1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
//! **The client registry** (REMOTE §1.5, §2, §4, §7; bl-8bbc): the durable
//! server-side fact that client C participates in workspace W, and the
//! per-client home everything else about C hangs off.
//!
//! **A registration is a file, and its existence IS the fact.** REMOTE §2:
//! *"Server-side, in the world, a file — the file religion applies; the wire
//! only ever transports the gesture that writes it."* So there is no registry
//! document to parse, no list to keep in step and no last-writer-wins window:
//!
//! ```text
//! <yog-state-root>/clients/<client>/pane.json the §7 pane-of-glass facts
//! <yog-state-root>/clients/<client>/tools.json the §5 advertised set (bl-4e08)
//! <yog-state-root>/clients/<client>/workspaces/<name> one empty file per registration
//! ```
//!
//! Registering is creating the file, **revocation is deleting it** (§4), and
//! the registered set is the directory listing. Nothing is stored that could be
//! computed: the client is the directory name, the workspace is the file name.
//! It sits at yog's own state root beside `ui.json` because it is yog's durable
//! state, not the operator's key material — the `wire/` directory holds what
//! yog can never mint (§8), and this holds what only yog ever writes.
//!
//! **First registration is an operator-written file** (§4). `mkdir -p
//! <state-root>/clients/<name>/workspaces && touch …/<workspace>` is the whole
//! bootstrap, and it is the same act that provisions the certificates —
//! out-of-channel, by ruling (§1.4). There is no first-client flow, because the
//! general path with an operator-seeded input is not a case of its own.
//!
//! **`local` is the reserved identity of every in-world caller** — the window,
//! the `gestures/` deposit inbox, `yog gesture`. They carry no certificate and
//! are not scoped (§3: each intake the religion of its domain), but they do own
//! a pane document, so they need a name for it. [`Client::parse`] refuses
//! `local` exactly as it refuses `.` and `..`: all three are names the layout
//! has already spent, which is one rule rather than three special cases.
use BTreeSet;
use io;
use ;
/// The certificate leaf name → client identity fold (REMOTE §2).
/// Which clients hold a live connection right now (REMOTE §5) — RAM, never a
/// file, because presence changes with every network blip.
/// The workspace's registered clients joined with their presence and their
/// advertised sets (REMOTE §5) — the one derivation both seats render.
/// What a tool host advertises, and the document it lands in (REMOTE §5).
/// The reserved identity of the window and every other in-world caller.
pub const LOCAL: &str = "local";
/// The registry root's leaf under yog's state root.
pub const CLIENTS: &str = "clients";
/// One client's §7 pane-of-glass document.
pub const PANE: &str = "pane.json";
/// The directory whose entries are one client's registrations.
pub const WORKSPACES: &str = "workspaces";
/// One client identity (REMOTE §2): a certificate leaf name, or [`LOCAL`].
///
/// It is a **path component by construction** — every reachable constructor
/// validates — because the identity names a directory, and a name that could
/// contain a separator would let a certificate address the filesystem.
;
/// **The default caller is the in-world one.** Every intake that carries no
/// certificate is `local` (§3), so the default is the identity rather than an
/// empty string nothing could resolve — a gesture always has a caller.
/// This client's directory: `<state-root>/clients/<client>`.
/// This client's §7 pane-of-glass document — server-held, so any two seats of
/// one client converge on the same panel sizes and view knobs.
/// This client's registration directory — one file per workspace it
/// participates in.
/// The workspace names `client` is registered in (§4). A client with no
/// directory, an unreadable one, or one holding nothing reads as the empty set
/// — the general path with no input, and the posture a fresh server has for
/// every certificate the operator has not yet seated.
/// Record that `client` participates in `workspace` (§4) — the auto-registering
/// half of a create, and the gesture an operator performs with `touch`.
/// Idempotent: an existing registration is rewritten to the same empty file.
///
/// The file is empty on purpose. A registration has no content — it is the
/// **pair**, and the pair is the path.
/// The engine-side invocation hand-off (REMOTE §5, bl-024b) — a queue per
/// client and a slot per invocation, RAM beside [`presence`] for its reason.
///
/// **Declared last, and out of order on purpose.** Every other `mod` sits at
/// the top, and adding a fifth there shifted every byte below it — which cost
/// this file its 100 % coverage floor, llvm-cov attributing a phantom
/// uncovered region to `impl Client {`. That is the hazard
/// `rules/locks-outside-state.yml` records twice over, met here by the remedy
/// `state.rs` already uses: append below every line that was here before.
/// **The local window's own client identity** (REMOTE §1.2, §4.1; bl-ae05):
/// `yog-window`, the subject common name yog's own mint puts on the window leaf
/// ([`Role::Window`](crate::wire::material::Role::Window)) — and therefore the
/// name the engine reads off the certificate the window presents, the directory
/// its §7 pane document lives in, and the name a registration seats. One
/// spelling, here, because an identity's home is the registry.
///
/// **The module doc and [`LOCAL`]'s own doc still say `local` is the
/// window's**, and they are deliberately not edited — the reason [`mailbox`] is
/// declared at the bottom of this file. Editing a byte above shifts every byte
/// below it, and llvm-cov then mis-attributes a phantom *uncovered* region onto
/// `impl Default for Client`, costing this file its 100 % floor (measured
/// twice). **REMOTE §4.1 is the authority and it is narrower than those lines
/// read: `local` is the certificate-less in-world callers — the `gestures/`
/// deposit inbox and `yog gesture` — and the window is not among them.**
pub const WINDOW: &str = "yog-window";
/// The window's identity as a [`Client`] — total, unlike [`Client::parse`],
/// because the name is yog's own const rather than a token read off a
/// certificate. A free function rather than a second `impl Client` block, for
/// the reason above: an added `impl` draws a phantom region onto itself
/// besides, which is the same hazard `state.rs` meets the same way.
/// **What a certificate authorizes** (REMOTE §4.2, bl-1dd3) — the grade its
/// subject carries, and the [`Peer`] an intake answers as.
///
/// Declared at the bottom beside [`mailbox`] and for its reason exactly:
/// adding a `mod` at the top of this file shifts every byte below it, and
/// llvm-cov then draws a phantom uncovered region onto `impl Client`.
pub use ;