Changes touching this path

  • Pure decide/execute split for reconcile_onto (#325) c23c23bd · dbf3dbe6…
  • ADR 0039 build: pure-projection review + carry-at-land (#362) Review mode (`ferry --with-wip` / `loot-first review`) is now a pure projection: no ingest, no dock reconcile, no mirror-main advance, no spine rewrite - it mints the provisional commit from the lane's own anchor marks and pushes only review/<position>. A lane behind git main reviews normally; REFUSE_REVIEW_STALE_ANCHOR is deleted with the fold it guarded (#292/#302), and the #349 review-mode trigger is structurally gone. Reconcile lives only at the signing verbs, and its diverged-line shape is now the carry (DagRepo::carry_line): a self-authored suffix replays onto landed main as superseding versions - same change id, same subject, single parent, stale original kept as predecessor - so landed history stays exactly one commit per change with no ferry: 1412f811 · dbf3dbe6…diff
  • Refit: plan/execute split for the change-rewrite verb family (#659) f2fdf6ed · dbf3dbe6…diff
  • workspace/reconcile: apply_plan executor owns the four arms (#663) 4ac0277a · dbf3dbe6…diff
  • loot adopt: the git-first catch-up fast-forwards content-identical work unsigned and names foreign paths (#705) 044c84ac · dbf3dbe6…diff
  • the adopt catch-up decides in the shared reconcile table, and keeps its own hands for the fold (#866) `adopt_harbor` is now the same three steps as the ferry reconcile: prologue (the two "cannot name the target" refusals, the #829 shared-graph ingest, the ADR 0047 hold refresh) then `adopt_view`, then `reconcile::decide`, then adopt's own executor. Ferry and adopt can no longer drift on WHAT to do. A sibling of `apply_plan`, not a mode flag on it: the same `Plan::Merge` means carry for the bridge (ADR 0039) and fold for adopt (ADR 0034), so that distinction stays a named seam rather than a runtime argument. Adopt's hands are `fast_forward_to` and `fold_line_in`, with `fold_line_in`'s internal short-circuits intact (`lane merge` is a live caller of them). The #418 seal-WIP override stays executor-side in both verbs as the typed `RepoError::SealWip`, deduped into one `seal_wip_gate` helper carrying the verb name. Routing it through `Plan::Refuse` would demote a matchable guard+override refusal to a stringly error, and it reads live state at the signing seam beside the mis-seal gate. The View is unchanged at six fields. Adopt becomes the first production caller that passes `covered: true` (its stale doc note is updated), and the first that captures BEFORE computing `covered`, which is legitimate because the table is order-indifferent: `covered` outranks every other field. The capture normalization stays verb-owned and is skipped once `covered` holds, so an already-current catch-up still leaves the operator's capture exactly where it was. One behavior change falls out of the routing: a catch-up with no local line at all (`pinned: None`) now takes the plan's Adopt arm and fast-forwards onto landed main, where it used to fall through to `fold_line_in` and refuse with "nothing to merge into yet, record a change first". Catching up is what the verb is for, and it is what `reconcile_onto` has always done in that state; `fast_forward_to` takes `Option<&Oid>` for the missing `from`. `loot adopt <version>` is untouched: taking a target wholesale makes no reconcile decision. Tests: the choices are the table's, so adopt's repo-materializing tests keep only what is still adopt's own, the prologue, the capture normalization, and each executor hand's effect. Added the second prologue refusal (a landed main the shared graph lost) and two executor smoke tests: the `pinned: None` adopt arm, and the no-op leaving a capture untouched. One duplicate drop-the-redundant-capture test folded into its twin. 46b3f587 · dbf3dbe6…diff
  • a ferry refusal reaches a machine consumer as itself, not as a generic error (#867) Every seam inside `ferry::run` returned `Result<_, String>`, so a pass — which is mostly other people's failures — flattened all of them before the CLI could emit them. A typed `RepoError` the engine had already coded, and the reconcile executor's `Plan::Refuse`, both reached a `--json` consumer as the generic `error` code. The prose was fine; the machine channel was the loss. The nine phase signatures now carry `CliError` end to end, which restores the engine's own slugs for free: engine calls propagate with a bare `?` instead of `.map_err(|e| e.to_string())`, which is precisely what was flattening them. Exactly three slugs join the frozen ADR 0023 contract (amendment recorded): `undescribed_parent` and `foreign_paths` from a new `reconcile::Refusal::code`, built alongside the unchanged wording by BOTH executors — `apply_plan` and #866's adopt catch-up — so two verbs sharing one table cannot become two taxonomies; and `git_mirror` where ferry lifts git2, deliberately coarse because the bit a consumer acts on is retry-the-environment versus obey. `git_mirror.rs` stays stringly inside: inventing a loot taxonomy for git2's errors would be fiction. `rollback_note` keeps the abort's code and grows only its message — a rollback is context about that failure, not a different one. Every refusal's wording is byte-identical; the human channel does not move. Ferry's own handful of refusals stay honestly generic, and so do the tier's remaining flatten sites, which graduate one at a time when a consumer needs them. The one loot-first line is the seam back out: its orchestrator keeps a String channel, so `From<CliError> for String` makes that a `?` rather than a hand-written `.to_string()` at every call. Found while pinning the codes: the uncaptured-WIP ferry test refuses with `foreign_paths`, not `undescribed_parent` as it reads. Both wordings offer `describe -m`, which is why prose was never a taxonomy. 4fc73479 · dbf3dbe6…diff
  • the primary stops authoring: describe -m and new -m refuse on a shared floor and print the exact lane take that carries the work onward - ADR 0058's loot lane take built, --allow-primary now a triple (#985) 67df9345 · dbf3dbe6…diff
  • the one-place path spellings become reachable and reach: tree_path goes pub(crate) and covers the five walk-derived surfaces that could not call it, lane merge stops being the face #1049 missed, and two doc claims shrink to what is true (#1063) 94908511 · dbf3dbe6…diff

Renames are not followed. loot's tree maps a path to an address, so a rename is a delete and an add. This list is the history of the name, not of the bytes.