Changes touching this path
- a land takes into main the ticket changes on the forge that landed main lacks (ADR 0098 §4, the sync half of §5, the #2390 half of §6, and §9): under the harbor after its finalize it asks its remote, when that answers as a forge, for its heads, takes in what they reach, and judges each change they reach that landed main does not; one signed by a key in the own key set of this identity and writing only under tickets/ is folded onto landed main ahead of the ferry reconcile, so the lane is carried onto it, the re-gate sees the tree as it lands and git main takes the lane commit alone, and any other fails the land closed naming the change and its paths outside tickets/. a sync push the forge refuses because a web write arrived during the land now merges that write onto landed main under the subject fold N ticket changes from the forge, with no gate and no git commit, catches the primary up and pushes again, a bounded number of times; the #2390 check accepts a primary ahead of landed main only by ticket-only changes the forge holds; a ticket file both the lane and the forge wrote bounces for loot resolve, or refuses before the pass naming loot pull-grants in the primary when the lane cannot open both sides, and a pass whose carry stops short of the fold projects nothing; a fold merge refuses a file landed main and the forge both wrote. the verdict gains folded=N before pusher=. ADR 0098, the ADR 0063 amendment, CONTEXT.md, workflow.md, the land-change skill, GATES and SOURCE_ROOTS say so, and the pin no_gate_input_reads_the_ticket_root covers the walk of the text gates only. six tests against an in-process forge, whose sync runs in-process, pin it beside four sync unit tests and four forge_fold tests; red under seventeen named mutations, each restored, over twelve loot-first pins and four loot-cli pins: no fold at the land (10 passed and 2 failed), the judgment ignoring paths (9 and 3, and 3 and 1 in loot-cli), an unsigned change read as own (3 and 1 in loot-cli), writes read against any parent (2 and 2 in loot-cli), no race fold (10 and 2), no adopt before a retried push (10 and 2), the #2390 allowance off the forge or without the judgment (11 and 1 each), a pass short of the fold projecting (11 and 1), no check for collisions the lane cannot open (11 and 1), a fold merge picking a side (3 and 1 in loot-cli), the race count dropped (11 and 1), the text walk reaching tickets (11 and 1), the token not the count (10 and 2), the race judging nothing (11 and 1), no attempt bound (11 and 1), and an ancestor head not skipped (3 and 1 in loot-cli). cargo test green, 4671 passed over 143 binaries with 13 ignored. client only, no deploy; loot-first changes, so the primary release binaries owe a rebuild (#2429)
357a8716 · dbf3dbe6… - review sweep 2 fix-up over #2429 (map #2422): each fold of the forge heads, at the land and at the race fold of its sync, now refuses naming the paths when the tree it reaches differs from landed main outside tickets/, and retires the merges it minted, where the per-change judgment read a merge of landed main with an ancestor of it that keeps the ancestor copy of a code file as writing nothing and folded that revert onto main, past every gate at the race fold. the race fold runs its pass with ferry::RunOpts::no_commit, which refuses a projection that would make a git commit before any ref names it, where a comparison of the mirror main after the pass left an ungated commit there for the next land to publish; a signed change that writes nothing, racing the land, was such a case. folded= is the count when the land read the forge heads, no-forge when the default remote is not a forge, and UNREAD with a FORGE NOT READ block naming why when it read none, where 0 said all three. a refused intake, a failed pass and a race fold that folds nothing drop the forge heads they read into the landing position, which kept them as heads of its own. collisions reads its base through GraphView::common_ancestor_tree, the base merge_tips merges from. the land-change skill says a ticket collision bounces for loot resolve and refuses only when the lane cannot open both sides; GATES and the ADR 0063 amendment state the gate-input property rather than kinds of gate; ADR 0098, workflow.md and CONTEXT.md, which now defines forge-only change and race fold, say what changed. pinned against an in-process forge, with the merges recorded through loot-core since no verb mints one, beside a ferry unit test; red under eleven named mutations, each restored: no property check (0 passed and 2 failed), the race fold without no_commit (0 and 1), the ferry guard off (4 and 1 in loot-cli, 0 and 1), an unreachable forge read as 0 (0 and 1), the token spelled 0 (0 and 1 over each of two pins), no block (0 and 1 over each of two pins), the intake keeping what it read (0 and 1), a failed pass keeping it (0 and 1), the fold keeping its merges (0 and 1), the race fold keeping what it read (0 and 1), and a race fold that took changes in not answering an unread intake (0 and 1). cargo test green, 4683 passed over 142 binaries with 13 ignored, three of them after a re-run: two timing flakes in loot-identity and loot-relay-contract that pass alone, and the Workspace width census, whose derived count this change moved to 406. client only, no deploy; loot-first changes, so the primary release binaries owe a rebuild (#2470)
c9c46384 · dbf3dbe6…diff - loot ticket and loot tickets read the ticket-only changes on the forge that have not landed, as a layer between landed main and this position (ADR 0098 §6, the overlay): forge_view asks the default remote for its heads when it answers as a forge, loads what the shared graph holds and stows the rest in memory through the relay append-only ingest, after which the handle refuses to persist, so no head, pointer or conflict of any position moves and #2390 is untouched; a head is overlaid only when every forge-only change it reaches passes the land judgment and its tree matches its base outside tickets/, and the layer holds only what that line wrote under tickets/. a write reads the ticket it names through the same layer, so a web ticket takes a comment before it lands, and a ticket the forge moved to another space is refused as #2454 refuses one landed main moved. every ticket leaf and loot tickets take --offline; a read says on stderr what it took from the forge or why it read locally (no forge, unreachable, --offline), human rows mark forge tickets, and a forge file this identity cannot open reads as an S row naming loot pull-grants in the primary. the bundles a read fetched are recorded in .loot/forge-view, a new position-owned store artifact excluded from undo, and a read inside forge_view::FRESH_SECS answers from it without asking. ADR 0098, the spec §6 note, CONTEXT.md and the usage lines say so, and the Workspace width census moves to 411. pinned against an in-process forge with a second clone of the identity as the web writer; red under named mutations, each restored: a read persisting what it stowed (0 passed and 1 failed), the persist guard off (0 and 1), --offline ignored (0 and 1), the judgment not read and the tree property off (each 0 and 1 over the judgment pin, and together 0 and 1 over the end-to-end pin, which each alone leaves green since the other still keeps a code write out), the layer ignoring its base (0 and 1), no forge_elsewhere (0 and 1), the record never fresh (0 and 1), a sealed forge file not counted (0 and 1), the layer not folded (0 and 1), and a leaf or the listing without --offline (0 and 1 each). cargo test green, 4707 passed over 143 binaries with 13 ignored. client only, no deploy (#2430)
8ca351c0 · dbf3dbe6…diff - review sweep 3 fix-up over #2430 and #2431 (map #2422): the browser ticket builder reads the rules and the ticket files a write answers to from the head it builds on instead of taking them from its caller as text, where a stale or forged .lootattributes handed in could publish what the head rules do not. loot-wasm ticket::reads names the objects a write reads on the head (.lootattributes, and the meta of the ticket it writes to with its body for an edit), the caller fetches them by address, and ticket::build opens each itself under the forge key lane or a key the session keyring holds, inflating a compressed one with a host zstd the caller passes (ADR 0040); a file it reads that no key opens refuses the write. an edit carries what the head held at each file it rewrites, and built again on a moved head that holds another version it answers a collision with both versions and builds nothing, while an append rebuilds freely (ADR 0098 §9, the browser half). the SDK publishTicket takes keyFor in place of context, resolves with the collision rather than publishing, reads again when the head moves between /ref and /fetch, and reports a 401 or 403 at /stow as an AuthError through assertStowAccepted. loot-ticket holds space_in, and its comment, resolution, label and wait files check their own values; the wasm lockout refusal is RepoError::Lockout; forge_fold keeps differs_outside_tickets alone. the spec §0 amendment records what #2430 and #2431 added past it, and CONTEXT.md, ADR 0098 and the SDK README say what changed. red under ten named mutations, each restored: unopenable rules read as none (0 passed and 1 failed), rules not read from the head (0 and 1), a copy handed over taken for the head file (0 and 2), meta not read (0 and 1), no collision check (0 and 1), an append compared like an edit (0 and 1), no inflate (12 and 3), a /ref to /fetch race refused (1 failed and 4 skipped in the SDK suite), a rebuild without its base (1 failed and 4 skipped), and a /stow refusal as transport (1 passed and 2 failed). cargo test green, 4728 passed over 144 binaries with 13 ignored, and the SDK gate green with npm test at 153 passed. client only, no deploy (#2479)
4efb1baa · dbf3dbe6…diff - a web ticket write no longer fails the land in a repo holding a Restricted path outside tickets/, and a fold keeps the holders main records (map #2422): the wire redacts a Restricted path holder list (#521), so the browser change carries each such path as Restricted([]), and forge_fold compared entries with ==, so the operator first web ticket read as writing docs/pitch/zk-host.md and every land after it would fail closed. what a change writes, what two lines collide on and what a forge head changes outside tickets/ now compare address and seal (forge_fold::same_entry over Visibility::same_seal, #1005). a fold no longer takes such a change as it is: its merge records fold_tree, the side that wrote each path since the fork and main own entry elsewhere, read off addresses and opening nothing, which replaces merge_tips in mint_fold_merge, a descendant is taken as it is only when that is the tree it holds, and fold_onto refuses a tip that does not record the main entry outside tickets/, address and seal alike. read against the live forge, the judgment takes the operator change (1 forge-only change, 0 refused, the overlay reads 1 and keeps out 0) and the fold merges it with 0 paths outside tickets/ recorded otherwise. item 4 found no defect in the web read: a native run of the browser read over the live head with the mailbox keys lists the ticket open with nothing unopened, and nothing was changed for it. pinned by a judgment and fold test and a fold_tree test in forge_fold, a forge_view test where a browser-filed ticket over a held path reads in the browser and in a lane, and two loot-first land tests that build the ticket with the browser builder over a base holding a Restricted path, one taken in at the intake and one racing the sync, each asserting main keeps the holders. red under named mutations, each restored: entries compared with == (21 passed and 3 failed over forge_fold and forge_view, 0 and 2 over the land tests), a descendant always taken as it is (22 and 1, 1 and 1), that and the fold check relaxed to same_seal (22 and 1, 1 and 1), and fold_tree taking the web entry where main did not write (21 and 2, 0 and 2). cargo test green, 4744 passed over 145 binaries with 13 ignored. no site change and no deploy owed; this land runs with the lane-built loot-first and loot (#2488)
d27f227f · dbf3dbe6…diff
Renames are not followed. loot's tree maps a path to an address, so a rename is a delete and an add. This list is the history of the name, not of the bytes.