1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
//! CLI outbound: the frontend's sole command surface to the harness. Every user
//! action is an `exec(<binary>, args)` and nothing else (ARCH §3.4/§3.5;
//! "resume" is no longer user-facing per the §2.9 amendment, bl-abf3).
//!
//! Three spawn shapes over one binary abstraction (DESIGN §8):
//! - [`Cli::run`] / [`Cli::run_in`] stream stdout/stderr with terminal exit
//! reporting and aggressive SIGTERM-then-SIGKILL cleanup on [`Stream`] drop;
//! `run_in` sets the child's `current_dir` (bl verbs run cwd = project, §8.2).
//! - [`Cli::spawn_detached`] fires a child in its own process group
//! (`process_group(0)`, safe std — a new group, not a session; enough, since
//! terminal signals hit the foreground group), stdin/stdout null, stderr to a
//! caller-named per-spawn sink file, no pipe and no signal — long-lived drivers
//! (§8.1) that yog's exit can't kill. Its one retained thread only *reaps* the
//! child (bl-3016): detachment never made yog stop being the parent, so
//! somebody has to take the status the kernel is holding.
//! - [`Streamed`] consumes a [`Cli::run`] child non-blocking and line-buffered,
//! live (§8's streamed-piped class: `bz --login`, [`crate::login`]).
//!
//! The crate's `unsafe` is confined to [`sys`] — the SIGTERM above, and the
//! process-env fold an in-process substrate arm stands in ([`sys::set_env`],
//! §16.2). Which binary a
//! [`Cli`] execs — and under what leading argv — is [`resolve`]'s concern: a
//! host PATH name / `*_BINARY` override, or (§16.7 W12) yog's own executable
//! under a namespace prefix — which file that is being [`self_exe`]'s, read
//! once per process so a replaced inode cannot rewrite it. A [`Cli`] carries the *physical* `program` +
//! `prefix` it execs and derives the *logical* [`binary`](Cli::binary) name
//! from them, so the ops-log argv (§8.2) is invariant across that switch. Pure
//! Rust — no egui — so a future `litany-ui-web` crate reuses it unchanged; the
//! caller supplies argv.
use ;
/// The values a running child hands back — [`Chunk`], [`ExitInfo`], [`CliError`]
/// — and the reader-thread pump behind them.
pub use ;
/// The streamed spawn (§8): [`Cli::run`]/[`run_in`](Cli::run_in)/
/// [`run_env`](Cli::run_env) and the one body behind them.
/// Binary resolution — the host/self-multiplex switch (§16.7 W12) + [`Binary`].
pub
pub use Binary;
/// Which file yog itself is, read once per process (bl-f558) — the one home of
/// that fact, which a live engine keeps across a replacement of its own inode.
pub
pub use self_exe;
pub use ;
pub use ;
/// The `yog exec` world escape hatch spawn (§8.4): [`Cli::exec_in_world`].
/// The stdin-piped spawn (REMOTE §5, bl-024b): [`Cli::run_input`], the shape a
/// tool host's own child is run under.
/// The fire-and-forget detached spawn (§8.1): [`Cli::spawn_detached`] and its
/// per-spawn stderr sink. Split out to hold [`self`] under the 300-line cap.
/// The confinement wrapper seam (§8.6): [`Cli::and_wrapper`] and the
/// wrapper-aware spawn base every shape starts from.
/// The crate's confined `unsafe`: raw `SIGTERM` in [`Stream`]'s drop, and the
/// process-env fold the nested world stands on ([`crate::world::inhabit`]).
pub