Changes touching this path
- the adr 0004 guard stops being a claim about a struct and becomes a question asked of the repo on disk: the pin it left asserts that no field of SealedObject is a function of plaintext, which stays green over a store that has the deleted digest back beside the struct, and that is measured rather than argued, since with DagRepo::put appending blake3 of the plaintext to a file in .loot the pin reports 1 passed and 0 failed while the new census reports 4 passed and 2 failed. plaintext_equality_census records two worlds through the same verbs, one with two paths holding the same bytes and one with them holding different bytes of the same length, builds each world four times, and refuses a persisted difference its readings can see between them: structure cancels because both worlds record the same tree, randomness is filtered by keeping only what every build of a world agrees on, and the wall clock is blanked by value, because adr 0043 stamps a second per version and a gap between two builds read red on that second alone. it walks the repo root rather than a named place, so relocation is the thing it is aimed at, and it is a lower bound and not a proof: a token shorter than its window, an index encrypted per build, and any write path the fixture does not run (a push, a pack, the mirror, the forge and the wire) are outside what it has looked at, which the new adr 0004 amendment states before a reader meets either guard. three oracles are planted as standing controls, one per reading, each the shape of a proposal that has actually been made. red under mutation, counts read each time: the sidecar planted in DagRepo::put (the census 4 passed and 2 failed, the struct pin 1 passed and 0 failed beside it), the value reading removed (5 passed and 1 failed), the shape reading stripped of its lengths (5 passed and 1 failed), the repetition reading removed (5 passed and 1 failed), the walk stopped from recursing (2 passed and 4 failed) and the two worlds made identical (3 passed and 3 failed). adr 0086 gains a pointer where it records the proposal this gap would have waved through, and CONTEXT.md says what the new reading reaches. no migration, no wire or format byte moves and no host behaviour moves, so this owes no deploy. the workspace suite is green (4092 passed over 131 binaries, 8 ignored) (#1894)
327f63f8 · dbf3dbe6… - the stale narrowing moves to the enum that defines the set, and the plaintext census stops asking its constants what the store holds: pinned.rs still said the opener refuses a directory git cannot name a revision for, which is the vocabulary of the round before #637 gave that door a loot arm, and #1895 had just pointed the corrected loot-perf-cli header at this paragraph as its argument, so the module header now names no arm and sends the reader to Names, the door doc says what the accepted set widens with, and the struct doc and the refusal beside it follow. the binary header stops calling the door the only constructor of the type a measurement is taken against, a claim about a set the module can grow with one function and nothing derived behind it, and states privacy instead, which the compiler holds: the fields are private to pinned, so a value cannot be made out there at all. the census clock window opened at the first redaction, which runs after the fixture has built every repo, so the seconds it redacts sat below the lower edge and only the slack held them in; it now opens at the span the fixture records itself writing in, frozen once so both worlds redact through one window, and the slack is stated as paying for skew between two clock reads rather than for build time. the same census read green over a fixture whose varied path never reached the store, every planted control still catching its oracle because an oracle is planted from the recorded constants; the premise is read back per build through the repo door now and compared on the bytes that come out. the keypair archive record stops making a later second part of why a re-run works, since ts is a whole second and the put-back frees the tag, so a re-run inside the refused second takes that tag back, which is what the test exercises now; the branch where the put-back is itself refused stays unexercised and that deviation is recorded at the code with what makes it unreachable from a fixture. adr 0066 stops answering how many today with the figures in one block, because the verb-line figure the census holds stands outside it, and says instead that what decides is surviving the cut. red under mutation, counts read each time: the fixture slowed by seventy seconds between the worlds under the old window (census 4 passed and 2 failed, the value rows naming one unix second against eight redaction bytes), the window start taken at the reading again (6 passed and 1 failed), the capture stopped from recording the varied path before the new reading existed (6 passed and 0 failed, every control green) and after it (6 passed and 1 failed, naming b.txt), the put-back removed (loot-identity 48 passed and 1 failed), the suffix search started past the refused tag (46 passed and 3 failed, the resume test naming rotated-7-2), and the amendment date requirement removed, re-measured on the landed tree (loot-cli bin 0 passed and 1 failed, naming line 15 and 111 lines where the landed record says 103, that document being 952 lines before this land and not 953). no migration, no wire or format byte moves and no host behaviour moves, so this owes no deploy. the workspace suite is green (4093 passed over 132 binaries, 8 ignored) (#2179)
19bc2ec4 · dbf3dbe6…diff - adr 0004 is now asked of what a repo encodes to send as well as of what it persists: plaintext_equality_census gains a wire half, which keeps per build the payloads its sent function has the fixture repo encode through the public Workspace doors loot bundle and loot push call (the full bundle, the /stow batches a push to an empty host sends, closed at one object a batch so the first-batch delta framing runs, and the /ingest payload around the metadata-only declaration bundle), and takes the same value, shape and repetition readings over them between the equal and distinct worlds; nothing was exported for it, since the ticket premise that a bundle is unreachable from the test crate was wrong. a premise test opens every object the payloads carry with the key riding beside it and holds each world to the plaintexts it records, a moving-bytes control refuses payloads that never change between builds, and three oracles are planted on the wire: the deleted identity_hash itself, an address-only grouping and a per-build-salted digest. the wire is clean: nothing plaintext-derived was found. the repetition reading, shared with the store half, now counts occurrences of repeated windows rather than distinct ones, because the payloads repeat content and a chance collision merged two repeated windows and lowered the count the minimum keeps: at the distinct count the wire half read red in 4 of 25 runs, at the occurrence count 60 of 60 green. red under mutation, counts read each time: the bundle producer appending a domain-separated blake3 of each carried plaintext (census 11 passed and 2 failed, while engine bundle_carries_no_plaintext_equality_oracle reports 1 passed and 0 failed beside it), sent building nothing (8 and 5), the push batches carrying no object (12 and 1), the value reading removed (11 and 2), the shape reading removed (11 and 2), the repetition reading removed (11 and 2), each restored to green. the forge question is answered in the new adr 0004 amendment: /stow and /ingest decode the same Frame and /ingest takes encode_ingest_payload, so a forge input is what the wire half reads, while what a forge or relay keeps of it is its own store and is not asked; the engine pin doc scopes it to the one value it searches for, and CONTEXT.md names the wire half. no migration, no format byte, no wire byte and no published wording moves, so this owes no deploy. the workspace suite is green (4351 passed over 138 binaries, 12 ignored) (#2172)
b98809ca · dbf3dbe6…diff - the review-sweep fix-up over #2303, #2159 and #2172. the wake-up sender: its client is built with no_proxy, so a proxy named in the environment is not used, pinned in a test binary of its own that sets the proxy variables and sees the request reach the pinned address and not the proxy; refused_wake_address now refuses every address that is not globally routable unicast, an ipv6 address carrying an ipv4 one (mapped, compatible, nat64 64:ff9b::/96, 6to4) judged by the one it carries, so 64:ff9b::a9fe:a9fe is refused, with the refused blocks copied from the iana special-purpose registries at the code and a table of example addresses pinning the rule; name resolution runs on a thread waited on for at most WAKE_TIMEOUT_SECS with the request given what is left, and the wake-ups in flight are bounded by MAX_WAKES_IN_FLIGHT, a resolver that outlives its wait keeping its place until it returns. the ingest kinds trailer is now a byte per head in head order, still absent when no head declares a kind, so each head is given jobs for its own kinds only and no job is made for a kind a head has no step of; the pre-2159 decoder still reads the new payload, the one-byte union shape was in no release, and neither format constant moves, pinned against the marker put_version writes rather than its digits. MetadataStore::ingest answers the jobs its commit wrote (store::Ingested) and a push wakes runners for those alone, so a triple a racing request filed first wakes nobody here; the proposal job half answers no error once the proposal is committed and logs instead. the job_cost no-kind pin now states the property, that the job half calls the store for nothing when nothing is declared, instead of a list of methods. the seek busy marker: one that does not parse is believed until its mtime is past the window, so the instant between its creation and its clock no longer admits two holders, and a marker that cannot be created for a reason other than one standing there is retried and then refused naming the state rather than counted as held; the held-marker comment is scoped to a round that claimed it. the census wire half plants each oracle into every payload sent builds and asks each payload for moving bytes, calls the now-public verbs::sync::forge_declaration instead of a copy, records that the fixture declares no kinds, and records the measured flake rate of its minimum reading (200 runs: 40 of 1600 store builds and 15 of 1600 wire builds above the floor, none red). false sentences fixed: jobs.rs says what a false proposal declaration costs the owner and what the trust floor does and does not stop, ADR 0091 section 7 and its 2159 amendment are corrected with a 2307 amendment and the reads-not-writes scope of the job cost measurement, ADR 0090 and ADR 0004 gain corrections, CONTEXT.md names the per-head trailer, the census module doc states the property instead of naming places, and an in_progress rewrap leftover is rewrapped. red under mutation, counts read each time, each restored to green: no_proxy dropped (0 passed and 1 failed), the 2159 refusal rule restored (2 and 2), embedded forms unrecognised (3 and 1), 6to4 unrecognised (3 and 1), the resolver thread not holding its place (0 and 1), the ceiling ignored (0 and 1), the resolve wait unbounded (0 and 1), the trailer encoding the union (25 and 2), the forge unioning kinds across heads (1 and 3), the memory ingest answering every handed job (4 and 2), the push waking for planned jobs (5 and 1), the proposal refusing after a failed job write (3 and 2), the job half reading with nothing declared (3 and 1), an unparseable marker read as idle (1 and 1), a failed create counted as held (1 and 1), the census reading the bundle alone (9 and 4), every payload a copy of the bundle (10 and 3), the ingest payload emptied (11 and 2). no migration, no format byte and no published wording moves; the forge binary changes, so the sender and per-head jobs are live once the forge is redeployed. the workspace suite is green (4360 passed over 138 binaries, 12 ignored), and green under bash ci/local.sh against Postgres 18 (#2307)
665b3cec · dbf3dbe6…diff - a push now carries an attestation recorded over a change the remote already holds, so loot tag after loot push reaches a relay and a forge instead of being left behind under a success line: a local attestation ledger (.loot/attestation-ledger) records per remote what each push delivered and is read by a push and by no open or save, written by RepoStore::record_attestations_sent as a read-merge-write under the shared-store lock; the push sends the attestations over the held changes of the remote that the ledger has not recorded beside the send set and prints how many, the bundle builder keeps a late attestation only over a change inside the have closure of the recipient whoever handed it in, the forge /ingest keeps one over any change its repo holds through a new changes_held store read that costs no query when every attestation rides its change, and /info gains an additive late_attestations field so a forge that does not advertise it is sent none, has nothing recorded as sent, and the push warns how many it left behind. the land gate store_file_reads is 24 on its workload with no move, where a first cut that read the ledger on every open measured 26 and was refused; an open reads 20 store files, 21 with that cut. the #48 bound holds on the wire: a push carrying one late tag sent 256 B at a relay and 306 B at a forge over both 2 and 24 held tags. the ticket recipe, whose fresh clone lacked late-tag2 through the 0.4.24 binary, shows it through a lane build. red under mutation, counts read each time, each restored green: the open reading the ledger again (0 passed and 1 failed), the ledger write overwriting instead of merging (0 and 1), the ledger ignored (0 and 2), the late lane dropped (0 and 2), the privacy filter removed (1 and 1), the forge back to in-this-bundle (2 and 1, and end to end 1 and 1), the forge keeping any change (2 and 1), a relay push recording nothing (0 and 2), a push recording to a forge that does not keep them (1 and 1), the /info flag ignored (1 and 1). no format constant, codec byte or migration moves; the forge change is live once the forge is redeployed. the pull half is not built: a pull still carries an attestation only with a change it sends. the workspace suite is green under bash ci/local.sh against Postgres 18 (4425 passed over 139 binaries, 13 ignored; site live suites 7 files passed) (#2251)
414ba6b2 · dbf3dbe6…diff - test scratch directories are named by one shared helper, common::scratch, from the process id and a per-process counter rather than the clock, so two tests asking for one tag at once are no longer handed one directory that the second caller empties and refills (the #2258 mechanism): 19 test files under crates/*/tests named a temp_dir path from SystemTime nanoseconds in 21 statements and now call fresh_dir or fresh_path, loot-cli files reaching it through mod common and loot-first exit_codes compiling the same std-only file by path, and revset_everywhere and plaintext_equality_census, which already counted, call it too. scratch_dirs.rs holds the #2258 pin, moved from revset_everywhere and aimed at the shared helper, red under the clock naming in 13 runs of 13 (0 passed and 1 failed, 1 to 16 of 400 directories handed twice), and a guard that walks every .rs file under crates/*/tests and refuses a temp_dir statement that reads the clock, red over the unconverted tree naming the 19 files (1 passed and 1 failed), red with buoy_exit put back (1 and 1) and red when the walk finds nothing (0 and 1), each restored green. no other test changes what it asserts. the workspace suite is green (4533 passed over 140 binaries, 13 ignored, from 4532 over 139: the guard is new and the pin moved into its own binary). test-only, so it owes no deploy (#2358)
6dd1e05b · dbf3dbe6…diff
Renames are not followed. loot's tree maps a path to an address, so a rename is a delete and an add. This list is the history of the name, not of the bytes.