1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
//! The capability family's **floor writer** (VISION §4.9's fifth rung, §4.11
//! item 7, DESIGN §8.6): revoke one conversation's tool auto-approval, and
//! restore it.
//!
//! One `ops.jsonl` row, and nothing else:
//!
//! ```text
//! ["yog-control","floor",<conversation id>,"raise"|"lower"]
//! ```
//!
//! which is at once the audit and the memory the control folds on its next
//! consult ([`crate::control::judge::Answers`] reads it back). The reader
//! landed with the shim; this is the writer, and between them the floor is a
//! *fold over rows* rather than a field anywhere — latest row wins, so the two
//! directions are one gesture and there is no order to get wrong.
//!
//! **Three things it deliberately does not do.**
//!
//! 1. *It launches nothing.* Answering a park drives the branch on because an
//! answer is about one invocation that is waiting; a floor is standing
//! policy, and §4.11 item 6 binds policy at the **next consult**. A restore
//! that also drove would spend a process on a conversation that may not be
//! parked at all, and the branch a floor *did* park is released by the
//! answer gesture that already exists — the one the operator is looking at.
//! 2. *It carries no reason.* The row's reason is the row before it: the
//! monitor's own `["yog-monitor",<verdict>,…]` line with its sentence, or a
//! `["yog-flag",…]`. Re-typing it here would give one fact two homes, and
//! the trail is read in order.
//! 3. *It checks nothing exists.* The floor matches by descent prefix, so
//! naming a conversation whose children are not born yet is the mechanism
//! working, not a mistake — refusing an absent id would refuse exactly the
//! pre-emptive floor the subtree match is for.
//!
//! **The receipt is re-derived, never echoed** (the `marks` precedent): the
//! reply says whether a floor *stands* over the conversation now, read back off
//! the trail this call just appended to. Those differ in the case that matters
//! — restoring a child whose parent is still floored leaves the child floored,
//! and a receipt that answered "restored" there would be a lie.
use Path;
use crateDeps;
use crateReply;
use crateAnswers;
use crate;
/// The ops-row verb naming a per-conversation floor, and its two states.
/// Mirrored from the fold that reads them, exactly as the once-answer's word
/// is: the reader owns its grammar, and a test holds the spellings equal.
const FLOOR: &str = "floor";
const RAISE: &str = "raise";
const LOWER: &str = "lower";
/// Write `agent`'s floor row on `workspace`'s trail, and answer with the floor
/// that stands over it afterwards.
pub