Changes touching this path

  • the loot-core tests stop sharing one repo and the shared store stops growing, and the design was already written one line above the bug: tmp said the temp root every fixture repo lives under while returning the root itself, so returning a fresh directory beneath a per-process root makes that sentence true as written with no doc edit and none of the 161 call sites changed. uniqueness is per call rather than per process, because the sites run on the harness's parallel threads inside one process, which is the half a pid does not touch and the half the isolation gradient had already separated - lib alone green, workspace red. a third hole neither ticket named is the larger one: 48 sites spelled DagRepo::init with the bare temp dir longhand, bypassing the helper entirely and invisible to both tickets, so the real set is 51 statements and not the sixty a three-line window had suggested - established by reading whole statements, since that window reads past short ones and stops short inside this crate's many multi-line format calls. the evidence is a paired experiment rather than a green run: two concurrent processes reddened object_reads five times in five, asymmetrically with the earlier starter losing every time, while the shared-store half needed six concurrent runs to reproduce at all and then failed 28 of 36 across four test names, two of them never recorded before, which is the fifth and sixth name for a ticket whose own point is that the name is not stable. after, the same experiments are ten of ten and thirty-six of thirty-six green, and a paired count on an idle machine has the unfixed arm adding 44 objects and rewriting graph, keyring and heads while the fixed arm moves nothing, byte-identical with mtimes unchanged to the millisecond. a census derives the property from source with no allowlist and was proved red four ways, including one site from the third hole that any list written from the two tickets would have passed, and including the census blinded, which reported ok on an empty set and was caught only by its own non-vacuity guard (#1667, #1688) 87c3aacb · dbf3dbe6…
  • a census door is one statement rather than one line, a transfer budget can no longer round below its own floor, and the pool split by body size is measured before it is kept: loot-cli temp_root_census read a forwarder as a body of two lines, so spawn_lane was a door only because its arguments happened to fit on one, and wrapping that call took it out of the door set with every site that reaches a refusal through it, while the property test stayed green and the only thing that fired was the blind-instrument clause naming workspace harbor.rs, which is a fact about where #2113 was found rather than a reading of what a door is; measured, the wrap took the walk from 26 door calls over 10 files to 24 over 9, and with the fix in place the same wrap reads 26 over 10 again. a body is now the one statement its lines join into, however many lines the arguments take, and a forwarder whose call is wrapped joins the fixture the file supplies, while a statement spelling a brace of its own stays outside the set the way the line count left it, said where a reader meets it. transfer_budget tested the floor in milliseconds against zero, so the branch written for a floor that cannot be stepped in fired for every floor under a millisecond and handed back the bytes own whole seconds, which is Duration ZERO for any body under an uplink floor and therefore below the floor rather than above it; the step is read in nanoseconds now, the resolution a Duration keeps, and the budget is built from nanoseconds rather than by multiplying the floor by a count that has to fit a u32, with the pin widened from the one floor where the old reading held to a run of floors from a nanosecond up. the pool keyed by transfer budget was decided on a measurement rather than on prose: a push shaped run of a probe, batches at the cap a push fills to and a short remainder keys two budgets and opens two connections at a host that counts them, so the repeated full batches share a pool and the bill is one connect per extra size class, once per host per process and never one per request, against the 160 ms a fresh HTTPS connection costs on the live hosts; keying on something size independent was checked against the vendored reqwest 0.12.28 and is not on offer, because a request own timeout becomes the async side total limit and is handed to the response body, which is #2064 exactly, and read_timeout lives on the async ClientBuilder alone and nowhere under blocking, so the choice is this keying or no per transfer budget at all, and the narrowing is now said at the client instead of waiting to be rediscovered. store_rename_census keys a row on a fn name where Rust makes a name unique inside an item scope rather than inside a file, so rather than read scopes textually and risk putting a wrong function name in a table that exists to be read by review, the case is held out of reach by a guard refusing a rename that sits in a name its own file declares more than once. the readings that had grown byte identical copies across the censuses, the source walk, the comment stripper, the qualifier test and the function header reader, now live in one file every caller compiles, by path across the package boundary the way loot-first already reaches loot-perf, and loose_object_removal_census gives up its narrower header reading for the shared one, which moves nothing in its expected set. loot-core temp_root_census gains the membership rule its what it cannot catch list had been standing on without one. red under mutation, counts read each time: the line count reading put back into sole_statement (2 passed and 1 failed), the step read in milliseconds again (0 passed and 1 failed), the pool keyed on a constant so one connection serves both classes (0 passed and 1 failed), no pool at all so five requests open five connections (0 passed and 1 failed), a second archive_keypair declared beside the renames in loot-identity (3 passed and 1 failed), and the shared qualifier test made to read no bare word, which reddens two packages from one edit (1 passed and 2 failed in loot-cli, 1 passed and 3 failed in loot-core). no migration, no wire or format byte moves and no forge or relay byte moves, since the budget arithmetic is entirely on the client side of the transport, so this owes no deploy. the workspace suite is green (4013 passed over 125 binaries, 7 ignored) (#2126) c5061276 · dbf3dbe6…diff

Renames are not followed. loot's tree maps a path to an address, so a rename is a delete and an add. This list is the history of the name, not of the bytes.