1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
//! The `models:` half of the §9.4 block grammar — **yog's own table, in
//! lernie's file** (bl-d9cb): the `models.yaml` block the §9.2 Declare control
//! authors and the §9.5 typed rows edit, plus the readers over it.
//!
//! **It used to be lernie's, and the picker used to write it.** The whole
//! justification was a cross-check — a role naming a model `models.yaml` did
//! not declare was a hard load error, so a pick wrote this half FIRST and the
//! assignment second. That check is gone at the pin: lernie's own
//! `config/cross/mod.rs` says *"There is no roles-against-models check any more
//! (bl-35e2): the global `models.yaml` carries no `models:` table, a role's
//! `providers.yaml` assignment is the single home of its (provider row, model
//! id) pointer"*, and its `config/models.rs` deserializes the file to one
//! optional `adapter:` field, documenting that *"A leftover `models:` block in
//! an operator's file is ignored on parse"*. So the picker writes ONE file now
//! (§9.4) and this block survives for the one fact still read out of it:
//! `context_window`, the §5.1 #35 fullness denominator ([`context_windows`]).
//!
//! **And since bl-3ffa the entry yog WRITES is only that fact: write less, read
//! the same.** bl-d9cb left the four-field entry standing and named the loose
//! end — two of the fields had no consumer anywhere, and one of them still had a
//! gate over it. `provider:` was read by a `declared` → `unknown_rows` chain
//! whose only consumer was the §9.2 Apply gate, so the gate refused a draft on
//! the strength of a field whose one reader was the refusal; `capabilities:` had
//! no reader in either program. Both are gone from the write and from the §9.5
//! controls, and the §9.2 gate went with them — the row judgement it made is
//! made where the pointer actually lives, on `roles.<r>.provider`, by
//! [`is_unknown_row`]'s three surviving sites.
//!
//! **The READS are unchanged, and deliberately tolerant.** This is anchored line
//! reads, not a parser, so an operator's existing entry keeps parsing with every
//! field it carries and [`context_windows`] still keys on `model_id` wherever one
//! is written. Writing fewer lines never stopped the reader accepting the old
//! shape — which is why nothing migrates.
//!
//! The reader is the same anchored grammar as [`roles`](super::roles), applied
//! to the other file.
use ;
/// The context window a hand-declared entry starts at (§9.2's Declare control).
/// Deliberately conservative, because under-stating a window degrades to early
/// compaction where over-stating it overflows the request.
///
/// **It is a declared default, and since bl-d9cb it is the only kind there is.**
/// Its one reader is §5.1 #35's fullness figure ([`context_windows`]), so a
/// wrong number shows up as a wrong percentage — which is why bl-848f had the
/// picker seed the entry from `Model.context_window` wherever brazen's roster
/// carried one, so a fabricated 200 000 could not sit beside a served number
/// looking identical. That seed is gone with the picker's write: the one seat
/// left that authors an entry is a hand-typed id with no roster behind it, so
/// every generated number is a declared default under a comment that says so,
/// and the indistinguishability bl-848f found cannot arise. Reading brazen's
/// served window is a *query*, not a field to seed (see [`context_windows`]).
pub const DEFAULT_CONTEXT_WINDOW: u32 = 200_000;
/// The comment yog writes above a generated entry, so its one fabricated field
/// is never mistaken for a fact anybody published, and so the operator reading
/// the file knows what the number is *for* (bl-d9cb — naming the one consumer is
/// what makes editing it an obvious move rather than a mystery).
const DECLARED_NOTE: &str = " # added by yog's Declare control in the models.yaml editor.\n \
# nothing published this line: it is a declared default, and the\n \
# denominator of yog's context-fullness figure. Edit it here.";
/// The `models.yaml` entry for a hand-declared model, at two-space indent —
/// **the id and the one fact anything reads out of it** (bl-3ffa). The entry key
/// is the wire id, which is what [`context_windows`] falls back to, so an entry
/// yog writes needs no `model_id:` line either: two spellings of one id is the
/// drift a fallback exists to avoid.
/// Declare `model` under the global `models:` block. `Ok(None)` means nothing to
/// write — the id is already declared, and the operator's own entry (whatever
/// fields it carries) stands untouched.
///
/// The entry is inserted **directly after the `models:` line**, not at EOF, so
/// a file that carries a later top-level key (`adapter:` — the one field lernie
/// still reads out of this file) stays valid. A file with no `models:` key at
/// all gets one appended; an inline `models: {}` is refused rather than
/// transformed.
///
/// **It takes no provider row since bl-3ffa**, so bl-bd89's re-point arm is gone
/// with the field it moved: an id declared "on another row" is no longer a
/// distinction this table can draw, because the table no longer names a row.
/// Declaring an id that exists is simply nothing to write.
///
/// **Its one caller is the §9.2 Declare control** since bl-d9cb. The §9.4
/// picker used to call it first and `set_role_model` second; lernie reads no
/// `models:` table any more, so the pick is one write and this is a hand
/// gesture over yog's own table.
/// Every declared model's **wire id** paired with the `context_window` its
/// entry declares (§9.2's own field, §5.1 #35) — the denominator of the
/// context-fullness figure, and the one home for it.
///
/// Keyed on `model_id`, falling back to the entry key when the entry declares
/// none, because the id a step's `request.json` names is the wire id lernie
/// sent — not the alias the entry is filed under. An entry with no
/// `context_window:` line, an unparseable one, or a zero is **absent from the
/// map**: a window nobody declared is unknown, and a percentage against a
/// fabricated denominator is exactly the capability theater the figure exists
/// to avoid (brazen's Usage zero-vs-unknown principle, applied one field over).
///
/// **This is the fact's one home, and since bl-d9cb it is the ONLY reader of
/// the `models:` block that reads a number.** lernie reads no `models:` table at
/// all (see this module's header), so the block is yog's own hand-configuration:
/// authored by the §9.2 Declare control, edited by the §9.5 form, read here.
/// One home, one number, operator-correctable.
///
/// **brazen's served window is not a second home, and must not become a
/// seeded field.** brazen carries `Model.context_window` on `--list-models` for
/// the providers that serve one (Google) and `None` for the ones that do not
/// (Anthropic, OpenAI, Ollama) — its own empty-set rule: *"a harness
/// hand-configures only what no provider serves"*. That number is the
/// provider's fact and it changes without yog's involvement, so copying it into
/// a file at pick time is a snapshot that goes stale — the same reasoning §9.4
/// already applies to the model roster (*"a stored candidate list would be a
/// second representation of a fact the provider owns"*). If the figure should
/// ever prefer a served window over a declared one, the shape is a **query** at
/// read time over the model cache
/// ([`model_cache_at`](crate::config_edit::brazen::model_cache_at), already on
/// disk inside the workspace's wall), not a field this file carries.
/// **The** provider-row judgement: does `provider` name no row in brazen's
/// effective table? Every site that asks it asks it here — the §9.4 pick gate
/// ([`plan`](crate::model_pick::plan)), the §9.4 role marks
/// ([`role_fault`](crate::model_pick::role_fault)), and the §9.5 pane's provider
/// control over `providers.yaml` ([`crate::config_edit::form`]) — so the three
/// can never disagree. Each judges the LIVE pointer, `roles.<r>.provider`, which
/// is the whole of a role's binding (bl-35e2), against the wall of the workspace
/// that holds it. Two sites are gone and both for the same reason, a judgement
/// made where the answer was not: the birth gate (bl-c3a9, retired bl-00ee)
/// asked before a wall existed, and the §9.2 Apply gate (bl-53be, retired
/// bl-3ffa) asked about `models.<id>.provider`, a field nothing dispatches
/// through.
///
/// `providers` is `bz --list-providers`' answer (built-ins included, which a
/// scan of `config.toml` would miss). An **empty** table is no answer rather
/// than an empty one — brazen could not be asked — so it judges nothing: no
/// surface may refuse on the strength of a question that went unanswered.