1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
//! Rules every hook body in this binary obeys, in one place.
//!
//! `recall`, `brief`, `touch`, `intercept`, `impact-hook` and `enrich` all run
//! as a host's hook: inside a short timeout, in front of or beside a tool call
//! the user is waiting on, with a store that may be missing, busy, or older
//! than this binary. Two of those rules are worth stating once rather than
//! restating in each module — how such a body opens a store
//! ([`open_for_hook`]), and how it keeps inside a byte budget ([`cut_to`]).
use Path;
/// Open `db_dir` the only way a hook body may.
///
/// - **Never create.** `RealFs::new` runs `create_dir_all`, so an unguarded
/// open from a hook left behind by an uninstall — or pointed at a typo'd
/// path — would leave an empty `mushroom-memory/` in the user's repository
/// and then answer out of it. The existence check is the guard.
/// - **Never migrate, never repair the WAL, read-only.** A hook running in
/// front of a tool call has no business writing to the store, and must never
/// wait on a lock: the user is waiting on the tool call, not on us.
///
/// `None` for every failure, which is also every hook body's answer to one:
/// the tool call proceeds exactly as it would with no hook installed.
pub
/// `s` cut to `max` bytes on a character boundary, with an ellipsis marking
/// the cut. Unchanged when it already fits.
///
/// The same idiom `recall` and `render` use for their own budgets: walk back to
/// a boundary rather than slicing blind, because a hook that panics is the
/// loudest possible failure and a `&str` index inside a multi-byte character
/// is the easiest way to get one.
pub