アーキテクチャ

The architecture.

One Rust binary. Five subsystems. Zero cloud dependencies. Every box below maps to a real module, port, or file on disk.

System topology.

出荷されるバイナリのプロセストポロジー:7つのエントリポイント、1つのランタイム、1組のローカルストア。以下の各ボックスは、実際のモジュール、ポート、またはディスク上のファイルに対応します。

One binary. Five subsystems. No cloud required.

データフロー Stage by stage.

Sheet 2は、ランタイムをステージごとに追跡し、繰り返し読み取りをほぼ無料にするキャッシュショートサーキットを含めて、1つのリクエストの流れを示します。シェルパスも同様の計算に基づいて並行して実行されます。

圧縮 engine.

Tree-sitter parses 27 languages into ASTs. 10 read modes select the right abstraction level — from full source to aggressive entropy filtering. 95+ shell patterns compress git, cargo, npm, docker, and kubectl output into compact evidence.

Explore read modes
ctx_read — mode selection auto
Available modes
full entire file, no compression
signatures fn signatures + type defs
map structural overview
diff uncommitted changes only
task query-conditioned extract
aggressive maximum compression
entropy information-dense lines
reference symbols + doc comments
lines:N-M specific line range
Selected: signatures (420 lines → 18 lines)
27 languages · tree-sitter −95.7%

Memory, agents, security.

Content-addressed caching collapses re-reads to ~13 tokens. A knowledge graph persists decisions across sessions. The agent bus coordinates multiple agents without duplicating context. PathJail, shell allowlists, and TOCTOU checks enforce deny-by-default boundaries on every call.

Security model
lean-ctx doctor all passed
Cache 47 entries · 73% hit rate
Knowledge 342 nodes · 1,205 edges
Agent bus 3 agents registered
PathJail root: /Users/dev/project
Allowlist 14 allow, 6 deny
Redaction .env, credentials.*
TOCTOU open-handle verify active
Ledger Ed25519-signed · 0 violations
8/8 subsystems healthy deny-by-default

Engineering data sheet.

図面を裏付ける参照テーブル:すべての表面とその輸送とライフサイクル、オンディスクレイアウト、適応学習層、およびランタイムが強制するセキュリティ境界です.

Aプロセスモデル

すべてのサーフェスは、異なる役割を持つ同じバイナリです。クラウド接続を必要とするものは何もありません。すべてがローカルファーストでバインドされます。

REF SURFACE TRANSPORT ENDPOINT LIFECYCLE コマンド
01 MCP server (stdio) JSON-RPC over stdin/stdout spawned per editor session child process of the editor lean-ctx
02 MCP server (HTTP) MCP Streamable HTTP localhost, configurable --host/--port foreground or service lean-ctx serve
03 IPC daemon Unix Domain Socket OS data dir, e.g. ~/Library/Application Support/lean-ctx/daemon.sock launchd / systemd autostart lean-ctx serve --daemon
04 Shell hook process exec, compressed stdout wraps IDE bash calls + interactive shells per command lean-ctx -c "<cmd>"
05 API proxy HTTP (LLM API pass-through) localhost:4444 (default) on demand lean-ctx proxy start
06 Web dashboard HTTP + bearer token localhost:3333 (default, --port) on demand lean-ctx dashboard
07 Terminal UI TTY (in-place redraw) live event stream / 1 s refresh interactive lean-ctx watch · gain --live

Bストレージレイアウト — ローカルXDGディレクトリ

永続的な状態は、XDGベースディレクトリ内のプレーンファイルです:検査可能、エクスポート可能、削除可能です。これらのローカルフォルダ以外に隠されたデータベースはありません。

アーティファクト FORM 目的
config.toml TOML Single config file — integration mode, compression, providers, opt-outs (config dir)
cache/ content-addressed Session file cache; unchanged re-reads collapse to ~13-token stubs (cache dir)
bm25 index inverted index Lexical search over code chunks + provider documents (data dir)
context_graph/ property graph Imports, calls, types across files and repos — powers map mode + deep queries (data dir)
knowledge SQLite Persistent facts, decisions, rooms — recalled across sessions, CCP (data dir)
savings ledger append-only JSONL Every compression event; Ed25519-signable for audit (data dir)
litm_calibration.json JSON Learned context-position hit rates (lost-in-the-middle calibration) (cache dir)
events.jsonl event stream Live feed consumed by watch, dashboard and efficacy reports (state dir)

C適応学習レイヤー

バウンスや編集失敗などの品質シグナルから、あなたの実際の使用状況に合わせて圧縮を調整する7つのオンライン学習メカニズム。 詳細:適応学習 →

  • L1
    Adaptive thresholds Online-learned compression aggressiveness from quality signals (bounces, edit failures, clean runs)
  • L2
    LITM calibration Empirical placement of critical context at positions the model actually attends to
  • L3
    Stigmergic scent field Multi-agent coordination via decaying markers: claimed, done, stuck, hot, avoid
  • L4
    Delta playbook Incremental checkpoint snapshots that survive context compaction
  • L5
    Query-conditioned IB Information-Bottleneck compression fused with query relevance
  • L6
    Theta-gamma chunking Wakeup facts grouped in attention-friendly bursts
  • L7
    Semantic dedup Likelihood-scored redundancy filtering across the session

Dセキュリティ境界

ランタイムで強制されるハード保証。 セキュリティモデル →

  • PathJail Every file access is canonicalised and confined to the workspace root
  • IDE config-dir jail Home-level IDE/agent config dirs (~/.claude, ~/.codex, ~/.codebuddy, …) are writable only when allow_ide_config_dirs is opted in; otherwise PathJail blocks them
  • Shell allowlist Deny-by-default command policy for agent-issued shell executions
  • Local-first All processing on-device; dashboard binds to localhost and requires a bearer token
  • Signed evidence Savings ledger entries are Ed25519-signable and batch-verifiable

Explore thesource.

LeanCTX is open source. Read the code, understand the design, contribute.

Support this project