Changes touching this path
- the KEYRING IS A CACHE, NOT THE GATE, and the reveal comparison is asked at every read off the sealed object own header rather than inherited from whatever a persisted keyring happens to hold. #1488 repaired the un-promoted state and left the other one: flush PROMOTES AND NEVER DEMOTES, and the promotion persists, so at a clock short of reveal_at a never-promoted repo REFUSED and an already-promoted repo GRANTED - one input, one clock, two answers, in the direction that ticket own done-bar calls worse than the bug. the sweep claim was REPRODUCED BEFORE ANYTHING WAS FIXED, twice: swapping the two arms of the old pin reddens its control, and two fresh repos differing ONLY in whether a flush ran first answer granted against Unauthorized. grant now reaches its object and key through ONE PRIVATE DOOR that flushes, looks the key up, then asks sealed can_open - which is open steps 1 and 2 VERBATIM, so the gate is the SAME FUNCTION a plain read uses and cannot drift from it. demotion was rejected on merits rather than taste: it would need the escrow to retain an entry it has HANDED AWAY, it would make a READ MUTATE CUSTODY BACKWARDS, and it would be one more copy of a rule vis already carries. the refusal stays Unauthorized deliberately, because rotate_regrants classifies by VARIANT and an Embargoed would turn a skipped standing embargo into a FAILED ROTATION WAVE. the doc defect is repaired where it actually sits: membership of the flush census is NECESSARY AND NEVER SUFFICIENT, since a flush repairs only the un-promoted arm, and the #1488 amendment now records the invariant it kept rather than the one it claimed. reachability is reported honestly rather than dramatised - a forward-only wall clock CANNOT reach it, because a promotion requires the clock to have passed reveal_at, so it needs a now BEHIND a clock at which a promotion already happened: the engine API directly, where a perf harness already passes a backdated now, or a backwards wall clock, which is ADR 0007 own D-threat. the structural violation is unconditional and is where the claim is made and measured. three mutations, and the two halves fail in OPPOSITE directions: removing the gate reddens the new pin and the re-pinned control while the rotation pin stays green, removing the flush reddens the two due-direction pins while the new one stays green - which is the separability #1488 lacked. and one limit is stated rather than dressed up: the both-ways-round half builds a fresh repo per arm, so no mutation can redden only the second run, and the doc says so (#1840)
ae911b61 · dbf3dbe6…
Renames are not followed. loot's tree maps a path to an address, so a rename is a delete and an add. This list is the history of the name, not of the bytes.