1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
//! `yog seat <gesture>` — **the wire's first shipped seat** (REMOTE §2, §8;
//! bl-b6fa): the same gesture surface `yog gesture` types, sent over the mTLS
//! channel instead of deposited into the world's inbox.
//!
//! **Two intakes, one boundary** (REMOTE §3). `yog gesture` is the *world's own
//! resident's* door — same machine, same disk, disk is the bus — and it stays.
//! This is the door for a caller across a trust domain, which is every caller
//! that holds a certificate and no world. The argv, the flags, the `--help`
//! rewrite and the refusals are literally the same reader
//! ([`argv::read_gesture`](crate::boundary::sugar::argv::read_gesture)), so the
//! two seats cannot drift; only the transport below them differs.
//!
//! It is a *seat*, not a verb: REMOTE §3's ban is on a capability that exists
//! on the wire and nowhere else, and this adds none — a gesture typed here is
//! the same envelope, answered by the same `dispatch`/`answer`. A TUI or a
//! phone is the next consumer of exactly this transport and needs nothing new
//! from the engine (REMOTE §8).
//!
//! **Which engine it reaches is the gesture's own workspace name** (REMOTE
//! §8.2). A name one of this box's [`entries`](super::entries) holds goes down
//! that entry's channel, on that entry's material, carrying the name that
//! workspace bears on its host; everything else — a name no entry holds, and a
//! gesture naming no workspace — goes to the flat directory's client material,
//! exactly as it always did. See [`channel`].
//!
//! stdout carries one product: the reply stream, one envelope per line (today
//! always one — see [`frame`](super::frame)). Exit: `0` the last reply is ok,
//! `1` it is not or the channel failed, `2` bad usage or no wire provisioned.
use Seat;
use ;
use ;
use crateargv;
use crate;
use crateEnv;
use Value;
/// This seat's own word, for the usage line its refusals carry.
const VERB: &str = "seat";
/// Bad usage, an undecodable gesture, or a machine with no wire.
pub const USAGE_EXIT: i32 = 2;
/// Run the seat verb: `args` is the multiplexed tail. See the module doc for
/// the exits.
/// **Which channel this gesture goes down, and what it carries there**
/// (REMOTE §8.2). The gesture's workspace name is resolved over the entries
/// this box holds *first*; a name no entry holds — and a gesture naming no
/// workspace — goes where it always went, the flat directory's client
/// material. The flat directory therefore stays what it has always been: the
/// box's own root, and the one client relationship the box holds without
/// naming it.
///
/// **This is the one place the leaf↔host-name mapping is spent** (§8.2). An
/// entry's leaf is the *client's* name for the workspace and its
/// [`WORKSPACE`](entries::WORKSPACE) file is the name that workspace answers to
/// on its host; when they differ the gesture is re-encoded carrying the host's
/// name, here, at the channel boundary — never earlier, because every seat
/// above this line reasons in the leaf, and never later, because below it is a
/// socket. When they agree the operator's own envelope crosses byte for byte,
/// as it always has.
///
/// A half-provisioned entry refuses with **its own** sentence (`entries`), and
/// that refusal is one entry's rather than the box's: nothing here reads
/// through to the flat root on a name an entry does hold, because an entry that
/// exists is the answer to that name.
/// This machine's own seat — the flat root's, which is what every caller with
/// no workspace to resolve wants. Shared with the tool-host client mode
/// (bl-024b), which is provisioned by the same out-of-channel act and refuses
/// in the same words.
pub
/// The flat directory's client material, or why this box has none. Absent
/// material is a refusal here rather than the silence it is at the engine: a
/// seat with nothing to present has nothing to do, and the remedy is the same
/// out-of-channel act (§1.4).
pub
/// Print the reply stream and exit on its last envelope's verdict. An empty
/// stream is an engine that terminated without answering — not ok.