1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
//! The §9 config family at the boundary (§8.5, bl-3f46): the config editors,
//! the §16.3 marks knob and the §9.4 model pick as real
//! [`Action`](super::Action) variants, executed here.
//!
//! Until this landed, §8.5 recorded these as *actions by the taxonomy but not
//! yet variants*: each already funnelled through its own single chokepoint
//! (`Editor::apply`, `edit::drive`, `world::marks::apply`) and logged to
//! `ops.jsonl`, so no gesture had two implementations meanwhile. They now enter
//! the enum through this one module, and the §8.5 compile gate covers them —
//! codec, line and dispatch are all exhaustive.
//!
//! **A config apply is a destination plus the full staged text.** That is the
//! whole reframe: [`ConfigFile`] enumerates *where* the bytes land, and the
//! pipeline follows from it — `bz` validates a brazen draft (§9.1), a
//! litany-global one is hash-guarded and renamed (§9.2), and a per-workspace
//! lineage is staged and committed by `litany config` (§9.3, the only lawful
//! writer of `config/*`). One variant, no per-file gesture.
//!
//! **One validator, at the one destination whose contents yog can judge.** §9.2
//! held a second between bl-53be and bl-3ffa, over `models.<id>.provider`; it is
//! retired with the field's last reader, so the three plain-file destinations run
//! the same unjudged pipeline rather than one of them being gated on a table's
//! shape (§9.2).
//!
//! **A deposit carries no hash guard, and needs none.** The §9 editors' guard
//! protects a *long-lived* RAM draft against a file that moved under it; a
//! gesture states its whole text in one atomic instruction, so the load and the
//! apply are microseconds apart and the guard degenerates to the must-not-exist
//! check a new file wants. Nothing here re-implements the pipeline: every write
//! is the same `stage → validate → hash-guard → atomic rename` the panes drive.
use crateconfig_file;
use crateEditOrigin;
use crate;
use crateLitanyGlobal;
use crate;
use cratemarks;
use Path;
use Deps;
use Reply;
/// The destination datum and its addressing — split at §12's cap (bl-f5f6).
pub use ConfigFile;
pub use Read;
pub
pub
use ;
use ;
/// Run one config apply (§9). The reply says what landed: a file destination
/// answers with the path written, a lineage with `litany config`'s captured run
/// — the same distinction every other action makes between a write and a spawn.
///
/// `ws` is the destination's own workspace, resolved by the chokepoint's one
/// address resolution (REMOTE §8, bl-523f) — the empty path for the three
/// destinations that name no world, which is the general path with no input:
/// no arm that takes it reads the value.
pub
/// Read one §9 destination's current bytes (§8.5, bl-0164): [`apply`]'s
/// read-only twin, and the file editors' Reload spelled headless. A file
/// destination that is not there yet answers empty text — the same "new
/// file" reading every editor's own load already gives — so only a real I/O
/// failure refuses. A **lineage** answers the pane's own Load (bl-dff8): `git
/// show config/<lineage>:<path>`, the very bytes an Apply on that destination
/// would be diffed against. It carries the write's `origin` and ignores it,
/// because where the next commit lands is not where the current bytes are;
/// [`Query::Lineages`](super::Query::Lineages) is the browse that says which
/// paths a lineage holds.
pub
/// The §9.3 browse (§8.5, bl-dff8): the workspace's lineages, each with the
/// files its tip holds — the pane's dropdowns, as one answer.
pub
/// The §9.4 roster (§8.5, bl-dff8): what `provider` offers **in this
/// workspace's wall** — the picker's own read, aimed by the gesture rather
/// than by a focus a headless seat does not have (bl-fcd5).
pub
/// **Which branch this agent tracks on** (§8.5, bl-0164): the marks pane's
/// `Read current`, over the same space [`set_marks`] re-reads after it writes.
/// Infallible — a space with nothing written reads as balls' own default, which
/// is the general path with no input rather than a refusal to render.
pub
/// One workspace's effective provider table, rendered (§8.5, bl-0164) — the
/// §8.3 login pane's `↻ providers + credentials`. The table is read **inside
/// the named sphere's wall** (bl-fcd5): a provider row reads *signed in* only
/// where this workspace signed it in, so the table is meaningless without the
/// workspace that scopes it. The credential fact rides the listing's own
/// `credential` column (bl-dba3) — one ask, and no second derivation over the
/// credentials directory. brazen unanswerable is an empty table, never an
/// error: the same "asked, never stored" contract [`Deps::provider_rows`]
/// carries.
pub
/// This workspace's **role assignments** (§9.4, §5.1 #27; bl-2410) — what
/// `/model`, `/effort` and `/priority` have actually set, read back.
///
/// It reads exactly where those three write: `providers.yaml` at the tip of the
/// lineage §9.3 writes, through the one anchored grammar this tree has. A read
/// and a write naming the place the same way is the discipline the §9 family
/// already keeps, and here it is also what makes the answer *current* — under
/// follow-the-tip that tip is what every conversation in this workspace
/// resolves at its next step, so a control showing it is showing what governs.
///
/// **A lineage it cannot read declares no role**, and that is an answer rather
/// than a refusal: a workspace with no config yet, or one whose `roles:` block
/// is absent or inline, has nothing set — which is exactly what a control
/// opening on it should show. That differs from the §11 `Governing` read, which
/// refuses, and the difference is real: *this conversation has no policy* is
/// never true, while *this workspace has assigned no role* is an ordinary state
/// a fresh world passes through.
pub
/// The named workspace's brazen locations (§16.2 as amended). **The gesture's
/// own workspace is the single source** (bl-fcd5): the executor lenses on it
/// rather than trusting whatever wall happened to stand in `deps.world`, so a
/// windowless seat reaches exactly the sphere it named and a window reaches
/// exactly the one it has focused. Infallible by construction — a wall is a
/// pure function of the world anchor and the workspace's leaf, and a gesture
/// with no workspace never got this far (the line reader and the codec each
/// refuse it by name).
pub
/// The world with `workspace`'s wall standing — the lens every brazen fold in
/// this module reads through. Idempotent, so re-lensing a `deps.world` the
/// window already lensed on its focus replaces the wall rather than stacking
/// one.
pub
/// **Amend this agent's tracking branch** (§16.3): write `branch` into the
/// workspace's own balls space (logged, §4.2), then answer with the **re-read**
/// branch — what actually landed, not what was asked for. An unlawful branch
/// refuses at the write in the words the grammar already refused it with.
pub
/// The §9.4 pick: **one write** (bl-d9cb) — the §9.3 lineage write of
/// `providers.yaml`, which is the single home of a role's (provider row, model
/// id) pointer. The text is composed first, so a dead provider row, an incapable
/// protocol or a file the grammar cannot read refuses before anything is
/// written.
///
/// It used to apply `models.yaml` through the §9.2 pipeline first, in that order,
/// because litany's cross-check refused a config naming an undeclared model.
/// litany retired that check and the table with it (its bl-35e2), so the first
/// write reached nothing that reads it.
///
/// The provider gate reads the rows of **the workspace being picked for**
/// (bl-fcd5), not of whatever wall stood in `deps.world`: the pick already
/// names its sphere, and a row that is dead in one workspace may be live in
/// another, so judging with the wrong wall would refuse a valid pick — or,
/// headless with no wall at all, gate on an empty table and let anything
/// through.
///
/// The table is handed to [`plan`](crate::model_pick::plan) **whole** since
/// bl-3d22: the gate asks whether the row exists AND whether its protocol can
/// carry a yog turn, and the second question is not answerable from a name.
pub
/// The §9.4 **tuning pair** (bl-23bd) — a role's effort level or its priority
/// lane, written into the same `providers.yaml`, on the same lineage, through
/// the same commit [`pick_model`] spends.
///
/// Beside it rather than inside it because the two answer different questions
/// of the same file: a pick moves the (row, id) pointer and must be gated
/// against brazen's live table, while a tuning knob is a value the config is
/// always free to carry — the capability decides which control a seat *offers*
/// (`ProviderRowView`'s two booleans), never whether a write is allowed. So
/// this reads no provider table at all, which is also why it cannot be a wider
/// pick: the pick's own gates would have nothing to judge.
///
/// The read → plan → commit shape is [`pick_model`]'s verbatim, and
/// deliberately so: one staging path, one `litany config` drive, one
/// [`Reply::Outcome`], so a tuning gesture and a pick fail the same way when
/// the lineage will not take an edit.
pub