1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
//! The capability boundary's one executor (VISION §4.11, DESIGN §8.6):
//! **answering a parked invocation**.
//!
//! The control itself writes nothing — it is re-consulted on every drive, so a
//! consult with a side effect would answer differently the second time. The
//! writer is here, and it writes exactly one `ops.jsonl` row:
//!
//! ```text
//! ["yog-control","answer",<tool_use id>,"pass"|"hold"|"refuse"]
//! ```
//!
//! which is at once the audit and the fold's memory ([`crate::control::judge`]
//! reads it back). No fourth durable artifact; the §4.9 monitor's own pattern.
//!
//! **Three moves, in this order, and each one earns its place.**
//!
//! 1. *Read the mark, live.* The held `tool_use` id is never typed and never
//! carried from a snapshot: it is read off `refs/litany/held/<agent>` at
//! fire time, so the answer names what is parked now. Nothing parked is a
//! refusal — a gesture is an instruction, and an answer aimed at nothing
//! must say so rather than report a silent success.
//! 2. *Write the row.* Durable before anything is launched, so a driver that
//! re-consults a microsecond later already sees the answer. The reverse
//! order would race the very thing it is trying to release.
//! 3. *Advance, detached* — but only when the answer **releases**. `pass` and
//! `refuse` both move the branch (one executes, one declines in band); a
//! `hold` answer is the operator saying *stay parked*, and launching a
//! driver to re-park would spend a process to reach the state it is already
//! in. The launch is detached for the reason every driver launch is: an
//! `advance` runs the conversation until it goes quiet, and no gesture may
//! block a frame or a consumer thread on that.
//!
//! **No enforcement path calls stop.** `litany stop` mid-tool-window wedges the
//! branch permanently (litany bl-b98d), so declining is in-band and parking is
//! a park — never a kill.
use Path;
use cratehold;
use crateRuling;
use crate;
use Deps;
use Reply;
/// The family's other writer — the §4.9 fifth rung's per-conversation floor
/// (bl-94b4). Its own file on a real seam: this one answers **one invocation**
/// off a live mark and drives the branch on; that one writes **standing
/// policy** for a whole descent and launches nothing.
pub use set_floor;
/// The ops-row verb naming a once-answer. Mirrored from the fold that reads it
/// ([`crate::control::judge`]); the two words are held equal by a test rather
/// than by a shared const, because the reader deliberately owns its grammar.
const ANSWER: &str = "answer";
// litany's re-drive verb — `litany advance <ws> <agent>` (its ARCH §6): one
// hop of the workflow chain, which re-enters the tool window under the mark
// and re-consults the control. That re-consult *is* the release. The token is
// `opslog::launch`'s since bl-b95e — the launch writes it into `ops.jsonl` and
// the §8.1 verdict reads it back out, so the join has one home.
use ADVANCE;
/// Answer the invocation parked at `(workspace, agent)`.
pub
/// Fire `litany advance <ws> <agent>` detached, logging the launch exactly as
/// the §8.1 fire logs its own: [`DETACHED_EXIT`] for a handoff that happened, a
/// §4.2 synthetic-failure line for a fork that never landed. The row is the
/// receipt — the answer's own reply says only whether the launch was made.
///
/// **Two callers, one body** (bl-9bef): the release above, and the §8.2 nudge —
/// the operator's own "run it again from here", which is this launch and
/// nothing else, since litany derives what is due from the transcript tail
/// (ARCH §6). Shared rather than re-written, so a driver launch has one home.
///
/// **The spawn is workspace-bound** ([`Deps::bound`], bl-bf79): what this
/// launches is a *driver*, which makes model calls, so it owes its workspace
/// the §16.2 wall — without it the driver's first `bz` dies with `no workspace
/// in this environment` and the turn produces an empty reply. That is the same
/// fold every §8.2 litany verb takes, and it was missing here.
pub
/// The §4.11 item-8 **confinement gate**: a workspace whose live policy
/// declares `confinement: required` fires a drone only where the platform's
/// one backend proves itself at this very birth — the derivation, the probe
/// and the refusal all live in [`crate::control::confine`]; this is the doors'
/// name for them. On Linux the backend is bubblewrap and a passing probe means
/// the fired spawn runs wrapped (the doors fold the wrapper on); everywhere
/// else, and wherever the probe fails, the standing refusal names exactly why.
/// Never a silent fallback, and no UI affordance for an absent layer — the
/// only surface it earns is the refusal.
///
/// Severable in both directions: absent, the gate is a no-op with nothing
/// configured; present, removing the line removes the policy, not the code.
pub