Changes touching this path

  • #652 step 4 lands as accept, and the seal stays (#652) ADR 0045 deferred one judgement -- whether the 2026-07-30 window means docs/pitch/zk-host.md should be treated as disclosed. Resolved by grilling: accept the disclosure, keep the seal. The instrument was wrong first. loot burn does not apply: zk-host.md was never mis-sealed in loot, and the loot object is correctly restricted to this day. What leaked was the git PROJECTION -- a plaintext blob in refs/pull/161/head, which is not a loot object and which burn cannot address. ADR 0038 section 4 already drew that line, and it was still reached for wrongly during this very decision, so the amendment records it explicitly. Nothing is rotatable in ~1.6 KB of product thinking, so ADR 0038's accept-and-rotate resolves to accept, chosen rather than defaulted to. The empirical half is recorded as inconclusive rather than reassuring: the ticket's premise that the repo has no traffic is false for the exposure day (9 of 14 days sit at uniques=1 tracking CI exactly; 07-30 shows 64 clones from 17 uniques), a tag-push fan-out is a plausible benign cause, and the same model fails on 07-24. The raw capture is deliberately not landed -- bare numbers without the baseline read as an incident. The seal stays on an asymmetry: unsealing cannot un-disclose the blob but would disclose the whole directory going forward. CONTEXT.md's Restricted bullet gains the escape path it never named. e7963d9b · dbf3dbe6…

Renames are not followed. loot's tree maps a path to an address, so a rename is a delete and an add. This list is the history of the name, not of the bytes.