance\\corpus\\sample-facade-materialize.conformance-fixture.v1.json\r\n```\r\n\r\nOr from the repository root:\r\n\r\n```powershell\r\nnode packages\\node\\src\\cli.cjs facade:generate --sej contracts\\conformance\\corpus\\sample-facade-materialize.conformance-fixture.v1.json\r\n```\r\n\r\nThe CLI may:\r\n\r\n- read command arguments\r\n- load JSON from `--sej`, `--fixture`, or `--contract`\r\n- load optional input JSON\r\n- call `resolver.resolveContract(...)`\r\n- print the resolver result\r\n- return an exit code\r\n\r\nThe CLI must not:\r\n\r\n- contain facade templates\r\n- contain SDK rules\r\n- contain product path policy\r\n- contain business workflow logic\r\n- mutate source truth\r\n- bypass primitive catalog governance\r\n\r\n## Sample Facade Materialization\r\n\r\nThe conformance fixture at:\r\n\r\n```text\r\ncontracts/conformance/corpus/sample-facade-materialize.conformance-fixture.v1.json\r\n```\r\n\r\ndeclares a disposable facade and receipt. Running it from the repository root materializes:\r\n\r\n```text\r\n.tmp/sample_script_facade/src_facades/sample.facade.cjs\r\n.tmp/sample_script_facade/evidence/sample-facade.receipt.v1.json\r\n```\r\n\r\nThose generated files are disposable outputs. The SEJ fixture is the source truth.\r\n\r\n## Fail-Closed Posture\r\n\r\nThe resolver must fail closed when:\r\n\r\n- a reference cannot be resolved\r\n- a primitive is unsupported\r\n- a materialization path is absolute or contains lexical parent traversal\r\n- an adapter or write step attempts to bypass resolver governance\r\n- product behavior appears where only generic primitive mechanics belong\r\n\r\nThe old `write` step remains blocked. Honest materialization must go through approved effect primitives such as `artifact.materialize.v1` and `evidence.emit.v1`.\r\n\r\n## Repository Goals\r\n\r\n- keep Resolver behavior generic and domain-neutral\r\n- preserve identical conformance across Node, Python, and C#\r\n- block product logic from leaking into the runtime boundary\r\n- publish evidence for inventory, conformance, and release state\r\n\r\n## Current Implementation Status\r\n\r\n- current package and approved release identity: `0.1.21`\r\n- release: `v0.1.21` with Node published to npm and Node, Python, and C# artifacts attached to the GitHub release\r\n- `v0.1.20` is retained as repository history but is superseded because it retained application-specific operations and evidence outside the resolver boundary\r\n- `v0.1.19` is retained as repository history but is superseded because its tagged source did not compile in C# and did not fully govern its newly registered primitives\r\n- 43 governed primitives with aligned Node, Python, and C# capability contracts\r\n- 95 shared cross-language conformance fixtures\r\n- primitive catalog v1 defined\r\n- Node, Python, and C# resolver packages implemented\r\n- shared cross-language conformance suite active\r\n- materialization effect tier admitted\r\n- thin Node resolver CLI doorway exposed\r\n- sample SEJ facade materialization fixture passing\r\n","readmeFilename":"README.md"}