1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
//! **The enrollment act, from argv** (yog's `docs/REMOTE.md` §8.4): one
//! gesture, and its answer said in every form a box can take it in.
//!
//! # One artifact, three renderings, and the operator picks ONE
//!
//! The product of an enrollment is the **§8.4 envelope** — one line of compact
//! JSON under `{"yog-enroll":1,…}`. A QR symbol is a picture of that line and
//! nothing else, so there are three ways to take the same bytes: the symbol
//! for a camera, the line for a keyboard, and `--into <dir>` for a box that
//! has neither. There is one place they are built
//! ([`crate::reply::enrolled::Enrolled::envelope`]).
//!
//! **Naming a destination picks one of the three, and the other two then stay
//! unsaid** (bl-768a). `--into` is the operator saying *write it down for me*,
//! and printing the symbol and the line beside the files it wrote would put a
//! private key in the one place the act cannot reach afterwards: a scrollback,
//! a `tmux` buffer, a capture, the job log of an unattended run. So a run that
//! files says the caption and the receipt, and the receipt says where the key
//! is. A run whose filing FAILED says everything, because then the screen is
//! the only place the material can be — the engine has already minted and
//! shredded, so a destination must never cost the material.
//!
//! It used to print the picture alone, and say so — *not written down
//! anywhere*. Two components could not be seated through it. A **foot** is by
//! definition a box the operator is not sitting at, with no screen and no
//! camera, so the one component the act exists to provision was the one it
//! could not reach (bl-1554). And the **phone** asks, in its own enrollment
//! screen, for *one line of JSON beginning `{"yog-enroll": 1`* — the exact text
//! the seat was drawing a picture of and discarding (bl-a8fd). Both had the
//! same workaround: spell the envelope by hand through `lernie ask` and
//! reassemble it against §8.4. A seat that makes an operator reimplement the
//! payload contract is not rendering the answer, it is withholding it.
//!
//! **The custody argument does not reach the text**, and that is why saying the
//! line at all was not a relaxation. What §4.15 rules out is a copy *nobody
//! chose* — a cache, a log, a temporary file. With no `--into` the envelope is
//! on the screen either way, drawn as a picture of itself; a photograph of a
//! private key is a private key. It is the same argument that withholds it once
//! a destination was chosen: the files are the copy the operator asked for, and
//! the scrollback is one they did not. What stays true on both paths is that
//! this seat keeps nothing of its own accord: with no `--into`, not a byte is
//! written, and the suite still asserts that over the whole tree.
//!
//! # Nothing is written unasked, and that is asserted rather than intended
//!
//! No file, no cache, no log line, no temporary anything. The material lives in
//! this function's locals and dies with them. `enroll::tests` drives the whole
//! act against the stand-in engine over a throwaway root and walks that root
//! afterwards, comparing the tree to what was there before — over the **tree**
//! rather than over the paths this code happens to know about, because a defect
//! here is precisely a path nobody thought of. A stated destination is walked
//! the same way, and what is found there is exactly the four files.
use Path;
use crateVerdict;
use crateSymbol;
use crate;
/// The envelope as an entry, where the operator names one.
/// The line under the material. It says the one thing an operator cannot see by
/// looking: that there is no second copy here, so what is on the screen is the
/// only one there will be until another `enroll` is spent.
const KEPT: &str = "the seat keeps no copy — scan the symbol or take the line; they are the same \
bytes. Enroll again if it is lost";
/// The line under a receipt. It says the one thing the four files cannot: that
/// the private key is in them and was not also printed here, so the terminal
/// this ran in holds no copy of it.
const ELSEWHERE: &str = "the private key is in that directory and was not printed here — this seat \
keeps no copy either, so those files are the only ones there are. Enroll \
again if they are lost";
/// What the seat says when the gesture crossed and no answer came back.
///
/// **`enroll` is the act whose doubt costs the most.** Its product is the one
/// reply this seat never keeps, so a registration that was minted and whose
/// answer was lost leaves a box registered with material that exists nowhere —
/// and `enroll again` (which [`KEPT`] rightly offers when the material WAS
/// said) would mint a second registration over a first nobody can see. So the
/// remedy is REMOTE §3's: read the world first.
const INDOUBT: &str = "the enrollment crossed with no answer, so it is IN DOUBT — a registration may \
exist whose material is gone. Do not enroll again until you have looked: \
`lernie ask '{\"op\":\"clients\"}'` says which clients that engine holds";
/// **Enroll a new box**, and say the material every way it can be taken.
/// The material, said the way the operator asked for it: filed and not drawn
/// where a destination took it, drawn every way this seat can where none did.
///
/// **A rendering that landed is a rendering that is not also printed** (bl-768a).
/// `--into` is the operator saying *this box has neither a camera nor a paste
/// box; write it down for me*, and the moment the four files exist the symbol
/// and the line are a second copy nobody asked for — one this seat cannot
/// shred, because it is in a scrollback, a `tmux` buffer, an `asciinema`
/// capture and the job log of anything that ran the act unattended. So the
/// caption and the receipt are the whole of what is said, and the receipt
/// names where the key is.
///
/// The rule reads on the failure the same way: when nothing was written, the
/// screen is the only place the material can be, so it is all drawn there.
/// Every rendering of the material at once, for the runs that have nowhere
/// else to put it: the caption, the picture where one fits, and the line.