1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
//! The shell's reads of the world clock and its entropy (§7.2, §4.2): the
//! three mintings that can only happen at the process boundary, in one place
//! because each is a fact two seats must agree on. The frame takes them as
//! parameters and stays testable; nothing here is derived, cached, or held.
/// An entropy seed for the conversation-mint RNG (§3.3), held stable in
/// [`StartState::mint_seed`] so the composer's preview and its fire agree —
/// **per prediction, not per session**: a landed fire spends its seed and draws
/// the next one here ([`StartState::spend_mint`], bl-28ba). Not
/// secret — the mint is collision-avoidance, and the occupied-set check is what
/// guarantees uniqueness (mirrors `names::SplitMix64::from_entropy`).
pub
/// The wall-clock `ops.jsonl` timestamp (§4.2) for the verb dispatchers, which
/// stay clock-free and testable by taking it as a parameter. Delegated to the
/// crate's one time seam ([`Clock::stamp`](crate::ui_state::Clock::stamp)) —
/// the §7.2 worker writes its own ops lines from the *injected* clock, and two
/// spellings of "now, as a string" would be two facts.
/// Wall-clock unix seconds for every seat that dates something (§11): the
/// conversation list's ages and the in-flight strip's elapsed (§5.1 #28). Minted
/// here at the shell boundary like [`now_ts`], in **one** place — two spellings
/// of "now, in seconds" would be two facts, and the two seats must agree on what
/// `42s` means.
pub