1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
//! **The client-side workspace** (yog's `docs/REMOTE.md` §2, §8.2; DESIGN §4.6)
//! — what this box holds so it can participate in a workspace hosted on
//! another box.
//!
//! An **entry** is a directory carrying the channel facts that reach one
//! workspace: the host engine's anchors, this box's leaf and key for it, the
//! host's address, and optionally the name that workspace bears *there*. It is
//! the client's half of the pair a server-side registration is the other half
//! of — **possession, where registration is permission** — exactly as a channel
//! needs both a certificate and its issuer's trust.
//!
//! ```text
//! <data root>/wire/workspaces/<leaf>/
//! ca.pem the HOST engine's anchors — that operator's trust root
//! client.pem this box's leaf for this workspace
//! client.key this box's private key for it
//! address the host engine, host:port — "the server", entire
//! workspace OPTIONAL: the name the workspace bears on its host, when it
//! differs from <leaf>; absent, the leaf is the name
//! ```
//!
//! **It is not a second noun, and there is no server object.** A workspace is
//! one word at both ends; "entry" names a *spelling* of it. The client-side
//! unit is the (server, workspace) participation and never the server, so
//! nothing here enumerates a server or holds a fact about one — a server is the
//! [`ADDRESS`](super::material::ADDRESS) inside an entry, entire. Two entries
//! naming one address are two trust relationships that happen to terminate at
//! one listener.
//!
//! **The fifth file exists because a host's namespace is the host's fact**
//! (§9.6: names are global per server), and two hosts may both call something
//! `home`. So `<leaf>` is the *client's* name — what this box's roster paints
//! and what every gesture typed here resolves against — and [`WORKSPACE`] is
//! what that workspace answers to on the far side. The remedy for a collision
//! between two entries is a local rename, which is `mv`, never a server-side
//! rewrite. The mapping between the two names is spent at exactly one place,
//! the channel boundary, in both directions ([`envelope`](crate::envelope)).
//!
//! **Separation is the absence of a mechanism.** Entries share nothing — not
//! anchors (two servers are two operators' trust roots), not leaves (one
//! certificate is one client identity), not addresses, not conversations. So
//! there is no inheritance from the flat root and no path by which one entry
//! can be read through another; the only structure below is a `readdir` and a
//! read per directory.
//!
//! **A refusal is one entry's, never the set's.** [`Entry::channel`] carries
//! its own `Result`, so a half-provisioned entry says so while every other
//! entry stands: a box holding three workspaces does not lose the two that are
//! fine. That is also why an entry that exists is the answer to its own name
//! even when it cannot be dialled — falling through to the flat root would send
//! a gesture to the wrong engine on the strength of a missing file.
//!
//! **Nothing here writes anything.** Material reaches an entry by the
//! operator's hand, out of channel, forever (REMOTE §1.4).
use ;
use ;
/// The material directory's leaf under the data root. The flat root itself:
/// the box's own client relationship, held without naming it.
pub const WIRE: &str = "wire";
/// The entries directory's leaf under [`WIRE`] — the one level of naming that
/// turns the flat client shape into a workspace this box holds elsewhere.
pub const ENTRIES: &str = "workspaces";
/// The optional file naming the workspace **on its host**, for when that
/// differs from the entry's leaf.
pub const WORKSPACE: &str = "workspace";
/// One workspace this box participates in elsewhere.
/// The flat root under a data root: the box's own client material.
/// Where entries live under a data root.
/// Every entry in `dir`, sorted by [`leaf`](Entry::leaf).
///
/// **A directory that will not read is zero entries, not a refusal.** Absent,
/// unreadable and empty are one fact — this box holds no workspace elsewhere —
/// and that fact is the shape every box had before §8.2 existed.
/// One directory read as the entry it claims to be.
/// The name this workspace bears on its host. Absent, unreadable and empty are
/// one branch for the reason [`material`]'s address read has one: they are one
/// fact — the entry states no host-side name — and the leaf is then the name.