Changes touching this path

  • the Tickets view on the private workbench, verdict E of #2411 (ADR 0094, ADR 0098 §1): a view module, its VIEWS line, routes for tickets, tickets/<id> and tickets/q/<query>, and a read route, /api/private/tickets, that answers the files the forge head holds under tickets/ as paths and addresses and each ticket path first touch in the head history with its generation. the browser fetches the objects from the forge by address, opens them with the session keys and folds them in wasm with loot_ticket::fold, the fold loot ticket now folds through too, moved out of loot-cli (ticket_read.rs: readTickets, ticketWants, ticketKinds), so the web reads a ticket as the CLI does and in the same causal order. the page is the conversation page for every ticket and map, a timeline ending in the resolution card, a comment and resolve composer and a right rail; the panel with search, saved views, maps, labels and kinds; and on a map a Conversation and Board switch whose board lays out Waiting, Frontier, In a lane and Resolved under the decisions so far, where a drop onto a card is a wait-on. sealed tickets are withheld rows, and each control names its loot ticket command. a write publishes one change through the SDK publish, now publishTicketWith over an injected core (sdk/src/ticket-publish.ts, assertStowAccepted moved to stow.ts); the pending bar holds writes in flight, and a collision shows both versions and asks. a session whose key is not the namespace owner reads, and lanes, which the web cannot see, are said to be so. connect-src is not widened, since the forge origin it names covers the repo endpoints, pinned by a CSP test, and a built private route loaded in headless Chrome under the enforced policy loaded the view and the wasm core with no violation but the control fetch meant to be refused. public surfaces grow by 229 to 236 B gzip, the route definitions. red under ten named mutations, each restored: the least touch taken as the latest (0 passed and 1 failed), the timeline ordered by name (0 and 1), waiting ignoring closure (0 and 1), the shared fold ignoring a label removal (0 and 2, the CLI label test and the browser read test), a touch outside the head history kept (1 failed and 2 passed), a generation counting a parent never sent (1 and 2), the board waiting column taking the frontier (1 failed and 7 passed), any session writing (1 and 7), an own key held without unsealing (1 failed and 16 passed), and the parent edges swapped in the read route SQL (1 failed and 78 passed over the live Postgres suites). cargo test green, 4739 passed over 145 binaries with 13 ignored, the site gate green at 856 passed, the live Postgres suites at 79 passed, and the SDK suite at 153 passed. owes a site deploy (#2432) 94447d12 · dbf3dbe6…
  • review sweep 4 fix-up over the live Tickets view (#2432) and the web ticket write (#2479, #2481), map #2422: no document key, href or URL of the view carries decrypted text any more, where a label in the panel opened a query whose URL held the label. a query is its own URL only when addressOnly finds every term an address, and any other, a label, a kind the ticket format does not name or a word typed into the search, is a search held in the workbench cache under a random handle that its key and URL carry instead (route tickets/s/<handle>), pinned by a render of the panel navigation, the lists, every ticket page and the board over a marked fold whose links and asked-for documents are scanned for the mark. an /ingest whose answer is lost, a thrown request or a 5xx, is settled by asking instead of read as not published: the SDK publish re-reads /ref, calls it published when the head is the change, sends the same built change again while the head is at the generation it was built on, and when the head moved asks an unbounded /fetch past its base whether the forge holds the change, which it does only when an ingest of it committed, building again only when not. until then the write reads unknown, the site asks until it knows, and an UnsettledIngestError names the change when the checks run out. the page asks before it unloads while a write has not settled. the board gains verdict E Take, which copies loot lane new --ticket <id>, on each frontier card and on a next in causal order callout. AGENTS.md states what the site build reads outside site/ as a property, site-main.yml paths gain sdk/src, loot-hygiene, loot-ticket and Cargo.toml, CONTEXT.md Stow-first publish and ADR 0098 §1 and §5 say what is true now, the member tier read of /api/private/tickets is pinned through forge_member_*, the keyring wait is Keyring.keyForSettled, data.ts uses lib/identity/bytes.ts, and the map kind is MAP_KIND. red under named mutations, each restored: a label opened as a query (1 failed and 6 passed), a label term taken as an address (3 and 4), unknown counted as settled (2 and 5), no beforeunload listener (1 and 6), no callout (1 and 6), no Take on a card (1 and 6), a lost answer read as a refusal (4 failed and 4 passed over the fake-transport suite, 3 and 5 against a real forge), a head at its generation rebuilt instead of resent (2 and 6), a moved head always taken as holding the change (1 and 7) and never (1 and 7 against a real forge), the keyring answering a lock without waiting (1 and 10), and the member read through the owner relation (1 failed and 79 passed over the live Postgres suites). the site gate green at 863 passed, the live Postgres suites at 80 passed, the SDK suite at 161 passed, and a CSP-enforced headless Chrome load of the built search, query and ticket routes met no violation but the control fetch. no Rust changed. owes a site deploy (#2486) 016ab4c2 · dbf3dbe6…diff
  • review sweep 5 fix-up (map ztrnpqko): a web ticket write settling a lost ingest answer no longer asks forever over a refusal. the SDK publish asks /ref and the unbounded /fetch again only when that answer is lost too, to a transport failure or a 5xx, and any other refusal (an expired session, a revoked key) fails the write, which the Tickets view shows where it asked every 30 s under checks: Infinity. pinned: a /ref 401 or 403 and a settle /fetch 403 while settling fail as a refusal, an /ingest 400 or 403 and a resend 403 stay refusals, and a resend answered 409 or 412 reads as a moved head, published when the forge holds the change and built again when not. lane new help and the refusal hints say --ticket <ticket-id>, the ticket id taken as the handle (spec §2.3) and t<n> only for a bare number, as does the site CLI page. issue-tracker.md gains A resolution is written before the land: the gist and body cite what exists by then, and a resolution that must cite the landed commit rides a follow-up lane; ticket-to-lane, afk-loop, land-change and workflow.md step 2 point to it. the fold_onto comment no longer says merge_tips is the only three-way, addressOnly takes a space: term as an address only for a space the index holds, site-main.yml paths gain rust-toolchain.toml and the files the site tests read outside site/ (loot-cli main.rs, usage.rs, telemetry.rs and Cargo.toml, forge migration 0027, README.md) and it and AGENTS.md state that set by its property, and issue-tracker.md, the implementer brief, afk-loop and the SDK README state the rule instead of a list. red under named mutations, each restored: a settle refusal read as lost (3 failed and 15 passed, the same against the file before this change), a resend 409 or 412 never asking whether the forge holds it (2 and 16), an /ingest 4xx read as lost (3 and 15), a resend 409 or 412 always read as held (2 and 16), and any space: value taken as an address (1 and 6). cargo test green, 4749 passed over 144 binaries with 13 ignored, the site gate green at 863 passed, and the SDK suite at 171 passed. owes a site deploy (wvotyytl) b88e295a · dbf3dbe6…diff
  • the Tickets view asks the consent a web write needs, and moves, attaches and shows attachments (map ztrnpqko): a write the core builds only with consent waits in the pending list while a sheet asks, publish naming each file that becomes world-readable for good beside a per-device do not show this again, which a notice above the view turns back on, demote naming who gains access and reveal refusing a secret-shaped name with an override, neither of which can be silenced, and a silenced device gives publish consent itself once per write; a composer on a public ticket shows a public badge either way. the rail moves a ticket to the spaces the head rules define, read by loot_wasm::ticket::spaces with the rule deciding each, and when they define none but internal it says so with the lines to add. the conversation takes a dropped or picked file, refused over ATTACHMENT_CAP before it is read, and an attachment opens through ticket_read::attachment: an image by its byte signature as a blob: URL in an img, the private CSP img-src widened by blob: alone, text by its declared extension escaped in a pre, and anything else a download of application/octet-stream. the filter term frontier becomes unblocked, frontier:<map> is the map frontier the core read, and a query holding the bare word redirects 301, /tickets/q/frontier to unblocked. ADR 0098 §11, the spec and CONTEXT.md record it. pinned natively (the spaces offered, a lockout group left out, internal alone with the lines to add, the attachment bytes the browser opens) and in the site. red under named mutations, each restored: img-src without blob: (41 passed and 2 failed), a quiet device dropping the demote question (42 and 1), the reveal question silenced (42 and 1), do not show this again beside every question (42 and 1), svg shown as text (42 and 1), an image judged by its name (42 and 1), a download typed text/html (42 and 1), an iframe preview (41 and 2), frontier:<map> read as map:<map> (42 and 1), no redirect (42 and 1), the badge off a public ticket (42 and 1), the internal-only note never shown (42 and 1), a lockout group offered (0 and 1), only the current space offered (0 and 1), the whole a/ file answered as the attachment (0 and 1). cargo test green, 4758 passed over 144 binaries with 13 ignored, the site gate green at 877 passed, and a CSP-enforced headless Chrome load of the built tickets routes with no violation, a blob: image loaded and a foreign image refused. owes a site deploy (vsropolo) 75a3eeb3 · dbf3dbe6…diff
  • the Tickets view first load fetches each ticket meta, labels and waits-on edges instead of every ticket file, and reads the rest when it is shown: loot_wasm ticket_read gains Reach, whose List, Tickets and Answers name the files that read (the list), read_tickets (a ticket whole, when its page shows it) and answers (the gist of a resolved ticket, when a row, a card or the decisions of a map show it) each open, and wants names them; the list carries a comment count, a path fact, and each map its resolved children, whose answers are its decisions, from the new loot_ticket fold::resolved_children and fold::answer, which fold::decisions now reads through in the order it opened files before. each of these /fetch requests sends the heads the list was read at as its have, so the head change node stays at the forge; the forge_view parity test now fetches each read that way from its test forge and asserts that no change node rides and that only the objects asked for do. an attachment opens from the read of its ticket. over the perf hunt dump of this tracker the first load asks for 2,161 objects and keys instead of 5,484, a sync answer of 493,894 B instead of 5,697,392 B and 511,513 B of plaintext instead of 10,309,763 B, and the 15 resolved rows of the home page add 15 objects and 7,952 B. pinned in site/test/workbench-tickets-read.test.ts over a fixture tracker the core seals, and in 3 ticket_read unit tests. red under named mutations, each restored: over the 2 read tests, the first load asking for every ticket file (1 passed and 1 failed), no have (0 and 2), gists fetched again (1 and 1), a whole read asking for the list files (1 and 1); over the 3 ticket_read tests, List naming every file (2 and 1), the list folding bodies (2 and 1), the list without waits-on edges (2 and 1), the last resolution taken as the answer (2 and 1); and the parity test with an empty have (0 and 1). cargo test green, 4785 passed over 145 binaries with 13 ignored, and the site gate green at 883 passed. owes a site deploy (vrxsvlsy) 77cc7fe7 · dbf3dbe6…diff
  • a loot-first land --dry-run is no longer timed: land_timed returns before the timing: line and the land-timings record whenever the dry run flag is set, so a dry run that fails before its stop (the pr-map lookup, the approval) no longer appends a landed:false record, and the land_timed and record_timing docs, workflow.md step 7, the land-change skill and the land_timings_path doc say a land run without --dry-run records. land, land_timed and land_via take the PR and its flags as one LandArgs and drop their clippy::too_many_arguments allows, and Timing and Timing::since are private to the orchestrator. in loot-wasm, ticket_read::read and ticket_read::read_tickets are now read_list and read_whole, and the exported read_tickets and read_tickets_of are read_ticket_list and read_whole_tickets, their JS names readTickets and readTicketsOf unchanged. the tickets data.ts comment, the ADR 0098 amendment and the workbench-tickets-read test header say the head change node stays at the forge only while the head has not moved since the list was read. the record_timing and boardOf docs lose their stray line breaks. pinned in the new a_dry_run_records_no_timing_whether_it_stops_or_fails; red under named mutations, each restored, over it and a_land_that_stops_is_recorded_as_not_landed: the old record condition, which records a dry run that failed (1 passed and 1 failed), and a dry run left untimed only when it failed (1 and 1). cargo test green, 4800 passed over 145 binaries with 14 ignored, and the site gate green at 886 passed. no deploy owed: the site and wasm edits are comments and Rust-side names (uqooxqvx) 077a90e3 · dbf3dbe6…diff
  • the Tickets view /fetch wants lane no longer falls to the residue query: since vrxsvlsy it names its heads as have, so every want reached repo_referenced_objects, whose plans on Postgres read every tree_entry row naming a want, every manifest of the repo, or the whole table; bundle_within now asks the new MetadataStore::referenced_by_versions of the manifests of the tips of what the caller named as held (serve::held_tips, tips because a CLI pull declares its closure) before the residue query, on Postgres pg::meta::REFERENCED_BY_VERSIONS, read one named version at a time and plan-pinned in pg::tests, and the answer is the same repo-scoped set. measured against a throwaway Postgres 18 with 2,200 ticket files of a 7,240-path head as wants and the head as have, the wants span went from 21.8-103.6 ms to 7.1-7.5 ms on the perf hunt fixture and from 575-1,820 ms to 11.4-15.2 ms on a repo whose ticket files sit in up to 1,000 manifests (the ADR 0075 zsxqmrtm amendment, and a note in ADR 0098). a /offer or /fetch step that fails now ends its own span before until_error; a budget refusal says how long since the walk began, keeping its leading words, and its objects-read count is taken once the gets in flight end, so it equals the cache_hit and cache_miss tallies summed; the fetch_latency cold test runs under an unspendable budget and asserts the fit from the width the tier saw instead of the wall clock. text: the timing module and CONTEXT.md say what a fact is and where facts are named instead of listing them (timing::count is timing::fact, Got.keeping is keep_time), the phases doc says the runner walk laps nothing and tallies no reads, and the lib.rs cache sentence names only the serving process. judgement calls: the route and the Tickets view build the ticket file list with the new site lib/workbench/ticket-files.ts and compare it by content, manifest.ts shares one private read, the wasm JS names are readTicketList and readWholeTickets, and ADR 0002 and the spike-crdt ignore reason say --include-ignored. red under named mutations, each restored: over the 16 offer_cost tests, no heads step (13 passed and 3 failed) and every named version read (15 and 1); the memory store reading every version (1 and 1 over the 2 conformance runs); the plan pin without OFFSET 0 (2 and 1); over the 27 serve tests, a failing step not lapped (26 and 1), the count taken at the refusal (26 and 1), the old spent wording (25 and 2), 16 in flight (26 and 1); the site ticket file compare as JSON text (2 and 1). the Postgres statement without its repo_id condition stayed green, as the RLS repo binding hides other repos. cargo test green, 4811 passed over 145 test result lines with 14 ignored, loot-forge green at 702 passed against a throwaway Postgres 18, the site gate green at 889 passed and its pg suites at 85. owes a forge deploy and a site deploy; it also carries the new ticket zsxqmrtm and comments on kwlxstko and zxkpzxvz (zsxqmrtm) ed102f51 · dbf3dbe6…diff

Renames are not followed. loot's tree maps a path to an address, so a rename is a delete and an add. This list is the history of the name, not of the bytes.