Changes touching this path

  • an api route answers an undeclared method with the same 404 an unserved path gets, and the all-platforms table goes through the counted hop with the direct link beside it loot#1925 and the last site item of loot#1647, in one change because both are about what a URL on this site tells a stranger. The router looks up handlers[method], then handlers.ANY, and on neither falls through to SSR - so GET /api/beacon answered 200 with 5 KB of HTML while /api/definitely-not-a-route answered 404, measured live the day the beacon deployed. The difference told a prober which routes exist, which is the oracle the download hop refuses to be. One ANY_NOT_FOUND spread into every api.* route answers the bare 404 an unserved path gets. NOT a 405: an Allow header is the polite answer and exactly the one that confirms the route and lists its methods. A declared method still wins, and that is pinned as a fact about the router read from its source rather than assumed. A test walks every api.* file, so a new endpoint cannot arrive without the fallback. The table links and the sentence about them moved TOGETHER, which loot#1647 insisted on: switching the links alone produces a page that counts a click it calls anonymous. Each row now links through loot.millerbyte.com/dl with the direct R2 URL visible beside it, hopHref is null for anything the hop would refuse so a row can never render a counted link that 404s, and the manual- install note says the hop counts the release, the platform and the time and sends you on to the CDN that serves anonymously. The checksum instructions still fetch sha256.sum direct, because the hop refuses it on purpose - every land fetches that file and admitting it would count every land as a download. Rendered: all five rows carry both links, the note reads as one sentence. 610 site tests, budget green. 7c4f1a17 · dbf3dbe6…
  • every compiled-in and current-tense loot host moves to loot.build (map #2412, ADR 0099): loot --help names security@loot.build and https://loot.build/trust, ALPHA_PROMISE_URL is https://loot.build/install and the telemetry DEFAULT_ENDPOINT https://loot.build/api/telemetry, so the next release carries them; the site install one-liners, R2_BASE and HOP_BASE (https://dl.loot.build, https://loot.build/dl), the metrics SITE_SCOPE and own-host referrer, the disclosure links on trust, terms, privacy and known-issues, and the install, quickstart and guides pages follow, with the privacy and terms markers moved to 25 September 2026 and re-pinned since readers see the new address; README, CONTEXT.md (the forge door now forge.loot.build), the release checklist, site CI and test fixtures follow, and the two specs carry a note instead of a partial rewrite. the destination census gains build in WEB_TLDS, without which security@loot.build would be invisible to its bare-host clause, and exempts the two shipped lines that tld makes read as hosts (state.build, r.build()) by their exact text; ADR 0074 section 9 says twelve-entry to match. 37 lines still name millerbyte.com outside ADR bodies, evidence, research and scratch, each kept on purpose: dated history, millerbyte.com the site and its @millerbyte/ui tokens, the two noted specs, and relay-era tooling with no successor host, filed as #2438. census red with build dropped from WEB_TLDS, restored; site gate 819 passed and within budget; workspace suite 4559 passed over 142 binaries, 13 ignored (#2418) c5663115 · dbf3dbe6…diff

Renames are not followed. loot's tree maps a path to an address, so a rename is a delete and an add. This list is the history of the name, not of the bytes.