1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
//! The launched driver's own-branch entry (ARCH §2.11 exit protocol).
//!
//! Every launch — a writer's post-deposit probe, the `lernie scan`
//! flush, an exiting executor's self-directed launch — spawns a driver
//! that runs this entry against its target agent. Warrant is decided
//! here, under the lock, never by the launcher (§2.11): [`drive`]
//! acquires-or-exits, and what it finds decides what happens.
//!
//! **The no-op driver path (§2.11 pin 1).** A driver that acquires and
//! finds nothing to deliver exits silently — no step, no epitaph — after
//! honouring the §2.11 **release rule** at its own lease release
//! ([`release_then_reprobe`], run by the `lernie advance` hop): only a
//! deposit its own last inbox read never saw fires a launch, so a
//! found-nothing drive over a quiet inbox launches nothing and the
//! exit-launch recursion terminates here, while a deposit racing that
//! last read is no longer stranded (bl-9c8f). Found mail is
//! delivered through the ordinary step-boundary drain ([`super::drain`]
//! — delivery commits, work-product transfers included), after
//! rematerializing the worktree if quiescence tore it down (§2.3
//! step 6).
//!
//! **Scope note.** The step that *reacts* to delivered mail — "found-mail
//! → step to a new terminal → exit-launch again" (§2.11) — is `lernie
//! advance`'s (§6, [`super::advance`]). This module is the own-branch
//! delivery entry that verb runs on arrival: `advance` holds its own
//! lease (adopted or acquired) and calls [`deliver`]; [`drive`] is the
//! acquire-and-deliver composition, the §2.11 contract in one call.
use ;
use crateError;
use crateinbox;
use crateGitRunner;
use crateworkspace;
use Path;
/// What one [`drive`] found and did — derived on the fly, nothing stored.
// `driver::drive` is a test-only entry; runtime delivers via `driver::deliver`.
/// Drive `agent_id`'s branch: acquire-or-exit, then deliver whatever is
/// pending — or exit silently when nothing is (§2.11 pin 1). The lock is
/// held for the whole delivery and kernel-released on return.
// test-only drive entry; runtime uses `deliver` (see DriveOutcome).
/// Deliver `agent_id`'s pending mail under a lease the *caller* already
/// holds (§2.11 *Delivery* — only a lock-holding executor delivers):
/// rematerialize the worktree if quiescence tore it down, then run the
/// real drain (stray recovery + delivery commits). An empty inbox over a
/// torn-down worktree touches nothing; an empty inbox over a live
/// worktree still runs the drain's stray recovery, closing the §2.11
/// rename-without-commit crash window before the caller reads the tree.
///
/// Returns the drain's [`drain::Delivery`]: the delivery count, plus the
/// identities of the deposits deliberately left pending — the seen-set
/// [`release_then_reprobe`] diffs against once the lease is gone (§2.11
/// release rule).
pub
/// The §2.11 **release rule** (the deposit rule's dual), as one funnel:
/// give up the lease, then re-read the inbox and — finding a deposit the
/// released executor's own last read never accounted for and whose own
/// warrant launches ([`deposit_warrants_launch`]) — complete that
/// deposit's launch through the unmodified writer seam
/// ([`inbox::probe_and_launch`]). A deposit racing the holder's last
/// inbox read meets a Busy probe (the writer defers to us), so the
/// launch it was owed becomes ours to make; the file our last read *did*
/// see and deliberately left (a gate-held result, §6) launches nothing,
/// so a hold never relaunch-loops. The diff runs on
/// [`drain::SeenDeposit`] file identities, never bare names: a delivered
/// or interpreted deposit frees its name for reuse, and a reused name is
/// a new deposit owed its launch like any other.
///
/// Ordering is the invariant: the re-read runs strictly *after* the
/// release, so a rival that took the freed lease first turns our probe
/// into the ordinary Busy deferral — no double-drive — and from the
/// release on this process only spawns and returns (§2.11 no-authority).
pub
/// The post-release half of [`release_then_reprobe`], split at the
/// release so the rival-holder deferral is exercisable deterministically
/// (a test acquires the lease, then runs this). Failures are logged and
/// swallowed — fire-and-forget, the §2.11 accepted crash class: the
/// stranding is late, never lost, and the next touch (a reprompt, a
/// hand-run `lernie scan`) heals it.
pub
/// Whether an unseen racing deposit is *owed* a launch — the racing
/// writer's own launch decision, replayed (§2.11): the release rule
/// completes the launch the deposit would have gotten had it landed a
/// millisecond after the release, no more. A plain message's writer
/// (`lernie message`, `lernie dispatch`, the scan flush) always
/// launches; a result message's launch is pin 2's one epitaph decision —
/// `final-response` (the child's own `revive_parent`) and `died` (the
/// scan flush behind the sweep's deposit) wake the recipient, while
/// `stopped` and `budget-exhausted` deliberately park it: the §2.11
/// "stays undelivered, the next explicit touch delivers it" state,
/// identical raced or unraced — launching for those would erase the
/// parked state pin 2 specifies (deliver a kill report to the parent the
/// operator may be stopping next, or spam an exhausted ceiling). An
/// illegible deposit launches: no launcher decides warrant — the
/// launched driver does, under the lock (§2.11).
/// Rematerialize a torn-down quiescent worktree off the persistent
/// branch ref (§2.3 step 6 — the worktree is disposable materialization,
/// never state): `git worktree add <path> agents/<id>`, run against the
/// workspace's bare `repo.git` (§2.2).