1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
//! **The enrollment act, from argv** (yog's `docs/REMOTE.md` §8.4): one
//! gesture, and its answer said in every form a box can take it in.
//!
//! # One artifact, three renderings, and the operator picks ONE
//!
//! The product of an enrollment is the **§8.4 envelope** — one line of compact
//! JSON under `{"yog-enroll":1,…}`. A QR symbol is a picture of that line and
//! nothing else, so there are three ways to take the same bytes: the symbol
//! for a camera, the line for a keyboard, and `--into <dir>` for a box that
//! has neither. There is one place they are built
//! ([`crate::reply::enrolled::Enrolled::envelope`]).
//!
//! **Naming a destination picks one of the three, and the other two then stay
//! unsaid** (bl-768a). `--into` is the operator saying *write it down for me*,
//! and printing the symbol and the line beside the files it wrote would put a
//! private key in the one place the act cannot reach afterwards: a scrollback,
//! a `tmux` buffer, a capture, the job log of an unattended run. So a run that
//! files says the caption and the receipt, and the receipt says where the key
//! is. A run whose filing FAILED says everything, because then the screen is
//! the only place the material can be — the engine has already minted and
//! shredded, so a destination must never cost the material.
//!
//! It used to print the picture alone, and say so — *not written down
//! anywhere*. Two components could not be seated through it. A **foot** is by
//! definition a box the operator is not sitting at, with no screen and no
//! camera, so the one component the act exists to provision was the one it
//! could not reach (bl-1554). And the **phone** asks, in its own enrollment
//! screen, for *one line of JSON beginning `{"yog-enroll": 1`* — the exact text
//! the seat was drawing a picture of and discarding (bl-a8fd). Both had the
//! same workaround: spell the envelope by hand through `lernie ask` and
//! reassemble it against §8.4. A seat that makes an operator reimplement the
//! payload contract is not rendering the answer, it is withholding it.
//!
//! **The custody argument does not reach the text**, and that is why saying the
//! line at all was not a relaxation. What §4.15 rules out is a copy *nobody
//! chose* — a cache, a log, a temporary file. With no `--into` the envelope is
//! on the screen either way, drawn as a picture of itself; a photograph of a
//! private key is a private key. It is the same argument that withholds it once
//! a destination was chosen: the files are the copy the operator asked for, and
//! the scrollback is one they did not. What stays true on both paths is that
//! this seat keeps nothing of its own accord: with no `--into`, not a byte is
//! written, and the suite still asserts that over the whole tree.
//!
//! # And `--json` is the envelope ALONE, because a picture is not capturable
//!
//! The three renderings above are what a PERSON is offered. A script is
//! offered one (bl-ac76): under `--json` stdout carries the §8.4 envelope on
//! one line and nothing else — no caption, no symbol, no colour, no receipt.
//! It printed the whole human rendering under the flag, so
//! `lernie --json enroll … | head` captured an ANSI block and left the
//! material behind; and because the engine has already minted and shredded by
//! then, and a second enrollment under one name is refused, what the script
//! kept was a picture of a key it could no longer ask for.
//!
//! **The two rules compose rather than colliding**, and the composition is one
//! sentence: under `--json`, stdout carries the envelope exactly when the
//! material was not written down. A run that FILED withholds it (bl-768a,
//! above) and so says nothing at all on stdout — the four files are the
//! answer, and the receipt naming them is a diagnosis on stderr, because it is
//! not a frame. A run whose filing failed says the envelope, for bl-768a's own
//! reason: the screen is then the only place the material can be.
//!
//! # Nothing is written unasked, and that is asserted rather than intended
//!
//! No file, no cache, no log line, no temporary anything. The material lives in
//! this function's locals and dies with them. `enroll::tests` drives the whole
//! act against the stand-in engine over a throwaway root and walks that root
//! afterwards, comparing the tree to what was there before — over the **tree**
//! rather than over the paths this code happens to know about, because a defect
//! here is precisely a path nobody thought of. A stated destination is walked
//! the same way, and what is found there is exactly the four files.
use Path;
use crate;
use crateSymbol;
use crateForm;
use crate;
/// The envelope as an entry, where the operator names one.
/// The line under the material. It says the one thing an operator cannot see by
/// looking: that there is no second copy here, so what is on the screen is the
/// only one there will be until another `enroll` is spent.
const KEPT: &str = "the seat keeps no copy — scan the symbol or take the line; they are the same \
bytes. Enroll again if it is lost";
/// The line under a receipt. It says the one thing the four files cannot: that
/// the private key is in them and was not also printed here, so the terminal
/// this ran in holds no copy of it.
const ELSEWHERE: &str = "the private key is in that directory and was not printed here — this seat \
keeps no copy either, so those files are the only ones there are. Enroll \
again if they are lost";
/// What the seat says when the gesture crossed and no answer came back.
///
/// **`enroll` is the act whose doubt costs the most.** Its product is the one
/// reply this seat never keeps, so a registration that was minted and whose
/// answer was lost leaves a box registered with material that exists nowhere —
/// and `enroll again` (which [`KEPT`] rightly offers when the material WAS
/// said) would mint a second registration over a first nobody can see. So the
/// remedy is REMOTE §3's: read the world first.
const INDOUBT: &str = "the enrollment crossed with no answer, so it is IN DOUBT — a registration may \
exist whose material is gone. Do not enroll again until you have looked: \
`lernie ask '{\"op\":\"clients\"}'` says which clients that engine holds";
/// **Enroll a new box**, and say the material every way it can be taken.
///
/// `at` is the route the enrolled box will dial and rides the gesture only when
/// the operator stated one (bl-971c); `into` is where the material is written
/// down on THIS box. They are independent — the first is a fact about the far
/// device and the second about this terminal — so each is read on its own and
/// neither is inferred from the other.
///
/// `warn` takes what is a diagnosis rather than a product: a destination that
/// would not take the files, and — under `--json`, where stdout is a frame and
/// not prose — the receipt for one that did.
/// The material, said the way the operator asked for it: filed and not drawn
/// where a destination took it, drawn every way this seat can where none did —
/// and for a machine, the envelope alone or nothing.
///
/// **A rendering that landed is a rendering that is not also printed** (bl-768a).
/// `--into` is the operator saying *this box has neither a camera nor a paste
/// box; write it down for me*, and the moment the four files exist the symbol
/// and the line are a second copy nobody asked for — one this seat cannot
/// shred, because it is in a scrollback, a `tmux` buffer, an `asciinema`
/// capture and the job log of anything that ran the act unattended. So the
/// caption and the receipt are the whole of what is said, and the receipt
/// names where the key is.
///
/// The rule reads on the failure the same way: when nothing was written, the
/// screen is the only place the material can be, so it is all drawn there.
/// Every rendering of the material at once, for the runs that have nowhere
/// else to put it: the caption, the picture where one fits, and the line.