1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
//! Test-only scaffolding for this binary: the fake effects and the fixture
//! world — and the suite's door onto the executable-file discipline
//! ([`fixture::write_exec`], a panic over [`crate::git_env::write_exec`]).
//!
//! There used to be a spawn lock here too, and the story of why it is gone is
//! the discipline. `fs::write` on a script holds a write fd; a `fork` in
//! another thread copies it into a child that keeps it until its own `exec`
//! completes; an `exec` of the script inside that window is ETXTBSY. bl-6397
//! answered from the fork side — one process-wide lock across
//! [`crate::git_env::spawn`], measured at zero against 8.3% unguarded — and
//! that held only while every fork in the process was yog's own. It was not:
//! the linked `balls`/`litany`/`brazen` fork `git` themselves and took no lock
//! of ours, so a beat driving one in-process reopened the window (bl-6bf5
//! measured 8 failures, bl-fd28 another 2).
//!
//! bl-fd28 moved the exposure instead of scheduling around it, and bl-e6c9
//! found the same hazard standing in the ENGINE — `world::tools::ensure_shim`
//! wrote a shim yog then exec'd — so the helper is production's now and this
//! module only spells it without a `Result`. Everything about the hazard, the
//! two measurements and the shapes that were rejected is stated once, in
//! [`crate::git_env::write_exec`]'s module doc.
//!
//! No lock is left in this module's own right: the `Mutex` below is a test
//! double's interior mutability, not serialization (`rules/locks-outside-state.yml`).
use crateFileIo;
use HashMap;
use ;
use Mutex;
/// In-memory [`FileIo`] for editor and pipeline tests: a flat path→bytes map.
/// `fail_write` forces the write step to error (the `Io` Apply arm). Shared by
/// the brazen, litany-global and pipeline test modules — one fake, one
/// behavior, so the write pipeline is exercised the same way everywhere.
pub
/// `providers.yaml` exactly as litany's own `template/providers.yaml` authors
/// it (the pinned engine) — what a materialized `litany new` commits,
/// worker tool pool included: yog grants nothing on top (§8.1, bl-7fc8).
pub const TEMPLATE_PROVIDERS: &str = "roles:\n worker:\n provider: anthropic\n \
model: claude-sonnet-5\n tools: [apply_patch, bash, cd, dispatch, load_skill, message, \
python, read_file, remember, search_history]\n compactor:\n provider: anthropic\n model: claude-haiku-4-5\n";
/// The `new)` arm of a fake `litany`: the workspace litany ARCH §2.2 describes,
/// authored in shell — a bare `repo.git` whose orphan `config/default` root
/// carries [`TEMPLATE_PROVIDERS`]. Every fake `litany` a start test drives
/// through shares this one arm.
pub
/// Re-prime the directory at `path`: **the same path, guaranteed a different
/// inode** (bl-e492).
///
/// The obvious spelling — remove it, create it again — is a coin toss. A
/// filesystem is free to hand the just-freed inode straight back, and the CI
/// runners do: the two watcher tests that assert "a replaced root leaves a deaf
/// watcher" were reproducing nothing there, because the inode they replaced was
/// the inode they started with (`left: Some(9211169) right: Some(9211169)`).
///
/// So the replacement is **allocated while the original is still linked** — two
/// live directories cannot share an inode, so the new one differs by
/// construction — and then renamed over the top. Nothing is left to the
/// allocator. It is also the truer reproduction: a re-primed clone is
/// materialized beside its target and moved into place, not built in the hole.
pub
/// The first half of [`replace_directory`], for the test that must observe the
/// hole between the two: the replacement directory, created beside `path` while
/// `path` is still linked — which is the whole of what makes its inode differ.
pub
/// The hermetic fixture world and the workspace wall it stands in — its own
/// file at §12's cap, on the seam between faking an *effect* and composing a
/// *world* (bl-fcd5).
pub
pub use ;
/// A real litany workspace on disk, for the tests that need one (§8.6's control
/// authoring and the start-flow abort it can raise). Its own file: the cap is a
/// tree-wide invariant, and this seeder is a self-contained fixture rather than
/// part of the spawn discipline above.
pub
/// The §9.5 wire's key material, minted at test runtime by the same
/// out-of-channel act an operator performs (REMOTE §1.4, bl-b6fa) — its own
/// file because a certificate fixture is never committed and the minting is a
/// self-contained seeder, not part of the spawn discipline above.
/// **The suite's own seat** — the client half of the wire, which the crate no
/// longer ships (bl-7942) and its own tests must still speak to prove the
/// listener.
pub
pub
pub
/// The §11 accessories that crossed with bl-296f — the altitude-0 chrome and
/// the selection's own detail — asked through the boundary, there being no
/// model accessor left to ask instead.
pub
/// The suite's spelling of [`crate::git_env::write_exec`] (bl-fd28, bl-e6c9),
/// plus the two narrow mode helpers for the "this file cannot be rewritten"
/// fixture — the one location `rules/no-hand-chmod.yml` still lets a mode bit
/// be set from.
pub
pub use write_exec;
/// The deterministic [`Clock`] every debounce and sweep branch is exercised
/// against — its own file at §12's cap, on the seam this file already had:
/// faking a *value* the crate reads, rather than the spawn discipline above.
pub
pub use FakeClock;