Keeping Python repos from turning into spaghetti.
Most linters catch bad code inside files. Fensu catches architectural drift: code crossing the wrong boundary, living in the wrong module, or growing into the wrong shape.
As a repository grows, code moves, lessons get forgotten, and the mental map decays. Tests preserve behavior and types preserve interfaces. Fensu makes the repository's architectural expectations executable.
Fensu enforces:
- which layers may import which;
- what each module or role file may contain;
- whether orchestrator functions stay small;
- whether dataflow and mutation are explicit;
- whether names such as
validate_*mean what they claim.
It ships a coherent default architecture rather than a blank rule framework, then lets projects disable, extend, or replace parts deliberately.
Fensu is functional and self-hosting, but remains pre-release.
Installation
pip install fensu
The authoring/API distribution is fensu. It installs the lockstep
fensu-cli binary package, which exclusively owns the fensu command.
Core-only check, init, rule, map, skills, memory, and --version
execution is native. Configured Python custom rules launch one compatible Python
host only for the policy metadata or callbacks they require.
Built-in commands are available only through the native fensu executable;
python -m fensu is retired. Installing fensu-cli from its source
distribution requires Rust.
Fensu requires Python 3.12+ and includes a compiled analysis core. Prebuilt
wheels cover Linux (x86_64, aarch64) and macOS (Intel, Apple silicon); on any
other platform, pip builds from source, which requires a Rust toolchain.
Release wheels are built for Windows x86_64 as well as the listed Linux and
macOS platforms.
Quick Start
Detect the repository layout, choose a starting ruleset, and write a validated configuration:
fensu init
For non-interactive setup, use fensu init --yes. To configure manually instead,
add fensu.toml at the repository root:
roots = ["src/my_package"]
tests = ["tests"]
tooling = ["scripts"]
[cache]
enabled = true
Then run:
fensu check
fensu init --yes installs repository-local guidance for Opencode, Claude, and
Agents by default; pass --no-skills only for explicit configuration-only
automation. Do not call onboarding complete until this succeeds:
fensu skills --check
All rule families are enabled by default. Product roots and tooling receive structural rules; tests receive test-convention and annotation rules.
Default Structure
Product code uses domain, optional subdomain, then role. Every leaf domain or
subdomain owns meaningful behavior through a direct main/ containing at least one
entry module. Branch-domain parents do not need their own main/; their leaf
subdomains do. Tests mirror the code they cover; tooling uses one ownership level
because scripts/ already establishes the outer boundary.
src/my_package/
└── domain/
└── subdomain/
├── main/
│ └── run.py
├── _helpers/
├── classes/
├── models.py
├── types.py
├── constants.py
└── exceptions.py
tests/unit/src/my_package/domain/subdomain/
├── _test_types.py
└── test_run.py
scripts/
├── run_tool.py
└── tool_name/
├── main/
├── _helpers/
└── classes/
Do not create an empty or initializer-only main/ to satisfy the layout. If a
package contains only passive models, types, constants, exceptions, or classes,
move those declarations into the closest domain or subdomain whose main/ behavior
owns and uses them. Fixed role files are siblings of _helpers/, never descendants
such as _helpers/entry/models.py.
Direct scripts/*.py files are thin command adapters. Supporting logic belongs
under scripts/<tool>/<role>/.
Core Commands
fensu init
fensu check
fensu rule FFS131
fensu map run_plan --depth 3
fensu init detects and validates an onboarding configuration, fensu check
enforces the configured architecture, fensu rule explains one rule and its
remediation, and fensu map renders a conservative downstream call tree. Mapping
follows project functions and class methods when imports,
annotations, constructors, or return types prove the receiver. Calls through
protocols and untyped parameters remain visible as unresolved dispatch seams
rather than guessed implementations. Mapping does not require Fensu
configuration or rule adoption.
fensu check stores disposable evaluation results in a repository-local
SQLite database under .fensu/cache/
and reuses them only after validating source, configuration, rule, implementation,
and project-query inputs. Caching is enabled by default; set cache.enabled = false
in configuration or pass --no-cache for an explicit uncached check. --cache
overrides a disabled project preference for one invocation.
Deleting .fensu/cache/ is always safe; ignore that directory rather than the
complete .fensu/ namespace, which is reserved for other Fensu-owned state.
Enforce It, Then See It
Because Fensu enforces the structure, it can also render it. fensu map
produces a deterministic downstream call tree with clickable path:line
locations, class-qualified method names, and explicit protocol seams while
marking unresolved dynamic calls, depth limits, and cycles.
$ fensu map run_map --depth 4
run_map(...) src/fensu/cli/main/map.py:21
├── _parser(...) src/fensu/cli/main/map.py:53
├── resolve_mapping_project(...) src/fensu/mapping/main/resolve_project.py:11
│ └── resolve_mapping_project(...) src/fensu/mapping/_helpers/project.py:15
│ ├── _find_project_root(...) src/fensu/mapping/_helpers/project.py:73
│ ├── _explicit_source(...) src/fensu/mapping/_helpers/project.py:65
│ ├── _optional_config_source(...) src/fensu/mapping/_helpers/project.py:38
│ │ └── find_config_source(...) src/fensu/config/main/find_config.py:12 (depth limit)
│ └── _configured_project(...) src/fensu/mapping/_helpers/project.py:45
│ ├── load_config(...) src/fensu/config/main/load_config.py:15 (depth limit)
│ └── _configured_source(...) src/fensu/mapping/_helpers/project.py:57
└── build_call_map(...) src/fensu/mapping/main/build.py:12
├── provider(...) src/fensu/mapping/main/build.py:24 (unresolved parameter call)
└── render_tree(...) src/fensu/mapping/_helpers/render.py:19
├── _child_lines(...) src/fensu/mapping/_helpers/render.py:41
│ └── _child_lines(...) src/fensu/mapping/_helpers/render.py:41 (cycle)
└── _label(...) src/fensu/mapping/_helpers/render.py:88
The map is useful precisely because it is not guessing. fensu check enforces
layers, roles, and public surfaces first, and fensu map then renders the
structure the code is required to expose.
Philosophy
Fensu is strict by default wherever it can make an honest deterministic claim. Following the rules should remove repeated architectural decisions from everyday work. Deliberate differences belong in selection, configuration, or custom rules, where they remain visible, rather than in scattered inline suppressions.
Unavoidable external calling conventions can use exact symbol-scoped exceptions:
[[rule_exceptions]]
rule = "FFS120"
path = "src/my_package/integrations/_helpers/callbacks.py"
symbols = ["ProgressCollector.update"]
reason = "The external API invokes this callback positionally."
Exceptions accept one exact rule code, repository-relative Python file, and one
or more qualified symbols. Globs, directories, line numbers, path-only entries,
and inline suppression comments are not supported. fensu check rejects stale
exceptions that no longer suppress a fault.
For a justified rule/path intersection that is broader than one exact finding,
keep the rules and project context active with [[rule_ignores]]:
[[rule_ignores]]
rules = ["FFA", "XGENERATED"]
paths = ["src/my_package/generated/**"]
reason = "Generated interfaces are checked by their source schema."
One declaration must match both the finding's rule code and its reported path. Unlike exact exceptions, path-scoped ignores are not stale-checked.
Agent Skills
Generate repository-aware guidance from the active ruleset:
fensu skills
fensu skills --global
The generated skill includes Fensu usage, rule-supported architecture examples,
navigation and work-handoff guidance, and every enabled core and custom rule.
Existing user-authored skill files are preserved unless --force is supplied.
Custom Rules
Custom checks use X... codes and the same RuleContext as core rules. Once
configured, they participate in fensu check, fensu rule, and generated agent
skills. Rules can use ctx.facts, ctx.project, ctx.text, ctx.syntax, and
ctx.relations; these are the same backend-neutral analysis zones used by Fensu's
built-in rules. Project and filesystem reads made through ctx.project are tracked
for cache invalidation. Raw ast.Module access remains available for checks that need
unrestricted Python syntax traversal. Semantic fact contracts and author-facing models
are public Python APIs, while their production extraction has one native Rust owner;
raw AST, syntax, and relation artifacts remain lazy CPython capabilities. Keep
project-owned checks in the canonical
scripts/fensu_policy/rules/ tooling role and load them explicitly:
tooling = ["scripts"]
rule_paths = ["scripts/fensu_policy/rules"]
See the custom-rule guide for the complete API and configuration.
Documentation
The quickstart, architecture model, configuration reference, adoption guide, and CLI reference live at docs.fensu.dev.
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distributions
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file fensu-0.4.0.tar.gz.
File metadata
- Download URL: fensu-0.4.0.tar.gz
- Upload date:
- Size: 439.0 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/6.1.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
ff948b09184af0e34e40b7d2d17e8cac156b247cbadb0db28da4a47dc8dc57b2
|
|
| MD5 |
66a4cbff09bf5f7246ba0ceddb304379
|
|
| BLAKE2b-256 |
dff416aef7899258ea20b0bd19458de02e352dbd84b1ea14c0a817a7699ab51a
|
Provenance
The following attestation bundles were made for fensu-0.4.0.tar.gz:
Publisher:
publish.yml on chio-labs/fensu
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
fensu-0.4.0.tar.gz -
Subject digest:
ff948b09184af0e34e40b7d2d17e8cac156b247cbadb0db28da4a47dc8dc57b2 - Sigstore transparency entry: 2219701981
- Sigstore integration time:
-
Permalink:
chio-labs/fensu@85121452f50a76542a7f937b4c48e33ccef1d2a1 -
Branch / Tag:
refs/heads/main - Owner: https://github.com/chio-labs
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish.yml@85121452f50a76542a7f937b4c48e33ccef1d2a1 -
Trigger Event:
workflow_dispatch
-
Statement type:
File details
Details for the file fensu-0.4.0-cp312-abi3-win_amd64.whl.
File metadata
- Download URL: fensu-0.4.0-cp312-abi3-win_amd64.whl
- Upload date:
- Size: 4.6 MB
- Tags: CPython 3.12+, Windows x86-64
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/6.1.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
ead0bdfa3df9b484399224055ac3b430553792084ae8875c11b48ef02456fb6f
|
|
| MD5 |
53f8a6617b0a7c6dfb371e8033d81f8c
|
|
| BLAKE2b-256 |
1ebf1a3ad3038a2c6c0fbff0de5e9a9245992e82b90323eecfbd9e41d401c144
|
Provenance
The following attestation bundles were made for fensu-0.4.0-cp312-abi3-win_amd64.whl:
Publisher:
publish.yml on chio-labs/fensu
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
fensu-0.4.0-cp312-abi3-win_amd64.whl -
Subject digest:
ead0bdfa3df9b484399224055ac3b430553792084ae8875c11b48ef02456fb6f - Sigstore transparency entry: 2219702222
- Sigstore integration time:
-
Permalink:
chio-labs/fensu@85121452f50a76542a7f937b4c48e33ccef1d2a1 -
Branch / Tag:
refs/heads/main - Owner: https://github.com/chio-labs
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish.yml@85121452f50a76542a7f937b4c48e33ccef1d2a1 -
Trigger Event:
workflow_dispatch
-
Statement type:
File details
Details for the file fensu-0.4.0-cp312-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl.
File metadata
- Download URL: fensu-0.4.0-cp312-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
- Upload date:
- Size: 5.1 MB
- Tags: CPython 3.12+, manylinux: glibc 2.17+ x86-64
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/6.1.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
4c7ffba5f086b631fb75826bad4813a3d174805c6e9efddf2df1d323ac45662a
|
|
| MD5 |
89860063e6b5a8eea6dddc603d99f167
|
|
| BLAKE2b-256 |
04f650380bebdc8e185e3ae2b45945f498e0af25610a529d1847fc97e7cebced
|
Provenance
The following attestation bundles were made for fensu-0.4.0-cp312-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl:
Publisher:
publish.yml on chio-labs/fensu
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
fensu-0.4.0-cp312-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl -
Subject digest:
4c7ffba5f086b631fb75826bad4813a3d174805c6e9efddf2df1d323ac45662a - Sigstore transparency entry: 2219702050
- Sigstore integration time:
-
Permalink:
chio-labs/fensu@85121452f50a76542a7f937b4c48e33ccef1d2a1 -
Branch / Tag:
refs/heads/main - Owner: https://github.com/chio-labs
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish.yml@85121452f50a76542a7f937b4c48e33ccef1d2a1 -
Trigger Event:
workflow_dispatch
-
Statement type:
File details
Details for the file fensu-0.4.0-cp312-abi3-manylinux_2_17_aarch64.manylinux2014_aarch64.whl.
File metadata
- Download URL: fensu-0.4.0-cp312-abi3-manylinux_2_17_aarch64.manylinux2014_aarch64.whl
- Upload date:
- Size: 5.1 MB
- Tags: CPython 3.12+, manylinux: glibc 2.17+ ARM64
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/6.1.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
88a75f4663efecce5c6fca1a3def0406ef01f1864aa3cf2275c207619c2eadde
|
|
| MD5 |
6e9bd44c1efd0e986c9dbc3150aaae33
|
|
| BLAKE2b-256 |
f6a566b28321395269ccdac0125d6dbdb8779c9c3498c2999fa4cb039156c2df
|
Provenance
The following attestation bundles were made for fensu-0.4.0-cp312-abi3-manylinux_2_17_aarch64.manylinux2014_aarch64.whl:
Publisher:
publish.yml on chio-labs/fensu
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
fensu-0.4.0-cp312-abi3-manylinux_2_17_aarch64.manylinux2014_aarch64.whl -
Subject digest:
88a75f4663efecce5c6fca1a3def0406ef01f1864aa3cf2275c207619c2eadde - Sigstore transparency entry: 2219702197
- Sigstore integration time:
-
Permalink:
chio-labs/fensu@85121452f50a76542a7f937b4c48e33ccef1d2a1 -
Branch / Tag:
refs/heads/main - Owner: https://github.com/chio-labs
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish.yml@85121452f50a76542a7f937b4c48e33ccef1d2a1 -
Trigger Event:
workflow_dispatch
-
Statement type:
File details
Details for the file fensu-0.4.0-cp312-abi3-macosx_11_0_arm64.whl.
File metadata
- Download URL: fensu-0.4.0-cp312-abi3-macosx_11_0_arm64.whl
- Upload date:
- Size: 4.7 MB
- Tags: CPython 3.12+, macOS 11.0+ ARM64
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/6.1.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
ecac3273aaf4e1a16e8e475925e2f38a39b43429ecf69ac83064e0b31dc7beec
|
|
| MD5 |
a7e7a3a550458668c3081d1f154cc9a3
|
|
| BLAKE2b-256 |
43e3a0f17d84bbbbeb76a92081a2072529b40ac505b85c330371e06ddc3eee41
|
Provenance
The following attestation bundles were made for fensu-0.4.0-cp312-abi3-macosx_11_0_arm64.whl:
Publisher:
publish.yml on chio-labs/fensu
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
fensu-0.4.0-cp312-abi3-macosx_11_0_arm64.whl -
Subject digest:
ecac3273aaf4e1a16e8e475925e2f38a39b43429ecf69ac83064e0b31dc7beec - Sigstore transparency entry: 2219702244
- Sigstore integration time:
-
Permalink:
chio-labs/fensu@85121452f50a76542a7f937b4c48e33ccef1d2a1 -
Branch / Tag:
refs/heads/main - Owner: https://github.com/chio-labs
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish.yml@85121452f50a76542a7f937b4c48e33ccef1d2a1 -
Trigger Event:
workflow_dispatch
-
Statement type:
File details
Details for the file fensu-0.4.0-cp312-abi3-macosx_10_12_x86_64.whl.
File metadata
- Download URL: fensu-0.4.0-cp312-abi3-macosx_10_12_x86_64.whl
- Upload date:
- Size: 4.8 MB
- Tags: CPython 3.12+, macOS 10.12+ x86-64
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/6.1.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
e4130a77f07f52e4116e4b5d43a215ceda8a50be6586269a97885cebee9b36fb
|
|
| MD5 |
48399c6b64ff182c284df2869210d21f
|
|
| BLAKE2b-256 |
adc2a2671a863b2e4f2d41c4bddea23d19c1b650346ef72b4a900bd7296ce964
|
Provenance
The following attestation bundles were made for fensu-0.4.0-cp312-abi3-macosx_10_12_x86_64.whl:
Publisher:
publish.yml on chio-labs/fensu
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
fensu-0.4.0-cp312-abi3-macosx_10_12_x86_64.whl -
Subject digest:
e4130a77f07f52e4116e4b5d43a215ceda8a50be6586269a97885cebee9b36fb - Sigstore transparency entry: 2219702149
- Sigstore integration time:
-
Permalink:
chio-labs/fensu@85121452f50a76542a7f937b4c48e33ccef1d2a1 -
Branch / Tag:
refs/heads/main - Owner: https://github.com/chio-labs
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish.yml@85121452f50a76542a7f937b4c48e33ccef1d2a1 -
Trigger Event:
workflow_dispatch
-
Statement type: