Changes touching this path

  • the forge half of #2130: the owner files key-only sealed grants for a runner of the repo through POST /runners/deposit, behind require_pusher, and a runner reads one version through POST /jobs/fetch, behind its runner row. a deposit is a SealedGrant with an empty body, due now and without an expiry, sealed to a live runner of this repo; grant::parse_runner_deposit refuses the rest by name, every blob of a request is judged before any is filed, and a request carries at most 1024, which the client splits by. that makes migration 0026's refused at the door true, through this route rather than the store method it names. the fetch takes one version id, any the repo holds, and answers a Frame::Sync bundle with the version's change node whole and the ciphertext of each object inside the runner's path scope, not burned, that the runner can open by a deposit or a live published key, and the runner's grants for exactly the objects whose bytes ride; a scope narrows content and not names, since a node cut to it would not verify. loot_net::runners::in_scope is the one scope rule, an entry naming a file or a directory and never a bare prefix, and the add route's pipeline check asks it too. the store gains runner_deposits_for, one runner's deposits by object, on both backends. act tags 12 and 13, and an old forge's 404 names #2130. ADR 0091 records the routes and the two operator decisions, and CONTEXT.md the key-only deposit. red under seventeen named mutations, each restored, counts read each time: no body refusal and no expiry refusal (0 passed and 1 failed over the parser test), no future-reveal refusal (0 and 1 there, 13 passed and 1 failed over the route tests), and 13 and 1 over the route tests each for no grantee row check, a retired grantee admitted, each blob filed as it parsed, no require_pusher on the deposit, no batch cap, no scope filter, bytes riding without a key, and grants not narrowed to what rides, which first survived at 14 passed until the test gained a keyed file whose bytes are gone; the memory read ignoring the runner or unsorted (1 passed and 1 failed over the two stamps), the Postgres read ignoring the runner or ordered by blob alone (0 passed and 1 failed on a throwaway Postgres 18), and a scope entry matching a bare prefix and the old-forge sentence naming #2158 (10 passed and 1 failed over the runner codec tests). bash ci/local.sh is green against Postgres 18, 4653 passed over 143 binaries with 13 ignored and the site live suites at 78. no migration; new routes, so this owes a forge deploy (#2130) fffb0cca · dbf3dbe6…

Renames are not followed. loot's tree maps a path to an address, so a rename is a delete and an add. This list is the history of the name, not of the bytes.