//! Config-editing view-models (DESIGN §9): load → edit a RAM draft → Apply =
//! stage → (validate, where a validator exists) → hash-guard → atomic rename.
//!
//! One discipline across the file-editing surfaces. The shared write pipeline
//! — the [`FileIo`] seam, temp-in-dir staging, the concurrent-edit hash guard
//! and the atomic rename — lives in [`pipeline`], the single source of truth
//! for how an edit reaches disk (§9). Each is a thin view-model over it:
//! [`brazen`] (§9.1, raw TOML gated by `bz`) and [`lernie_global`] (§9.2, raw
//! `models.yaml`/`workflows/*.yaml` with no validator). Every editor is pure
//! over the injected seam, so Linux tarpaulin drives each transition with a
//! fake and no real disk.
//!
//! [`branch`] is the third surface (§9.3): the per-workspace config *branches*
//! (`config/*` git refs), not files on disk. Its browse half reads through the
//! env-scrubbed `git_tree::cmd` wrapper and derives each agent's governing
//! config; the `$EDITOR`-driven edit half ([`branch::edit`], Y21) is the only
//! lawful writer of `config/*` and so bypasses the [`FileIo`] pipeline
//! entirely — it stages drafts and drives `lernie config`, whose `$EDITOR`
//! callback re-enters this binary in [`apply`] shim mode to copy them over the
//! checkout. lernie commits.
pub use RealFileIo;
pub use FileIo;
pub use ;