Changes touching this path

  • the Tickets view on the private workbench, verdict E of #2411 (ADR 0094, ADR 0098 §1): a view module, its VIEWS line, routes for tickets, tickets/<id> and tickets/q/<query>, and a read route, /api/private/tickets, that answers the files the forge head holds under tickets/ as paths and addresses and each ticket path first touch in the head history with its generation. the browser fetches the objects from the forge by address, opens them with the session keys and folds them in wasm with loot_ticket::fold, the fold loot ticket now folds through too, moved out of loot-cli (ticket_read.rs: readTickets, ticketWants, ticketKinds), so the web reads a ticket as the CLI does and in the same causal order. the page is the conversation page for every ticket and map, a timeline ending in the resolution card, a comment and resolve composer and a right rail; the panel with search, saved views, maps, labels and kinds; and on a map a Conversation and Board switch whose board lays out Waiting, Frontier, In a lane and Resolved under the decisions so far, where a drop onto a card is a wait-on. sealed tickets are withheld rows, and each control names its loot ticket command. a write publishes one change through the SDK publish, now publishTicketWith over an injected core (sdk/src/ticket-publish.ts, assertStowAccepted moved to stow.ts); the pending bar holds writes in flight, and a collision shows both versions and asks. a session whose key is not the namespace owner reads, and lanes, which the web cannot see, are said to be so. connect-src is not widened, since the forge origin it names covers the repo endpoints, pinned by a CSP test, and a built private route loaded in headless Chrome under the enforced policy loaded the view and the wasm core with no violation but the control fetch meant to be refused. public surfaces grow by 229 to 236 B gzip, the route definitions. red under ten named mutations, each restored: the least touch taken as the latest (0 passed and 1 failed), the timeline ordered by name (0 and 1), waiting ignoring closure (0 and 1), the shared fold ignoring a label removal (0 and 2, the CLI label test and the browser read test), a touch outside the head history kept (1 failed and 2 passed), a generation counting a parent never sent (1 and 2), the board waiting column taking the frontier (1 failed and 7 passed), any session writing (1 and 7), an own key held without unsealing (1 failed and 16 passed), and the parent edges swapped in the read route SQL (1 failed and 78 passed over the live Postgres suites). cargo test green, 4739 passed over 145 binaries with 13 ignored, the site gate green at 856 passed, the live Postgres suites at 79 passed, and the SDK suite at 153 passed. owes a site deploy (#2432) 94447d12 · dbf3dbe6…
  • review sweep 4 fix-up over the live Tickets view (#2432) and the web ticket write (#2479, #2481), map #2422: no document key, href or URL of the view carries decrypted text any more, where a label in the panel opened a query whose URL held the label. a query is its own URL only when addressOnly finds every term an address, and any other, a label, a kind the ticket format does not name or a word typed into the search, is a search held in the workbench cache under a random handle that its key and URL carry instead (route tickets/s/<handle>), pinned by a render of the panel navigation, the lists, every ticket page and the board over a marked fold whose links and asked-for documents are scanned for the mark. an /ingest whose answer is lost, a thrown request or a 5xx, is settled by asking instead of read as not published: the SDK publish re-reads /ref, calls it published when the head is the change, sends the same built change again while the head is at the generation it was built on, and when the head moved asks an unbounded /fetch past its base whether the forge holds the change, which it does only when an ingest of it committed, building again only when not. until then the write reads unknown, the site asks until it knows, and an UnsettledIngestError names the change when the checks run out. the page asks before it unloads while a write has not settled. the board gains verdict E Take, which copies loot lane new --ticket <id>, on each frontier card and on a next in causal order callout. AGENTS.md states what the site build reads outside site/ as a property, site-main.yml paths gain sdk/src, loot-hygiene, loot-ticket and Cargo.toml, CONTEXT.md Stow-first publish and ADR 0098 §1 and §5 say what is true now, the member tier read of /api/private/tickets is pinned through forge_member_*, the keyring wait is Keyring.keyForSettled, data.ts uses lib/identity/bytes.ts, and the map kind is MAP_KIND. red under named mutations, each restored: a label opened as a query (1 failed and 6 passed), a label term taken as an address (3 and 4), unknown counted as settled (2 and 5), no beforeunload listener (1 and 6), no callout (1 and 6), no Take on a card (1 and 6), a lost answer read as a refusal (4 failed and 4 passed over the fake-transport suite, 3 and 5 against a real forge), a head at its generation rebuilt instead of resent (2 and 6), a moved head always taken as holding the change (1 and 7) and never (1 and 7 against a real forge), the keyring answering a lock without waiting (1 and 10), and the member read through the owner relation (1 failed and 79 passed over the live Postgres suites). the site gate green at 863 passed, the live Postgres suites at 80 passed, the SDK suite at 161 passed, and a CSP-enforced headless Chrome load of the built search, query and ticket routes met no violation but the control fetch. no Rust changed. owes a site deploy (#2486) 016ab4c2 · dbf3dbe6…diff
  • the Tickets view asks the consent a web write needs, and moves, attaches and shows attachments (map ztrnpqko): a write the core builds only with consent waits in the pending list while a sheet asks, publish naming each file that becomes world-readable for good beside a per-device do not show this again, which a notice above the view turns back on, demote naming who gains access and reveal refusing a secret-shaped name with an override, neither of which can be silenced, and a silenced device gives publish consent itself once per write; a composer on a public ticket shows a public badge either way. the rail moves a ticket to the spaces the head rules define, read by loot_wasm::ticket::spaces with the rule deciding each, and when they define none but internal it says so with the lines to add. the conversation takes a dropped or picked file, refused over ATTACHMENT_CAP before it is read, and an attachment opens through ticket_read::attachment: an image by its byte signature as a blob: URL in an img, the private CSP img-src widened by blob: alone, text by its declared extension escaped in a pre, and anything else a download of application/octet-stream. the filter term frontier becomes unblocked, frontier:<map> is the map frontier the core read, and a query holding the bare word redirects 301, /tickets/q/frontier to unblocked. ADR 0098 §11, the spec and CONTEXT.md record it. pinned natively (the spaces offered, a lockout group left out, internal alone with the lines to add, the attachment bytes the browser opens) and in the site. red under named mutations, each restored: img-src without blob: (41 passed and 2 failed), a quiet device dropping the demote question (42 and 1), the reveal question silenced (42 and 1), do not show this again beside every question (42 and 1), svg shown as text (42 and 1), an image judged by its name (42 and 1), a download typed text/html (42 and 1), an iframe preview (41 and 2), frontier:<map> read as map:<map> (42 and 1), no redirect (42 and 1), the badge off a public ticket (42 and 1), the internal-only note never shown (42 and 1), a lockout group offered (0 and 1), only the current space offered (0 and 1), the whole a/ file answered as the attachment (0 and 1). cargo test green, 4758 passed over 144 binaries with 13 ignored, the site gate green at 877 passed, and a CSP-enforced headless Chrome load of the built tickets routes with no violation, a blob: image loaded and a foreign image refused. owes a site deploy (vsropolo) 75a3eeb3 · dbf3dbe6…diff
  • the Tickets view keeps the forge objects it reads in a browser cache and reads no code manifest: the list, a ticket read whole and the answers now take each object an IndexedDB cache in the vault database holds by content address, once the core has decoded the entry as the object at that address, and ask the forge /fetch only for the rest, so a repeat visit moves only new objects. an entry is a sync frame holding one object, ciphertext only, and an object whose key rode in the forge answer is not kept; the cache is bounded at 32 MiB, evicts the least recently used, is wiped with the vault, and reads as empty where storage is missing. the workbench asked for the whole head manifest on every entry and opened the explorer first, so a Tickets visit moved the whole tree, about 376 KB gzip as the ticket measured it: a view now has an ahead hook the shell runs beside the repo header, Files asks for the manifest there and Tickets for its route, and the shell opens the side panel of the view it was entered at, so a History link now opens the History panel; the list fetch starts from a manifest only when one is already held. pinned in vitest: a repeat visit asks the forge for nothing, a partial hit asks only for the misses, a damaged entry and an entry of another object are refused and asked for again, no keyed object is kept, a write lands only while the vault holds the identity, no storage asks every time, and a Tickets entry reads the route asked ahead and no manifest; and in loot-wasm, what an entry is and what it refuses. red under named mutations, each restored: the cache read skipped (3 failed and 11 passed), every want fetched on a miss (2 and 12), entries held unchecked (1 and 13), the list fetch loading the manifest (2 and 12), the entry view ignoring the document (1 and 13), the vault check dropped (1 and 11), an entry held under any address (1 failed and 3 passed in cargo, 1 and 10 in vitest), and keyed objects kept (1 and 3 in cargo, 1 and 10 in vitest). cargo test green, 4886 passed over 144 test result lines with 15 ignored, and the site gate green at 925 passed. owes a site deploy (qqypkwst) b7bcb3b5 · dbf3dbe6…diff

Renames are not followed. loot's tree maps a path to an address, so a rename is a delete and an add. This list is the history of the name, not of the bytes.