1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
//! The §9.4 model picker's widgets — coverage-excluded glue like the rest of
//! `src/shell/*`. Everything it decides is tested elsewhere: the block grammar
//! and the one-pick [`plan`](crate::model_pick::plan), the roster query's
//! settle arms, the [`fault`](crate::model_pick::grammar::fault) sentence a
//! dead role row paints, the row the settings seat wears
//! ([`crate::model_pick::header`]), and the two write pipelines in `config_edit`
//! (§9.2 provider gate + hash-guard + rename, §9.3 staged `lernie config`
//! drive).
//!
//! This wires them to widgets: [`seat`] paints the row both surfaces carry,
//! [`select`] holds the two brazen-sourced dropdowns and the role strip,
//! [`lines`] the derivation behind the row, [`ram`] the cross-frame state and
//! [`write`] the write half.
//!
//! **The row IS the picker's pair control** (bl-cd2a). The ruling: the model
//! selection in the conversation window carries both dropdowns, provider and
//! model, and the whole line becomes `<provider> - <model>` and nothing else.
//! So the two dropdowns are not
//! behind a *change…* button and are not duplicated on the row: they *are* the
//! row, always painted, and the pane keeps only what a row cannot hold — the
//! role strip that re-scopes them, the fault a dead assignment earns, the write
//! receipt, and the two routes out. One pair of dropdowns in the app, one state,
//! one write path.
//!
//! The pane has **no buttons at all** (bl-fb6b): choosing a model is the write,
//! and the role strip is the scope it writes to — so there is neither a Set
//! button to forget nor a per-role apply to pick the wrong one of.
//!
//! **The roster is asked when the model list is opened**, not when a surface
//! appears (bl-cd2a amends §9.4's "every time the picker is triggered"): the
//! dropdowns are on screen from the moment a conversation is, and a control that
//! fired a provider query on sight would spawn one per glance. Opening the list
//! is the trigger, and it still survives nothing — no candidate set outlives a
//! close, nor a role change onto another provider row. The two facts read
//! *about* the current assignment — brazen's provider rows and the global
//! `models.yaml` — are asked once per open of the pane and discarded with it
//! (§5.3), because they answer "is what you already have usable?", a question
//! only asked while the pane is on screen.
//!
//! **Two seats, one row** (bl-824e): the open conversation's settings rows and
//! the §11 birth-config block — since bl-2e18 the same bottom seat, one branch
//! on the selection apart. Only the scope claim differs, so [`seat`] takes that
//! sentence rather than deriving it: [`conversation_scope`] names a conversation
//! already frozen, [`birth_scope`] one not started yet. A second picker would be
//! a second authority on the same two files.
use crateCli;
use crateconfig_file;
use crate;
use crateCenterTab;
use crate;
use crate;
use crateShellState;
use cratetheme;
use Path;
pub
/// The §9.4 role strip — the *scope* over the pair row, split from
/// [`select`] at §12's cap on the seam that file's own doc draws (bl-dd7f).
/// One role row as painted: the assignment plus why its model is unusable, or
/// `None` when it is fine (§9.2's judgement, surfaced at the point of choice).
type Marked = ;
pub use PickerState;
pub use ;
/// The workspace's leaf name — what both scope sentences call the blast radius.
/// The scope a pick claims when the picker was opened from an open
/// conversation's model line (§9.4): the branch moves, this conversation does
/// not.
pub
/// The scope a pick claims when the picker was opened from the §11 birth-config
/// block: the same branch write, said in the terms the birth surface has —
/// there is no frozen conversation to exempt, and the workspace default moves
/// (bl-824e; lernie 0.0.3 offers no per-conversation config).
pub
/// The picker pane (§9.4) — since bl-cd2a, only what the row cannot hold: the
/// role strip that re-scopes the row's two dropdowns, the fault a dead
/// assignment earns, and the scope the write claims. Returns the §11 tab the
/// operator asked to be taken to (the §9.1 brazen editor); the caller owns
/// surface routing, so the pane names the request rather than performing it.
pub
/// Fire the roster query when there is none, or when the selected role moved to
/// a different provider row — the §9.4 "every time the picker is triggered".
pub
/// Poll the roster and hand back its **settled** view. `None` while no query has
/// been fired or one is still in flight — the row paints the pulse inside the
/// open list rather than beside it (bl-cd2a), because that is the only place the
/// operator is waiting for it. A *failed* roster settles to a view with an empty
/// model list, so the list's custom-id entry stays reachable and a provider that
/// cannot be listed is not a dead end.
pub
/// Paint a settled roster's failure and, when it is auth-shaped, the way out of
/// it (bl-91f1): what this row needs in yog's own words and the control that
/// goes and does it. Returns the §11 tab the operator asked for.
///
/// The three layers are deliberate. brazen's sentence stays **verbatim** on top
/// (INV-2 / §7.3 — a failure renders as itself), the run-by-hand command stays
/// **underneath** (§8.3's fallback grammar), and the remedy sits between them:
/// additive, so §8.3 rule 5's "a wrong derivation must never become the only
/// way out" holds here too. `row` is `None` only where the selected provider is
/// not in brazen's table at all, which is the one case with nothing to say
/// about its credentials.
pub