Map the PHP repository
Codna builds a dependency and blast-radius graph of the repository from its import patterns. No model call, zero tokens.
Codna maps your PHP project for zero tokens, fixes from evidence, and runs PHPUnit or Pest until it passes.
The problem
Codna builds a dependency and blast-radius graph of the repository from its import patterns. No model call, zero tokens. use statements and includes are the edges, so the agent follows the call chain from the failing test through the trait to the method that returns null.
How Codna fixes it
Codna builds a dependency and blast-radius graph of the repository from its import patterns. No model call, zero tokens.
The agent receives an evidence bundle scoped to the issue: the suspect files, the call paths, the failing test. Codna prints the raw-to-bundle token size on every run. Every fix reports root cause, confidence, blast radius and regression risk, and passes a risk gate before it is applied or a pull request opens.
Run codna fix --tests --apply and Codna runs your tests in a sandbox and re-fixes until they pass, up to the iteration limit you set. Set fix.test_command in codna.yaml, or pass --test-cmd, when your runner is not pytest. With --open-pr, or through the GitHub App, the pull request states the issue, the root cause, the symbols touched and a confidence score, and asks for review before merging. Codna never merges.
pip install codna codna fix . --issue "InvoiceService::total() returns null when a discount trait is applied" --tests --apply --test-cmd "vendor/bin/phpunit --log-junit $CODNA_JUNIT"
What you get
--log-junit writes the report Codna reads. Set fix.test_command or pass --test-cmd.
On-device recall parses .php files with tree-sitter.
Framework code is part of the graph like any other namespace.
The proof
Codna builds a dependency and blast-radius graph of the repository from its import patterns. No model call, zero tokens. The agent receives an evidence bundle scoped to the issue: the suspect files, the call paths, the failing test. Codna prints the raw-to-bundle token size on every run. Every fix reports root cause, confidence, blast radius and regression risk, and passes a risk gate before it is applied or a pull request opens.
A fix tool. It returns a patch with root cause, confidence, blast radius and regression risk, and opens a pull request if you ask.
Yes. Namespaces and includes are edges in the map. Point the test command at your suite.
PHPUnit and Pest, or any runner that writes JUnit XML.
Traits are followed through use statements. Magic methods are a lower bound; your tests verify the behaviour.
Understanding runs on your machine and spends no tokens. Only the evidence bundle or the diff reaches your model provider, with your key from the OS keychain. Set privacy.egress to fail-closed in codna.yaml and Codna runs your tests only under kernel-level network denial. Secret redaction is always on.
Related