Changes touching this path

  • the delta reaches the TypeScript SDK as a SHAPE rather than as prose, and it is the FIRST INSTANCE of #1763 rule rather than a bespoke design: DeltaShape::of is a PROJECTION of the seam and nothing else - the mark is the #306 gutter rather than a new alphabet, the rung is the LineDelta variant, the counts are its own counts and the tally is the disclosure verbatim - so nothing here was hand-designed and the shape cannot drift from what the human rendering shows. three decisions carry the weight. added and deleted are NEVER ZERO where the count is unknown, they are absent, exactly where --stat calls a row uncounted, and ONE function now feeds both channels so the two cannot disagree. a sealed row WITHHOLDS the path, the from-path and the recipient list in both channels, because a path name is CONTENT under #306 - the shape refuses to leak through the encoding what the prose refuses to print. and the machine channel is ONE SHAPE REGARDLESS of --content and --stat, verified byte-identical, because those flags pick WORDS over a delta while this picks an ENCODING of it. the contract number is the shared VERDICT_CONTRACT and not a per-verb one, which ADR 0023 already answered for every shape and #1516 declined explicitly for porcelain, and an SDK test asserts diff and status report the SAME number so a per-verb version would go RED. a defect was caught BEFORE the freeze, which is the only time that is cheap: the first encoder used to_string_lossy, so on Windows a FROZEN contract would have shipped a backslash path beside a human line printing a forward slash - caught by the pin that compares the two RENDERINGS rather than asserting each is non-empty, and its unit pin uses an EMBEDDED backslash rather than a nested path, because a nested-path fixture is vacuous on POSIX. wire names stay snake_case deliberately, since a camelCase mirror would be a second vocabulary for one frozen contract and the only thing it could do is drift. nine mutations with counts read, and the ceiling comes DOWN 57 to 56 - the first entry on that list to PAY rather than be excepted (#1554) ac5700af · dbf3dbe6…
  • a newline in a path does not LOOK WRONG, it FORGES ROWS - a name spelled notes.md then newline then percent then four numbers injects a SECOND DISCLOSURE TALLY, which is the number an agent reads before it asks for content - so porcelain WITHHOLDS an unframeable name rather than escaping it, refusing it, or leaving it to a sentence: path becomes dash, flags gains unprintable, and --json carries the name escaped. the three alternatives are rejected WITH REASONS AT THE SITE - documenting JSON as the only safe channel is the trade ADR 0082 already refused for CRLF, since a porcelain consumer has no way to DETECT it; escaping mints a second spelling of one path inside one tool, the #988 class whose answer was ADR 0051 ONE spelling; and refusing denies the OTHER rows, disagrees with --stat, and lets anyone who can name a file BLIND the machine channel. a tab is deliberately NOT withheld, because the path is last and the documented split recovers it - the rule is exactly as wide as the frame it protects - and with both withholdings flagged, a bare dash with NEITHER flag is now unambiguously a file NAMED dash. flags order is frozen as the encoder own, sealed first because it is the member a reader must not miss, and later members APPEND so every combination without a new one keeps todays bytes. and the run caught itself: #1554 re-created the class #1553 had fixed FIVE HOURS EARLIER, four pub items with zero out-of-crate callers, one of them a pub wrapper returning exactly what #1553 had narrowed to pub(crate) - the narrowing undone THROUGH A NEW DOOR - so all four are narrowed and the rule gains its worked example for the FUNCTION half, the half nothing enforces. the frozen shape description is corrected in four places, including a TypeScript doc that omitted the bare restricted token a peer-received path really carries, which would have mis-parsed in a consumer. the residue attribution in #1860 doc is WITHDRAWN rather than explained, restated as unexplained with what measuring it would take, because that document own thesis is that unmeasured causal claims about the instrument are the defect. eight mutations with counts read, four compile_fail probes with positive controls, and ONE MUTATION WAS CAUGHT BEING TOO WEAK - un-backticking a single table row left the pin GREEN, so it proved nothing and was redone against all four mentions (#1870) 3dfefe4f · dbf3dbe6…diff

Renames are not followed. loot's tree maps a path to an address, so a rename is a delete and an add. This list is the history of the name, not of the bytes.