1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
//! **The shell's one spelling of a wire act** (REMOTE §1.2, §9.8; bl-4841) —
//! the write-side twin of [`super::wire`].
//!
//! Since the 2026-08-14 ruling the window is a client of its own engine over
//! loopback mTLS, and a frame may never wait on a socket. So a click no longer
//! *runs* a gesture and reads its `Reply` in the same frame: it **posts** one and
//! holds a [`Ticket`], and the receipt lands frames later
//! ([`AppModel::post_act`]).
//!
//! Two shapes, because acts come in two kinds and no more:
//!
//! - **[`fire`] — the act whose receipt is nothing.** Every §8.2 verb whose
//! durable record is its own `ops.jsonl` line (INV-2): the ball verbs, the
//! `lernie` short verbs, a fork's cohort. Nobody held the reply before either
//! — it was discarded on the spot — so nobody holds a ticket now. The
//! re-derivation the fire used to trigger is not lost: it moved to the receipt,
//! where it belongs, and the model runs it for every act
//! ([`AppModel::settle_acts`]).
//! - **[`Held`] — the act whose receipt is a sentence.** The four surfaces that
//! paint what came back: the marks pane, the model picker's two writes, the
//! lineage config editor. Each already held a status string across frames, so
//! what it gains is one field beside it — the ticket — and the in-flight
//! state is that same line saying so.
//!
//! **The `Cli` pair does not come here, and that is the point.** A dispatched
//! act needed `boundary_deps`, which carries the verb binaries this box
//! resolved; a posted one carries nothing but the gesture, because the engine
//! owns the binaries and a seat never did. A remote seat could fire every act
//! in this file.
//!
//! Coverage-excluded glue like the rest of `src/shell/*`: the posting, the
//! ticket and the receipt are covered where they live (`app::acts`,
//! `wire::post`).
use crateAppModel;
use crate;
use crateTicket;
/// What marks a line whose act has not been answered yet. An **ellipsis on the
/// sentence the click already wrote**, rather than a second phrasing to learn:
/// the operator reads what this gesture means, with one mark saying the engine
/// has not confirmed it. A clean receipt drops the mark and nothing else moves;
/// anything else appends the reason.
const IN_FLIGHT: &str = " …";
/// Fire one act nobody is holding a receipt for (§8.2, INV-2): the ops trail is
/// the durable record, and a refusal reaches the operator as the §7.3 banner
/// reads that trail back.
pub
/// One act a surface is holding: the ticket it was posted under, and the
/// sentence its landing means.
pub
/// **What a receipt says went wrong, if anything** — the arm three of the four
/// held surfaces share, so a refusal reads the same wherever it landed.
///
/// `None` is a clean landing, and a clean landing means the sentence the fire
/// already wrote. A non-zero exit is spelled through the one projection
/// (bl-afa9): a bare `-1` reads as a signal death rather than "ran, status not
/// observable".
pub