Metadata-Version: 2.4
Name: collective-phase-control-fabric
Version: 0.6.0
Summary: Evidence-bound analysis and finite intervention control for collective workflows.
Project-URL: Documentation, https://github.com/kadubon/collective-phase-control-fabric#readme
Project-URL: Issues, https://github.com/kadubon/collective-phase-control-fabric/issues
Project-URL: Repository, https://github.com/kadubon/collective-phase-control-fabric
Author: Collective Phase Control Fabric contributors
License-Expression: Apache-2.0
License-File: LICENSE
Keywords: audit-trail,collective-intelligence,decision-support,digital-signatures,dsse,evidence-control,fastapi,kubernetes,multi-agent-systems,network-science,oidc,petri-nets,postgresql,provenance,python,reaction-networks,reproducibility,scientific-computing,supply-chain-security,uv
Classifier: Development Status :: 4 - Beta
Classifier: License :: OSI Approved :: Apache Software License
Classifier: Operating System :: OS Independent
Classifier: Programming Language :: Python :: 3
Classifier: Programming Language :: Python :: 3.12
Classifier: Programming Language :: Python :: 3.13
Classifier: Programming Language :: Python :: 3.14
Classifier: Typing :: Typed
Requires-Python: !=3.14.0,!=3.14.1,<3.15,>=3.12
Requires-Dist: cryptography<50,>=49
Requires-Dist: httpx<1,>=0.28
Requires-Dist: jsonschema<5,>=4.26
Requires-Dist: keyring<26,>=25.7
Requires-Dist: networkx<4,>=3.6.1
Requires-Dist: pydantic<3,>=2.13.4
Provides-Extra: all
Requires-Dist: alembic<2,>=1.18.5; extra == 'all'
Requires-Dist: azure-identity<2,>=1.24; extra == 'all'
Requires-Dist: azure-keyvault-keys<5,>=4.11; extra == 'all'
Requires-Dist: boto3<2,>=1.39; extra == 'all'
Requires-Dist: click<9,>=8.3.3; extra == 'all'
Requires-Dist: fastapi<1,>=0.139; extra == 'all'
Requires-Dist: google-cloud-kms<4,>=3; extra == 'all'
Requires-Dist: httpx[http2]<1,>=0.28; extra == 'all'
Requires-Dist: opentelemetry-api<2,>=1.35; extra == 'all'
Requires-Dist: opentelemetry-exporter-otlp-proto-http<2,>=1.35; extra == 'all'
Requires-Dist: opentelemetry-sdk<2,>=1.35; extra == 'all'
Requires-Dist: psycopg[binary,pool]<4,>=3.2; extra == 'all'
Requires-Dist: pydantic-settings<3,>=2.10; extra == 'all'
Requires-Dist: pyjwt[crypto]<3,>=2.10; extra == 'all'
Requires-Dist: python-pkcs11<1,>=0.9; extra == 'all'
Requires-Dist: sqlalchemy[asyncio]<2.1,>=2.0.51; extra == 'all'
Requires-Dist: uvicorn<1,>=0.35; extra == 'all'
Requires-Dist: z3-solver<4.17,>=4.16; extra == 'all'
Provides-Extra: aws-kms
Requires-Dist: boto3<2,>=1.39; extra == 'aws-kms'
Provides-Extra: azure-kms
Requires-Dist: azure-identity<2,>=1.24; extra == 'azure-kms'
Requires-Dist: azure-keyvault-keys<5,>=4.11; extra == 'azure-kms'
Provides-Extra: gcp-kms
Requires-Dist: google-cloud-kms<4,>=3; extra == 'gcp-kms'
Provides-Extra: pkcs11
Requires-Dist: python-pkcs11<1,>=0.9; extra == 'pkcs11'
Provides-Extra: runner
Requires-Dist: httpx[http2]<1,>=0.28; extra == 'runner'
Provides-Extra: server
Requires-Dist: alembic<2,>=1.18.5; extra == 'server'
Requires-Dist: boto3<2,>=1.39; extra == 'server'
Requires-Dist: click<9,>=8.3.3; extra == 'server'
Requires-Dist: fastapi<1,>=0.139; extra == 'server'
Requires-Dist: opentelemetry-api<2,>=1.35; extra == 'server'
Requires-Dist: opentelemetry-exporter-otlp-proto-http<2,>=1.35; extra == 'server'
Requires-Dist: opentelemetry-sdk<2,>=1.35; extra == 'server'
Requires-Dist: psycopg[binary,pool]<4,>=3.2; extra == 'server'
Requires-Dist: pydantic-settings<3,>=2.10; extra == 'server'
Requires-Dist: pyjwt[crypto]<3,>=2.10; extra == 'server'
Requires-Dist: sqlalchemy[asyncio]<2.1,>=2.0.51; extra == 'server'
Requires-Dist: uvicorn<1,>=0.35; extra == 'server'
Provides-Extra: solver
Requires-Dist: z3-solver<4.17,>=4.16; extra == 'solver'
Provides-Extra: worker
Requires-Dist: alembic<2,>=1.18.5; extra == 'worker'
Requires-Dist: boto3<2,>=1.39; extra == 'worker'
Requires-Dist: click<9,>=8.3.3; extra == 'worker'
Requires-Dist: fastapi<1,>=0.139; extra == 'worker'
Requires-Dist: opentelemetry-api<2,>=1.35; extra == 'worker'
Requires-Dist: opentelemetry-exporter-otlp-proto-http<2,>=1.35; extra == 'worker'
Requires-Dist: opentelemetry-sdk<2,>=1.35; extra == 'worker'
Requires-Dist: psycopg[binary,pool]<4,>=3.2; extra == 'worker'
Requires-Dist: pydantic-settings<3,>=2.10; extra == 'worker'
Requires-Dist: pyjwt[crypto]<3,>=2.10; extra == 'worker'
Requires-Dist: sqlalchemy[asyncio]<2.1,>=2.0.51; extra == 'worker'
Requires-Dist: uvicorn<1,>=0.35; extra == 'worker'
Description-Content-Type: text/markdown

# Collective Phase Control Fabric

Collective Phase Control Fabric (CPCF) is an evidence-control toolkit for finite collective
workflows. It validates provenance, exact resource constraints, causal formation, catalytic
support, verification capacity, independence, perturbations, coordination, and externally
registered trial bindings.

CPCF reports an `operational_organization_profile`. It does not create, detect, or certify a
collective-superintelligence phase. It also does not certify causality, statistical validity,
thermodynamic feasibility, physical phase behavior, or runner isolation.

> Release status: v0.6.0 is a Beta research package. Package publication does not establish
> deployment assurance. Operational evidence remains unavailable until the external security,
> restore, soak, and independent-review gates in [release readiness](docs/release-readiness.md) pass.

## Install

The one public distribution contains the offline core, CLI, schema registry, bundle verifier,
runner protocol models, and all import packages.

```text
pip install collective-phase-control-fabric
pipx install collective-phase-control-fabric
pip install "collective-phase-control-fabric[server,solver]"
```

Available extras are `server`, `worker`, `runner`, `solver`, `aws-kms`, `gcp-kms`, `azure-kms`,
`pkcs11`, and `all`. Service commands detect missing extras and print the exact installation
command.

## Five-minute offline orientation

These commands do not require an API or credentials:

```text
cpcf agent explain --json
cpcf self-check --json
cpcf schema list --json
cpcf schema show phase-contract --json
cpcf bundle verify PATH_TO_BUNDLE --json
```

An unsigned bundle can establish content consistency only. Distribution authenticity remains
unknown unless the bundle carries an admitted root attestation and a trust policy is supplied.

## Remote workspace use

Remote operations require a configured control plane and a short-lived OIDC access token. The CLI
does not persist bearer tokens.

```text
set CPCF_API_URL=https://cpcf.example.org
set CPCF_TOKEN=OIDC_ACCESS_TOKEN
cpcf workspace create WORKSPACE --root-spki-fingerprint sha256:ROOT_SPKI_SHA256 --genesis-envelope-fingerprint sha256:GENESIS_ENVELOPE_SHA256 --json
cpcf workspace status WORKSPACE --json
cpcf agent onboard --workspace WORKSPACE --json
```

On POSIX shells, use `export`. Mutations require an `Idempotency-Key`; changes to existing
workspaces also require the expected immutable generation through `If-Match`.

## Operational profile

Each required dimension is `satisfied`, `violated`, `unknown`, or `unknown_due_to_budget`:

1. provenance integrity
2. trust quorum
3. temporal integrity
4. structural reachability
5. causal formation
6. dimensional consistency
7. exact self-maintenance
8. finite-horizon resource persistence
9. target-bound generative catalysis
10. verification capacity
11. effective independence
12. coordination protocol integrity
13. perturbation robustness

Compatibility requires every required dimension to be satisfied in one immutable analysis
snapshot. Hypothetical planner output cannot satisfy a scientific dimension before receipt-backed
promotion.

## Development

Contributors use the checked-in universal `uv.lock`; pip is only a consumer installation path.
Development uses CPython 3.14.6 and supports CPython 3.12–3.14 on Windows and Linux.

```text
uv sync --frozen --all-extras --group dev --group security
uv run --frozen ruff format --check .
uv run --frozen ruff check .
uv run --frozen mypy src packages/cpcf-api/src packages/cpcf-cli/src packages/cpcf-worker/src packages/cpcf-runner-protocol/src
uv run --frozen pytest
uv run --frozen python scripts/check_schemas.py
uv run --frozen python scripts/generate_references.py --check
uv run --frozen python scripts/check_publication_hygiene.py --source-tree
uv build
```

The root project builds exactly one wheel and one source distribution named
`collective-phase-control-fabric`. The five import packages remain
`collective_phase_control_fabric`, `cpcf_cli`, `cpcf_api`, `cpcf_worker`, and
`cpcf_runner_protocol`.

## Documentation

- [Documentation index](docs/index.md)
- [Installation](docs/installation.md)
- [Offline orientation](docs/offline-orientation.md)
- [Remote workspace use](docs/remote-workspaces.md)
- [Evidence model](docs/evidence-model.md)
- [Scientific boundaries](docs/scientific-boundaries.md)
- [Security and publication hygiene](docs/security.md)
- [Complete installed-wheel tutorial](docs/tutorial-v0.6/README.md)
- [Release readiness](docs/release-readiness.md)

## License and security

All repository content is English and licensed under Apache-2.0. Report vulnerabilities using the
private process in [SECURITY.md](SECURITY.md); never include credentials, tenant evidence, or live
endpoints in a public issue.
