1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
//! **The interface-parity gate** — yog's `docs/PARITY.md` §5, this seat's half.
//!
//! The operator's requirement is that the desktop seat and the android client
//! have interaction parity: *if something is interactable in one it must exist
//! in the other*, and drift between them must be caught mechanically rather
//! than noticed by hand. The contract answers that without either client ever
//! reading the other's tree — **each client is judged against the roster**, and
//! the roster is yog's help table published through the vendored corpus
//! ([`roster`]). A client-vs-client diff would have no authority when the two
//! disagreed, would drift with whichever updated last, and would go quadratic
//! on a third surface.
//!
//! Four assertions, and the last two are what keep the ledger honest:
//!
//! ```text
//! roster − exemptions ⊆ inventory no control-classed op is silently absent
//! tags(inventory) ⊆ ops(roster) no act: token names a verb the wire lacks
//! ∀ exemption ∈ roster.control no rotted row: upstream still owes it
//! ∀ exemption ∉ inventory no stale row: it is not surfaced already
//! ```
//!
//! # The instrument is the sibling harness's, never a second one
//!
//! The inventory comes off the SAME AccessKit tree [`super::clipped`] judges
//! and [`super::reach`] walks (bl-dc07). A second walk would be a second
//! opinion about what is on the window, and the first defect it found would be
//! a disagreement between the two instruments rather than about the seat.
//!
//! **Presence is the claim; depth is the harness's.** This asserts a tagged
//! node exists in the walked tree. Whether it is reachable in bounded gestures,
//! not clipped off-screen and not painted over are the other three assertions'
//! questions and stay theirs. A tag on a dead button passes here on purpose
//! (PARITY §8) — driving the tagged node and asserting the emitted envelope's
//! `op` equals the tag is the rung above, and it is filed rather than built.
//!
//! # Unproven is red
//!
//! A control that exists only on a screen the walk never visits fails honestly.
//! The walk's screen set — [`super::worlds`] — is part of the instrument, and
//! the start control is why it has four worlds rather than three: extend the
//! walk, or move the control.
use BTreeSet;
use crate;
use Harness;
use ;
pub
pub
/// **Every op tagged on a control in one settled frame.**
///
/// It reads `author_id`, which is where [`crate::ui::act::tag`] writes and what
/// AccessKit reserves for an author's own machine identification of a node —
/// so a control's spoken label is not consulted and cannot drift into this.
/// Hidden nodes are skipped: `is_hidden` is the tree's own statement that the
/// node is not currently offered to anybody, and a control nobody is offered is
/// not a surfaced control.
pub
/// **The four assertions.** An empty answer is parity holding.
///
/// Every complaint names what to do about it, because the three ways this
/// reddens want three different acts — build a control, fix a typo, or edit one
/// line of `parity.toml` — and a reader looking at a red gate is a reader who
/// does not yet know which of the three they are in.
pub