1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
//! Where the wire's key material lives, and what its absence means (REMOTE
//! §1.4, §8; bl-b6fa).
//!
//! **yog never mints a certificate.** Provisioning is an act the operator
//! performs on the boxes, out-of-channel by ruling — so this module only ever
//! *reads*, and the three answers it can give are the whole trust bootstrap:
//!
//! - **Nothing provisioned** — `Ok(None)`. The wire is simply off: the engine
//! listens on nothing and a seat has nowhere to dial. Removing the directory
//! deletes config, not code (the severability test), which is why absence is
//! an answer and not an error.
//! - **Partly provisioned** — `Err(remedy)`, naming what is missing and the
//! target that mints it. Half a trust store is a misconfiguration, and a
//! misconfiguration that silently degrades to *no encryption* is the failure
//! mode this design exists to exclude.
//! - **Provisioned** — `Ok(Some(Material))`: the anchors, this role's leaf and
//! key, and the one address.
//!
//! **An address is one fact with one home, and the home is the relationship**
//! (REMOTE §8 as amended, bl-aaec). A server binds its own `wire/address` and a
//! local seat dials it; a workspace held elsewhere names its host in its own
//! entry's `address` file ([`entries`](super::entries), REMOTE §8.2). Every
//! address still has exactly one file and no flag — two spellings of one
//! address is exactly the drift §8's name-resolution ruling removed from the
//! boundary — and one address per relationship is what a client of many
//! servers needs, no more.
//!
//! **It sits beside the world, not inside it** (`<yog-data-root>/wire`, the
//! sibling of `<yog-data-root>/world`). The world subtree is a *generated*
//! artifact — yog seeds it, and it is wiped and reseeded — while key material
//! is operator-provisioned and irreplaceable by anything yog can do. Nesting it
//! under a directory yog rebuilds would make a reseed a revocation. Entries sit
//! *inside* `wire/` ([`entries::ENTRIES`](super::entries::ENTRIES)) for that
//! same reason: an entry is the same operator-provisioned, irreplaceable class
//! of fact.
use crateEnv;
use ;
/// The material directory's leaf under the yog data root.
pub const DIR: &str = "wire";
/// The operator CA both ends verify against — one anchor set, both directions.
pub const ANCHORS: &str = "ca.pem";
/// The file naming the address the engine binds and a seat dials.
pub const ADDRESS: &str = "address";
/// The directory a **client** box files one host's material under, inside its
/// own [`DIR`] — `wire/workspaces/<leaf>/` (REMOTE §8.2). yog holds no
/// entries since bl-7942 (a seat does), but it still *issues* the leaf a
/// visiting box files there (`WIRE_LEAF`), and the instruction that goes with
/// the pair has to name the destination. One home for the word, so the mint's
/// sentence and the client that reads the directory cannot drift.
pub const ENTRIES: &str = "workspaces";
/// The act that mints the lot, named in every refusal so a seat that cannot
/// start says how to make it start.
///
/// **The verb, never the make target** (bl-a0dd). It said `make wire-certs`,
/// which is a wrapper over `cargo run` and so wants a checkout: a deployed
/// engine is an installed binary or the OCI image (DESIGN §10.1) and has
/// neither. That is REMOTE §8's own argument for retiring `wire-certs.sh` —
/// *"an installed binary has no repository to find a script in"* — and it
/// condemns a Makefile exactly as far as it condemned a script. The one
/// spelling every box has is the verb.
pub const REMEDY: &str = "yog wire-certs";
/// Which end of the wire is asking. One certificate is one client identity
/// (REMOTE §2), and the server's is its own — so the leaf names differ and
/// nothing else does.
///
/// **[`Window`](Role::Window) is the local window's own end** (REMOTE §1.2 as
/// executed, bl-ae05). The window is a wire client of loopback like any other
/// client: it presents a leaf, is identified by that leaf's common name, and is
/// scoped by its registrations. It is a role of its own rather than the
/// [`Client`](Role::Client) leaf because one certificate is one identity — the
/// window and a terminal seat sharing a leaf would be one client holding two
/// pane documents' worth of facts under one name.
/// Every role a mint issues a leaf for, in the order it issues them.
pub const LEAVES: = ;
/// One end's provisioned material.
/// The material directory for a composed world.
/// Read `role`'s material out of `world`. See the module doc for the three
/// answers; the `Err` names every missing file at once, because a remedy that
/// reveals one gap per run is a remedy run four times.
/// [`read`] against a directory outright — the world-free core, so a test names
/// its own scratch tree the way the folds elsewhere do.