Changes touching this path

  • a burn at the forge drops the grants naming a burned address on every run of the burn delete job, derived from burn_tombstone in one keyed statement (GrantInbox::drop_burned_grants, pg::inbox::DROP_BURNED_GRANTS_SQL) and recorded nowhere, so burn_bytes_deleted records the blob delete alone and nothing the previous forge records during a deploy can end the drops, where a record it wrote after migration 0032 owed a burn again ended them for good; the deposit read after filing is a fast path that owes nothing, and a filing that fails is the deposit answer whatever that drop does; the grant door refuses a grant whose body carries an object other than the one its header names, or anything in its keys, changes or attestations lanes (grant::parse_deposit), and the builders whose grants a deposit sends are pinned to carry that object or none and leave those lanes empty; a 400 from that door reads as the door refusing the grant with the forge reason, where it told the reader to compare format versions; a migration waits at most 5 s for a lock (pg::migrate::MIGRATION_LOCK_TIMEOUT, below the pool checkout wait), and a wait past it stops --migrate with that migration rolled back and named, which stops setup-forge.js before the container swap; a test fails if a statement this crate ships deletes from or truncates repo_change, which would leave repo_object stale; a forge push refusal names an address burned here apart from one not held here, with the remedy of each. CONTEXT.md and ADRs 0038, 0046 and 0057 say so, the 0057 amendment carrying the deploy window the checksummed 0032 text does not. pinned: a_burn_leaves_no_grant_naming_its_address_in_any_mailbox over memory and Postgres 18 (a drop that fails, then a run with the blob delete on file, then a grant filed past the deposit check), a_failed_filing_is_the_answer_when_the_drop_after_it_fails_too, a_grant_carrying_an_object_its_header_does_not_name_is_refused, a_grant_carrying_a_key_in_its_body_is_refused, a_grant_carrying_a_change_in_its_body_is_refused, a_grant_carrying_an_attestation_in_its_body_is_refused, a_browser_grant_carries_its_object_and_nothing_else, a_forge_grant_door_400_says_the_door_refused_it_and_why, the_burned_grant_drop_asks_the_index_by_address, no_statement_this_crate_ships_deletes_a_version_from_a_repo, a_migration_waiting_past_the_lock_timeout_gives_up_and_applies_nothing, the_lock_timeout_is_below_the_checkout_wait, a_sealed_grant_carries_the_object_its_header_names_and_no_other, a_self_grant_carries_the_object_its_header_names_and_no_other and a_history_naming_an_object_burned_here_is_refused_as_burned; red under named mutations, each restored, over the nine selected forge tests against a throwaway Postgres 18: no drop in the job (2 failed and 7 passed), the Postgres drop a no-op (1 and 8), the memory drop a no-op (1 and 8), no burn read after a deposit (2 and 7), the drop error answered before the filing error (1 and 8), no door check (1 and 8), the drop written as IN (SELECT) (1 and 8), a repo_change delete in meta.rs (1 and 8), the timeout at 15 s (1 and 8); the drop run only while a blob delete is owed (2 failed and 0 passed over the two burn pins), no lock_timeout (1 failed and 0 passed, applied after 20 s), seal_grant carrying a second object (the custody pin 1 failed and 0 passed, and a_forge_push_deposits_embargoed_keys_to_peers_and_to_self refused with a 400 at the door, 1 and 0), the ticket self-grant carrying a second object (1 and 0), the burn log not asked (1 and 0); no keys, changes or attestations check at the door (each 1 failed and 11 passed over the grant tests), seal_grant carrying a key (the custody pin 1 failed and 0 passed, and the embargo push refused at the door, 1 and 0), the browser grant carrying a key (1 failed and 1 passed), the ticket self-grant carrying a key (1 and 1), the door 400 routed to the generic text (1 failed and 3 passed), the reason dropped (1 and 3). ci/local.sh green over the forge database steps and cargo test with the live suites, 5011 passed over 145 test result lines with 15 ignored, and the site gate 1071 passed. owes a forge deploy, with no migration of its own, and 0032 deploys with it (wurtzskp) 8cf84317 · dbf3dbe6…

Renames are not followed. loot's tree maps a path to an address, so a rename is a delete and an add. This list is the history of the name, not of the bytes.