1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
//! The effectful half of the start flow (DESIGN §3.3, §8.1, §15 M6 Z3): the
//! piped `bl`/`litany` executors and the shapes the
//! [`prepare`](super::prepare) orchestrator threads through them. The claim and
//! its worktree cross-check are [`claim`], split off at §12's pre-split band:
//! every other verb here is done when it exits zero, and that one is the step
//! whose *answer* still has to be checked against the bl-delivery formula. The detached fire — and the §3.3 conversation mint it
//! stamps with — is [`prompt`](super::prompt); everything here is piped, gated
//! and re-runnable.
//!
//! Every non-spawn abort leaves a `["yog-step",<name>]` ops row before it returns
//! (§4.2, Z5's [`log_step_failure`]): the conversation mint's pool exhaustion
//! ([`on_mint`], applied at the fire), the workspace `mkdir`
//! ([`execute_ensure_workspace`]),
//! and the claim cross-check [`Drift`](StartError::Drift) — so no error class is
//! invisible to the §7.3 failed-action surface (the eprintln purge left none
//! behind).
use crate;
use crateCli;
use crateOrigin;
use crateseed;
use MintError;
use io;
use ;
const CREATE: &str = "create";
const AS: &str = "--as";
const BODY: &str = "--body";
pub const NEW: &str = "new";
/// The workspace marker (§3.1); a workspace is a dir directly holding it.
pub const REPO_MARK: &str = "repo.git";
/// The `["yog-step",<name>]` step names for the non-spawn aborts (§4.2).
const MINT: &str = "mint";
pub const MKDIR: &str = "mkdir";
/// The rename that turns a finished birth into the workspace (bl-1af5) — the
/// one act between litany's last write and the name being addressable, and the
/// one non-spawn abort the create can still hit.
pub const BIRTH: &str = "birth";
/// The §8.6 authoring of the capability control onto `config/default`.
pub const CONTROL: &str = "control";
pub use crateDETACHED_EXIT;
/// The ball rung's claim and the worktree cross-check that follows it (§3.3,
/// §5.1 #5) — the one step whose success still has to be *checked* rather than
/// merely exited-zero.
pub use ;
/// The injected binaries + the ops-log target (§14). Owned — [`prepare`] borrows
/// each field as it threads them into the per-step executors.
/// The composer's fire-time parameters (§8.1): the resolved workspace `name` (for
/// `YOG_NAME` alone — it never enters the goal text, §3.3), the `workspace` it
/// was prepared in, the per-rung binding, and the editable `goal` prefill (the
/// conversation's identity line is minted and stamped at fire, not carried here).
///
/// **A prepare reply is also the next gesture** (§8.1), so it obeys the wire's
/// own rule (REMOTE §8, bl-f5f6): `workspace` is the **name**, re-resolved when
/// the deferred [`Prompt`](crate::boundary::Action::Prompt) lands. `binding` is
/// the one path left, and it is not an identity — it is litany's `--cwd`, a
/// filesystem fact the engine minted and the engine consumes, carried back
/// verbatim by a seat that never reads it.
///
/// It carried a separate `name` — the §3.2 `--as`/`YOG_NAME` stamp — until
/// bl-f5f6. §3.1 makes a workspace's name its directory leaf and §3.2 makes
/// that same leaf the claim identity, so once `workspace` became the name the
/// two fields were one string twice, and the second went.
/// A start-flow failure. Every variant is already a durable ops row before it
/// rides back (a ran-non-zero verb's [`Outcome`], a synthetic step-failure line
/// for the mint / mkdir / [`Drift`](StartError::Drift)).
/// Map a mint result to a name or a **logged abort** (§8.1): an exhausted pool
/// leaves a `["yog-step","mint"]` row (Z5) before it returns, so neither mint's
/// one non-spawn failure — the §3.1 workspace name here, the §3.3 conversation
/// name at fire — is ever a dropped error.
/// `bl create <title> --as <name> [--body B]` in the project (§8.2). Returns the
/// minted id (bl prints it on stdout). An empty body is elided.
/// Return `out` iff the verb exited 0, else a [`StartError::VerbFailed`] carrying
/// its already-logged [`Outcome`] (§8.2) — **unless the capture is git saying it
/// can name nobody**, which is one named prerequisite and not a capture at all
/// (bl-c28c, [`crate::git_ident`]).
///
/// Here rather than at the one verb that reproduced it: every spawned verb in
/// this file ends in a commit somebody else writes — `litany new` authors the
/// workspace's first, `litany config` advances a lineage, `bl create`/`claim`
/// seal a ball — so a box with no identity fails all of them with the same
/// twelve lines and the same remedy. One classification at the one place a
/// capture becomes a refusal.
pub