1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
//! brazen `config.toml` editor — a pure view-model (DESIGN §9.1, §5.1
//! rows 19–23).
//!
//! The editor is **raw TOML text**, never form fields: brazen's schema is
//! versionless and full of open valves, so `bz` is the only lawful parser
//! (§9.1). yog therefore adds no TOML dependency — it edits bytes and lets
//! `bz` validate them. Since §16.7 W10 that `bz` is *linked*, so "the only
//! lawful parser" is enforced by the linker rather than by a version gate: the
//! validator and the loops' adapter are one exact-pinned implementation.
//!
//! The file edited is the **focused workspace's own** — since the
//! blast-radius ruling (§16.2) brazen's config lives inside that workspace's
//! wall ([`crate::world::wall`]), so switching workspace switches providers,
//! sign-ins and model cache together. An unfocused surface has no wall and so
//! no paths ([`BrazenPaths::of`] answers `None`); it renders a guard rather
//! than falling back to the machine's own brazen state.
//!
//! The view-model is pure over two injected effects, exactly the
//! [`LockProbe`](crate::git_tree) shape: a [`BzRunner`] (the sole `bz`
//! command surface — validate / effective-dump / provider table / list-models)
//! and the shared [`FileIo`](super::FileIo) seam. A fake pair drives every
//! state transition under Linux tarpaulin; the real [`RealBzRunner`] is a thin
//! shell over [`crate::bz_host`] plus one recorder-covered spawn.
//!
//! The three on-disk locations themselves — and the read that needs nothing but
//! them ([`model_cache_at`]) — are [`paths`], split off at §12's pre-split band:
//! a layout is not an editor, and that read was already documented as free of
//! one.
//!
//! Apply is the shared [`pipeline`](super::pipeline) (stage → hash-guard →
//! atomic rename) with brazen's one addition, the `bz` validator gate:
//! ```text
//! draft ──stage──▶ .config.toml.yog-tmp-<pid> (temp in the dest dir)
//! ──gate──▶ bz --config <temp> --dump-config
//! non-zero exit ─▶ Rejected{stderr} (draft kept, temp discarded)
//! ──commit──▶ hash-guard + atomic rename
//! snapshot moved ─▶ Conflict (offer reload, temp removed)
//! else ─▶ Ok (loaded snapshot updated)
//! any fs error at any step ─▶ Io{error}
//! ```
//! `BRAZEN_CONFIG` is never leaked into the child env: the gate passes
//! `--config <temp>` explicitly, which overrides `bz`'s default search path
//! (`bz --help`: "--config <file> … else the default search path").
use ;
use Path;
pub use RealBzRunner;
/// The wall's brazen layout and the read that needs only it (§5.1 #19/#23) —
/// free of the editor, because every caller asks without one.
pub use ;
pub use ;
/// The captured result of one `bz` invocation. `success` is exit code 0.
/// yog's entire `bz` command surface. Injected so the view-model is driven
/// by a fake in tests; [`RealBzRunner`] answers the three read verbs through
/// the **linked** brazen (§16.7 W10, [`crate::bz_host`]) and keeps a spawn only
/// for the one verb that goes to the network.
/// The terminal state of an Apply (§9.1).
/// The static hint that provider rows are compiled into `bz` and never appear
/// in the file or the dump (§5.1 row 21). Rendered beside the §9.1 editor.
/// Deliberately count-free: the number is brazen's, and pinning it here would
/// be a second representation of a fact the crate already owns — the login
/// surface's [`BzRunner::providers`] listing is where they are actually named.
///
/// It used to end *"(the Login provider list shows them)"*. Since bl-20cb the
/// §9.1 pane states outright that the Login tab is where the rows are named, so
/// the parenthetical was that same routing said twice on one surface
/// (QUALITY H1) — this line is now only the fact the *file* is short of.
pub const BUILT_IN_ROWS_HINT: &str =
"built-in provider rows are compiled into bz and are not shown in this file";
/// The brazen config editor view-model. Holds only the RAM carve-out (the
/// unsent draft, §5.3) and the loaded-content hash for the concurrent-edit
/// guard; every other datum is derived through an injected effect on demand.