1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
//! The crate's lock chokepoint (Bootstrap rule 7): the cross-thread
//! shared-mutable-state locks live in this one file, so the whole-crate
//! shared-state inventory is auditable in one place.
//! `rules/locks-outside-state.yml` enforces the confinement; the only carve-outs
//! are test scaffolding and one documented exception,
//! [`git_tree::probe_cache`](crate::git_tree) — the macOS TTL cache's `Mutex` is
//! single-thread interior mutability local to the probe stack, not cross-thread
//! shared state, and a generic decorator folded in here would break llvm-cov's
//! per-line coverage (see that module's doc). Two residents:
//!
//! - [`WatchSetHandle`] — the shared [`WatchSet`](crate::watch::WatchSet) behind
//! `Arc<Mutex<…>>`; the frame reconciles it, the
//! [`Bridge`](crate::watch::Bridge) polls it. [`new_watchset`] is the single
//! site its `Mutex` is constructed.
//! - [`DirtySet`] — the bridge→frame dirty-root hand-off (§7.2): a mutex-guarded
//! set the bridge fills and the frame drains.
use BTreeSet;
use PathBuf;
use ;
use crateWatchSet;
/// The shared [`WatchSet`](crate::watch::WatchSet): the frame reconciles it, the
/// [`Bridge`](crate::watch::Bridge) polls it. A transparent alias so `.lock()`
/// stays ergonomic at the use sites while the `Mutex` token itself is confined
/// here.
pub type WatchSetHandle = ;
/// Build a fresh, empty [`WatchSet`](crate::watch::WatchSet) behind its shared
/// handle — the one place `Mutex::new` is applied to the watch set (the app then
/// reconciles the desired roots through the returned handle).
pub
/// Lock the shared watch set, poison-immune: a panic while the guard was held
/// leaves the data intact, so we recover it rather than propagate the panic
/// ([`PoisonError::into_inner`]). Keeping the `.lock()` and the recovery on one
/// line is deliberate — a split isolates the never-taken recovery on its own
/// line, which reads as uncovered under `ignore-panics`.
pub
/// The bridge→frame hand-off: dirty root paths. Cloning shares the inner set
/// (the bridge holds one clone, the frame another).