1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
//! Test-only spawn discipline for this binary — **one lock, held by the crate's
//! one fork** ([`crate::git_env::spawn`]), and by nothing else.
//!
//! `fs::write` on a fixture script holds a write fd. A `fork` in another thread
//! copies that fd into a child, which keeps it until its own `exec` completes;
//! an `exec` of the script inside that window is ETXTBSY, so a test that writes
//! a fake binary is reddened by a peer test three modules away. The lock is one
//! static for the whole binary because per-module locks do not exclude each
//! other's threads.
//!
//! It is taken **around the fork** (bl-6397). The older discipline asked every
//! test that wrote a script to bracket its own write and exec, which is a
//! contract each new test must be told about and most were not — the two tests
//! that flaked were one of each kind: a victim that held the guard correctly,
//! and an unguarded sign-in fixture that was both victim and cause. Guarding
//! the fork alone is *sufficient*: a peer fork cannot land inside anyone's
//! write window without holding the lock, and it returns the lock only once its
//! child has exec'd. Measured with writes left entirely unguarded, 8
//! write-then-exec threads against an 8-thread fork storm, ~9,600 pairs: zero
//! ETXTBSY, against 8.3% with the fork unguarded.
//!
//! The write-side brackets tests used to hold are gone with the contract, and
//! they were not merely redundant: a test that holds the lock across a body
//! whose WORKER THREAD forks starves that fork for the whole test — the wire
//! host's tool span, which this change caught the moment the fork started
//! taking the lock. Write the script, exec it: the fork boundary holds, and
//! nothing in a test body needs to know it is there.
use crateFileIo;
use HashMap;
use ;
use ;
pub static SPAWN_LOCK: = new;
/// Acquire `SPAWN_LOCK` poison-immune: a panicking fork frees the guard with
/// its `()` intact, so recover rather than cascade-poison peer tests. Recovery
/// stays on one line — a split reads as uncovered under `ignore-panics` (the
/// same discipline as `state::lock_watchset`).
pub
/// In-memory [`FileIo`] for editor and pipeline tests: a flat path→bytes map.
/// `fail_write` forces the write step to error (the `Io` Apply arm). Shared by
/// the brazen, litany-global and pipeline test modules — one fake, one
/// behavior, so the write pipeline is exercised the same way everywhere.
pub
/// `providers.yaml` exactly as litany's own `template/providers.yaml` authors
/// it (the pinned engine) — what a materialized `litany new` commits,
/// worker tool pool included: yog grants nothing on top (§8.1, bl-7fc8).
pub const TEMPLATE_PROVIDERS: &str = "roles:\n worker:\n provider: anthropic\n \
model: claude-sonnet-5\n tools: [apply_patch, bash, cd, dispatch, load_skill, message, \
multi_tool, read_file]\n compactor:\n provider: anthropic\n model: claude-haiku-4-5\n";
/// The `new)` arm of a fake `litany`: the workspace litany ARCH §2.2 describes,
/// authored in shell — a bare `repo.git` whose orphan `config/default` root
/// carries [`TEMPLATE_PROVIDERS`]. Every fake `litany` a start test drives
/// through shares this one arm.
pub
/// Re-prime the directory at `path`: **the same path, guaranteed a different
/// inode** (bl-e492).
///
/// The obvious spelling — remove it, create it again — is a coin toss. A
/// filesystem is free to hand the just-freed inode straight back, and the CI
/// runners do: the two watcher tests that assert "a replaced root leaves a deaf
/// watcher" were reproducing nothing there, because the inode they replaced was
/// the inode they started with (`left: Some(9211169) right: Some(9211169)`).
///
/// So the replacement is **allocated while the original is still linked** — two
/// live directories cannot share an inode, so the new one differs by
/// construction — and then renamed over the top. Nothing is left to the
/// allocator. It is also the truer reproduction: a re-primed clone is
/// materialized beside its target and moved into place, not built in the hole.
pub
/// The first half of [`replace_directory`], for the test that must observe the
/// hole between the two: the replacement directory, created beside `path` while
/// `path` is still linked — which is the whole of what makes its inode differ.
pub
/// The hermetic fixture world and the workspace wall it stands in — its own
/// file at §12's cap, on the seam between faking an *effect* and composing a
/// *world* (bl-fcd5).
pub
pub use ;
/// A real litany workspace on disk, for the tests that need one (§8.6's control
/// authoring and the start-flow abort it can raise). Its own file: the cap is a
/// tree-wide invariant, and this seeder is a self-contained fixture rather than
/// part of the spawn discipline above.
pub
/// The §9.5 wire's key material, minted at test runtime by the same
/// out-of-channel act an operator performs (REMOTE §1.4, bl-b6fa) — its own
/// file because a certificate fixture is never committed and the minting is a
/// self-contained seeder, not part of the spawn discipline above.
/// **The suite's own seat** — the client half of the wire, which the crate no
/// longer ships (bl-7942) and its own tests must still speak to prove the
/// listener.
pub
pub
pub
/// The §11 accessories that crossed with bl-296f — the altitude-0 chrome and
/// the selection's own detail — asked through the boundary, there being no
/// model accessor left to ask instead.
pub
/// The deterministic [`Clock`] every debounce and sweep branch is exercised
/// against — its own file at §12's cap, on the seam this file already had:
/// faking a *value* the crate reads, rather than the spawn discipline above.
pub
pub use FakeClock;