Changes touching this path
- the push-time deposit plan asks the seal which lane a path belongs in, so a lying tree entry can no longer move a key between the internal and restricted lanes, and the bound the deferral rested on turns out to be false: #2187 asked for the key-not-tier claim to be tested before anything was built on it and it does not hold, because the Escrow is where the doors that read the seal own vis file an embargoed key and neither grant-apply door does - a tag-1 bundle files straight into the keyring with no embargo question asked at all, and apply_sealed_grant files by the frame reveal_at rather than the seal one, which is that verb recorded cooperative-defence posture - so a position keyring can hold the key to a live embargo and keyring.holds was never the guard that sentence said it was, pinned now rather than described. the cost was measured here rather than imported from #2196, whose zero was its projection already-open object: the question is asked behind the key guard, so it is one store read per row a lane returns and not one per finalized-tree path as the deferral estimated, and 64 held internal rows cost 64 object gets and 64 disk reads alone against zero disk reads behind a push, because a change node carries a full manifest and ride_entry has already opened every one of those addresses by the time push_with reaches the deposit plan. a disagreement withholds rather than substitutes or refuses: filing the path under the tier the seal records would move an embargoed seal into the timed lane, whose rows are crossed with every registered peer, and refusing would stop a push over an entry its operator may not have written. the comparison is std::mem::discriminant and never an equality, because #521 keeps holder names local so a wire-redacted restricted entry over a seal this repo persists the name in is the ordinary case and not a lie, and a tier added to Visibility needs nothing there; an unreadable seal keeps the row on embargoed_paths own permissive arm and its defence, grant_sealed refusing on the same address, which is what keeps a rotted object from costing a second machine the standing self-grant it opens the path with. a counted note beside the DepositPlan embargo one was weighed and declined: it would need each lane to hand back what it withheld as well as what it kept, for a state an honestly captured tree cannot enter. red under mutation, counts read each time: internal_paths no longer asking (70 passed and 3 failed), restricted_paths no longer asking (72 passed and 1 failed), the tier comparison made an equality (72 passed and 1 failed, the wire-redacted row dropped), the unreadable-seal arm made to drop (72 passed and 1 failed), the seal question moved ahead of the key guard (72 passed and 1 failed, object_gets reading 65 where 64 belongs), the fixture embargoed seal made unproducible (72 passed and 1 failed, the vacuity control firing) and the tag-1 door given an embargo gate (72 passed and 1 failed), each restored to 73 passed and 0 failed. the census row keeps its class and stops calling the widening unmeasured, and ADR 0012 takes a tenth amendment recording the direction, the measurement and the refuted bound. no migration, no wire or format byte moves and no host behaviour moves, but which keys a push deposits moves on the client, so this rides the next release and owes no deploy. the workspace suite is green (4127 passed over 132 binaries, 8 ignored) (#2187)
51ebdcfd · dbf3dbe6…
Renames are not followed. loot's tree maps a path to an address, so a rename is a delete and an add. This list is the history of the name, not of the bytes.