1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
//! **The frame's half of the act path** (REMOTE §1.2, §9.8; bl-4841): what the
//! window has sent over the wire, and what came back for it.
//!
//! The read half ([`link`](super::link)) keys a standing question by its own
//! encoded envelope, because asking twice is asking once. **An act cannot be
//! keyed that way.** A gesture is not idempotent — two clicks of Nudge are two
//! nudges, and a resend is never free — so the envelope is not a handle, and
//! nothing about the act's own bytes can be. Something has to *mint* one:
//! [`Ticket`], a number from a counter the frame owns, minted at the send and
//! spent at the receipt. It is what survives the repaints in between, because
//! the surface that fired holds it in its own RAM while the frame it was
//! clicked in is long gone.
//!
//! **Every ticket earns exactly one receipt, so there is no "never came".** The
//! poster is the only thing that can answer, and it answers on every path it
//! has: the engine's reply, the engine's refusal, a decode it could not read, a
//! socket it could not open. A send that cannot even reach the poster — a window
//! whose engine minted no material, so nothing is behind this end of the channel
//! — is answered *in the send*, with the same one `Err` a refusal is. No
//! timeout, no clock and no expiry sweep: the one bound that exists is
//! [`Seat`](super::client::Seat)'s own read timeout, which turns an engine that
//! has stopped answering into a sentence.
//!
//! **The receipts a nobody holds are dropped.** A landed receipt waits to be
//! read, and the map is bounded at [`RECEIPTS_KEPT`] by dropping the oldest
//! ticket: a receipt still unread after that many later gestures has no holder,
//! and a bound is what makes that a fact rather than a hope.
use Landed;
use Value;
use BTreeMap;
use ;
/// How many landed-but-unread receipts are kept. A receipt is normally taken
/// the frame after it lands; this is the ceiling on the ones nobody ever asks
/// for, so the map is bounded by construction rather than by every caller
/// remembering to collect.
pub const RECEIPTS_KEPT: usize = 64;
/// What a window with nothing behind it says. The same one `Err` a refusal is
/// (REMOTE §9.8): a frame cannot paint the act's answer, and here is why.
/// `pub(crate)` since bl-dc14: the wireless window's whole-frame refusal
/// (`shell::refusal`) heads itself with the same sentence every act receipt
/// carries — one sentence, one home.
pub const NO_WIRE: &str = "this window has no wire behind it";
/// **An act's receipt identity** — minted at the send, spent at the read.
///
/// Opaque and mintable only by [`Post::send`], which is what makes "one act,
/// one receipt" structural: nothing else can name a ticket it did not earn.
;
/// The window's end: what it has sent and what has landed for it.
/// The poster's end: the acts to send, and where their receipts go.
/// A fresh pair, minted together for [`link::pair`](super::link::pair)'s reason
/// exactly: neither end is useful alone, so neither can be attached later.
/// **A post nobody sends.** The model holds one from the moment it boots and
/// the engine hands it a live one when there is a wire to send over — so firing
/// a gesture is the same call whether or not this box got a listener up, and
/// what a surface paints is the sentence rather than a branch.