1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
//! Per-root-kind path allowlists (DESIGN §7.1).
//!
//! One `fs_watcher::Watcher` runs per watched root, and each root has a *kind*
//! that fixes which paths under it are worth surfacing. [`is_watched`] is the
//! single pure predicate generalizing the previously-hardcoded Workspace
//! allowlist over every kind in the §7.1 table. It is path-only (no stat, no
//! I/O), so it is exhaustively testable and shared unchanged by a future
//! `litany-ui-web`. Event *kind* (create vs remove) and recursion *scope*
//! (top vs recursive) are the watcher's concern, never the allowlist's.
use Path;
/// Workspace-root paths (ARCH §2.2, §3.5): the shared `steps/` and `inbox/`
/// trees, outside every worktree, namespaced by agent id. Control files are
/// no longer loose here — they live in the config commit (§2.2), observed
/// through the refs below.
const ROOT_CONTROL_PREFIXES: & = &;
/// Per-agent-worktree paths (ARCH §2.2 layout). Each agent occupies a worktree
/// at `agents/<agent-id>/`, with this set of files inside.
const WORKTREE_PREFIXES: & = &;
/// Refs and HEAD live in the bare workspace repository at `repo.git`
/// (ARCH §2.2). Branch existence is read from refs/ — no sidecar state file
/// (PRINCIPLES.md "Single source of truth").
///
/// `packed-refs` is load-bearing, not decoration: yog reads refs through `git
/// for-each-ref`, which reads the loose tree **and** the packed file. After a
/// `git pack-refs` (which `git gc` runs) the loose tree is empty, and deleting a
/// packed ref then rewrites `packed-refs` alone — touching nothing under
/// `repo.git/refs/`. Without this entry that deletion is invisible to the
/// watcher and reaches yog only via the 15 s sweep: a reproducible dropped
/// event, proven in `drift_tests`.
const REFS_PREFIXES: & = &;
/// The kind of root a [`Watcher`](super::Watcher) guards, selecting its
/// allowlist (DESIGN §7.1). `Hash` so `(root, kind)` keys a
/// [`WatchSet`](crate::watch::WatchSet) map (Y6).
///
/// The set is exactly what `desired_watches` arms — there is no kind here that
/// nothing watches. `BrazenConfig` and `LitanyConfig` used to be, and were
/// retired unarmed at bl-9130: config is operator-authored draft state that
/// feeds no re-derivation, its concurrency answer is §9's hash guard, and the
/// litany config root *is* the litany data root under the world's `LITANY_HOME`
/// collapse (§16.2), so arming it recursively is the watcher §7.1 rejects. The
/// §9 editors re-read on pane open instead.
/// True when `path` (expected under `root`) falls in `kind`'s allowlist. Pure
/// and path-only: a rejected path is never surfaced by the watcher.
/// The original Workspace allowlist (ARCH §3.5), byte-for-byte.
/// The `$XDG_STATE_HOME/balls/clones/` allowlist (§7.1): each clone dir itself,
/// its `tasks/tasks/*.md` task files and `config/config/**` landing subtree;
/// the multi-MB unrotated per-clone `log` is filtered to avoid event storms.