1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
//! **Project instructions freeze at the binding** (DESIGN §3.7, from bl-e249's
//! Claude Code comparison): the deterministic walk that finds a project's
//! instruction files and the `--pin` specs that freeze them into the agent's
//! dispatch commit before the first inference.
//!
//! The input is the §3.3 typed work target and nothing else — no rung table:
//! the ball rung's claim-derived `work/<id>` worktree, the path rung's
//! directory, and for the bare rung (and a not-yet-created ball) no binding at
//! all, which discovers nothing. The general path with empty inputs.
//!
//! **yog reads no instruction bytes.** It stats candidates and names paths;
//! litany's caller-supplied pinned documents (ARCH §2.5, released 0.0.4 as
//! bl-fb5c, in the `=0.0.8` pin) load, validate, write and commit them — in the
//! CLI layer, before any branch, ref or inference exists. There is no yog-side
//! copy of anything, which is the whole "no opaque automatic memory" clause.
//!
//! The two halves that make the freeze *visible* live beside this walk:
//! [`names`] is the severable filename policy, [`manifest`] the glob that makes
//! a frozen document actually compose into assembled context (§3.7 item 4 —
//! pinning is not composing).
use ;
/// The largest instruction document that rides. A bigger one is **skipped
/// whole, never truncated**: half a rule reads exactly like a whole rule, so a
/// truncated instruction is worse than a missing one (§3.7 item 1).
const MAX_BYTES: u64 = 128 * 1024;
/// The most documents one freeze carries — the bound on a chain of deeply
/// nested directories each declaring its own, and what keeps the rank two
/// digits wide.
const MAX_DOCS: usize = 16;
/// The pin destination's first segment. None of litany's reserved harness names
/// (`goal.md`, `soul.md`, `name`, the control files, `descriptions/`,
/// `messages/`, `summary/`), so the pin is accepted.
const DEST_ROOT: &str = "instructions";
/// What marks a git checkout root: a directory in an ordinary clone, a **file**
/// in a `work/<id>` worktree (the gitdir pointer). Either is the authority root.
const GIT_MARK: &str = ".git";
/// `--pin`'s own separator, split at the *first* occurrence — so a destination
/// may not contain one (a source may).
const SEP: char = '=';
/// The `--pin <dest>=<src>` arguments for every instruction document the
/// `binding`'s project declares, in precedence order — outermost directory
/// first, `names`' declared order within each.
///
/// This is the module's whole interface: the fire appends these to its one
/// argv (§3.3's "built once and spawned *and* logged from it"), so what the
/// agent froze and what `ops.jsonl` records can never disagree.
/// One document to freeze: where it lands on the dispatch commit, and the file
/// it is read from.
/// The §3.7 walk: authority root → binding, each configured name at each level,
/// ranked in discovery order.
/// The nearest ancestor of `binding` — itself included — holding a [`GIT_MARK`],
/// else `binding`. **The walk never ascends above it**, which is the whole
/// answer to untrusted parent instructions (§3.7 item 1): a `$HOME/AGENTS.md`
/// is not skipped by a check, it is unreachable by construction.
/// `root` → `binding` inclusive, outermost first — the precedence order, so the
/// most specific instructions arrive last. `root` is an ancestor-or-self of
/// `binding` by construction ([`authority_root`] only ascends), so the ascent
/// always terminates on it.
/// `src`'s authority-root-relative path when it may be frozen, else `None`:
/// a **regular file** by `symlink_metadata` (a symlink is skipped — the freeze
/// is byte-exact and a link can point out of the root), within [`MAX_BYTES`],
/// and spellable as a destination (UTF-8, and no [`SEP`], which `--pin` splits
/// on). A candidate that only fails the *read* later is litany's loud pre-fork
/// refusal, not a silent partial (§3.7 item 2).