1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
//! The capability boundary's one executor (VISION §4.11, DESIGN §8.6):
//! **answering a parked invocation**.
//!
//! The control itself writes nothing — it is re-consulted on every drive, so a
//! consult with a side effect would answer differently the second time. The
//! writer is here, and it writes exactly one `ops.jsonl` row:
//!
//! ```text
//! ["yog-control","answer",<key>,"pass"|"hold"|"refuse",<scope>]
//! ```
//!
//! which is at once the audit and the fold's memory ([`crate::control::judge`]
//! reads it back). No fourth durable artifact; the §4.9 monitor's own pattern.
//!
//! **Three moves, in this order, and each one earns its place.**
//!
//! 1. *Read the mark, live.* The held `tool_use` id is never typed and never
//! carried from a snapshot: it is read off `refs/litany/held/<agent>` at
//! fire time, so the answer names what is parked now. Nothing parked is a
//! refusal — a gesture is an instruction, and an answer aimed at nothing
//! must say so rather than report a silent success. **An answer wider than
//! the call reads the mark for its CLASS too** (bl-94a5): the sentence yog
//! wrote into that mark says which class was parked
//! ([`crate::control::reason::class_of`]), and the class is half the key a
//! standing answer stands over. A mark whose class cannot be read takes
//! `--scope call` only — fail-closed, because a key nobody can compute is a
//! grant nobody can bound.
//! 2. *Write the row.* Durable before anything is launched, so a driver that
//! re-consults a microsecond later already sees the answer. The reverse
//! order would race the very thing it is trying to release.
//! 3. *Advance, detached* — but only when the answer **releases**. `pass` and
//! `refuse` both move the branch (one executes, one declines in band); a
//! `hold` answer is the operator saying *stay parked*, and launching a
//! driver to re-park would spend a process to reach the state it is already
//! in. The launch is detached for the reason every driver launch is: an
//! `advance` runs the conversation until it goes quiet, and no gesture may
//! block a frame or a consumer thread on that.
//!
//! **No enforcement path calls stop.** `litany stop` mid-tool-window wedges the
//! branch permanently (litany bl-b98d), so declining is in-band and parking is
//! a park — never a kill.
use Path;
use cratehold;
use crate;
use crate;
use Deps;
use Reply;
/// The releasing driver launch, shared with the §8.2 nudge — its own file
/// because it is a *launch*, not a judgment: nothing in it reads a mark, a row
/// or a policy.
pub use advance;
/// The family's other writer — the §4.9 fifth rung's per-conversation floor
/// (bl-94b4). Its own file on a real seam: this one answers **one invocation**
/// off a live mark and drives the branch on; that one writes **standing
/// policy** for a whole descent and launches nothing.
pub use set_floor;
/// The ops-row verb naming an answer to a held call. Mirrored from the fold
/// that reads it (`crate::control::judge::answers`); the words are held equal
/// by a test rather than by a shared const, because the reader deliberately
/// owns its grammar.
const ANSWER: &str = "answer";
/// **What one answered park is**: the invocation the answer landed on, read
/// live off the mark rather than typed; the tool it named; the answer written
/// — verdict and the scope it now stands over; and whether the releasing
/// `litany advance` was launched. Its own named type rather than four fields
/// on [`Reply`], the [`Acknowledged`](crate::boundary::answer::queue::Acknowledged)
/// shape: a receipt is a thing, and this one is minted here and spelled in
/// exactly two other places.
/// Answer the invocation parked at `(workspace, agent)`.
pub
/// **What this answer stands over**, in one word for the row: the held
/// `tool_use` id at [`Scope::Call`], and the class of the held call — the same
/// tool at the same reach — at either wider scope, prefixed by the answering
/// conversation where the scope is that conversation's descent.
///
/// Two refusals, and both are the fail-closed direction. A class the mark's
/// sentence does not name cannot bound a standing grant, so the answer is
/// narrowed to the call by refusing outright rather than by silently answering
/// something else; and loss and credentials take the call alone
/// ([`Answer::permits`]), which is the shipped table's own line answering a new
/// question rather than a new floor.
/// The §4.11 item-8 **confinement gate**: a workspace whose live policy
/// declares `confinement: required` fires a drone only where the platform's
/// one backend proves itself at this very birth — the derivation, the probe
/// and the refusal all live in [`crate::control::confine`]; this is the doors'
/// name for them. On Linux the backend is bubblewrap and a passing probe means
/// the fired spawn runs wrapped (the doors fold the wrapper on); everywhere
/// else, and wherever the probe fails, the standing refusal names exactly why.
/// Never a silent fallback, and no UI affordance for an absent layer — the
/// only surface it earns is the refusal.
///
/// Severable in both directions: absent, the gate is a no-op with nothing
/// configured; present, removing the line removes the policy, not the code.
pub