Changes touching this path

  • shallow clone lands with the cut on the RECEIVING side, and that is why no wire moves and no format major does either: the fetch body is a format-marked pair of oid runs, so a depth field would be a new wire shape and therefore a bump, where taking the whole change lane and KEEPING n generations needs no new field, no new endpoint and no server change - a shallow client works against every relay and forge already deployed, including older ones. the price is stated rather than glossed: the change lane metadata crosses once in full on the first round, and what is saved is the object bodies, which is where a history bytes are, exact from the second round onward. the no-false-absence guard lives in THREE places and none of them is a verb - assemble, which every CLI open lands in, measures the frontier; apply_bundle_reaching, the only thing that can move one, re-measures it; and the dispatcher states it on stderr after BOTH the success and the refusal arm, because a refusal is a false absence WORST shape. it cannot be bypassed by a verb that forgets to ask: there is no path from the CLI to history that skips assemble, and the one way to open without measuring is to declare RepoNeed without graph, which makes the first history read PANIC - so the declaration that would silence the notice is the same one that aborts the verb. it rides stderr rather than the shape, so json and porcelain stay byte identical under ADR 0023, and a complete position emits nothing at all. depth never reaches the remote AT ALL, pinned three ways: every recorded request re-encoded through the real codec is exactly header plus 32 bytes per id with no room for a depth or a path, the union of every have and wants is a SUBSET of what the relay itself named in a prior answer, and the aimed one is that two positions cloning the same history at the same depth and differing ONLY in their sparse view emit BYTE IDENTICAL requests. the test relay recorder had to start capturing IDS rather than counts, because a privacy claim about a request cannot be checked against a length. two findings came out of the sweep rather than the design. one mutation stayed GREEN and refuted a claim already written into four files - that shallowness is stable because the frontier id rides the declared closure - since a declared have IS a closure claim and the held tips therefore already subtract everything behind the cut; every occurrence is now the narrow true sentence with the refutation beside it. and a count assertion caught a silent no-op: the obvious deepen posture, the closure minus the frontier, comes back with an EMPTY change lane REPORTING SUCCESS, because the remaining ids are still descendants of the cut - a deepen must declare NOTHING, and the posture is now derived from the bound so the wrong pair cannot be spelled. the body-deferring filter is NOT attempted and is the one criterion left: it needs a lazy object read on every get, surface and diff path plus a policy for what happens offline, and half-building it would put a FIFTH kind of not-here into a store that already distinguishes four (#1527) 2cccbe27 · dbf3dbe6…
  • the no-false-absence guard 1527 landed was BYPASSABLE, and the bypass was neither of the two escape routes its doc ruled out: buoy and bisect return from main before the notice single call site, so assemble measured the frontier and threw it away unprinted, and a plain loot buoy on a shallow position exits 2 with no buoy - a REFUSAL-SHAPED false absence, which the comment four lines up calls the shape an operator most needs the line for. the repair is SHAPE rather than a third bullet: main is now a two statement wrapper and the whole former body is dispatch(), which is the only expression in main that produces an exit code, so every exit code the binary emits is that call return value and a return anywhere inside it - any depth, any verb, ahead of the table or behind it - returns INTO the notice. a new early return is not a new escape route, it is the SAME route, and because nothing is enumerated nothing has to be maintained. that matters because the old doc argued unbypassability by ENUMERATING escape routes and closing each, which reads as exhaustive, is not, and failed on the first route nobody listed - the same shape as a hand written count beside a derived number, which this run watched go stale three times. the residual is STATED rather than enumerated away: a process that never returns through main, process::exit or abort or panic, which is a property of process TERMINATION and not of the verb table, so nothing a verb does BY RETURNING can miss the notice. a census pinning exactly one raw exit was considered and refused, because that walker own consumer count is itself a derived-and-pasted census and adding a consumer churns it. the failed enumeration is kept as HISTORY, marked as the thing that failed, with the shape argument replacing it, and a THIRD site carrying the same claim was found in CONTEXT.md glossary which the ticket never named. FRONTIER_WIDTH stops being a process global read by verbs that hold the authority: both callers now ask their own workspace, and the public spelling no longer compiles from outside the module, which is the narrowing made structural rather than promised. three pins that asserted nothing are gone. the re-encoding privacy pin is DELETED because no byte seam is reachable - the transport is a TYPED seam, so the test re-encoded its own recorded id vectors and asserted the codec is linear in their length, true for every possible input - and its doc now records what it did against what it claimed, with the criterion standing on the other two pins, which carry positive controls. the partition pin is read out of the RENDERED sentence now rather than from literal triples the constructor never saw. two mutations make the case by experiment: moving the notice back to the end of dispatch reddens the new pin while log and show stay GREEN, and re-adding the old partition body under a scratch name PASSES, so vacuity is demonstrated rather than argued. an eighth pin was written and then deleted, because a mutation proved the existing assertion already sits on the live case (#1828) b5eb05df · dbf3dbe6…diff
  • the note rule moves to the LANE WRITE SEAM and stops being a property of one verb: Workspace::attest takes a Record rather than a role string, so there is NO OTHER WAY TO SPELL A ROLE IT ACCEPTS, and two wildcard-free matches answer for every variant - role mints the string and refuses an operator one in the reserved namespace, prose declares the free-text payload and Some IS the gate. adding a fifth variant produces TWO compile errors, one per match, which is the obligation put where a list cannot be forgotten. all three doors were REPRODUCED FIRST and a FOURTH was found that no ticket named - tag --retire -m writes the operator reason to the same lane - which is why the repair is a seam rather than three verbs remembering. door one is REACHABLE rather than theoretical: unwrap_or_default meant an unreadable tree read as NO SEALED PATHS and allowed the write, and a shallow position supplies one, because HEAD~n walks one parent edge past the oldest change HELD and resolves onto a FRONTIER ID - signed, named as a parent, not held - so the gate now fails CLOSED and names fetch --deepen. door two leaked real bytes end to end: notes add refused, then attest with a reserved-shape role exited 0 and show printed the secret on a Restricted change. and ADR 0025 had that door WRITTEN DOWN AS AN ACCEPTED COST, saying a user who reaches past the verb can still attest the sentinel and the signature binds it to their key - the hole was documented as the price of the encoding, and it was a DEFECT rather than a cost, because the role parses back as a note, renders as one and rides the bundle as one. tag -m is GATED rather than excepted, and the line is KEY VERSUS PAYLOAD: a landmark name is a namespace key a reader re-types and matches by equality, so gating it would take ADR 0018 sign-off and ADR 0025 resolver down on every change in a repo with one sealed path, while a message, a reason and a note body are prose ABOUT one change content. that refuses tag -m in THIS repo, where .lootattributes seals a path on every change, and the bare name, the bare retirement, buoy and attest all still work. eight mutations with counts read, and mutation three is the argument: neutering the seam reddens three pins while #1519 OWN PIN STAYS GREEN, which is why the first gate could not see any of this (#1847) 93cc4944 · dbf3dbe6…diff
  • the control that proved its claim by reading a process-global stops depending on what an unserialised sibling wrote, and the claim gets STRONGER rather than weaker: it is now two positions over the same history, cloned from the same bundle, differing ONLY in depth, asked the same question through the same status call with the same opts in the same process, and answering DIFFERENTLY - so the contrast rules out ANY single shared authority rather than one whose value the test happened to observe, and nothing in the file reads shallow_notice any more. the other two options are rejected with their reasons at the site: setting the global locally MANAGES the race rather than removing it, because the window between the set and the read is open to any sibling open_at and could not be shown closed, and a mutex would be a lock existing only because the TEST reads a static that the production path, after #1828, no longer reads at this site. the #1828 narrowing is not weakened, and that was READ rather than assumed - 87797fe moved FRONTIER_WIDTH to one consumer, the dispatcher that holds no Workspace, and made every Workspace-holding caller derive from the frontier it already holds, which is exactly what the new control pins. the acceptance mutation proves the control still bites: pointing the status arm back at the process-global is RED five runs out of five at 7 passed 1 failed, and a second mutation proves the complete-position half is not decoration by reddening at the other assertion, so each half bites on its own. the verification carries its OWN positive control, because a green run under siblings proves little on its own: an aggressor thread doing nothing but opening SHALLOW positions in a loop, with the OLD assertion recorded but not asserted, shows the old control FAILING ten times out of ten in exactly the runs where both new assertions PASS - a direct demonstration that the old one depended on sibling writes and the new one does not. sixty-five full-file runs, sixty-five green: twenty-five consecutive, and forty more run directly with test-threads eight under eight concurrent spinners, since the flake is scheduling-dependent - with the COUNT read every run, so a filtered-to-nothing ok could never read as a pass. the file has EIGHT tests rather than the five the ticket assumed, and exactly one ever read the global: five are library-only and WRITE it without reading it, and two go through a subprocess that carries its own static, which is why they never flaked. that is recorded as a SHAPE rather than as a list, because a list of safe tests is one added test out of date. and the residual is stated rather than buried: the mutation red is empirical rather than structural, since under the wrong build a sibling could in principle flip the global between the two adjacent calls - a false green under a DELIBERATE mutation, which is strictly cheaper than the false red on a correct build that this ticket exists to remove (#1864) 67d2b79e · dbf3dbe6…diff
  • a published speedup that exceeded a ceiling measured three paragraphs below it is WITHDRAWN rather than explained, and the instrument that measured the ceiling is REFUTED BY MEASUREMENT rather than by argument: a discarded second read_graph measures the MARGINAL cost of an extra decode while the pool is still alive, not the first call share - it reads 151.5 ms against a whole region of 148.4 on one after binary and 162.5 against 157.7 on a second, over 100 percent of the quantity it is a fraction of, twice, on separately built binaries. the replacement stops the function instead of doubling the read, and its bands SUM to the region: read_graph plus pool build 154.3 ms at 89.8 percent, walk and splice 16.2, objects and keyring 1.4, against a region of 171.9 - so the ~89 percent decode finding SURVIVES the loss of the instrument that first produced it, and on that pair the change removes 13.9 of the 16.2 ms it could touch, a delta that FITS. the magnitude itself is re-measured across 156 gate runs in one sitting on an idle machine, every run exit 0, discarded 0 batches, carrying a VALUE rather than reading skipped, with the harness own probe at 1 to 9 percent and no exit 3 or 4 anywhere: three independently built before-and-after pairs read minus 13.6, minus 8.1 and minus 10.6 percent at depth 1024, disjoint at both depths in every pair, with graph-load flat across the same invocations - so the answer is published as minus 8 percent conservative and about minus 10 middle, and the spread is the BINARY rather than the machine. the residual is stated and NOT reconciled: the clean pair 22.5 ms exceeds the 16.2 ms band it should sit inside, and the clean pair own band cannot be measured without making it un-clean, with corroborating evidence that the instrument perturbs what it measures - the stop-instrumented after binary reads a read-and-pool band ABOVE its own whole region, an early return costing more than the work it skips, six rounds out of six. what would settle it is named as an exact allocation counter over the region that no half records today, and it is left as instrument work rather than done here. the copy in the fixture now quotes NO figure at all, keeping only the shape, because a figure quoted anywhere else is a copy. the in-loop guard stops checking the OTHER guard than the one its prose names and is asked every rep of the position under measurement - proved by a mutation pair where a no-op ingest is caught RED at 156 passed 2 failed and, with the same guard disabled, GREEN at 158 passed 0 failed, which demonstrates the blindness rather than arguing it. the ADR masthead stops enumerating its own amendments and points at the inline marks that already carry their tickets, the fixture stops claiming the ancestry is the real path when its root is parentless and the walk stop predicate never fires, the Err arm stops asserting a merge as the cause it never established and hands over the selector quoted refusal instead, and the shallow header stops calling a convention mechanical when nothing enforces it (#1888) dc524dd2 · dbf3dbe6…diff
  • ADR 0089 records the shallow-clone decision #1527 declined to mint from a lane, and a push from a shallow position to a host that cannot be shown to hold the history behind the cut is refused before anything is sent. the cut is on the receiving side because a depth on the wire would be a FORMAT_MAJOR move; the price is the change lane metadata crossing once in full on the first round; the guard is a shape, measured at assemble and at apply_bundle_reaching and stated by main around the dispatch, with the #1828 correction recorded beside the enumeration it replaced; the notice rides stderr; and the refuted frontier-rides-the-closure claim is kept as refuted. each bullet was checked against the tree rather than the landing message, and two did not survive the check: the landing pinned no-depth-on-the-wire three ways and #1828 deleted the re-encoding one as unable to fail, so the ADR names the two that remain; and #1527 did touch loot-core, which the relay is built from, so the true sentence is that neither the wire crate nor a server crate moved. the push decision was measured first through the real binaries on this desktop: bob at depth 2 pushed to an EMPTY relay at exit 0 with pushed 6 new object(s), the relay took the lane because stow appends every node without asking after its parents and the forge parent_trees treats an unseen parent as no comparison, and carol cloning that relay came out shallow without asking, with doctor reading recorded by a bound this store no longer records and a remedy that host could not answer; pushing back to the origin relay with nothing new, with a new change, and after the origin moved on all succeeded and still do. the rule is frontier subset of declared union ancestor_closure(declared) over the pusher own graph, asked of /haves at a relay and /ref at a forge, ahead of /wants, the first disclosing request, and free on a complete position, which returns before any question is asked; the declared half of the union is for the host whose tip IS the frontier id, which the closure walk seed filter drops and which holds everything behind it. loot pull is named only when the host declares a head this position does not hold, the moved-on shape, and fetch --deepen all is named on every refusal; a host that cannot say what it holds is refused with its own words, the ADR 0084 fail-closed clause. nothing, a warning, a receiver-side refusal and an override flag are each rejected in the ADR with the reason. red first, three ways: the gate call removed reddens the two end-to-end pins (0 passed, 2 failed, the push exiting 0 as it did) and the forge pin (0 passed, 1 failed); the declared half of the union dropped reddens its own pin and leaves the three-shape pin green (1 passed, 1 failed); the pull remedy dropped reddens the moved-on pin and leaves the empty-host pin green (1 passed, 1 failed). the body-deferring filter is NOT done and is deliberately not decided in the ADR: the ticket itself calls it a ticket-sized change against ObjectStore that introduces a fifth absence state, and the coordinating session splits it into its own issue. CONTEXT.md Shallow position points at the ADR instead of restating the cut argument, and its not-yet-guarded paragraph is now the guard. no migration, no wire or format byte moves, and no forge or relay byte moves, so this owes no deploy. the workspace suite is green (3868 passed over 120 binaries, 7 ignored) (#1826) 7a09ceb6 · dbf3dbe6…diff
  • a fetch gains a depth the host honours: the request carries a trailing depth after its wants, written only above zero so a request at zero is byte for byte what every client sent before, and an old host decoder returns after the wants and never sees it, which is what makes it safe to send to any host; the relay and the forge confine the change lane to the nodes within that many generations of their live heads, one being the heads and nothing older, intersected with the delta past have and, on the forge, after the entitlement gate, so a caller refused metadata in a full bundle is refused it at any depth and a node the caller holds is never re-sent, while a want is answered by address whatever the depth, the lane walking the cut changes as it walks the held ones; the seeds are live heads and not childless ids, the forge reading the ref declared set a client computed with its retire applied and the engine excluding any version a node names as a predecessor, since on a host that ingests amends a superseded sibling stays childless and would otherwise seed a generation of its own, 213 such tips against 31 real on this repo; /info advertises it as fetch_depth, false when absent, so a caller that needs the bound refuses a host without it and a caller that can afford the fallback proceeds. the receiver still cuts and that stays the rule, ADR 0089 amended rather than overturned: pull_metadata_via and the depth round of a bounded pull ask the host for the depth they will keep, FromTips as its n and a deepen as zero since the frontier is this position own, and applies IngestDepth to whatever arrives, so a host that predates the field sends the history and the position is the same one generation deep, which the test relay pins both ways by playing a host that honours the depth and one that does not. the WASM core encodes the same bytes, frozen in the parity suite against the native vector at depth one. decided by a grill of six questions on 2026-09-20 and recorded on the ticket and in the ADR: bounded per invocation regardless of persistence, a depth on the existing fetch rather than a listing endpoint, counted from the host heads, search kept on the receiving side over bodies fetched by address, the host cut an optimisation the client never depends on, and the SDK and the cache cap to follow. this is the wire half of the browser SDK stopping its 53 MB stateless read and of the serverless runner per-job pull; measured against the live relay in the landing comment once the hosts are deployed. pinned on the same shapes at each host so the two walks are held to one answer, a chain at depths one, two and zero and past a have, a fork whose two heads are both seeds, a superseded sibling that never is, and depth zero byte-identical to the one-pass walk this walk replaced, the forge with a reader the gate refuses getting nothing at any depth; in loot-net on the field decoded both ways with an old body as zero, an odd remainder refused, a pre-field info as false and one frozen vector both encoders pin; over the wire on a spawned relay and a spawned forge each answering one node of two at depth one and advertising the cut, with a want riding across the cut; and in the CLI cache refresh asking depth one. a clone at a depth asks the host too, so its declined count is 0 under a host that cut, since nothing behind the cut arrives to be declined, and the frontier width is what says the position is bounded, which the shallow suite now pins against a host that honours the depth and one that predates it; the count stays exact on a deepen, which asks the host for no cut because the frontier it deepens from is this position own. red under mutation, counts read each time: the engine ignoring the depth (0 passed and 1 failed), the engine cut counting one generation too many (0 passed and 1 failed), the depth never written (1 passed and 1 failed), the depth never read (1 passed and 1 failed), the relay not advertising the cut (1 passed and 1 failed), the relay handler dropping the depth (0 passed and 1 failed), the forge ignoring the depth (0 passed and 1 failed), the forge cutting before the gate (0 passed and 1 failed), the forge not advertising the cut (0 passed and 1 failed), the cache refresh asking no depth (0 passed and 1 failed), the receiver stopping its own cut when the host cuts (0 passed and 1 failed), the wasm framing never writing the depth (0 passed and 1 failed), the forge handler dropping the depth (0 passed and 1 failed), the engine seeding from a superseded version (0 passed and 1 failed), the forge seeding from every childless id declared or not (0 passed and 1 failed), an odd remainder read as no depth (1 passed and 1 failed), and the wants lane skipping the cut changes (0 passed and 1 failed). no migration and no format major move: a trailing field the old side never reads is a minor move, and /info default false is the whole compatibility story; the relay and the forge owe a deploy, which the release cut carries. the workspace suite is green (4017 passed over 126 binaries, 7 ignored) (#2123) e3ddfdce · dbf3dbe6…diff
  • buoy joins the dispatch table and bisect is left alone on the early path with the only reason that is still its own: #1764 made an output shape able to carry its own exit code, which was the whole of why buoy was dispatched ahead of COMMANDS, so the arm is gone and cmd_buoy returns a shape like every other verb. emit::Buoy reads ADR 0025 exit codes off the BuoyVerdict it already holds, one arm per row of that table, so the rendered answer and the code are one decision and the empty porcelain of the none row cannot come apart from its 2; buoy --nearest carries its code as a value on the message instead, having collapsed to one token with no structure to read an outcome back off; and buoy_write is deleted rather than moved, because the dispatcher outcome was already byte-for-byte the same #870 rule about a reader that left early. everything that walked the table and the buoy spec separately now walks the table alone — the telemetry note_dispatched call, the machine-output census, the verb census, the documented-flag census, the template-flag census, help_for and the completion list — and nothing is counted twice: the telemetry report is asserted to say buoy once, the table is asserted to declare no name twice, the offered completion names are asserted to hold each name once, and the census sum is now an equality with the table rather than the table plus one. going through the argv door means declaring an arity, so exactly one invocation moved: loot buoy reviewed junk refuses by name and exits 1 where an open claim used to drop the word and resolve for reviewed, which is #1562 reaching a verb that had been standing outside the gate enforcing it. every code is pinned through the spawned binary in tests/buoy_exit.rs, each outcome in every rendering it accepts. red under mutation, counts read each time: the verdict codes flattened to zero (buoy_exit 4 passed and 2 failed, emit_snapshot 12 passed and 1 failed), Message::coded discarding the code it is handed (loot-cli lib 1334 passed and 1 failed, buoy_exit 5 passed and 1 failed), the early telemetry call put back beside the one in the table (telemetry 2 passed and 1 failed, reporting buoy three times for two runs), buoy pushed onto the completion list beside its own row (loot-cli bin 125 passed and 1 failed, buoy_exit 5 passed and 1 failed), the row declared twice (loot-cli bin 121 passed and 5 failed), the row declining its arity again (loot-cli bin 123 passed and 3 failed, buoy_exit 5 passed and 1 failed), and the census sum left at the table plus one (loot-cli bin 125 passed and 1 failed). ADR 0025 records where each code now comes from and the one that moved, ADR 0076 closes the open work it had recorded and narrows the early-dispatch path to bisect, ADR 0066 moves the split inside its dispatched total, and CONTEXT.md stops naming buoy beside bisect. no migration, no wire or format byte moves and no host behaviour moves, so this owes no deploy. the workspace suite is green (4058 passed over 129 binaries, 8 ignored) (#1976) fa68a7d3 · dbf3dbe6…diff

Renames are not followed. loot's tree maps a path to an address, so a rename is a delete and an add. This list is the history of the name, not of the bytes.