Changes touching this path
- the harbor read face becomes workspace/harbor.rs: eleven mirror predicates and the raw ledger parses leave the workspace namespace, and the write side stays inside the ferry pass where ADR 0055 pins it (#1290)
be35c3f6 · dbf3dbe6… - deleting a named read on Workspace stops being free, because the 377 places that reached past it into the engine and the store now go through those faces instead — repo() no longer exists, store() is module-private, and the three extracted children share their fixtures by name rather than through the parent's private test module (#1411)
c454db04 · dbf3dbe6…diff - an unexpected head stops being something the operator can only fold on faith, because `loot heads` lists every live head with what introduced it and how many changes it holds of its own — and since a head is a tip no other head reaches, a count of zero can only mean the head is not live, so #1477s empty head is superseded and the converge it asks for would merge nothing (#1496)
955ec9ff · dbf3dbe6…diff - the catch-up stops leaving its own consequence to a runbook the reader may never have loaded: adopt now prints the git step IT JUST CREATED, and only when it actually moved the tree and the checkout is measurably behind - naming the paths it wrote, which is exactly the set needing the proof. the ancestry is judged on the LOOT GRAPH through the mark map rather than by asking git, because git cannot answer it: the checkout has not fetched the landed commit. there are two arms by position, since which git command is correct depends on where HEAD is, and neither arm ever recommends git before a catch-up, because git-first WEDGES the primary and loot-side-first is and stays the order. and the land closing note is narrowed so its final word about the primary cannot read as being about the checkout: it now says which thing the fast-forward moves, says HEAD does not move with the dock, and names the verb that says the rest. the finding that changed the procedure is bigger than the ticket: the skill had the FETCH AFTER THE PROOFS, and a land pushes main FROM THE MIRROR, while the only fetches a land runs in the checkout are its pre-land drift and ADR guards - so at the exact moment an operator needs this procedure their origin/main is stale by that very land, every landed path reads as differing, and the freshly landed perf point does not resolve at all. followed literally the skill produced the precise wrong conclusion it exists to prevent, so the fetch is hoisted with the reason recorded, and the printed block fetches first by construction. twelve mutations with counts read, of which two are worth the reading. the tenth is a CONTROL: the skill quote wraps across two indented lines, so with the whitespace flattening removed the citation pin reddens over LAYOUT rather than over words, which is what makes the flattening load-bearing rather than decorative. and the fifth is the one to learn from - the lane guard test PASSED WITH THE GUARD DELETED, because the lane was silent for an unrelated reason, landed main having been recorded on the primary so the lane lineage-filtered graph had never seen it and the ancestry answered false. a pass that survives deleting the thing under test is not a pass, so the arrangement was rebuilt with landed main recorded THROUGH the lane and two explicit preconditions proving the lane reaches the checkout and can answer the ancestry at all - after which the same mutation reddens. what is NOT done is said rather than implied: a bare ferry still says nothing about git, its catch-up being a different path, so the note claims only the dock for it; the block deliberately stays silent on a repeat adopt, because its claim is that THIS run wrote over your tree and a no-op cannot make that claim; and none of this was reproduced live (#1679)
c8ebe232 · dbf3dbe6…diff - a loot-cli test can no longer inherit a temp position an earlier run left behind: workspace::harbor::tests::nothing_is_said_from_inside_a_lane spawned its lane at a sibling of its temp root, named for the process id and removed only at the end of the test, so a run that failed left the lane on disk and the next run to draw that pid was refused with is already a loot position, which is what blocked a land while #2026 was being tested. reproduced through the test binary, seeding the lane directory for the pid the run was handed: red with the panic at harbor.rs naming the refusal (0 passed and 1 failed), green under the same seeding once the sibling is cleared before the spawn (1 passed and 0 failed), and the three directories this machine had already leaked are gone. the property is derived rather than listed, in crates/loot-cli/tests/temp_root_census.rs: a door is a function in this crate that refuses a path already holding a loot position, found by the words it refuses with and by the one-call forwarders that reach them, which is how spawn_lane reaches spawn_lane_as; a root is a path a function builds from the system temp directory, where a join stays inside it and any other derivation names a sibling the clear never reached; and a site is a door call on a root the same function built, safe when that root was cleared first or carries the clock beside the pid. it reads 26 such calls over 10 files today. the pid keying stays, decided in the file rather than site by site, and the loot-core census was not widened because it pins a different property and says itself that its scope is deliberate. red under mutation, counts read each time: the clear removed from harbor.rs (2 passed and 1 failed), the clock dropped from the explain.rs root which is safe for the other reason (2 passed and 1 failed), the forwarder half of the door reading removed so spawn_lane stops being a door (1 passed and 2 failed, the fixture and the reach guard together), every derivation made to inherit so a sibling reads as cleared (2 passed and 1 failed), and a refusal reworded so the walk finds no door for it (2 passed and 1 failed). no migration, no wire or format byte moves, and nothing outside a test moves, so this owes no deploy. the workspace suite is green (4007 passed over 125 binaries, 7 ignored) (#2113)
fb0539fa · dbf3dbe6…diff - a plain loot ferry in a lane refuses to project anything no land has carried, where it projected the lane unlanded line onto the mirror main every position shares so the next land from any of them pushed it unreviewed: the pass asks what it would project before the ingest and again at the gate seam after the reconcile, since --seal-wip can seal into the line, and loot-first land marks its own pass with RunOpts landing; a lane catch-up that projects nothing runs as before, and the refusal names the land of the PR that carries the lane tip or else the fresh-lane route of #962. the review reap says landed only from a land pass, on main for a projected version otherwise, and signed, no land has carried it for an unprojected one, where it said landed for any signed version. the seal-wip recovery recipe is chosen by position: the primary keeps its follow-up round and a lane gets the fresh-lane route, one const shared with the #2314 refusal. reproduced through the 0.4.24 binaries in a scratch repo with its own lanes (the advised ferry projected 2 lane changes and printed landed) and checked through the lane-built binary (refused, mirror main unmoved, lane catch-up still runs, reap and recipe reworded). the lane-simulated lands in the ferry tests now run as land passes, and 2 primary reap pins read on main. pinned by six new tests; red with each piece undone, counts read each time, each restored green over the ferry tests: the guard off (69 passed and 3 failed), a land pass refused too (61 and 11), every lane pass refused (70 and 2), the seam ask dropped (71 and 1), the PR route dropped (71 and 1), the old reap word (69 and 3), the recipe always the primary one (71 and 1) or always the lane one (71 and 1). ADR 0039 amended, CONTEXT.md, concurrent.md and the land-change skill updated. no format constant, codec byte or migration moves. the workspace suite is green (4442 passed over 139 binaries, 13 ignored) (#2366)
dac3385d · dbf3dbe6…diff
Renames are not followed. loot's tree maps a path to an address, so a rename is a delete and an add. This list is the history of the name, not of the bytes.