1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
//! **What an ops row stands at** (DESIGN §7.3, §6, §4.2) — the one fold that
//! makes the failure banner an *answer* rather than a derivation every seat
//! re-implements.
//!
//! §7.3 rules that a failed action is a stated fact, said exactly once, at the
//! surface its `origin` names, and that its alarm ends two ways: **retirement**
//! by a newer clean op of the same verb (§6, [`super::outcomes`]) or the
//! operator's **ack** watermark ([`super::since_ack`]). Both readings lived
//! here and neither crossed the §8.5 boundary, so a seat wanting the banner had
//! to re-derive the retirement key, the ack scan and the sentinel table — five
//! duplications whose failure mode is silent divergence rather than a compile
//! error (bl-4d81).
//!
//! [`Standing`] is those two readings folded into one **total** vocabulary, and
//! [`standings`] is the projection that produces it. "One banner per origin" is
//! then the rows whose standing is [`Standing::Live`], grouped by the `origin`
//! the row already carries — a seat renders and never classifies.
//!
//! **Total, not three-valued, and never absent.** §7.3's three words —
//! live / retired / acked — describe a *failure*'s standing; a clean row and a
//! handoff have one too, and leaving the field off for them would make a reader
//! tell "ran clean" from "handed off, no exit observed" by re-reading the `exit`
//! integer, which is the whole defect. So the vocabulary is [`OpOutcome`]'s
//! four arms — the crate's one classification, the same one `badge::op_badge`
//! is keyed on — with the ack's [`Standing::Acked`] added to split the failed
//! one. Nothing is stored: this is a read over a tail, like everything else in
//! [`super::live`].
use ;
/// Where one row of the trail stands **right now** — its §6 outcome folded with
/// the §4.2 ack watermark. Total over every row, so a reader never has to ask
/// the `exit` field anything.
/// One row of the trail **as a reader is answered it** (§8.5): the durable line
/// and what it stands at. The row's own per-row readings — `failed`,
/// `exit_label` — stay methods on [`OpRow`], because they are recomputable from
/// the line itself and a second copy of a derivation is what this crate keeps
/// refusing to grow; the standing cannot be, since it is a fact about the row's
/// *position* in the tail.
/// The tail with each row's [`Standing`] beside it — the §7.3 carrier, and the
/// one composition of §6's retirement projection with §4.2's ack watermark.
///
/// **A prefix may be sliced off before this runs.** Retirement looks only at
/// rows *later* than the one it judges, and an ack line dropped with the prefix
/// leaves every remaining row after it, which is what those rows already were —
/// so answering the last `max` of a longer tail gives each row the standing it
/// had over the whole of it ([`since_ack`] states the same argument).