1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
//! The embedded brazen host (DESIGN §16.7 W10) — brazen's `bz` binary, in
//! yog's process.
//!
//! yog links `brazen` at an exact pin with the `native-host` feature, which
//! re-exposes the impure shim the `bz` bin owns (`brazen::native`: the rustls
//! `ureq` transport, the XDG credential store and model cache, the loopback
//! login receiver, the system clock/browser/RNG). This module is the *only*
//! place that shim is wired, and it reproduces `bz`'s own `main.rs` verbatim:
//! build [`brazen::Args`], read the route off argv with brazen's authoritative
//! [`brazen::route`], and hand each route its seam bundle.
//!
//! **One entry, two callers.** [`run`] takes its stdio as injected writers, so
//! the same wiring serves both consumers with no second code path:
//!
//! - [`crate::multiplex`]'s `bz` arm — `yog bz <argv…>` — passes the real
//! process stdio and [`Tty::probe`]. That is `bz` the command, whichever
//! process image invokes it.
//! - [`RealBzRunner`](crate::config_edit::brazen::RealBzRunner) passes an empty
//! stdin and two byte buffers, so the config projection (`--dump-config`, the
//! `--list-providers` table) is a *function call* — no spawn, no pipe, no
//! parse of a foreign binary's stdout.
//!
//! **What stays out of here** (brazen's own note on the exposure): the
//! process-global effects of `bz`'s `main` do not lift. yog never resets
//! SIGPIPE — the disposition is `SIG_IGN`, so a closed stdout surfaces as a
//! `BrokenPipe` write error that brazen's own `ExitClass::from_io` maps to the
//! same 141, and restoring it would need an `unsafe libc::signal` outside the
//! one sanctioned site (AGENTS.md rule 3). The two isatty facts are read
//! through safe `std::io::IsTerminal` instead of `libc::isatty`.
//!
//! **Env — the wall, not the machine (§16.2 as amended by the blast-radius ruling).** All three
//! of brazen's locations resolve inside the focused workspace's wall
//! ([`crate::world::wall`]), folded once by
//! [`BrazenPaths`](crate::config_edit::brazen::BrazenPaths) off the caller's
//! [`Env`]: the config path is *injected* into the [`brazen::EnvSnapshot`] this
//! module builds (so brazen's own fold can never fall through to
//! `$XDG_CONFIG_HOME`), and the credential store and model cache are yog's own
//! wall-rooted seams ([`store`]) rather than brazen's process-env ones. One
//! fold, three consumers — the pane's presence read, the in-process call, and
//! the spawned `yog bz` on the far side of a fork all name the same files.
//!
//! **No wall, no `bz`.** A seat inside no workspace has no providers,
//! credentials or model cache to read, so [`run`] refuses with
//! [`NO_WALL_CODE`] instead of falling back to the machine's own brazen state.
//! Every yog surface guards before it calls; a spawned `bz` inherits the wall
//! from the loop that fired (§16.2's inheritance note), so the refusal is only
//! ever reached by a `bz` invoked outside any workspace.
use ;
use crateBrazenPaths;
use crateEnv;
pub
use Seams;
/// brazen's own config selector, injected into the snapshot from the wall.
const BRAZEN_CONFIG: &str = "BRAZEN_CONFIG";
/// The exit code a `bz` invocation outside any workspace wall answers with —
/// brazen's own usage class (64), because naming no wall is exactly a usage
/// error: the invocation is well-formed but addresses no sphere.
pub const NO_WALL_CODE: i32 = 64;
/// The message that refusal prints, naming the fix rather than the fault.
const NO_WALL_MSG: &str = "bz: no workspace in this environment — providers, sign-ins and the model \
cache belong to a workspace, and there is nothing shared to fall back to. \
Run this inside a yog workspace, or focus one in yog.\n";
/// The wall root a **discovery probe** outside any workspace stands on
/// (bl-52ed). `--help`/`--skill`/`--version` are answered by `brazen::run`
/// *before* it reads a config file or touches a seam, so the three paths folded
/// from this root are provably unread — and an absolute path that cannot exist
/// keeps that provable rather than merely intended: were the invariant ever to
/// break, the read finds nothing instead of finding the machine's own brazen
/// state, which is the one thing §16.2 forbids.
const NO_WALL_PROBE_ROOT: &str = "/nonexistent/yog-no-wall";
/// The two isatty facts `bz`'s shim injects into [`brazen::Args`] — the only
/// terminal knowledge the pure library cannot observe for itself. Carried as
/// one value so [`run`] keeps a narrow parameter list.
pub
/// Run one `bz` invocation in-process and return its exit code. `argv` is
/// brazen's argv **without** a program name (what `yog bz …` slices off, and
/// what `std::env::args().skip(1)` gives `bz` itself).
pub