1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
//! **The client registry** (REMOTE §1.5, §2, §4, §7; bl-8bbc): the durable
//! server-side fact that client C participates in workspace W, and the
//! per-client home everything else about C hangs off.
//!
//! **A registration is a file, and its existence IS the fact.** REMOTE §2:
//! *"Server-side, in the world, a file — the file religion applies; the wire
//! only ever transports the gesture that writes it."* So there is no registry
//! document to parse, no list to keep in step and no last-writer-wins window:
//!
//! ```text
//! <yog-state-root>/clients/<client>/tools.json the §5 advertised set (bl-4e08)
//! <yog-state-root>/clients/<client>/workspaces/<name> one empty file per registration
//! ```
//!
//! Registering is creating the file, **revocation is deleting it** (§4), and
//! the registered set is the directory listing. Nothing is stored that could be
//! computed: the client is the directory name, the workspace is the file name.
//! It sits at yog's own state root beside `ui.json` because it is yog's durable
//! state, not the operator's key material — the `wire/` directory holds what
//! yog can never mint (§8), and this holds what only yog ever writes.
//!
//! **First registration is an operator-written file** (§4). `mkdir -p
//! <state-root>/clients/<name>/workspaces && touch …/<workspace>` is the whole
//! bootstrap, and it is the same act that provisions the certificates —
//! out-of-channel, by ruling (§1.4). There is no first-client flow, because the
//! general path with an operator-seeded input is not a case of its own.
//!
//! **`local` is the reserved identity of every certificate-less in-world
//! caller** (REMOTE §4.1) — the `gestures/` deposit inbox and `yog gesture`;
//! the window presents a certificate and is [`WINDOW`]. They are not scoped
//! (§3: each intake the religion of its domain), but they still need a name
//! for their directory. [`Client::parse`] refuses `local` exactly as it refuses `.` and `..`: all three are names the layout
//! has already spent, which is one rule rather than three special cases.
use BTreeSet;
use io;
use ;
/// **Enrollment's two values** (REMOTE §1.4 as amended, §4.2; bl-f4e3) — what
/// an operator asks for when a device joins, and what the engine answers with.
/// The certificate leaf name → client identity fold (REMOTE §2).
/// The engine-side invocation hand-off (REMOTE §5, bl-024b) — a queue per
/// client and a slot per invocation, RAM beside [`presence`] for its reason.
/// **What a certificate authorizes** (REMOTE §4.2, bl-1dd3) — the grade its
/// subject carries, and the [`Peer`] an intake answers as.
/// Which clients hold a live connection right now (REMOTE §5) — RAM, never a
/// file, because presence changes with every network blip.
/// The workspace's registered clients joined with their presence and their
/// advertised sets (REMOTE §5) — the one derivation both seats render.
/// **When each client last connected** (REMOTE §5 as amended, bl-d542) — the
/// third durable fact a registration carries.
/// What a tool host advertises, and the document it lands in (REMOTE §5).
pub use ;
/// The reserved identity of every certificate-less in-world caller (REMOTE
/// §4.1) — the `gestures/` deposit inbox and `yog gesture`.
pub const LOCAL: &str = "local";
/// **The local window's own client identity** (REMOTE §1.2, §4.1; bl-ae05):
/// `yog-window`, the subject common name yog's own mint puts on the window leaf
/// ([`Role::Window`](crate::wire::material::Role::Window)) — and therefore the
/// name the engine reads off the certificate the window presents, the directory
/// its registrations live in, and the name a registration seats. One spelling,
/// here, because an identity's home is the registry.
pub const WINDOW: &str = "yog-window";
/// The registry root's leaf under yog's state root.
pub const CLIENTS: &str = "clients";
/// The directory whose entries are one client's registrations.
pub const WORKSPACES: &str = "workspaces";
/// One client identity (REMOTE §2): a certificate leaf name, or [`LOCAL`].
///
/// It is a **path component by construction** — every reachable constructor
/// validates — because the identity names a directory, and a name that could
/// contain a separator would let a certificate address the filesystem.
;
/// **The default caller is the in-world one.** Every intake that carries no
/// certificate is `local` (§3), so the default is the identity rather than an
/// empty string nothing could resolve — a gesture always has a caller.
/// This client's directory: `<state-root>/clients/<client>`.
/// This client's registration directory — one file per workspace it
/// participates in.
/// The workspace names `client` is registered in (§4). A client with no
/// directory, an unreadable one, or one holding nothing reads as the empty set
/// — the general path with no input, and the posture a fresh server has for
/// every certificate the operator has not yet seated.
/// Record that `client` participates in `workspace` (§4) — the auto-registering
/// half of a create, and the gesture an operator performs with `touch`.
/// Idempotent: an existing registration is rewritten to the same empty file.
///
/// The file is empty on purpose. A registration has no content — it is the
/// **pair**, and the pair is the path.