1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
//! **The start flow's first rung** (DESIGN §8.1, §8.3; bl-1fd0): can the wall
//! this start aims at reach a model at all, and if not, what the pane says
//! instead of inviting a goal.
//!
//! The operator ruling this exists for: *"On a wall holding no usable provider
//! credential, typing a goal and hitting Enter will work zero percent of the
//! time — the conversation is born, immediately dies on no-models, and the
//! operator learns it from a dead row (or from nothing at all). The pane is
//! inviting the one act that cannot succeed while hiding the one act that must
//! come first."* It was hit live, twice in one evening, and both first goals
//! were wasted.
//!
//! **It is a pure read of a table the frame already holds** — brazen's
//! effective provider rows (§5.1 #20/#21), folded by the same §8.3 `ask` that
//! populates the Login roster. No network, no spawn, no per-frame cost.
//!
//! **A keyless row is not a credential, and it is not an escape either.** The
//! ruling reads *"any row `stored` or `not required`"*. Taken literally that is
//! vacuous: brazen merges its built-in table under every config, so `ollama`
//! and `claude-code` read `not required` on **every** wall there can be, and a
//! predicate they satisfy is a predicate nothing ever fails — the rung would
//! not appear on the wall it was ruled for. Nor are they what a doomed start
//! was routed to: both claim no model prefixes and are reached only by an
//! explicit `--provider`, so a start whose role names an uncredentialled row
//! dies exactly as the ruling describes with both of them sitting in the table.
//! So `not required` does not make a wall ready; it only changes what the rung
//! says, because an operator looking at two keyless rows deserves to be told
//! why they do not count.
//!
//! **Every other credential spelling IS ready**, including the two the ruling's
//! enumeration omitted (`ambient`, `inline`) and any this build has never heard
//! of. Refusing a wall whose rows carry a credential a run would actually spend
//! would block a working setup, and no surface here refuses on the strength of
//! a question that went unanswered — the rule `providers::capability` already
//! keeps for the `protocol` column.
//!
//! **What this still cannot see** (the residual, recorded rather than hidden):
//! *which* row a start routes to. That is `roles.<r>.provider` on the config
//! branch — several git reads, and §9.4's subject, not the pane's — so the gate
//! judges the wall rather than the route. It is therefore exactly right when
//! nothing at all is signed in and conservative for an operator whose roles all
//! name a keyless row: they are told to sign in when their setup needs no
//! sign-in. The remedy is the same one sentence, so the cost is a sentence.
use crate;
/// The rung's refusal, and the whole of what Send says instead of firing. One
/// sentence, as the ruling asks — and short, because it is painted above the
/// goal box in a pane the operator sized for typing, where every line it takes
/// is a line the roster beneath it does not get.
const NO_CREDENTIAL: &str = "nothing on this wall is signed in, so a goal started here reaches no model. Sign a \
provider in below — your draft is kept.";
/// Appended when the wall's only credential-free rows are the keyless ones, so
/// the operator reading `no credential needed` beside two of them is told why
/// they are not the answer.
const BUT_KEYLESS: &str = " Its keyless rows are reached only by an explicit provider.";
/// What one wall's provider table says about reaching a model (§8.1) — two
/// booleans over the `credential` column, and the whole of what the gate reads.
///
/// Derived where the §8.3 roster is derived, off the same rows, so the rung and
/// the roster beneath it can never disagree about the same wall.
/// The start pane's first rung (§8.1) — three states, total over the two facts
/// the pane can hold about its target wall.