Changes touching this path

  • the repo never goes public, so the anonymous download path moves to R2 (#652) #652 recorded a gate: flipping this repo public discloses sealed docs/pitch/zk-host.md through PR #161 surviving refs/pull/161/head, verified live 2026-07-30. Re-swept today across 321 PR head refs (up from 242), two ways -- still exactly one carrier, unchanged. But the gate own remedy needs GitHub Support, is not self-service, and has no date. ADR 0045 stops waiting. The repo stays private permanently, and the anonymous artifact path moves to Cloudflare R2 at dl.millerbyte.com instead. Attestations are out rather than deferred; sha256 is the integrity story by decision. Build: #806 DNS zone move, #807 R2 artifacts, #808 installer retarget and the smoke test back on, #809 the Install page attestation claim. ADR 0037 is superseded in two places and docs/specs/loot-site.md in three, marked in place with dated blocks. The comments that called #652 a temporary gate now say permanent, and CONTEXT.md no longer calls the GitHub mirror public. 9a04ab6f · dbf3dbe6…
  • the ADR 0045 markers now carry the day they were actually written (#652) The supersession blocks landed in de79d39 were dated 2026-08-05. The work happened on 2026-08-07 -- the date was taken from surrounding context rather than from the clock. Ten markers across four files, including the two read-date citations on the Cloudflare documentation that settled the subdomain-setup and r2.dev questions, where when it was read is the whole point of recording it. Corrected: ADR 0045 (3), ADR 0037 supersession blocks (3), docs/specs/loot-site.md amendments (3), CONTEXT.md correction note (1). Untouched: the six other 2026-08-05 entries in CONTEXT.md, which belong to ADR 0044, ADR 0046, #39 and #621 and are correctly dated. 80d4409e · dbf3dbe6…diff
  • the ADR 0045 markers go back to 2026-08-05, which was right the first time (#652) 2f3c162 moved ten dated markers from 2026-08-05 to 2026-08-07 on the theory that they recorded the wrong day. They did not. de79d39, the commit carrying them, is stamped 2026-08-06T05:02:51Z -- which is 2026-08-05 23:02 local, and this repo dates its markers in local time. Two other landings from the same hour agree: ADR 0046 (f3f8a3d, 05:23Z) and the ADR 0015 amendment for #621 (f88cf89, 05:33Z) both read 2026-08-05 in CONTEXT.md. The 39-hour gap between that land and the correction was real elapsed time inside one session, not a clock defect -- a land taken immediately after the gap stamped within 22 seconds of the OS clock. The three doc files are restored byte-identical to the blobs de79d39 landed. CONTEXT.md keeps everything other sessions have added since; only its one date line reverts. 97218886 · dbf3dbe6…diff
  • #652 step 4 lands as accept, and the seal stays (#652) ADR 0045 deferred one judgement -- whether the 2026-07-30 window means docs/pitch/zk-host.md should be treated as disclosed. Resolved by grilling: accept the disclosure, keep the seal. The instrument was wrong first. loot burn does not apply: zk-host.md was never mis-sealed in loot, and the loot object is correctly restricted to this day. What leaked was the git PROJECTION -- a plaintext blob in refs/pull/161/head, which is not a loot object and which burn cannot address. ADR 0038 section 4 already drew that line, and it was still reached for wrongly during this very decision, so the amendment records it explicitly. Nothing is rotatable in ~1.6 KB of product thinking, so ADR 0038's accept-and-rotate resolves to accept, chosen rather than defaulted to. The empirical half is recorded as inconclusive rather than reassuring: the ticket's premise that the repo has no traffic is false for the exposure day (9 of 14 days sit at uniques=1 tracking CI exactly; 07-30 shows 64 clones from 17 uniques), a tag-push fan-out is a plausible benign cause, and the same model fails on 07-24. The raw capture is deliberately not landed -- bare numbers without the baseline read as an incident. The seal stays on an asymmetry: unsealing cannot un-disclose the blob but would disclose the whole directory going forward. CONTEXT.md's Restricted bullet gains the escape path it never named. e7963d9b · dbf3dbe6…diff
  • a lane carries its own hold, and custody crosses back whole at finalize (#811) 941cafb9 · dbf3dbe6…diff
  • you cannot build it from source, and the page says so: the Install page stops offering a command no reader can run (#841) `cargo install --git https://github.com/Connor-Miller/loot loot-cli` was labelled as needing read access to a repo that is not public — true, and still a command every reader of a public page is unable to run. Read strictly, #809 first acceptance criterion (no command on the Install page fails against the current release) was not met while it stood. Removed rather than relabelled, because the honest answer is a position and not a caveat: the source is private permanently (ADR 0045), so there IS no build-from-source route, and there is no source archive to fetch either. A labelled command reads as an invitation and pays out an error; a stated position lets a reader decide about loot instead of debugging their own access. What it costs is stated on the page rather than promised away — you are trusting bytes you did not compile — and the counterweight already exists and is now pointed at: every archive carries its SHA-256 in the all-platforms table, and Evidence (#840, which just made those receipts openable anonymously) carries the run output behind each claim. ADR 0045 gains the amendment the ticket asked for, because this is a consequence of that decision nobody had written down: the ADR moved the DOWNLOAD path to R2 and never said what happens to the BUILD path. It also records the only thing that would restore one — #672 crates.io naming call, which makes `cargo install loot-cli` work without the repo being public — and that a source tarball on R2 would be the wrong way to do it, publishing source through a side door of a decision that was about binaries. Verified: zero github.com anywhere in the built Install page, suite 77 passed | 23 skipped, build green. 5b43d681 · dbf3dbe6…diff
  • the crates.io door closes on a premise the ticket had backwards: only 3 of 13 crates refused to publish, so ADR 0045's stated position was held up by nobody having typed the command (#672) 36e46da6 · dbf3dbe6…diff
  • main stops carrying two ADR 0063s, and the forge door gets its own number back: a blanket renumber in #1048 rewrote citations that were never its to move (#1105) 1b8f3e8d · dbf3dbe6…diff
  • the docs gate themselves: a land refuses a link that resolves to nothing, five rotted ADR cross-links are fixed, every amended ADR warns in its status, and the artifact sweep retires with its producer 586e3260 · dbf3dbe6…diff
  • ADR 0099 records the move of loot from millerbyte.com to loot.build (map #2412): the site and one-liner at the apex with www redirecting, artifacts at dl.loot.build, the forge at forge.loot.build, security@loot.build through Cloudflare Email Routing with no catch-all, the relay not recreated, and the production Clerk instance on loot.build; and a hard cutover, the operator decision, in which the new names serve beside the old, a release carries them, every clone re-points its forge remote, and the old names are removed with no alias or redirect kept. it states what that breaks for anything made before it, read from the code: an opted-in old binary POSTs telemetry to the old name silently, so the old names must end NXDOMAIN rather than answered by the millerbyte.com wildcard, which would hand those reports to Vercel; old --help links; installers and manifests pinned to dl.millerbyte.com; the crates.io placeholders published with the old homepage, which only a new publish by the operator fixes; and it records the measured costs of the move (a 19.2 s first unlock on the new origin, no forge change because a signed request does not bind the host). ADRs 0037, 0041, 0045, 0049, 0061, 0064, 0066, 0067, 0074 and 0097, whose decisions name a loot host, each gain an amendment pointing here, and a banner where they had none; their bodies keep the names they were written with (#2414) bf2242c5 · dbf3dbe6…diff

Renames are not followed. loot's tree maps a path to an address, so a rename is a delete and an add. This list is the history of the name, not of the bytes.