Changes touching this path
- the persisted plaintext digest is REFUSED, and the ceiling is the decisive half: the ticket estimated roughly 250 ms and the measurement says 43.9. two knowingly-wrong binaries from one tree differing only in the mechanism, interleaved, twelve runs a side over four rounds on an idle machine - every loose read deleted reads minus 43.9 ms, and the read replaced by one stat per path reads minus 22.3, with the sets DISJOINT in every round and the bands SUMMING to the region, 22.3 plus 21.6 against 43.9 end to end. the stat arm is the honest ceiling under the never-authoritative rule, so a SOUND index tops out at 22.3 ms against a tier spread of about 13, BEFORE it pays to read, parse, look up and rewrite itself - and the stat does not even buy equivalence, being blind to rotted FRAMING, which decode_object refuses today and which is can_open answering false. the ticket carried both answers already: three paragraphs above its own roughly-250 figure it quotes #1591 measuring the span at 207 ms with ZERO object reads, and that is the reading this reproduces. the custody argument was written FIRST, before any code, and refuses on five grounds of which the first and the fourth are each sufficient alone. can_open needs the seal own vis and the grant state, and vis sits OUTSIDE the content address - sealed.rs pins that appending the world grant must not move the address - so an index keyed by the address is a cache WHOSE KEY DOES NOT DETERMINE ITS VALUE, justifiable only by nothing rewrites a vis today, which is the reasoning the ticket itself forbids. invalidation splits in two: correctness is cheap and DESTRUCTION is not, because burn leaves the change graph, the ids, the signatures and the keyring untouched, so after a burn the key is still held and a surviving plaintext digest is a CONFIRM-A-GUESS ORACLE over exactly what the burn destroyed - and erasing it means rewriting the index in EVERY position and on every peer honouring a purge, which an older loot would silently not do. object_store had already refused this shape in the module that would host it: a burn whose two lists disagreed is ciphertext coming back from the dead. the rotted case is not a fourth way to guess but something worse, because the digest was recorded while the bytes were readable and so is still RIGHT - same_content would call a path clean out of the index while surface propagates HeldUnreadable for the same address in the same tree, one tree and two books, the class #1581 closed three commits ago. and ADR 0004 deleted this field once already, behind a guard that is a claim about the STRUCT, so it stays green while the forbidden thing moves into a sidecar file: a pin defeated by RELOCATION. so what lands is the decision as ADR 0086, a positive control proving a fixture reaches the code at exactly 2N+1 gets and N reads against 1 read on the ceiling build, and one glossary correction - and what does not land is any index. two citation corrections ride along: the expired-grant trap is #20 rather than #536, and that trap is already OUTSIDE can_open, asked beside it as an in-memory manifest lookup costing no read (#1595)
d5f75151 · dbf3dbe6…
Renames are not followed. loot's tree maps a path to an address, so a rename is a delete and an add. This list is the history of the name, not of the bytes.