Changes touching this path

  • day 0: loot hosts loot f4c30e75 · dbf3dbe6…
  • evidence: crew minted and verified (#86) 1fada823 · dbf3dbe6…diff
  • normalize working tree to LF: byte-stable co-located bridge (.gitattributes -text) e58fdda6 · dbf3dbe6…diff
  • content whose embargo has already lifted stops reading as sealed, because promoting due keys out of escrow is now the construction of the reader every content read hangs off instead of a doc-comment obligation six callers hoisted by hand, and deleting four of those hoists left all 2438 tests green while loot surface told an author to request a grant from herself (#1464) e59e46b3 · dbf3dbe6…diff
  • delta_of's modified arm stops reporting a due-embargoed path nobody edited as an uncaptured edit that wedges every #436 clobber-guard verb, because the base read it decides on hangs off the promoting reader its sibling arm in the same match already used instead of the bake-off trait's frozen public door, and ADR 0007 stops claiming a compiler forbids that spelling while the shipped tree held one (#1471) fbd758fe · dbf3dbe6…diff
  • three claims stop outrunning the code they describe, because ADR 0007's escrow census is now the output of a grep the ADR states rather than a list someone re-derived and left two files short, `Args::any_path`'s short circuit now runs above the ancestor walk it always claimed to skip and is pinned as a walk that does not happen, and CONTEXT's settle count now names the unit it counts — which is what made a number that was right read as wrong (#1482) bd385596 · dbf3dbe6…diff
  • loot migrate and loot maroon stop refusing an author's own revealed content as unauthorized, because the two re-seals promote due embargoed keys at their own first line instead of borrowing one from a capture that --no-snapshot skips outright and that an unchanged working tree short-circuits past before the engine is ever called (#1485) 34b5bb79 · dbf3dbe6…diff
  • the reader seam's own doc stops telling a loot-core author that content can only be read through it, because the sentence #1464 wrote into four places and #1471 corrected in three is now enumerated in ADR 0007 as one thing that changes together, and spawn.rs likewise stops claiming every command every gate runs while GATES row 0 shells out to git beside it (#1486) b6657789 · dbf3dbe6…diff
  • grant promotes at the clock it grants at, and the conservative alternative turns out to be an ORDERING ARTIFACT rather than a policy: skipped_unheld recorded only whether some earlier command in the repo whole history happened to open a reader, so one input at one clock gave two answers, and no state anywhere expresses that a reader has revealed an embargo. the flush goes on grant first line and rotate_regrants inherits it BY CONSTRUCTION rather than by a second flush, because it reads no content key except through self.grant - so the two cannot drift apart the way four hand copies of one body did. grant_sealed gets NOTHING and the ticket premise is refuted there: its keyring-OR-escrow lookup is already order-independent, which is why its pin was the one GREEN BEFORE THE FIX, and that measurement is recorded rather than a flush added to make the set look uniform. the eager direction, promoting a not-yet-due key, is not expressible through this seam because a flush IS the reveal gate applied - Escrow::flush now >= reveal_at is sealed::open own comparison. what WOULD be a hole is an escrow FALLBACK that skips the gate, which grant_sealed has deliberately for ADR 0027 timed deposit and grant must never copy, since a tag-1 bundle is a plaintext key in a file. the cost is asymmetric and lands on rotation: a grant dropped from the loot id rotate wave is access PERMANENTLY LOST, and the report line about what the outgoing key can no longer read was false for a due embargo. three pins, ONE REPO PER ARM because Escrow::flush promotes EVERY due entry and a second embargoed path in one repo makes the second arm vacuous - the trap #1485 hit - and both clocks pinned on each, since a fix that reveals early is worse than the bug. four mutations make the case: deleting the flush reddens grant AND rotate, which is what proves the by-construction inheritance, and giving grant the escrow fallback reddens the CONTROL arms instead. the caller list on flush_due_keys stops being a hand-written count and becomes a membership rule with a grep census, which is what kept it right while it gained a caller (#1488) 1d44cc64 · dbf3dbe6…diff
  • the KEYRING IS A CACHE, NOT THE GATE, and the reveal comparison is asked at every read off the sealed object own header rather than inherited from whatever a persisted keyring happens to hold. #1488 repaired the un-promoted state and left the other one: flush PROMOTES AND NEVER DEMOTES, and the promotion persists, so at a clock short of reveal_at a never-promoted repo REFUSED and an already-promoted repo GRANTED - one input, one clock, two answers, in the direction that ticket own done-bar calls worse than the bug. the sweep claim was REPRODUCED BEFORE ANYTHING WAS FIXED, twice: swapping the two arms of the old pin reddens its control, and two fresh repos differing ONLY in whether a flush ran first answer granted against Unauthorized. grant now reaches its object and key through ONE PRIVATE DOOR that flushes, looks the key up, then asks sealed can_open - which is open steps 1 and 2 VERBATIM, so the gate is the SAME FUNCTION a plain read uses and cannot drift from it. demotion was rejected on merits rather than taste: it would need the escrow to retain an entry it has HANDED AWAY, it would make a READ MUTATE CUSTODY BACKWARDS, and it would be one more copy of a rule vis already carries. the refusal stays Unauthorized deliberately, because rotate_regrants classifies by VARIANT and an Embargoed would turn a skipped standing embargo into a FAILED ROTATION WAVE. the doc defect is repaired where it actually sits: membership of the flush census is NECESSARY AND NEVER SUFFICIENT, since a flush repairs only the un-promoted arm, and the #1488 amendment now records the invariant it kept rather than the one it claimed. reachability is reported honestly rather than dramatised - a forward-only wall clock CANNOT reach it, because a promotion requires the clock to have passed reveal_at, so it needs a now BEHIND a clock at which a promotion already happened: the engine API directly, where a perf harness already passes a backdated now, or a backwards wall clock, which is ADR 0007 own D-threat. the structural violation is unconditional and is where the claim is made and measured. three mutations, and the two halves fail in OPPOSITE directions: removing the gate reddens the new pin and the re-pinned control while the rotation pin stays green, removing the flush reddens the two due-direction pins while the new one stays green - which is the separability #1488 lacked. and one limit is stated rather than dressed up: the both-ways-round half builds a fresh repo per arm, so no mutation can redden only the second run, and the doc says so (#1840) ae911b61 · dbf3dbe6…diff
  • a prose pass narrows claims that read wider than the code, and LineDelta::rendered goes crate-private. ADR 0007, CONTEXT.md and the object_and_key_at doc say the reveal gate is asked at every read through the grant key door, not at every read, since grant_sealed keeps its escrow fallback by design; the Refit enum count, the family list in CONTEXT.md and the refit.rs header, and a stale claim that every planner runs the draft check, now point at the enum and the wildcard-free minted_edges match instead of a count; role_display gets back the blank doc line rustdoc folded into the last bullet, verified in the built HTML, and a record type added to ReservedRecord replaces a third record type; the Landmark entry records the one-line rendering from #1519; the revset named door and the hunkpick PATCH constant state the exceptions a reader finds (grep writing its own refusal, restore spelling -p out under the main.rs census); the ChangeGraph insert doc stops saying the callers do not insert parents-first, names DagRepo::apply_sync for an apply_bundle DagRepo does not have, and says why the ordered ingest_shared_lineage splice stays on insert; ADR 0023 now says what #1870 wrote in the delta_shape header, that the reveal_at split is about the field and not the number, which embargoed@ can carry. nineteen assertion messages lose the run of spaces a rewrap left inside the literal. LineDelta::rendered and Rendered become pub(crate), with a compile_fail probe and a positive control: the probe was red before the narrowing (2 passed, 1 failed), and making the method pub again reddens it (3 passed, 1 failed). items 2, 8 and 14 need no fix here: the #1515 raise is real because #1516 lowered the ceiling between the two raises, #1968 dropped the width narrative, and #1860 withdrew the figures. cargo doc warnings are unchanged for loot-core, loot-codec and loot-cli. no migration, no wire or format byte moves, and no forge or relay byte moves, so this owes no deploy. the workspace suite is green (3913 passed over 123 binaries, 7 ignored) (#1848) eb966bdb · dbf3dbe6…diff
  • both grant doors weigh the seal before they choose a lane, so an early-releasing sender can no longer file a live embargo key into a receiving position Keyring: #2205 asked for every premise to be re-verified on the tree first and each of them held, a tag-1 frame asking no embargo question at all and a tag-3 grant filing by the frame reveal_at, which is the sender word, so at a clock of 0 against a seal recording Embargoed reveal_at 9_000 both doors left keyring.holds true and escrow.holds false. the framing question is answered where a reader meets it rather than inherited by proximity: which lane a key waits in is decided once, at the door that files it, because a route carrying a key from one position custody to another reads one lane and writes the same one and Escrow::flush promotes but never demotes, so a filing is the answer every position that key later reaches inherits with nothing re-asking, and ADR 0007 states its guarantee over identities rather than over one door, which makes a door that does not ask a gap in it rather than the Escrow scope. one rule in one body, because two doors asking one question in two places is how they come to disagree about it: a grant-borne key is staged until the latest instant any party to the handoff named, so a party added later is another term of the same max rather than another arm. a disagreement withholds rather than refusing or dropping, refusing costing a recipient a grant over a claim they did not write with a remedy that is not theirs to act on, and taking the seal instant alone being strictly weaker, because a grantor own delay over content under no embargo is ADR 0027 timed deposit and a seal contributing 0 would release it on arrival; withholding costs only the wait the seal already imposes on every reader of those bytes, sealed::open embargo gate refusing them at that clock whichever lane the key sits in. the seal is read back from this store and never off the arriving bundle, because the address does not cover vis and put is first-write-wins, so weighing the incoming copy is reading the sender word a second time under another name, pinned on a fixture whose lying copy keeps the address and is therefore a dedup. the two doors get one answer for two reasons and the difference is recorded: tag 3 had a recorded cooperative-defence posture and this applies it to a second party, which is why ADR 0007 takes a #2205 amendment, while tag 1 had no decision at all, existing to bypass the entitlement question and having taken the embargo one with it, which sealed::open first gate separates in four words, time not identity. the cost is measured rather than assumed: one object get per key the door files and zero disk reads where the grant carried the object its key is for, eight keys costing eight gets beside a ninth address the same bundle carried no key for. red under mutation, counts read each time: the seal term dropped from the staging max (654 passed and 3 failed), the tag-1 door reverted to filing into the Keyring (654 passed and 3 failed), the frame term dropped (655 passed and 2 failed), the staging comparison widened to greater-or-equal so an undue key stages (653 passed and 4 failed), the seal weighed off the bundle copy rather than this store (654 passed and 3 failed, the held-seal pin naming the lane), the question moved ahead of the key guard (656 passed and 1 failed, object_gets reading 17 where 8 belongs), and each of the two fixtures inverted as a vacuity control (656 passed and 1 failed, the control firing), each restored to 657 passed and 0 failed. ADR 0012 takes a twelfth amendment recording that this class is a sibling of its own, the disagreement being with a frame rather than a tree entry so no census row moves, and that keyring.holds is still not a bound, a key some door filed before this change being in .loot/keyring still. no migration, no wire or format byte moves and no host behaviour moves, but which lane a grant-borne key is filed into moves on the client, so this rides the next release and owes no deploy. the workspace suite is green (4131 passed over 132 binaries, 8 ignored) (#2205) ec80ad4d · dbf3dbe6…diff
  • the sync ingest door weighs the seal this store holds rather than the one that arrived beside the key, so a tag-0 bundle spelling a weaker tier at an address this position already owns can no longer file a live embargo's key into the Keyring: #2212 asked for item 1 to be demonstrated before it was repaired and the reproduction read exactly as the ticket claimed, bob holding oid sealed Embargoed 9_000 and a Sync frame carrying a byte-identical object that spells vis Internal beside the real key leaving bob's Keyring holding that key at a clock of 0, which is the state #2205's own new pin forbids reached by changing the frame tag, no plaintext escaping because sealed::open's header gate still refuses. the same read carries grant_ids and that half was demonstrated too, a copy spelling the ANYONE marker over a held Restricted seal getting a key past the entitlement filter #864 built, so every question this door puts to a seal now goes to the copy that will stand at the address. it is asked before the put while the arriving object is still in hand, because first-write-wins makes the held copy the standing one only where the store holds the address at all, so the cost is zero store reads on a fresh address and one on a dedup, which is the read the key verification already owed and now answers the seal's questions with its own; the already-held guard consults both lanes, so the lane the first door chose is the one that stands. the prose is the harder half and the lesson is sharper than do not list members: the sentence that failed was in the correct derived shape, the set of them is Keyring::insert's callers which the compiler enumerates, with a hand-maintained count welded on in the same breath, and the count is the half that was wrong, so every replacement names what decides membership and stops there, at ADR 0007's amendment, escrow.rs, CONTEXT.md, custody.rs twice, ADR 0012's tenth and twelfth amendments, negotiation.rs and the grant-door pin, and escrow.rs's headline stops claiming that no route moves a key between lanes when flush is one and a grant is a new filing at the recipient rather than a carry. secondary items: the stale pin citation and the now-false claim around it, spawn.rs's three false statements about the orphaned child, the unproducible-seal fallback recorded as releasing nothing only at the instant it files, expires_at declined as a term of the staging max with the reason at the code, the demotion refusal naming which of the two recordings fired, the census group sentence that named its members, ADR 0012's push qualifier at the tip with no want, the ingest cost fixture given a publishes-nothing control, workflow.md's three refusals derived from CargoTestFailure and the PRE_LAND constants, a usize subtraction restated as a sum so the sentence beside it can print, and orchestrator.rs's tombstoned pin names declined with the reason. red under mutation, counts read each time: the vis term reverted to the arriving copy (659 passed and 1 failed), the grant_ids term reverted (659 passed and 1 failed), the already-held guard narrowed to the one lane it writes (659 passed and 1 failed), the seal question asked through a second store read (659 passed and 1 failed, object_gets reading 8 where 0 belongs), the lying sync copy made a different object (659 passed and 1 failed, the vacuity control firing), the lying grant ids made to agree (659 passed and 1 failed, the second vacuity control firing), the publishes-nothing control inverted (1353 passed and 1 failed), the refusal made to say both either way (1352 passed and 2 failed) and the ingest cost relation moved by one (1353 passed and 1 failed), each restored to 660 and 1354 passed with 0 failed. no migration, no wire or format byte moves and no host behaviour moves, but which lane a sync-borne key is filed into moves on the client, so this rides the next release and owes no deploy. the workspace suite is green (4140 passed over 132 binaries, 8 ignored) (#2212) c643aadc · dbf3dbe6…diff
  • the arc's one self-contradiction is gone and its newest list shape is answered wherever it stands: #2214 asked for every premise to be re-verified on the tree first and items 1-5 all held, and two sites the ticket did not cite held with them plus one list that was already stale — ADR 0007's own #2205 header carried both the hand-maintained variant count and a second copy of the false carry claim, and the impl doc over the store door named the ingest paths where the chokepoint property would have named itself, missing the tag-1 grant door and put_published. the self-contradiction is ADR 0012's twelfth amendment, which #2212's commit message lists as corrected and which it edited one clause later, still saying a crossing between positions carries a key into the lane it is already in while ADR 0007 and escrow.rs both say a grant is a new filing at the recipient that reads the seal and answers for itself; the clause is deleted with the false reason named rather than quietly dropped, because the surviving conclusion has to be seen standing on what an older binary already wrote and on the absence of any route that takes it back out. the sharper lesson is item 4's and it is sharper than do not list members: the sentence that failed was already in the correct derived shape, and a count welded on beside it in the same breath was the half that went stale, so every replacement says what decides membership and stops there — store's call sites are the ingest paths and the compiler enumerates them, file_granted_key's call sites are the Frame variants that carry a grant, and the headline over the grant-door pin stops counting the doors it drives. secondary items: the store door's promise that a garbage key is rejected rather than filed is narrowed to the held-address arm with the fresh arm's literal true named as vacuous where a reader meets it, the carry definition stops being true by construction and says what a carry does to the lane so its own falsifier lands on that axis, the three co-travelling seal facts become a Weighed struct whose third field is named for what both arms make it, embargo_reveal_at delegates its Visibility half to embargo_instant so Embargoed is destructured for an instant in one place and the zero belongs to whoever asks for a number, the demotion refusal spells every bool pair and returns the name from the match so no arm asserts a pair it cannot be reached with, embargo instant becomes the glossary's reveal_at, the 127-character ADR line is rewrapped, and the one-address sync fixture preamble collapses into sync_of_one. red under mutation, counts read each time: the entry arm of the demotion refusal made to say the seal (2 passed and 1 failed), embargo_reveal_at's collapse moved off zero (655 passed and 5 failed) and the fresh arm's unrefuted made false (523 passed and 137 failed), each restored to 3 and 660 passed with 0 failed. no migration, no wire or format byte moves, no host behaviour moves and nothing an operator or a client can observe moves, so this rides the next release and owes no deploy. the workspace suite is green (4140 passed over 132 binaries, 8 ignored) (#2214) ea968e98 · dbf3dbe6…diff

Renames are not followed. loot's tree maps a path to an address, so a rename is a delete and an add. This list is the history of the name, not of the bytes.