Changes touching this path

  • loot-site map #204: buildable spec + ADR 0037 (#211), installer integrity research (#221) Assembles the loot-site map into docs/specs/loot-site.md (the hand-off spec for loot.millerbyte.com), docs/adr/0037-loot-product-site-and-install.md (the product-site + install decision; renumbered from 0036 which the harbor took), and docs/research/windows-installer-integrity.md (the #221 TLS-only + attestations decision). Break-glass direct commit — the primary loot state is mid-reconcile (diverged heads from the #229 harbor land); the next ferry ingests this. c5e7f70a · dbf3dbe6…
  • the repo never goes public, so the anonymous download path moves to R2 (#652) #652 recorded a gate: flipping this repo public discloses sealed docs/pitch/zk-host.md through PR #161 surviving refs/pull/161/head, verified live 2026-07-30. Re-swept today across 321 PR head refs (up from 242), two ways -- still exactly one carrier, unchanged. But the gate own remedy needs GitHub Support, is not self-service, and has no date. ADR 0045 stops waiting. The repo stays private permanently, and the anonymous artifact path moves to Cloudflare R2 at dl.millerbyte.com instead. Attestations are out rather than deferred; sha256 is the integrity story by decision. Build: #806 DNS zone move, #807 R2 artifacts, #808 installer retarget and the smoke test back on, #809 the Install page attestation claim. ADR 0037 is superseded in two places and docs/specs/loot-site.md in three, marked in place with dated blocks. The comments that called #652 a temporary gate now say permanent, and CONTEXT.md no longer calls the GitHub mirror public. 9a04ab6f · dbf3dbe6…diff
  • the ADR 0045 markers now carry the day they were actually written (#652) The supersession blocks landed in de79d39 were dated 2026-08-05. The work happened on 2026-08-07 -- the date was taken from surrounding context rather than from the clock. Ten markers across four files, including the two read-date citations on the Cloudflare documentation that settled the subdomain-setup and r2.dev questions, where when it was read is the whole point of recording it. Corrected: ADR 0045 (3), ADR 0037 supersession blocks (3), docs/specs/loot-site.md amendments (3), CONTEXT.md correction note (1). Untouched: the six other 2026-08-05 entries in CONTEXT.md, which belong to ADR 0044, ADR 0046, #39 and #621 and are correctly dated. 80d4409e · dbf3dbe6…diff
  • the ADR 0045 markers go back to 2026-08-05, which was right the first time (#652) 2f3c162 moved ten dated markers from 2026-08-05 to 2026-08-07 on the theory that they recorded the wrong day. They did not. de79d39, the commit carrying them, is stamped 2026-08-06T05:02:51Z -- which is 2026-08-05 23:02 local, and this repo dates its markers in local time. Two other landings from the same hour agree: ADR 0046 (f3f8a3d, 05:23Z) and the ADR 0015 amendment for #621 (f88cf89, 05:33Z) both read 2026-08-05 in CONTEXT.md. The 39-hour gap between that land and the correction was real elapsed time inside one session, not a clock defect -- a land taken immediately after the gap stamped within 22 seconds of the OS clock. The three doc files are restored byte-identical to the blobs de79d39 landed. CONTEXT.md keeps everything other sessions have added since; only its one date line reverts. 97218886 · dbf3dbe6…diff
  • the one app serves from the VPS, and loot.millerbyte.com flips to it (#752) ca5f93ec · dbf3dbe6…diff
  • the site stops shipping 298 grammars to highlight two languages, and a three-line meta helper stops dragging fifteen more into the entry chunk of every page including the ones with no code at all (#1244) b06ca1b5 · dbf3dbe6…diff
  • loot 0.4.17: the Known Issues page is re-reviewed against the binary it now names, four entries move because their fixes shipped, and the land runbook learns that a skip drops three gates and not one 44de9890 · dbf3dbe6…diff
  • ADR 0099 records the move of loot from millerbyte.com to loot.build (map #2412): the site and one-liner at the apex with www redirecting, artifacts at dl.loot.build, the forge at forge.loot.build, security@loot.build through Cloudflare Email Routing with no catch-all, the relay not recreated, and the production Clerk instance on loot.build; and a hard cutover, the operator decision, in which the new names serve beside the old, a release carries them, every clone re-points its forge remote, and the old names are removed with no alias or redirect kept. it states what that breaks for anything made before it, read from the code: an opted-in old binary POSTs telemetry to the old name silently, so the old names must end NXDOMAIN rather than answered by the millerbyte.com wildcard, which would hand those reports to Vercel; old --help links; installers and manifests pinned to dl.millerbyte.com; the crates.io placeholders published with the old homepage, which only a new publish by the operator fixes; and it records the measured costs of the move (a 19.2 s first unlock on the new origin, no forge change because a signed request does not bind the host). ADRs 0037, 0041, 0045, 0049, 0061, 0064, 0066, 0067, 0074 and 0097, whose decisions name a loot host, each gain an amendment pointing here, and a banner where they had none; their bodies keep the names they were written with (#2414) bf2242c5 · dbf3dbe6…diff

Renames are not followed. loot's tree maps a path to an address, so a rename is a delete and an add. This list is the history of the name, not of the bytes.