Changes touching this path
- the owner side of a proposal is decided, and only one of ADR 0075 three terminal states had a producer: close_proposal accepts withdrawn, declined and landed and both stores implement it, but its sole non-test caller is propose::withdraw and every other call site is a test or a conformance case, while propose::list had no caller outside its own tests and propose::read only handle_propose_withdraw, so an owner could not see, decline or land anything and the half of ADR 0075 naming their acts was unreachable rather than undecided. landing stays LOCAL and the forge only observes, foreclosed three independent ways rather than by preference: the forge would have to mint a HeadDeclaration carrying generation_expected, which is the one artifact this design has a client sign; ADR 0091 decides the forge runs nothing because it holds ciphertext and cannot run a step over a sealed path, and a land is a converge plus a gate; and a runner cannot stand in because ADR 0091 puts it under no account, so both write doors refuse it by absence. ingest closes the row pre-computed OUTSIDE its transaction, because IngestTxn is assembled and validated outside so the transaction is pure writes after the CAS, and that same CAS is what makes the pre-computation sound rather than racy, generation_expected pinning the very head set it assumed. the decline binds the repo, the change id AND the tip, the tip because re-proposal after a decline is permitted and a captured envelope must not end a revised one. the read surface is two transports sharing no path, the CLI over HTTP and the site over Postgres barrier views, so both are owed and a conformance pin demands that visible_to and the views answer with identical row sets, or the web discloses what the CLI conceals and nothing fails. the presenting key is world-visible and the propose-time disclosure now says so rather than naming existence alone. and one consequence of this ADR was WRONG: landing a proposal does not take policy::approval off its SelfAuthoredFastPath arm, because that function compares a GitHub PR author login with the GitHub account running the land and reads the loot change author nowhere, so an owner opening the PR keeps the fast path and a stranger code lands on the weakest approval signal with nothing in the gate knowing it was not theirs, which is why a distinct owner-signed review/approve role is required rather than the question handed to map #1014. ADR 0091 gains the landing policy home and the second human role, CONTEXT.md and spec section 7 gain the owner acts, graduated as #2174 through #2178 with #2180, #2181 and #2182 filed beside them. docs only: no code, no migration, no wire or format byte moves, so this owes no deploy (#2162)
31ecdf50 · dbf3dbe6…
Renames are not followed. loot's tree maps a path to an address, so a rename is a delete and an add. This list is the history of the name, not of the bytes.