1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
//! The crate's lock chokepoint (Bootstrap rule 7): the cross-thread
//! shared-mutable-state locks live in this one file, so the whole-crate
//! shared-state inventory is auditable in one place.
//! `rules/locks-outside-state.yml` enforces the confinement, and its only
//! carve-out is test scaffolding.
//!
//! **The residents, and they are the whole inter-thread interface** (§7.2).
//! This file is the complete inventory of what yog's threads share:
//!
//! - [`WatchSetHandle`] — the shared [`WatchSet`](crate::watch::WatchSet): the
//! worker reconciles it, the [`Bridge`](crate::watch::Bridge) drains it.
//! - [`DirtySet`] — **announcements → worker**: a map of root → [`Mark`] (why it
//! is dirty). The bridge fills it from the watchers; the frame fills it when a
//! dispatched verb changed something the watch would only find later. The
//! worker drains it.
//! - [`LoginCell`] — **the §8.3 sign-in runs** (REMOTE §8.3): the act seats a
//! `bz --login` child, its own reader thread drains it, and any number of
//! held lanes read the buffer.
//! - [`SnapshotCell`] — **worker → frame**: the latest *completed*
//! [`Snapshot`]. The worker swaps a fresh `Arc` in; the frame clones it out
//! once per frame. The lock is held for exactly one pointer move on either
//! side, so "the frame never blocks on the worker" is true by construction —
//! there is no derivation inside this critical section to wait for.
//! - [`PresenceCell`] — **the wire server → every answer**: which clients hold
//! a live connection (REMOTE §5, [`registry::presence`](crate::registry::presence)).
//! - [`MailCell`] — **the invocation mailbox** (REMOTE §5): the queue per client
//! and slot per invocation a routed tool call crosses
//! ([`registry::mailbox`](crate::registry::mailbox)).
//! - [`hub_slots`] / [`hub_backend`] — **the process's one `notify` instance**
//! and its fan-out registry (§7.1, [`fs_watcher`](crate::fs_watcher)): the
//! backend's event thread delivers through the registry every watcher arms.
//! - `ProbeCacheCell` — the macOS 2 s liveness-probe TTL cache (§10), compiled
//! only where it is used (macOS, and tests).
use BTreeMap;
use PathBuf;
use Sender;
use ;
use ;
use crateSnapshot;
use crate;
/// The shared [`WatchSet`](crate::watch::WatchSet): the §7.2 worker reconciles
/// it, the [`Bridge`](crate::watch::Bridge) drains it. A transparent alias so
/// `.lock()` stays ergonomic at the use sites while the `Mutex` token itself is
/// confined here.
pub type WatchSetHandle = ;
/// Build a fresh, empty [`WatchSet`](crate::watch::WatchSet) behind its shared
/// handle — the one place `Mutex::new` is applied to the watch set.
pub
/// Lock the shared watch set, poison-immune (see [`lock_cell`] for the same
/// one-line recovery discipline).
pub
/// The published derivation (§7.2): the worker writes, the frame reads. A
/// transparent alias so the `Mutex` token itself stays confined here.
pub type SnapshotCell = ;
/// Build the cell around the model's starting (empty) snapshot — the one place
/// `Mutex::new` is applied to it.
pub
/// Lock the cell, poison-immune: a panic while the guard was held leaves the
/// `Arc` intact, so we recover it rather than propagate ([`PoisonError::into_inner`]).
/// Keeping the `.lock()` and the recovery on one line is deliberate — a split
/// isolates the never-taken recovery on its own line, which reads as uncovered
/// under `ignore-panics`.
/// Publish a completed derivation (worker side).
pub
/// The latest completed derivation (frame side) — an `Arc` clone, so the frame
/// renders from a value nothing can mutate under it.
pub
/// The engine's live sign-in runs (REMOTE §8.3, bl-c285): one `bz --login`
/// child per workspace × provider, written by the act and by each run's own
/// reader thread, read by every lane held on one. A transparent alias, so the
/// `Mutex` token stays confined here while the map and every rule about it live
/// with the runs ([`login::runs`](crate::login::runs)).
pub type LoginCell = ;
/// Lock the sign-in runs, poison-immune — [`lock_cell`]'s one-line discipline.
pub
/// The dirty-root hand-off: root paths, each with the [`Mark`] naming **why**
/// it is dirty (§7.2 instrumentation). Cloning shares the inner map (the frame
/// holds one clone, the worker another).
/// The live-connection map (REMOTE §5, bl-4e08): per identity, one stated
/// corpus edition per connection it holds. The wire server writes it, every
/// answer reads it; the map and every rule about it live with
/// [`Presence`](crate::registry::presence::Presence).
pub type PresenceCell = ;
/// Lock the presence map, poison-immune — [`lock_cell`]'s one-line discipline.
pub
/// The invocation mailbox (REMOTE §5, bl-024b), shared by handle exactly as
/// [`PresenceCell`] is; its slots and rules live with
/// [`Mailbox`](crate::registry::mailbox::Mailbox).
pub type MailCell = ;
/// Lock the mailbox, poison-immune — [`lock_cell`]'s one-line discipline.
pub
/// One watch-hub subscriber (§7.1, bl-908c): a canonical watched root and the
/// channel the watcher over it drains.
pub type HubSlot = ;
/// The hub's fan-out registry — a process singleton the backend's event thread
/// delivers through, so its callback captures nothing.
static HUB_SLOTS: = new;
/// The process's one `notify` backend, or `None` if it could not be created.
static HUB_BACKEND: = new;
/// The hub's registry, locked poison-immune.
pub
/// The hub's backend, built by `build` on first use and locked poison-immune;
/// `None` where it could not be built. The rule about never taking it while
/// [`hub_slots`] is held lives with the hub (`fs_watcher::hub`).
pub
/// The macOS liveness-probe TTL cache's map (§10): target path → when it was
/// observed and what was seen. Single-thread in practice (the probe traits
/// observe through `&self`); a resident here because every lock is.
pub type ProbeCacheCell =
;
/// Lock the probe cache, poison-immune — [`lock_cell`]'s one-line discipline.
pub