Change Ledger
One row per change, not per commit. The pusher declares which versions are live; this walks their ancestry, newest first, and bands each change by what this server can actually read. Nothing here is merged, rewritten, or picked for you.
1 declared head · 1298 changes walked
- the visibility gate goes on reading the whole object and the ticket is refused on a ceiling, because a binary with the read deleted outright still reads one loose object file per recorded path: can_open consults facts that sit beside the ciphertext rather than inside it, so reading less looked free, and the measurement says the read does not belong to this seam at all. a knowingly wrong body answering from the store index and the keyring alone, reading no object bytes, is strictly less work than any header only spelling could do, and over 200 paths of incompressible bytes at 1 KB and 16 KB and 128 KB it moves loot status from 14.13 and 20.57 and 67.91 ms to 14.21 and 20.84 and 66.73 ms and loot surface from 16.64 and 23.11 and 59.09 ms to 16.58 and 23.18 and 56.16 ms, a spread that runs in both directions and peaks at 5 percent on the largest fixture. THE COUNTER IS WHAT MAKES THAT A REFUTATION RATHER THAN A QUIET READING: object_disk_reads reads 200 on every one of those twelve readings, before and after alike, while object_gets falls from 401 to 201 on status and from 600 to 400 on surface, so the span really was deleted and the file reads moved rather than went away. they move to the pass that wants the bytes - same_content behind status and the clobber guard behind surface - which the read memo makes free today and which would pay for the whole tree if this call stopped filling it, and a header only body would add its own opens on top of that. the signal the ticket opened with is therefore not added either: the read counter that exists already settles the question, and a byte counter would have read the same total under the ceiling and a larger one under any header only body. so the code is UNCHANGED and what lands is the reading, recorded on can_open where the next hunt reads it before refiling. one list class defect is corrected beside it: the sentence naming two further sites that could move to this predicate named a merge site that cannot, since the readability question there sits on the theirs side of a cherry pick delta restriction and its own comment says the content must be read to re-seal it, and the sentence now states what decides membership instead of naming members. no mutation proof, because nothing was fixed and no pin was added, and the measurement controls stand in its place: the get counter moves, so the instrument is not blind to the span the ceiling deletes, and restoring the pristine body returned both counters and both timings to the landing band. no migration, no wire or format byte moves and no host behaviour moves, so this owes no deploy. the workspace suite is green (4174 passed over 132 binaries, 8 ignored) (#2223)nothing readable · 3 sealed · 3 internal
- the probe memo #2226 asked for was built and measured and then refused, because the probe it removes is under a twentieth of the walk: locally_missing_objects asks its membership question once per change and manifest entry pair while the answer is a set of distinct addresses, which is 25600 probes for 327 answers on a 200 path missing fixture, and the obvious shape is the probed BTreeSet copied from offered_objects. the named signal reads WORSE with it, in a paired opt-in --missing A/B at the fixture depth, one binary built from each arm and the gate reporting an idle machine on every reading: 18.3 ms to 20.9 ms at width 200 and 96 ms to 110 ms at width 800, because the probe here is a single BTreeMap lookup in the store index rather than the object read the sibling spells, so a set insert over a map of the same order costs more than the lookup it skips. THE CEILING IS WHAT MAKES THAT A REFUTATION RATHER THAN ONE BAD MEMO: a knowingly wrong binary with the probe deleted outright reads 17.5 ms and 91.5 ms on those two fixtures, so any probe-side change on this walk is bidding for under a twentieth of it, and with the manifest walk deleted too the same measurement reads 0.03 ms, which says what the walk spends is materializing and walking each deferred manifest to read the addresses out of it, a loot-codec seam and not this one. so the code is UNCHANGED and what lands is the reading, recorded on the function where the next hunt reads it before refiling. one list-class defect is corrected in the same doc: three callers stood asserted as the whole set beside a pub passthrough on Workspace that is a fourth, and the sentence now names what the callers share instead of how many there are. no mutation proof, because nothing was fixed and no pin was added, and the measurement controls stand in its place: the ceiling binary moves the reading at all, so the half is not blind to the probe, and restoring the pristine body returned it to the landing band. no migration, no wire or format byte moves and no host behaviour moves, so this owes no deploy. the workspace suite is green (4174 passed over 132 binaries, 8 ignored) (#2226)nothing readable · 2 sealed · 2 internal
- the sentence written to replace a deleted list names the definer instead of counting, and the fix-up is read back under the rule it enforces: ADR 0073 said the gated work counters were the object pair and a further one at each amendment since, which is false because the #1903 amendment added none, so the clause now names measure::WORK_COUNTERS and stops. every other count beside a set that can grow is replaced by what decides membership rather than by a corrected number - the first nine and the six artifact counters and the other three Work variants in gate::COUNTERS become every row WORK_COUNTERS does not name, the Tally Display doc shows one label=value per Work::ALL entry and an ellipsis instead of hand-listing the labels, the deposit lane counts point at kind.widens, and the landed proposal state points at store::ProposalState. THE SWEEP MISSED THREE COPIES OF ITS OWN ITEMS and they are corrected here too, because a corrected claim left standing in a second copy is how #1903 shipped one stale: the three lanes sentence in loot-core custody and again in its test, and the ADR 0075 three terminal states sentence duplicated in a forge server test. two code fixes ride along: #2174 landed the wire_state doc inside the propose withdraw doc comment, so the may_propose rationale documented the wrong function and the route documented nothing, and the stale-tip refusal was broken across source lines with no continuation, so an operator read the indentation of the source in the middle of the message. ONE ITEM IS CORRECTED RATHER THAN FOLLOWED: the ticket reads that literal as carrying a newline, and on the tree it is a single line carrying two runs of collapsed indentation, so the rendering defect is real and its shape is runs of spaces rather than a break. red under mutation, counts read each time: the continuations removed so the break rides in the string again failed the strengthened pin (0 passed and 1 failed, the panic printing the refusal across three lines), restored to 1 passed. the CONTEXT rewrap is a pure reflow, identical byte count and identical word stream, so the generated membership sentence and its pin are untouched. no migration, no wire or format byte moves and no host behaviour moves, so this owes no deploy. the workspace suite is green (4174 passed, 0 failed, 8 ignored) (#2234)nothing readable · 11 sealed · 11 internal
- a deposit plan builds the tree it ships once instead of once per custody lane, and the first act had to be an instrument that could see the difference: no counter a land can read moved over a repeated whole-graph pass, so Work::GraphSorts now tallies ChangeGraph::in_order and is gated at 0% beside the object pair and store_file_reads, reading 8 on the gated fixture and one string across the drift pin repetitions. THE TICKET ASKED FOR THE TALLY TO REUSE Work::TreeWalks INSIDE finalized_tree and for ADR 0073 to re-decide that exclusion, and that was refused rather than followed: tree_walks counts a whole-tree FILESYSTEM walk of a working tree and this is a graph pass, and the in-process tier links loot-core and never loot-cli while nothing in loot-core outside its own tests calls the deposit lanes, so a tally there would have read zero on that tier anyway and the pin would have stayed green while its stated reason went false. the exclusion therefore stands unmoved on its own measurement, and the ADR records the trigger that did not fire rather than a re-decision it did not force. measured in the counter and not in wall clock: a forge plan over a fixture carrying an embargoed path, a Restricted path and the Internal default read 3 sorts before and 1 after, a relay plan 2 before and 1 after, the three lanes now taking the finalized tree as an argument plan_deposits builds once. the tips membership test inside that build became a set lookup rather than a Vec scan, which no counter can see and which is named as such rather than claimed. red under mutation, counts read each time: the shared build removed so each lane derives its own again failed the new pin (0 passed and 1 failed, graph_sorts 3 against 1, and with the forge arm relaxed the relay arm failed at 2 against 1), the tally dropped from in_order failed the anti-vacuity pin (10 passed and 1 failed) and the new pin (0 passed and 1 failed), and graph_sorts dropped from gate::COUNTERS failed four at once (7 passed and 4 failed), each restored to 11 and 1 passed. the two generated membership sentences in CONTEXT.md and HUNT-PERF.md are pasted by hand as their pins demanded, the hand-written workspace width in verbs/mod.rs moves to 390, the visibility census gains the two argument bindings the by-reference lanes create, and a count in loot-count that was wrong in the commit that wrote it is replaced by the property. no migration, no wire or format byte moves and no host behaviour moves, so this owes no deploy, though the gate records a new metric from the next land. the workspace suite is green (4174 passed over 132 binaries, 8 ignored) (#2225)nothing readable · 16 sealed · 16 internal
- adopt and ferry stop re-reading the whole shared graph once per absent tip, and the correctness question came before the perf one: ingest_shared_lineage is the one seam that re-reads that file mid-process (#265) because another session may have written it, so nothing may be memoised across a verb, and what lands is a LineagePool the verb owns rather than a cache the repo holds. a pool is one read of the file, handed to the tips of a single pass and dropped with it, and it is never trusted to say no: a tip it cannot name refills it from disk, which is the authoritative answer the per-tip loop used to take every time, so a change another session lands mid-pass is still found. WHAT IS GIVEN UP IS NAMED RATHER THAN LEFT TO BE FOUND: a node the pool holds and the file no longer does is spliced where a fresh read would have called it absent, which needs a prune inside the window between a pass reading the graph and that same pass reaching a tip. objects and custody catch up once per pool at its first arrival instead of once per tip, on the ordering the per-tip version already rested on, a node the pool names having been in the graph file before that scan ran and its objects written before its graph entry. measured in store_file_reads, a count that is bit-exact under load, and not in wall clock, because another session had the desktop. a ferry pass over trailered commits whose changes landed outside the lineage-filtered load read 42 store files over 2 such commits and 48 over 5 before, and reads 40 at both after; resolving an adopt prefix over the same two shapes read 6 and 12 before and reads 3 at both after, the prefix search having been a whole read of the same file on its own. red under mutation, counts read each time: ferry put back to a read per commit failed its pin (0 passed and 1 failed, 43 against 49), the adopt resolution put back to a read per tip failed its own (0 passed and 1 failed, 6 against 12), a pool believed on a miss failed the later-arrival pin (1 passed and 1 failed) and a pool that never catches up failed the every-tip-brings-its-bytes pin (1 passed and 1 failed), each restored. the hand-written workspace width in verbs/mod.rs moves to 389, which its own derived census demanded. no migration, no wire or format byte moves and no host behaviour moves, so this owes no deploy. the workspace suite is green (4162 passed over 132 binaries, 8 ignored) (#2224)
- ↳ supersedes
f0bca1c6· not stored here - Kept, not rewritten: a carry replays a suffix as a new version and the one it replaced stays addressable. That is the difference between a carry and a rebase.
nothing readable · 6 sealed · 6 internal - ↳ supersedes
- a withdrawal binds the tip it was written for, and the format minor deliberately does NOT move: a withdrawal names a proposal by its durable change id, which is stable across revisions on purpose, so a captured envelope replayed after a REVISED re-proposal ended an offer its author never withdrew - and the author is the only party withdraw admits, so the captured envelope is exactly the one that works. the signed bytes now carry the tip, compared inside the retry loop against the row that round actually read rather than once outside it, which is the same window #1959 closed for the author check. the replay is run end to end: the author withdraws at one tip, revises and offers again, and the byte-identical envelope is refused with the proposal left open, while a withdrawal naming the version actually on file still works, so the refusal is the binding and not a wall. ⚠⚠ the ticket instructed a FORMAT_MINOR bump and following it would have been a mistake, which is the finding worth more than the field: the marker's minor is ONE GLOBAL CONSTANT stamped onto every artifact rather than a per-payload version, and persist_codec's is_canonical compares a persisted store against the major and minor pair to decide whether the graph file must be REWRITTEN, so bumping it to announce one optional field on one wire message would force a rewrite of every local store on every machine. every read_version caller discards the minor, so the bump buys no reader anything the trailer's presence does not already give, and a test pins both constants unmoved with that reasoning beside it. the same plan sits on #2159 for its kinds trailer and is flagged there rather than left. an older client sends no tip and is accepted unbound, exactly as safe as before the field existed and no less, since an attacker cannot cause that shape and can only replay one already signed - so the exposure shrinks to withdrawals old clients signed rather than widening. both interop directions are pinned: an old payload decodes here reporting no binding rather than inventing one, and a new payload is byte-identical to an old one up to the trailer, which is what every deployed forge reads. red under mutation, counts read each time: the tip comparison made unreachable so the replay succeeds (430 passed and 1 failed, restored to 431). ⚠ three rounds of missed call sites, each invisible to the scope before it - a package lib run compiles neither integration tests nor other packages, and only the full suite answered. no migration, FORMAT_MAJOR and FORMAT_MINOR both unmoved, and the forge behaviour moves, so this rides the next deploy. the workspace suite is green (4169 passed over 132 binaries) (#2180)nothing readable · 7 sealed · 7 internal
- landed becomes a state something actually writes, and the walk that decides it had to see the push's own changes: ADR 0075 declares three terminal proposal states and until now close_proposal's only non-test caller was propose::withdraw, so landed - the one that is nobody's act, the work being in ref_head - was unreachable and a row read open over work the repo had already taken. ingest now closes the proposals its declared head set lands, decided OUTSIDE the transaction because IngestTxn is assembled and validated outside so the transaction stays pure writes after the CAS, and that same CAS is what makes the decision sound rather than racy: generation_expected pins exactly the head set the walk assumed, so an interleaved push fails the swap and takes the closes down with it. the ticket and ADR 0092's predecessor both said this needed nothing new because walk already reports an empty extent for a landed tip, and that is true of the STORED graph and the stored graph is the wrong one: a maintainer lands a proposal by MERGING it, so the change making the tip an ancestor of the new head set rides in this bundle and is not in the store yet, and walking stored edges alone closes nothing on exactly the push this exists for. the walk overlays the prepared changes' parent edges and is red without that overlay. only open rows are candidates and the store applies the decided row only over an open one, so a proposal that went terminal between the decision and the commit keeps its own declaration and its own date - a push cannot overwrite a withdrawal it never saw, asserted in the conformance suite against both stores rather than in one. a repo with no open proposal reads its proposal rows and stops without fetching the graph at all, which is every push to every repo never proposed to. red under mutation, counts read each time: the prepared overlay dropped, so the merge in this bundle lands nothing (421 passed and 1 failed, restored to 422). the SQL is new so it was run rather than read: bash ci/local.sh against a throwaway Postgres, where pg::tests::an_ingest_closes_the_proposals_it_declares_landed passes beside its memory twin and 166 pg tests ran, so the UPDATE was parsed by a real server rather than only by a text test. no migration, no wire or format byte moves, and the forge behaviour moves, so this rides the next deploy (#2177)
- ↳ supersedes
266dd9c6· not stored here - ↳ supersedes
650563f7· not stored here - ↳ supersedes
c9652523· not stored here - Kept, not rewritten: a carry replays a suffix as a new version and the one it replaced stays addressable. That is the difference between a carry and a rebase.
nothing readable · 12 sealed · 12 internal - ↳ supersedes
- a forge push declares the delta past the heads the forge itself names rather than the whole history: declare_forge_heads built its bundle with have = &[] while the RefState it had just read for the CAS generation carried heads it read no other field of, so every push re-encoded and re-POSTed every finalized change in the repo, each with its whole manifest (#288), however little had moved. this is push own #728 move made on the route a forge declares heads on, and the forge side needed nothing built: prepare resolves against already-stowed state and the completeness refusal is over the changes in the bundle, so a change the /stow batches defer is one the push is introducing, which nothing the forge declares reaches, and it still rides. a declared head this position does not hold expands to nothing because the closure walk filters its seeds, so it subtracts nothing and whatever only it would have covered is sent as before, which is the safe direction since /ingest writes content-addressed change rows. WHAT IS GIVEN UP IS NAMED RATHER THAN LEFT TO BE FOUND LATER: the ANYONE key lane no longer re-presents a key for every published object in the history on every push, so a publication row missing for history already ingested no longer heals on the next push of anything; the steady state is untouched, published_key being global and append-only and publication being per oid and repo with a terminal retraction, both written by the ingest that first carries the change. measured twice and both readings live in the tree rather than out of repo: on the real binary against a real forge the /ingest request body of a push moving one change over a 7-change history of 16 paths reads 8880 B before and 2104 B after, and on the bundle at two depths over 24 paths the empty have reads 12039 B over 8 changes and 22615 B over 16 while the scoped arm reads 2817 B over 1 change at both, so the before figure grows with the history where the after one does not. red under mutation, counts read each time: the helper made to ignore its have failed both pins (30 passed and 1 failed in the sync unit tests, 11 passed and 1 failed in forge_push), the call site made to pass the empty have again failed only the wire pin as designed (31 passed and 0 failed in the unit tests, 11 passed and 1 failed in forge_push, reading 8880 B against the 7906 B of the first push), and the deep fixture made no deeper than the shallow one failed the growth control (30 passed and 1 failed, 12039 B then 12039 B), each restored to 31 and 12 passed with 0 failed. the now-false prose is corrected where it stood: RemoteSync haves and declared_heads, the loot-forge ingest and publish module docs, the publish re-verification comment, two forge test comments, the ADR 0024 amendment and the CONTEXT Ingest entry. no migration, no wire or format byte moves and no host behaviour moves, but what a client sends at /ingest moves, so this rides the next release and owes no deploy. the workspace suite is green (4142 passed over 132 binaries, 8 ignored) (#2222)
- ↳ supersedes
37c9b0df· not stored here - Kept, not rewritten: a carry replays a suffix as a new version and the one it replaced stays addressable. That is the difference between a carry and a rebase.
nothing readable · 8 sealed · 8 internal - ↳ supersedes
- the owner can finally see what was offered to them, and a read request had to stop being a withdrawal in disguise: propose::list had no caller outside its own tests and propose::read only handle_propose_withdraw, so ADR 0075's store half was built and unreachable and an owner could see nothing. /propose/read and /propose/list join the contribution family with loot propose --show and --list on the CLI side, flags rather than a verb because a new verb trips seven censuses here and a flag does not. the finding the ticket did not anticipate is that a read naming repo and change id would have encoded BYTE-IDENTICALLY to a withdrawal, and the route lives in the URL rather than in the bytes the envelope signs, so a captured read envelope from the tip's author - the one party withdraw admits - could have been re-posted to /propose/withdraw and ended their own offer, a non-destructive act becoming a destructive one with no forgery at all. every new payload in this family now leads with an act tag and the replay is run in both directions rather than argued. the reads dispatch before run and touch ProposeTransport nowhere, because that seam exists to make the propose-time ordering assertable and a read has no ordering to assert, and --show resolves its handle before the remote and before the key so a mistyped id is answered by the refusal for the thing mistyped. terminal rows are listed rather than filtered at the last hop, an empty list says visible to you rather than claiming the repo has none, and an underivable tip is rendered beside its row rather than as a refusal. the propose-time disclosure gains the presenting key, which ADR 0075's #2162 amendment decided is world-visible on a metadata-public repo and which the old sentence omitted while naming the author. two enums share one vocabulary by WORD rather than by numbering, pinned total and injective, because loot-forge depends on loot-net and never the reverse. three censuses refused and each was right: the dispatch table lost a row to a multi-line verb declaration, a source-walk anchor spelling [Route; 16] went stale and is now count-free per the rule its own header already states, and the selector census demanded --show declare its kind, which is evolog's - one proposal by construction, borrowing evolog's resolver rather than growing a fourth. red under mutation, counts read each time: the act tag dropped (118 passed and 1 failed), the handler telling concealed from absent (422 passed and 1 failed), the list filtering terminal rows (422 passed and 1 failed) and the disclosure reverted to naming only the author (11 passed and 1 failed), each restored to 119, 423, 423 and 12. no migration and FORMAT_MAJOR does not move, but two routes are new, so an old forge 404s them and this owes a forge deploy before the flags answer against the live host. the workspace suite is green (4156 passed over 132 binaries, 8 ignored) (#2174)nothing readable · 10 sealed · 10 internal
- the install page names v0.4.23 now that the artifacts and the detector have landed, which is the condition the constant own comment states: RELEASE_TAG is deliberately not moved by a release cut because it names what dl.millerbyte.com can serve rather than what the workspace is versioned at, and v0.4.23 reached the public bucket in one finalize pass shipping three of five triples with the two darwin ones carried forward on the signed manifest platform_pins, after which the published detector installed it anonymously through all four surfaces and read back loot 0.4.23 exactly. DARWIN_CARRY_TAG is deliberately left at v0.4.14 because the macOS rows are served by that carried pin and not by this tag, so following the tag here would point both rows at a 404, which is the one failure the per-row override exists to prevent; an exhaustive search of the tree finds no other occurrence of 0.4.22 outside this constant, so nothing historical had to be weighed and left standing. the bump is verified rather than asserted, release-pin.net.test.ts running live against the CDN rather than returning early and confirming the published sha256.sum lists each non-carried row asset. the site gate is green from the lane (669 passed and 62 skipped over 61 files, the seven skipped being the pg suites with no test URLs) and the byte budget refused nothing and recorded nothing, all 62 surfaces under ceiling, with privacy reading 592 bytes over its recorded figure and 901 of headroom, a figure the cut already measured and not this change own. no migration, no wire or format byte moves and no host behaviour moves, but the published install page changes, so this owes a site deploy. the workspace suite is green (4140 passed over 132 binaries, 8 ignored) (#2221)nothing readable · 2 sealed · 2 internal
- loot 0.4.23: loot-cli and loot-forge move to 0.4.23 with their two lock entries, the first public release since 0.4.22 and the one that carries the seal-over-tree-entry arc, where every site that acted on a change tree entry unsigned visibility field now asks the seal instead (#2185 the three acting sites, #2188 the timed deposit lane, #2187 the push-time deposit plan, #2196 the git bridge projection, #2203 the git-side ingest, #2205 both grant doors and #2212 the sync ingest door, with #2206 and #2214 measuring and correcting the prose behind them), beside the forge runner and job tables (#2157, ADR 0091, migration 0018), the owner side of a proposal (#2162, ADR 0075), the pre-land gate learning which stream a doctest reports on and refusing a cargo it could not start (#2084, #2140, #2199, #2066), a patch that carries the ending of the line it shows (#2005), the relay mailbox taking the door the relay already writes objects through (#2112), and every other land since 3cfbe9b, 30 in all, the first of which is the RELEASE_TAG move that published 0.4.22 (#2147). format major stays at 14, format.rs has no diff at all in the range, and both live hosts answer format_major 14 over /info, so ADR 0066 has nothing to sequence. the top forge migration is now 0018_runner_and_job.sql where the 0.4.22 cut said 0017, so unlike the last release this one DOES owe a schema step: 0018 is include_str-ed into MIGRATIONS and rides the forge binary, so the forge deploys BEFORE the site. the Known Issues page is re-reviewed by running the 0.4.23 binary in a throwaway home, with HOME and USERPROFILE and XDG_CONFIG_HOME and XDG_CACHE_HOME all redirected into a temp directory and a local loot-relayd for the pull half, rather than by re-reading source: the one entry reproduces word for word, change xoxokopy has descendants - v1 edits only a tip (childless) change at exit 1, while loot edit on the tip reopens version 0101b025 as the working change, so it stays. the custody prose was re-run rather than re-read as well: once loot lock cleared the session, status, log, diff, grep, surface, whoami, describe and push each refused with the ADR 0068 message while lock and unlock still ran, a wrong LOOT_PASSPHRASE said so and was ignored, the session file held loot-unlock v2 and machine and sealed hex with the passphrase own hex in no file under the config directory, loot id phrase refused both a pipe and a redirect with no override, loot undo refused across the push barrier in the words the page quotes, and loot burn printed the never-pushed and pushed tiers with one line per disclosed host. ONE CLAIM IS CORRECTED, and it had rotted without an edit: the locked-pull paragraph read since {REVIEWED_AGAINST} the ingest writes down the claim it could not check, which was exact when #2089 wrote it at v0.4.21 and false one cut later, .loot/stale-disk-unverified being in the v0.4.21 tag and absent from v0.4.20, so it is the literal v0.4.21 now, for the reason the session-file boundary is the literal v0.4.17; the behaviour itself was re-run and holds, a locked pull leaving the receiving disk on the old bytes and parking .loot/stale-disk-unverified while the rehome its note names materialized the arrived version after unlock. REVIEWED_AGAINST moves to v0.4.23 and LAST_REVIEWED to 2026-09-21. RELEASE_TAG is deliberately NOT moved: it names what dl.millerbyte.com can serve, and this release has reached nothing yet. the site byte budget is NOT re-recorded, because no ceiling has to move: all 62 surfaces are under theirs, /known-issues is +7 B against a 208896 B ceiling, and the one figure worth a reader eye is /privacy at +586 vs recorded with 907 B of headroom, which is not this cut own since nothing here touches that page. the site gate is green in the lane (tsc, the build, 669 passed and 62 skipped over 61 files, and the budget), the workspace suite is green (4140 passed over 132 binaries, 8 ignored, 0 failed) and cargo build --release --locked validates the lock edit (loot 0.4.23 from the lane binary, and loot-forge 0.4.23 built beside it)
- ↳ supersedes
fe8005be· not stored here - Kept, not rewritten: a carry replays a suffix as a new version and the one it replaced stays addressable. That is the difference between a carry and a rebase.
nothing readable · 5 sealed · 5 internal - ↳ supersedes
- the land gate gets the predicate it was specified without, and proposal-derived turns out to be the wrong concept: ADR 0075's #2162 amendment said the local land enforces attestations for a proposal-derived change and never defined it, which could not be built at all because loot-first reads no loot change author anywhere and the only author it sees is the GitHub PR login, the very field that amendment had to correct. ADR 0092 replaces the concept rather than implementing it, firing on a change whose author is not in the lander's own key set, the active signing key plus the rotation archive, because what a gate should care about is code the lander did not write and the route it arrived by is incidental, which also catches a colleague's change carried in with no proposal at all, the case ADR 0075 calls a feature. two predicates stay separate on purpose and each names its own question: carry_line asks may I re-author this and must compare the current key since a rotated key cannot sign, while the gate asks did I write this and spans every key the identity has used since a rotation does not make earlier work somebody else's, so a rotated operator's own change is Foreign to the carry and theirs to the gate, and the natural repair of unifying them breaks one caller in either direction. that same Foreign arm is what makes a verdict usable at a land at all, since an attestation binds a version and a foreign suffix is merged rather than replayed, so version ids survive where a replay would have detached every pass in silence and read as not yet verified. the judged set is the ancestor closure of the lane tip minus what main covers rather than carry_line first-parent chain, because a stack containing a merge of its own would otherwise smuggle unapproved work in on a second parent and report green. an absent author counts as foreign and that was already shipped. gating is the repo policy, declared per requirement in the LANDED .lootpipeline and defaulting to advisory, which is what makes the #2162 rule about reading the landed copy load-bearing rather than prudent, while detection is always on and the verdict line states foreign authorship so that advisory never becomes invisible. the predicate itself is not configurable, authorship being a fact rather than a preference. ADR 0091 section 6 is corrected in passing: its sentence that a change step judges the merged tree at a land is an intention, loot-first naming .lootpipeline nowhere and a land running the Land gate phase off the untracked .loot/gates instead. CONTEXT.md gains Foreign authorship, and #2178 is re-specified and shrinks. docs only: no code, no migration, no wire or format byte moves, so this owes no deploy (#2216)nothing readable · 5 sealed · 5 internal
- the arc's one self-contradiction is gone and its newest list shape is answered wherever it stands: #2214 asked for every premise to be re-verified on the tree first and items 1-5 all held, and two sites the ticket did not cite held with them plus one list that was already stale — ADR 0007's own #2205 header carried both the hand-maintained variant count and a second copy of the false carry claim, and the impl doc over the store door named the ingest paths where the chokepoint property would have named itself, missing the tag-1 grant door and put_published. the self-contradiction is ADR 0012's twelfth amendment, which #2212's commit message lists as corrected and which it edited one clause later, still saying a crossing between positions carries a key into the lane it is already in while ADR 0007 and escrow.rs both say a grant is a new filing at the recipient that reads the seal and answers for itself; the clause is deleted with the false reason named rather than quietly dropped, because the surviving conclusion has to be seen standing on what an older binary already wrote and on the absence of any route that takes it back out. the sharper lesson is item 4's and it is sharper than do not list members: the sentence that failed was already in the correct derived shape, and a count welded on beside it in the same breath was the half that went stale, so every replacement says what decides membership and stops there — store's call sites are the ingest paths and the compiler enumerates them, file_granted_key's call sites are the Frame variants that carry a grant, and the headline over the grant-door pin stops counting the doors it drives. secondary items: the store door's promise that a garbage key is rejected rather than filed is narrowed to the held-address arm with the fresh arm's literal true named as vacuous where a reader meets it, the carry definition stops being true by construction and says what a carry does to the lane so its own falsifier lands on that axis, the three co-travelling seal facts become a Weighed struct whose third field is named for what both arms make it, embargo_reveal_at delegates its Visibility half to embargo_instant so Embargoed is destructured for an instant in one place and the zero belongs to whoever asks for a number, the demotion refusal spells every bool pair and returns the name from the match so no arm asserts a pair it cannot be reached with, embargo instant becomes the glossary's reveal_at, the 127-character ADR line is rewrapped, and the one-address sync fixture preamble collapses into sync_of_one. red under mutation, counts read each time: the entry arm of the demotion refusal made to say the seal (2 passed and 1 failed), embargo_reveal_at's collapse moved off zero (655 passed and 5 failed) and the fresh arm's unrefuted made false (523 passed and 137 failed), each restored to 3 and 660 passed with 0 failed. no migration, no wire or format byte moves, no host behaviour moves and nothing an operator or a client can observe moves, so this rides the next release and owes no deploy. the workspace suite is green (4140 passed over 132 binaries, 8 ignored) (#2214)nothing readable · 8 sealed · 8 internal
- the sync ingest door weighs the seal this store holds rather than the one that arrived beside the key, so a tag-0 bundle spelling a weaker tier at an address this position already owns can no longer file a live embargo's key into the Keyring: #2212 asked for item 1 to be demonstrated before it was repaired and the reproduction read exactly as the ticket claimed, bob holding oid sealed Embargoed 9_000 and a Sync frame carrying a byte-identical object that spells vis Internal beside the real key leaving bob's Keyring holding that key at a clock of 0, which is the state #2205's own new pin forbids reached by changing the frame tag, no plaintext escaping because sealed::open's header gate still refuses. the same read carries grant_ids and that half was demonstrated too, a copy spelling the ANYONE marker over a held Restricted seal getting a key past the entitlement filter #864 built, so every question this door puts to a seal now goes to the copy that will stand at the address. it is asked before the put while the arriving object is still in hand, because first-write-wins makes the held copy the standing one only where the store holds the address at all, so the cost is zero store reads on a fresh address and one on a dedup, which is the read the key verification already owed and now answers the seal's questions with its own; the already-held guard consults both lanes, so the lane the first door chose is the one that stands. the prose is the harder half and the lesson is sharper than do not list members: the sentence that failed was in the correct derived shape, the set of them is Keyring::insert's callers which the compiler enumerates, with a hand-maintained count welded on in the same breath, and the count is the half that was wrong, so every replacement names what decides membership and stops there, at ADR 0007's amendment, escrow.rs, CONTEXT.md, custody.rs twice, ADR 0012's tenth and twelfth amendments, negotiation.rs and the grant-door pin, and escrow.rs's headline stops claiming that no route moves a key between lanes when flush is one and a grant is a new filing at the recipient rather than a carry. secondary items: the stale pin citation and the now-false claim around it, spawn.rs's three false statements about the orphaned child, the unproducible-seal fallback recorded as releasing nothing only at the instant it files, expires_at declined as a term of the staging max with the reason at the code, the demotion refusal naming which of the two recordings fired, the census group sentence that named its members, ADR 0012's push qualifier at the tip with no want, the ingest cost fixture given a publishes-nothing control, workflow.md's three refusals derived from CargoTestFailure and the PRE_LAND constants, a usize subtraction restated as a sum so the sentence beside it can print, and orchestrator.rs's tombstoned pin names declined with the reason. red under mutation, counts read each time: the vis term reverted to the arriving copy (659 passed and 1 failed), the grant_ids term reverted (659 passed and 1 failed), the already-held guard narrowed to the one lane it writes (659 passed and 1 failed), the seal question asked through a second store read (659 passed and 1 failed, object_gets reading 8 where 0 belongs), the lying sync copy made a different object (659 passed and 1 failed, the vacuity control firing), the lying grant ids made to agree (659 passed and 1 failed, the second vacuity control firing), the publishes-nothing control inverted (1353 passed and 1 failed), the refusal made to say both either way (1352 passed and 2 failed) and the ingest cost relation moved by one (1353 passed and 1 failed), each restored to 660 and 1354 passed with 0 failed. no migration, no wire or format byte moves and no host behaviour moves, but which lane a sync-borne key is filed into moves on the client, so this rides the next release and owes no deploy. the workspace suite is green (4140 passed over 132 binaries, 8 ignored) (#2212)nothing readable · 13 sealed · 13 internal
- the git-side ingest asks the seal for the tier it guards on and for the one it reuses under, so an entry overclaiming Internal can no longer buy a silent demotion nor ride into the next tree as this position own recording: #2203 asked for every premise to be re-verified on the tree first and the body named one reader where there are two decisions a few lines apart over one field, the demotion refusal taking demotes(&old_entry.1, &vis) and the Act::Reuse decision comparing old_entry.1 with the derived tier and then carrying that entry oid AND its tier forward, beside a third use that decides nothing, parent_tree going over whole to ingest_change as the base every untouched path is carried on. the two decisions get two answers because they are two questions and proximity is not an argument, that being what produced the bound #2187 had to refute: the guard is about the tier a path is recorded at, a path in disagreement is recorded two ways, so both are weighed and the narrower stands, the seal supplying the half that was missing while the entry keeps the withholding half it has at public_delta_tree, because asking the seal alone would have deleted a refusal rather than repaired one — an entry narrower than its seal is exactly what withholds that path from the projection, so ingesting over it widens the recording that was doing the withholding. the reuse gets the object alone, its question being whether a fresh put_sealed would produce what is already on disk, which the entry is not a recording of, and a disagreement there needs no refusal because withholding a reuse only means doing the work; it refuses where the projection drops, because dropping a path here drops a break-glass commit edit out of the very change that stands for that commit. the comparison is == and not the deposit lanes discriminant (#2187), the holder list here being exactly who could open the object a reuse declines to re-seal. the cost is measured at this site rather than inherited from #2196 already-open projection object: the arm pays 2 object_gets for a path the parent tree records and 0 for one it does not, read as a difference over a real ingest_commit, and the entry spelling cost the same pair. red under mutation, counts read each time: the seal term dropped from the guard (62 passed and 1 failed), the entry term dropped (62 passed and 1 failed), the reuse comparison reading the entry (61 passed and 2 failed), Act::Reuse carrying the entry tier (62 passed and 1 failed), the tier taken by a second store read (62 passed and 1 failed, object_gets reading 4 where 3 belongs), the overclaiming fixture seal made unopenable (62 passed and 1 failed, the vacuity control firing) and the underclaiming fixture entry made honest (62 passed and 1 failed, the refusal correctly stopping), each restored to 63 passed and 0 failed. the site is a census row for the first time, the field having been reached through .1 which that census header names as outside its needle, so its silence was never evidence, and ADR 0012 takes a thirteenth amendment recording the two answers, the measurement and the carry this does not repair. no migration, no wire or format byte moves and no host behaviour moves, but which git commits ingest moves on the client, so this rides the next release and owes no deploy. the workspace suite is green (4137 passed over 132 binaries, 8 ignored) (#2203)nothing readable · 5 sealed · 5 internal
- both grant doors weigh the seal before they choose a lane, so an early-releasing sender can no longer file a live embargo key into a receiving position Keyring: #2205 asked for every premise to be re-verified on the tree first and each of them held, a tag-1 frame asking no embargo question at all and a tag-3 grant filing by the frame reveal_at, which is the sender word, so at a clock of 0 against a seal recording Embargoed reveal_at 9_000 both doors left keyring.holds true and escrow.holds false. the framing question is answered where a reader meets it rather than inherited by proximity: which lane a key waits in is decided once, at the door that files it, because a route carrying a key from one position custody to another reads one lane and writes the same one and Escrow::flush promotes but never demotes, so a filing is the answer every position that key later reaches inherits with nothing re-asking, and ADR 0007 states its guarantee over identities rather than over one door, which makes a door that does not ask a gap in it rather than the Escrow scope. one rule in one body, because two doors asking one question in two places is how they come to disagree about it: a grant-borne key is staged until the latest instant any party to the handoff named, so a party added later is another term of the same max rather than another arm. a disagreement withholds rather than refusing or dropping, refusing costing a recipient a grant over a claim they did not write with a remedy that is not theirs to act on, and taking the seal instant alone being strictly weaker, because a grantor own delay over content under no embargo is ADR 0027 timed deposit and a seal contributing 0 would release it on arrival; withholding costs only the wait the seal already imposes on every reader of those bytes, sealed::open embargo gate refusing them at that clock whichever lane the key sits in. the seal is read back from this store and never off the arriving bundle, because the address does not cover vis and put is first-write-wins, so weighing the incoming copy is reading the sender word a second time under another name, pinned on a fixture whose lying copy keeps the address and is therefore a dedup. the two doors get one answer for two reasons and the difference is recorded: tag 3 had a recorded cooperative-defence posture and this applies it to a second party, which is why ADR 0007 takes a #2205 amendment, while tag 1 had no decision at all, existing to bypass the entitlement question and having taken the embargo one with it, which sealed::open first gate separates in four words, time not identity. the cost is measured rather than assumed: one object get per key the door files and zero disk reads where the grant carried the object its key is for, eight keys costing eight gets beside a ninth address the same bundle carried no key for. red under mutation, counts read each time: the seal term dropped from the staging max (654 passed and 3 failed), the tag-1 door reverted to filing into the Keyring (654 passed and 3 failed), the frame term dropped (655 passed and 2 failed), the staging comparison widened to greater-or-equal so an undue key stages (653 passed and 4 failed), the seal weighed off the bundle copy rather than this store (654 passed and 3 failed, the held-seal pin naming the lane), the question moved ahead of the key guard (656 passed and 1 failed, object_gets reading 17 where 8 belongs), and each of the two fixtures inverted as a vacuity control (656 passed and 1 failed, the control firing), each restored to 657 passed and 0 failed. ADR 0012 takes a twelfth amendment recording that this class is a sibling of its own, the disagreement being with a frame rather than a tree entry so no census row moves, and that keyring.holds is still not a bound, a key some door filed before this change being in .loot/keyring still. no migration, no wire or format byte moves and no host behaviour moves, but which lane a grant-borne key is filed into moves on the client, so this rides the next release and owes no deploy. the workspace suite is green (4131 passed over 132 binaries, 8 ignored) (#2205)nothing readable · 8 sealed · 8 internal
- the deposit cost test measures the shape its comment claimed and the ships-nothing push is measured rather than assumed: #2206 asked for every premise to be re-verified on the tree first and the leading one holds, the comment saying a peer that already holds the tip while the code passed have = &[], a peer that holds nothing, so what it measured was the shipping push twice — the promotion the zero rests on comes from ride_entry probing every entry of every sent change, and send nothing, promote nothing. the missing shape is on the same fixture now: have = [tip] with no want promotes no address at all, the send pass skipping a held change before it touches the manifest and the wants lane skipping on empty wants, so the deposit plan behind it pays the whole cold walk, 64 object gets and 64 disk reads against the zero disk reads behind a push that ships, which is the cold arm number and not the pushing one. it is recorded rather than repaired and the reason stands where a reader meets it: the waste is plan_standing already-deposited filter, a map lookup, running after each lane has built its list with a store read per row, and putting the ledger first needs the remote and the recipient the lanes take no argument for, which gives the dedupe rule two spellings whose failure direction is a standing self-grant silently not planned, so it is #2208 and ADR 0012 takes an eleventh amendment carrying the number, the measurement and the scope the tenth amendment zero really had. the third Visibility comparison keeps the discriminant and says why rather than leaving it to a later tidy, the value under a tier being unable to move a path between lanes so that reading it withholds a self-grant over a difference that files the key in the same place, with same_seal named as the strictly stricter call it must not become and the row that separates them pinned; the case that doc named and the function cannot see, an entry spelling an embargo instant the seal does not, is gone. the two grant-apply doors asserted as complete become the question that decides membership — Keyring::insert callers against the one filing keyed on obj.vis — at the code, in the ADR and in #2205 body, refresh_hold and the save/load unions being routes the count missed. the silent drop keeps its decline and stops resting on a state an honestly captured tree cannot enter, an ingested tree being the only kind the repair is for. the standing fail-open arm is asserted over both lanes in one comparison, a struct Run no longer collides with a test-local alias, unjudged residual arm stops claiming the suite answered, kept_or_unwind records that its resume orphans the child, and the ungrammatical no-verdict sentence is fixed at the gate doc and in workflow.md. red under mutation, counts read each time: the tier comparison made same_seal (73 passed and 1 failed), the fail-open arm made to drop (73 passed and 1 failed, both lanes empty), the seal question moved ahead of the key guard (73 passed and 1 failed, object_gets reading 65 where 64 belongs), the ships-nothing peer made to hold nothing (73 passed and 1 failed, the bundle opening 65 where 0 belongs), the new pin fixture made to agree (73 passed and 1 failed, the vacuity control firing) and the Internal lane made to stop asking (71 passed and 3 failed), each restored to 74 passed and 0 failed. no migration, no wire or format byte moves, no host behaviour moves and nothing an operator can observe moves, the one string that changed being a clause no refusal quotes today, so this rides the next release and owes no deploy. the workspace suite is green (4128 passed over 132 binaries, 8 ignored) (#2206)nothing readable · 6 sealed · 6 internal
- the push-time deposit plan asks the seal which lane a path belongs in, so a lying tree entry can no longer move a key between the internal and restricted lanes, and the bound the deferral rested on turns out to be false: #2187 asked for the key-not-tier claim to be tested before anything was built on it and it does not hold, because the Escrow is where the doors that read the seal own vis file an embargoed key and neither grant-apply door does - a tag-1 bundle files straight into the keyring with no embargo question asked at all, and apply_sealed_grant files by the frame reveal_at rather than the seal one, which is that verb recorded cooperative-defence posture - so a position keyring can hold the key to a live embargo and keyring.holds was never the guard that sentence said it was, pinned now rather than described. the cost was measured here rather than imported from #2196, whose zero was its projection already-open object: the question is asked behind the key guard, so it is one store read per row a lane returns and not one per finalized-tree path as the deferral estimated, and 64 held internal rows cost 64 object gets and 64 disk reads alone against zero disk reads behind a push, because a change node carries a full manifest and ride_entry has already opened every one of those addresses by the time push_with reaches the deposit plan. a disagreement withholds rather than substitutes or refuses: filing the path under the tier the seal records would move an embargoed seal into the timed lane, whose rows are crossed with every registered peer, and refusing would stop a push over an entry its operator may not have written. the comparison is std::mem::discriminant and never an equality, because #521 keeps holder names local so a wire-redacted restricted entry over a seal this repo persists the name in is the ordinary case and not a lie, and a tier added to Visibility needs nothing there; an unreadable seal keeps the row on embargoed_paths own permissive arm and its defence, grant_sealed refusing on the same address, which is what keeps a rotted object from costing a second machine the standing self-grant it opens the path with. a counted note beside the DepositPlan embargo one was weighed and declined: it would need each lane to hand back what it withheld as well as what it kept, for a state an honestly captured tree cannot enter. red under mutation, counts read each time: internal_paths no longer asking (70 passed and 3 failed), restricted_paths no longer asking (72 passed and 1 failed), the tier comparison made an equality (72 passed and 1 failed, the wire-redacted row dropped), the unreadable-seal arm made to drop (72 passed and 1 failed), the seal question moved ahead of the key guard (72 passed and 1 failed, object_gets reading 65 where 64 belongs), the fixture embargoed seal made unproducible (72 passed and 1 failed, the vacuity control firing) and the tag-1 door given an embargo gate (72 passed and 1 failed), each restored to 73 passed and 0 failed. the census row keeps its class and stops calling the widening unmeasured, and ADR 0012 takes a tenth amendment recording the direction, the measurement and the refuted bound. no migration, no wire or format byte moves and no host behaviour moves, but which keys a push deposits moves on the client, so this rides the next release and owes no deploy. the workspace suite is green (4127 passed over 132 binaries, 8 ignored) (#2187)nothing readable · 4 sealed · 4 internal
- the git bridge projection asks the seal for the tier it publishes on, so a restricted seal entered as internal stops reaching a pushed branch: #2196's premise was re-verified on the tree first and it holds, ferry's public_delta_tree chose from the change tree entry's visibility, a field sealed::seal's address does not cover and compute_change_id_raw discards before the finalize signature is taken over it, and the bound was never the mirror being local but the open, which refuses an unauthorized or embargoed seal, so a live embargo never rode a lying entry out while a restricted seal this position holds the key for did, as did an embargo whose reveal had passed. the cost was measured rather than assumed: workspace::readable_object_and_class, the door #1581 built, hands back the seal's tier and sealed::open's bytes from the one DagRepo::object the projection was already paying for, and the same projection moves object_gets by 3 before and after with every other counter identical, so the store-read objection that defers #2187's lane selection does not arise at this site; it also retires ferry's hand-rolled copy of the sealed-to-you rule. the entry is still read and can now only withhold, which is what keeps a pass over every unrepresented change from opening a store object per sealed path, and on a disagreement the path is dropped into the omitted-sealed-paths report rather than refusing, because project walks every change no mark stands for and a refusal there would stop every land and every review push over an entry the refusing operator did not write. both directions are pinned on one hand-recorded tree, under a control asserting each lying seal opens from this position so an omission cannot pass for the open's doing. red under mutation, counts read each time: the seal's tier ignored again (55 passed and 2 failed), the match tightened so nothing projects (37 passed and 20 failed), the entry's cheap withholding half dropped (56 passed and 1 failed, object_gets reading 4 where 3 belongs), the disagreement dropped off the report (55 passed and 2 failed) and the fixture's seal made unopenable (56 passed and 1 failed, the vacuity control firing), each restored to 57 passed and 0 failed. the census row moves with the decision and stops asserting which sites have moved, and ADR 0012 takes a ninth amendment recording the direction, the measurement and the git-side ingest demotion guard this does not reach. no migration, no wire or format byte moves and no host behaviour moves, but what a ferry projects moves on the client, so this rides the next release and owes no deploy. the workspace suite is green (4123 passed over 132 binaries, 8 ignored) (#2196)
- ↳ supersedes
a85ec67a· not stored here - Kept, not rewritten: a carry replays a suffix as a new version and the one it replaced stays addressable. That is the difference between a carry and a rebase.
nothing readable · 5 sealed · 5 internal - ↳ supersedes
- the owner side of a proposal is decided, and only one of ADR 0075 three terminal states had a producer: close_proposal accepts withdrawn, declined and landed and both stores implement it, but its sole non-test caller is propose::withdraw and every other call site is a test or a conformance case, while propose::list had no caller outside its own tests and propose::read only handle_propose_withdraw, so an owner could not see, decline or land anything and the half of ADR 0075 naming their acts was unreachable rather than undecided. landing stays LOCAL and the forge only observes, foreclosed three independent ways rather than by preference: the forge would have to mint a HeadDeclaration carrying generation_expected, which is the one artifact this design has a client sign; ADR 0091 decides the forge runs nothing because it holds ciphertext and cannot run a step over a sealed path, and a land is a converge plus a gate; and a runner cannot stand in because ADR 0091 puts it under no account, so both write doors refuse it by absence. ingest closes the row pre-computed OUTSIDE its transaction, because IngestTxn is assembled and validated outside so the transaction is pure writes after the CAS, and that same CAS is what makes the pre-computation sound rather than racy, generation_expected pinning the very head set it assumed. the decline binds the repo, the change id AND the tip, the tip because re-proposal after a decline is permitted and a captured envelope must not end a revised one. the read surface is two transports sharing no path, the CLI over HTTP and the site over Postgres barrier views, so both are owed and a conformance pin demands that visible_to and the views answer with identical row sets, or the web discloses what the CLI conceals and nothing fails. the presenting key is world-visible and the propose-time disclosure now says so rather than naming existence alone. and one consequence of this ADR was WRONG: landing a proposal does not take policy::approval off its SelfAuthoredFastPath arm, because that function compares a GitHub PR author login with the GitHub account running the land and reads the loot change author nowhere, so an owner opening the PR keeps the fast path and a stranger code lands on the weakest approval signal with nothing in the gate knowing it was not theirs, which is why a distinct owner-signed review/approve role is required rather than the question handed to map #1014. ADR 0091 gains the landing policy home and the second human role, CONTEXT.md and spec section 7 gain the owner acts, graduated as #2174 through #2178 with #2180, #2181 and #2182 filed beside them. docs only: no code, no migration, no wire or format byte moves, so this owes no deploy (#2162)
- ↳ supersedes
fb47dde1· not stored here - Kept, not rewritten: a carry replays a suffix as a new version and the one it replaced stays addressable. That is the difference between a carry and a rebase.
nothing readable · 5 sealed · 5 internal - ↳ supersedes
- the no-verdict refusal stops telling a lander there is nothing to fix when a doctest really did fail, and the two lists asserted as complete are replaced by the question that decides membership: #2199 asked for every premise to be re-verified on the tree first and each of them held — cargo test here carries no --no-fail-fast, so the step cargo names on stderr is the one that failed and every step it ran before that one passed, and doctest_artifact_form returns the first rlib line whatever else the stream holds, while the two pins that cover those posed the real error and the rlib line in separate fixtures, so nothing saw the combination. the fix is the prose and not the classifier, because deciding which error on a stream is the genuine one is the text guess #2079 declined, while what a run left the gate unable to judge is a fact the gate already holds: unjudged is an exhaustive match over CargoTestFailure that takes no wildcard, so a classification added there cannot inherit a sentence written for a different one, which is exactly how this defect arrived; each run's line in the refusal now carries its own clause, the shared sentence says only that neither run reached a verdict, the heading says neither run reached one rather than neither run judged the tree, and the merged-tree remedy stops saying there is nothing to fix in it. one stream holding a genuinely broken doctest and the held-rlib line is entered as a fixture in both crates, red-first. the verdict-line test stops naming three runbooks that quote it and says what makes something a reader of that line, and ADR 0088 section 4's V4 decline keeps its load-bearing claim while stating the membership question instead of four ways to miss, two of the hits fitting none of the four. Spawner::tee carries a dead drain thread's panic through instead of reading it as empty stdout, which is the pre-#2084 blindness reached by another route. red under mutation, counts read each time: the wide shared sentence restored (196 passed and 1 failed), the ArtifactForm arm inheriting the crash sentence (196 passed and 1 failed), the per-run clause dropped from the layout (196 passed and 1 failed), the heading's coverage claim restored (196 passed and 1 failed), the merged remedy's nothing-to-fix restored (196 passed and 1 failed), the drain panic swallowed again (loot-cli 1344 passed and 1 failed) and the classifier made to weigh the rest of the stream (loot-hygiene 40 passed and 1 failed), each restored to 197 passed, 1345 passed and 41 passed. no migration, no wire or format byte moves and no host behaviour moves, but what a pre-land refusal prints moves on the client, so this rides the next release and owes no deploy. the workspace suite is green (4120 passed over 132 binaries, 8 ignored) (#2199)nothing readable · 7 sealed · 7 internal
- the pre-land gate reads the stream a doctest reports on, and the four failures in the sighting turn out to be the four that link rather than the compile_fail probes: #2084 asked for the condition to be reproduced rather than guessed, and it reproduces in one command, a transitive dependency rlib under target/debug/deps held open with no sharing, after which cargo test --locked -p loot-cli --doc comes back 6 passed and 4 failed with rustc saying crate socket2 required to be available in rlib format, the four being the doctests that link, cargo not rebuilding because the rlib mtime is as readable as ever, and the handle released giving 10 passed again. two premises in the ticket body are corrected off its own land log: the four it names are the doctests without compile_fail, a compile_fail probe never reaching a link at all, and the feature-unification hypothesis is refuted by profile, since the perf gate builds loot-perf-gate with --features count under --release into target/release while the suite reads target/debug, and that land test build was already fresh at 0.66s, so nothing in the invocation built anything to collide with. the gate could not see any of it because the evidence is on stdout, under the libtest captured-output heading, while tee_stderr set Captured stdout to empty by construction, so classify_cargo_test_failure read a finding off a stream that could not hold it. tee_stderr becomes tee and drains both pipes, stdout on a thread of its own because two pipes read in turn deadlock; CargoTestFailure gains ArtifactForm, keyed on cargo naming the doctest step on stderr together with a line opening error: crate on stdout, which is the widening #2079 declined and which answers the objections of that ticket rather than stepping around them; a first run classified that way buys the re-run #1873 already gives, and the same condition on both runs refuses as a no-verdict rather than as a finding, so a merged pass owes cargo clean and never the ADR 0055 story. the NO VERDICT heading says neither run judged the tree now rather than naming a crash, the third question is answered no in the doc of the gate itself with what a split would cost, and the stale #2079 bullet saying this classifier reads stderr is corrected where it stands. red under mutation, counts read each time: the stdout half never asked (loot-hygiene 39 passed and 1 failed, loot-first 193 passed and 3 failed), the doctest-step anchor dropped (39 passed and 1 failed, a real compile failure reading ArtifactForm), the line-start anchor dropped (39 passed and 1 failed, a quoted source line classifying), the real adapter dropping stdout again (loot-cli 17 passed and 1 failed), a doctest link failure counted as a verdict on the tree (194 passed and 2 failed) and the no-verdict closing sentence removed (195 passed and 1 failed), each restored to 196 passed, 40 passed and 1344 passed. no migration, no wire or format byte moves and no host behaviour moves, but what the pre-land gate prints and whether it retries moves on the client, so this rides the next release and owes no deploy. the workspace suite is green (4117 passed over 132 binaries, 8 ignored) (#2084)nothing readable · 6 sealed · 6 internal
- the adr guard says on the verdict line that its fetch did not answer, and the test whose subject is that fetch asks whether it ran before it reads the refusal: #2140 was filed from a land refused by the_adr_guard_fetches_the_collision_the_local_refs_still_hide under the note that origin could not be reached, which is the documented degrade, so the guard did exactly what it promises and the test failed anyway with a message naming a property rather than a cause. the premise was narrowed on the tree first, and the ticket asks for that: the test never reaches a real origin at all, origin_and_clone builds a git repo under the temp dir and clones it, so pointing it at a local fixture remote was already done and what failed in the sighting was a local git fetch. severing that remote reproduces the sighting byte for byte, the same note above the same panic reading the fetch must surface the collision the local refs hide, so the condition was made rather than waited for. the ask carries its degrade out now as well as speaking it: refuse_adr_collision returns an AdrAsk of a refusal and a reason, git_fetch_main says which step did not answer instead of a bare none, and the note both fetch-before-read guards share quotes that reason, the sighting having captured nothing beyond the note itself. the test reads the fetch before the refusal, so under the same severed remote it says the fetch did not run and that it measured nothing about the collision, with the reason beside it. the loudness question is answered yes and recorded as an ADR 0065 amendment: a degraded guard reaches the verdict line as adr=STALE-REFS with a block under it, on the #1251 posture, because the note from the first ask lands minutes of cargo and npm above the verdict and what a stale answer can publish is a duplicate ADR number on main, which is #1080 itself. the field reports the last ask a land made, every ask putting the same question to the same landed main, so an ask that fetched supersedes one that did not. red under mutation, counts read each time: the ask dropping its reason again (190 passed and 3 failed), the pass no longer recording it (192 passed and 1 failed), the verdict word made unconditional (191 passed and 2 failed), the block taken off (191 passed and 2 failed), the reason no longer naming the step (191 passed and 2 failed) and the kill no longer naming the bound it happened at (192 passed and 1 failed), each restored to 193 passed and 0 failed. no migration, no wire or format byte moves and no host behaviour moves, but what a land prints on its verdict line moves, so this rides the next release and owes no deploy. the workspace suite is green (4111 passed over 132 binaries, 8 ignored) (#2140)nothing readable · 5 sealed · 5 internal
- the permissive deposit arm gets the pin its defence was resting on, the standing-lane assertion that could not fail gets a comparison, and the declined cross-shape census weighs the instrument it never considered: #2194 carries the sweep 14 fix-ups plus the five a focused review of #2188 found, each premise re-verified on the tree first. item 8 is judged kept rather than closed to match its siblings, because where the seal cannot be produced embargoed_paths keeps the tree entry claim and the tree entry instant, which an unsigned tree can spell 0, and the recorded defence is real, grant_sealed reading the same object through the same door before it seals anything; so the arm stays and both halves are asserted now, the row surviving with the number the entry chose and the grant that row plans refusing at the same address, under a control that the same call succeeds while the seal reads. item 9 is made to bite: a second path over the same Restricted seal is entered honestly, so the standing-lane arm is a comparison rather than an absence, and the comment names the mutation that reddens it. item 10 narrows a pin message that reached past what it asserted, onto the deposit-plan pins that do assert the fan-out. item 1 corrects the ADR 0023 cost paragraph, which named the spool leaf where the endpoint moved too, off an unescaped format string onto the shared escaping, so an endpoint holding a quote or a backslash had been emitting JSON a parser rejects; the matching commit correction is already a comment on #1971. item 3 weighs the text census and records a measurement instead of an assumption: it needs no visibility widening and spawns nothing, so no census can was the wrong shape of decline, but what a text census reads is a spelling and section 3 is a rule about rendered bytes, and measured, the comma-join needle finds its own home and sites that are not columns while the contract field is not spelled one way, so a needle on either spelling reads a subset and says nothing about a shape carrying no such field at all, which is the defect #1971 came here to fix. item 2 replaces a false inference in the land-change skill: those three headings belong to the cargo test gate, and every other gate arrives as a finding under prose of its own, the line-ending gate among them, so an unfamiliar heading is another gate before it is a new kind; workflow.md scopes the same sentence. item 11 takes the completeness claim off the deposit accessor doc, where privacy is what bounds the callers, and off the census block that asserted a key guard over a membership rule which does not check it. item 12 names the two readers still deciding off the entry, the mirror projection and the forge manifest fold, with what bounds each, and records that neither belongs to #2187. items 4 to 7 are the smells: the forwarding closure, the clone taken and then borrowed, the exemption pin that read the real machine config and now builds its report from values, and the reversed import. red under mutation, counts read each time: the unreadable-seal arm dropped (68 passed and 1 failed, the row reading empty), that arm handing on a substituted instant (68 passed and 1 failed, 9999 where 0 belongs), restricted_paths made to ask the seal (68 passed and 1 failed, secret.txt joining owned.txt in the standing lane), a contract field added to the report the sender posts (6 passed and 2 failed) and joined_col joining with a semicolon (loot-cli 1335 passed and 8 failed), each restored to 69 passed and 0 failed. no migration, no wire or format byte moves and no host behaviour moves, and no output byte moves either, every code edit here being a refactor or a test, so this owes no deploy. the workspace suite is green (4110 passed over 132 binaries, 8 ignored) (#2194)nothing readable · 11 sealed · 11 internal
- a cargo that could not be started gets its own refusal and the merged pass stops sending that lander after a combination nothing compiled: #2066 asked where a failed spawn belongs and the answer is a kind of its own rather than the no-answer one #2071 sharpened, because NoAnswer needs a crash on both runs while a spawn failure is never re-run at all, an emptied incremental cache being unable to put a program on PATH, and because its remedy is cargo clean, a cargo command for an operator whose cargo would not start, which is the #944/#962 shape of naming a remedy the tool then declines. the premise verified on the tree, where cargo_test_once minted a Refusal::Finding for the one thing a Spawner Err can mean and merged_refusal handed that to regate_remedy, the ADR 0055 semantic-conflict story plus loot edit. cargo_test_once returns the operating system reason as text now and the gate, which knows what the first run reached, decides the kind: Refusal::NotRun under a PRE_LAND_NOT_RUN heading, whose merged remedy keeps the lane-state facts and drops both the loot edit procedure and the cargo clean, naming the machine instead. the #2071 rule is asked of the new kind too, so a re-run that could not start after a first run that reached diagnostics stays a finding, those diagnostics being the only verdict either run reached, and the retry is deliberately not widened to a missing program. red under mutation, counts read each time: the first-run spawn arm minting a Finding again (191 passed and 1 failed, the refusal reading Finding where NotRun belongs), NotRun routed to the no-answer remedy (191 passed and 1 failed, cargo clean back in the merged prose), the diagnostics-then-spawn case made a NotRun (191 passed and 1 failed), the first-run spawn failure sent on to the re-run (191 passed and 1 failed, the fake naming an unstubbed second cargo test) and the heading taken off the not-run prose (190 passed and 2 failed), each restored to 192 passed and 0 failed. workflow.md and the land-change skill carry the third heading and point at the Refusal enum as what defines the set, and the From impl records that the other spawning gates are still on the finding default. no migration, no wire or format byte moves and no host behaviour moves, but what a merged-tree gate prints moves on the client, so this rides the next release and owes no deploy. the workspace suite is green (4109 passed over 132 binaries, 8 ignored) (#2066)nothing readable · 4 sealed · 4 internal
- the two shapes that graduated without a record get their amendments, telemetry status and off carry the contract field, and the comma-joined column gets one home: #1971 carries the ADR 0088 section 4 follow-ups and asks for each premise to be re-verified first, so each was read against the tree — ADR 0023 held no amendment for count-objects (#1523) or telemetry (#1658), telemetry status and off printed no contract field and the string dash where V3 says null, and the Verdict entry in CONTEXT.md still typed 17 of the 68 beside a roster where the dispatch table derives 32 emitting verbs and 51 prose-only ones; the ticket comment correcting item 2 is the later word and is taken as such, telemetry on printing report JSON for the same deliberate reason as show. ADR 0023 gains two dated amendments describing what shipped: the one-metric-per-mark census rows, and the name-keyed telemetry rows with the divergences frozen beside them. status and off lead their JSON with contract now and spell an unresolvable spool null, rendered by status_shape and off_shape, which take values rather than reading the config so all three renderings are assertable; show and on stay exempt because what they print is the report the sender posts, and the exemption is pinned over Report::to_json rather than over a verb, that string being what the endpoint receives. The shared flag column item 3 asks for is verdict::joined_col, the comma join with the dash when empty, and what defines membership is that spelling rather than a roster, so the columns spelled that way are its callers: blame, delta_shape, explain, heads, log, evolog, attestation_shape, refit_shape, seek, tag, both pipeline listings and lanes route through it and no frozen shape pin moved. The cross-shape census is declined with its cost recorded in ADR 0088 section 4, since a census over values needs a pub on each shape that #1553 refuses, one over a spawned binary reads nothing for a verb whose arguments it cannot supply, and its exemption table would be a hand-maintained list asserted as complete. Red under mutation, counts read each time: joined_col joining with a tab (loot-cli 1335 passed and 8 failed), the empty set printing an empty field instead of the dash (1324 passed and 19 failed, and loot-core 647 passed and 1 failed naming lanes_porcelain_rows_are_the_frozen_contract), the contract field taken off status and off (5 passed and 3 failed), the spool null spelled as the string dash again (7 passed and 1 failed), and a contract field added to the report the sender posts (6 passed and 2 failed), each restored. No migration, no wire or format byte moves and no host behaviour moves, but two leaves of client JSON move, so this rides the next release and owes no deploy. The workspace suite is green (4107 passed over 132 binaries, 8 ignored) (#1971)nothing readable · 18 sealed · 18 internal
- the clean sieve asks the separator rule at the half that descends too, and the census says which direction it reads rather than certifying the other one: #2033 routed Sieve::keep and left Sieve::descend handing the walk native rel straight to extra.ignores_dir and to ignore.descend, inert because each rule it feeds normalizes what it is given, and descend asks policy::unix_separators now so that half stops passing on a spelling it never decided. the reason #2035 gave for the census not seeing that site is refuted, and measured refuted: ignores_dir takes rel as a &str, so it is a door by the census own reading, and a hand-spelling planted in descend reddens the census naming src/clean.rs fn descend, before the routing and again with it undone (0 passed and 1 failed each time). what the census is really blind to is the ABSENCE of an answer rather than a second one, which is the same direction its own fixture had been calling the fixed shape, so that leg says the direction this census does not read instead, and the blindness note states the one shape it reads and calls everything outside it blind by definition rather than carrying a roster that grows. measured on the tree: rel.to_string() in Sieve::keep leaves the census green and reddens the behaviour pins (11 passed and 4 failed, a_recorded_path_with_uncaptured_edits_survives naming sub/recorded-deep.txt, a recorded file the verb would have deleted). the coverage the pair census gave up is stated too: a door is read off a signature naming a path, so Patterns::push taking text is not one and delta::Pathspec::new asks none, and widening the door reader to text: &str is declined on a measurement, since it admits push, whose bare name is Vec::push, and the census then reports its own home unix_separators beside three more functions spelling a store key or a display line, the other axis. the count-nonzero floor over the walked files goes, replaced by the property it stood in for, that a crate-wide census must have read a door caller outside the file its doors come from, which reads red with the walk truncated to policy.rs (0 passed and 1 failed, naming the eight askers left in it). the offence list is computed once rather than twice, for the assertion and its message. the ADR 0038 sentence #2033 rewrote stays: it cites a pin that stopped naming that path in the same land, so restoring it would restore a stale citation, and the paragraph below it already records the move. the record correction owed on #2030 is reported to the spawning session, being a comment. no migration, no wire or format byte moves and no host behaviour moves, so this owes no deploy. the workspace suite is green (4103 passed over 132 binaries, 8 ignored) (#2035)nothing readable · 3 sealed · 3 internal
- the timed deposit lane asks the seal whether a path belongs in it and not only when its key is released: #2185 took the reveal instant off the seal at embargoed_paths and left the tree entry deciding whether that lane was reached at all, so an entry claiming an embargo over a seal that records none was answered 0 by embargo_reveal_at, the number for content under no embargo, and a Restricted seal content key was fanned out to every registered peer as a timed grant the relay releases on arrival - the same disclosure direction widened by the repair that narrowed the other one. reproduced at the plan before deciding, running the disagreement cases through embargoed_paths, restricted_paths and internal_paths and through plan_timed and plan_standing, where the row read c.txt to bob and to carol at 0. membership of the lane comes out of seal_visibility now rather than embargo_reveal_at, because the tier and the instant come out of one read and the number alone cannot tell an agreeing entry from one whose seal records no embargo; the unreadable seal fallback stays, the deposit it feeds refusing on the same read. which lane a path is offered to is still matched off the entry and stays with #2187, deferred on the store read per finalized tree path it would cost rather than on impossibility, and both missing directions are pinned: the claimed embargo the seal denies, and the internal claiming entry over an embargoed seal, where what keeps the untimed lane off the path is the key and not the tier, a live embargo key being staged in the escrow that lane does not read. the sentence naming the internal lane as the one a lying entry moves to now names what selects a lane, the reason that argued a seal knows nothing about paths says cost and #2187 instead, the negotiation stop rule comment cites its pin under the name #2185 gave it, the key lane fixture says what defines the set of builders rather than counting them, the census helper doc says compiled into rather than asking, the spike crdt key lane records why the census cannot see it, and BTreeSet stops being spelled in full beside an imported BTreeMap. red under mutation, counts read each time: the dropped arm made to plan the row again (custody 67 passed and 1 failed, reading Some(0) where None belongs), internal_paths widened to the escrow (67 passed and 1 failed, the live embargo reaching the untimed lane), and the lane selection made to ask the seal, which is the #2187 repair (67 passed and 1 failed, the timed lane reading cve.txt and other.txt where other.txt alone belongs), each restored to 68 passed and 0 failed. no migration, no wire or format byte moves and no host behaviour moves, but what a push deposits moves on the client, so this rides the next release and owes no deploy. the workspace suite is green (4103 passed over 132 binaries, 8 ignored) (#2188)nothing readable · 8 sealed · 8 internal
- the three sites that acted on a tree entry unsigned visibility ask the seal now, and the bundle key lane stops reading that field at all: #1892 censused who reads a change tree entry visibility, refused a blanket ingest check at apply_sync, and left these three deciding on a value that sits outside the content address, outside the change id and outside the finalize signature, so on a tree that came from a peer it is a claim under no signature. ride_entry read open off the manifest entry while reading anyone off the object a line above, so an entry recording Internal over an embargoed seal put that content key into a sync bundle any peer can hold; it reads the seal the same probe already returned, memoised per address beside anyone, and costs no store read the walk was not already paying. the same predicate on the batched path moves with it, since a transfer with a second batch would otherwise reach the old answer: the key rule comes out of wanted_finalized_entries, which answers presence alone now, and bundle_objects_only asks the object it is already holding. embargoed_paths takes the reveal_at a timed relay grant is withheld until from embargo_reveal_at, the door #1578 built for that number at loot grant --relay, and the entry number survives only where the seal cannot be produced, which is a state where grant_sealed cannot produce a deposit either. publish_gate asks seal_visibility beside the oid_is_published read it already makes of the same object, and refuses where the seal cannot be read rather than swallowing, because a swallowed published-ness read asks for consent already given while a swallowed embargo publishes content nothing could say was unsealed. each pin carries both directions, since a repair that only tightens is as wrong as one that only loosens, and none of them compares the two recordings, which ADR 0012 records as supposed to differ once put_vis_redacted has stripped a holder list on the wire. the rows for the sites that stopped binding the field left #1892 census rather than changing class, a discard being no row by its own definition. red under mutation, counts read each time: ride_entry open restored to the manifest entry (negotiation 34 passed and 3 failed, the byte-identity difference red beside both direction pins, and the census 2 passed and 1 failed naming bundle_impl_within@1#1 and @1#2), the batched key arm stopped from asking (35 passed and 2 failed, naming the follow-up batch arm), the deposit reveal time taken off the entry again (custody 65 passed and 1 failed, reading Some(0) where Some(9000) belongs), the publish gate embargo read taken off the anchor entry again (loot-cli 0 passed and 2 failed, red in both directions, and the census 2 passed and 1 failed naming publish_gate@1#1) and the unreadable seal swallowed (2 passed and 1 failed, naming ghost.txt). no migration and no wire or format byte moves, but the key lane decision moves on the client bundle builder and on the relay fetch path, so this rides the next release and owes a relay deploy. the workspace suite is green (4101 passed over 132 binaries, 8 ignored) (#2185)nothing readable · 6 sealed · 6 internal
- the ingest check is refused and the census that would have judged it is what lands: a change tree entry records a visibility that sealed::seal leaves outside the address, that compute_change_id_raw discards on the way into the version id the finalize signature covers, and that ObjectStore::put keeps from whichever bundle arrived first, so on a tree that came from a peer that field is a claim under no signature. tree_entry_visibility_census.rs derives every two-identifier vis pair spelled under crates/*/src and carries per site what a lie in that field would change - rendered, acted on, re-recorded, or not a tree entry at all - keyed by file, enclosing fn, which declaration of that name and which binding under it, because bundle_codec and loot-wasm each declare a name this keys on more than once and a key on the name alone would hand two functions one ordinal run, the ambiguity store_rename_census holds out of reach with a guard instead. the class is a judgement and is not measured; what is measured is that a row cannot be written without one. the sites it turns up as acted on are what the ADR 0012 entry rests on: ride_entry reads the tree entry rather than the seal when it decides whether an anyone-granted content key rides a bundle, embargoed_paths hands a timed relay grant the reveal_at the entry records, and publish_gate refuses an embargoed publication on the anchor entry tier - each of them holding or reaching the object it could ask instead, which is why the repair is per site rather than a global refusal at apply_sync, where the check would be partial exactly where it is wanted (a change ships its whole tree, ciphertext rides only for the addresses a bundle carries), where disagrees is not is false once put_vis_redacted has stripped a holder list on the wire and same_seal exists because of it, and where one refusal rejects the whole bundle. the workspace walk moves into census_text under its own admission rule, now that a second workspace-scoped census wants it. red under mutation, counts read each time: a planted binding in maroon_inner (2 passed and 1 failed, naming maroon_inner@1#2), a named row deleted (2 passed and 1 failed, naming bundle_impl_within@1#1), the type exclusion dropped from the needle (1 passed and 2 failed, the fixture naming qualified@1#1 off an (Oid, Visibility) annotation), the declaration ordinal dropped from the key (2 passed and 1 failed, twice@1#2 where twice@2#1 belongs, the table green beside it) and the walk blinded (0 passed and 3 failed, the guard saying gone blind rather than clean). no migration, no wire or format byte moves and no host behaviour moves, so this owes no deploy. the workspace suite is green (4096 passed over 132 binaries, 8 ignored) (#1892)nothing readable · 9 sealed · 9 internal
- the stale narrowing moves to the enum that defines the set, and the plaintext census stops asking its constants what the store holds: pinned.rs still said the opener refuses a directory git cannot name a revision for, which is the vocabulary of the round before #637 gave that door a loot arm, and #1895 had just pointed the corrected loot-perf-cli header at this paragraph as its argument, so the module header now names no arm and sends the reader to Names, the door doc says what the accepted set widens with, and the struct doc and the refusal beside it follow. the binary header stops calling the door the only constructor of the type a measurement is taken against, a claim about a set the module can grow with one function and nothing derived behind it, and states privacy instead, which the compiler holds: the fields are private to pinned, so a value cannot be made out there at all. the census clock window opened at the first redaction, which runs after the fixture has built every repo, so the seconds it redacts sat below the lower edge and only the slack held them in; it now opens at the span the fixture records itself writing in, frozen once so both worlds redact through one window, and the slack is stated as paying for skew between two clock reads rather than for build time. the same census read green over a fixture whose varied path never reached the store, every planted control still catching its oracle because an oracle is planted from the recorded constants; the premise is read back per build through the repo door now and compared on the bytes that come out. the keypair archive record stops making a later second part of why a re-run works, since ts is a whole second and the put-back frees the tag, so a re-run inside the refused second takes that tag back, which is what the test exercises now; the branch where the put-back is itself refused stays unexercised and that deviation is recorded at the code with what makes it unreachable from a fixture. adr 0066 stops answering how many today with the figures in one block, because the verb-line figure the census holds stands outside it, and says instead that what decides is surviving the cut. red under mutation, counts read each time: the fixture slowed by seventy seconds between the worlds under the old window (census 4 passed and 2 failed, the value rows naming one unix second against eight redaction bytes), the window start taken at the reading again (6 passed and 1 failed), the capture stopped from recording the varied path before the new reading existed (6 passed and 0 failed, every control green) and after it (6 passed and 1 failed, naming b.txt), the put-back removed (loot-identity 48 passed and 1 failed), the suffix search started past the refused tag (46 passed and 3 failed, the resume test naming rotated-7-2), and the amendment date requirement removed, re-measured on the landed tree (loot-cli bin 0 passed and 1 failed, naming line 15 and 111 lines where the landed record says 103, that document being 952 lines before this land and not 953). no migration, no wire or format byte moves and no host behaviour moves, so this owes no deploy. the workspace suite is green (4093 passed over 132 binaries, 8 ignored) (#2179)nothing readable · 7 sealed · 7 internal
- the cli tier header stops saying that pointing loot-perf-cli at a lane fails by design, because it never has and the lane is where the readings were taken: PinnedCheckout gained a loot arm in #637, which is the next change to touch this file after #635 wrote that refusal into the header, and it left the sentence standing, so the refusal was a later decision the header never learned about rather than an accident nobody had judged, which is what #1895 asked to be established before the words moved. the replacement states the door rather than a list of the positions it allows: the checkout is whatever PinnedCheckout::open can name a revision for, that door being the only constructor of the type a measurement is taken against, so this binary can neither widen nor narrow what is accepted, and a lane is named positively as a position it measures and the position to measure from where a reader has one, a lane being single-writer and not moving while git worktree add buys the same property for a reader who has none. the live primary stays the thing to keep out of, now with the verb that actually moves it, a catch-up in another session, since ADR 0050 took the land off that tree. two more sites in the crate carry the same narrowing, both stale since #637 rather than wrong when written, and both are corrected: the Unpinned doc called the target one git cannot name when that refusal needs the loot arm to decline as well, and the RevisionMoved message sent a reader who is already in a lane off to build a worktree, where what it wants is a position nothing else writes. #1595 recorded its before and after that way and said so, loot-perf-cli on the lane, both exit 0 and discarded 0 batches. red under mutation, counts read each time: the loot arm deleted from PinnedCheckout::open takes the pinned suite to 5 passed and 8 failed, and restoring it reads 13 passed and 0 failed. the only shipped move is the text of one refusal, with no wire byte, format or schema moving and no verb or flag added, so this owes no deploy. the workspace suite is green (4092 passed over 131 binaries, 8 ignored) (#1895)nothing readable · 3 sealed · 3 internal
- the adr 0004 guard stops being a claim about a struct and becomes a question asked of the repo on disk: the pin it left asserts that no field of SealedObject is a function of plaintext, which stays green over a store that has the deleted digest back beside the struct, and that is measured rather than argued, since with DagRepo::put appending blake3 of the plaintext to a file in .loot the pin reports 1 passed and 0 failed while the new census reports 4 passed and 2 failed. plaintext_equality_census records two worlds through the same verbs, one with two paths holding the same bytes and one with them holding different bytes of the same length, builds each world four times, and refuses a persisted difference its readings can see between them: structure cancels because both worlds record the same tree, randomness is filtered by keeping only what every build of a world agrees on, and the wall clock is blanked by value, because adr 0043 stamps a second per version and a gap between two builds read red on that second alone. it walks the repo root rather than a named place, so relocation is the thing it is aimed at, and it is a lower bound and not a proof: a token shorter than its window, an index encrypted per build, and any write path the fixture does not run (a push, a pack, the mirror, the forge and the wire) are outside what it has looked at, which the new adr 0004 amendment states before a reader meets either guard. three oracles are planted as standing controls, one per reading, each the shape of a proposal that has actually been made. red under mutation, counts read each time: the sidecar planted in DagRepo::put (the census 4 passed and 2 failed, the struct pin 1 passed and 0 failed beside it), the value reading removed (5 passed and 1 failed), the shape reading stripped of its lengths (5 passed and 1 failed), the repetition reading removed (5 passed and 1 failed), the walk stopped from recursing (2 passed and 4 failed) and the two worlds made identical (3 passed and 3 failed). adr 0086 gains a pointer where it records the proposal this gap would have waved through, and CONTEXT.md says what the new reading reaches. no migration, no wire or format byte moves and no host behaviour moves, so this owes no deploy. the workspace suite is green (4092 passed over 131 binaries, 8 ignored) (#1894)nothing readable · 6 sealed · 6 internal
- a refused keypair archive puts back the half it moved, and the cut that blanks amendment records stops blanking half the document: #2112 made the order safe and left the re-run broken, because the suffix is a tag the two halves share and the search wants both names free, so a refusal at the second rename orphaned the public half under rotated-ts and sent the next run to the next suffix, handing back a path nothing had written. archive_keypair now undoes its own first rename before it returns, so the run after it meets the repo the refused one met and archives a pair under a tag of its own, which is what a re-run at a later second needs, and where the put-back is itself refused the refusal names where the public half was left; the archived public path comes back as None where there was no id.pub to move, so what it hands back is where a file is and not a name it picked. the amendment cut now asks for a date, the date being the whole reason an entry is not read: ADR 0066 opens with an undated Amended inline header and the reader blanked from there to the end of that quote, 482 lines of 953, taking the index of the amendments and the claims around it with no guarded phrase lost and nothing to say so. its control is new and reads the other way, walking every blanked line up to the header it stands under and spelling that header itself rather than reading the constant, so a widening from either end arrives red naming the lines and the guarded phrases on them, where the old control was green over half a document and the per-row found check fires only when the cut takes the last copy of a phrase. ADR 0066 stops pointing the reader at the newest entry, which is blanked, and says instead that the figures in that block are the ones held against the code, and what makes a block an entry. use_items stops naming one cost for two callers: a false item is refused in the resolver only where it also spells the module name, and is blanked in the call walk, which is the #1946 direction in the reading written to close it. the judgement items: both sides unterminated over a line they share and an empty file in each direction are pinned through the binary, the empty-lines arm in the marker test is gone with its reason moved onto the expect that ends_clean makes true, a name bound to two types three lines apart in the apply path is split, and the walk guard in store_rename_census reads the workspace members instead of the crates directory it already walks, asserted both ways. red under mutation, counts read each time: the put-back removed (loot-identity 48 passed and 1 failed, the refusal leaving id.pub.rotated-7 orphaned), the public path returned unconditionally (48 passed and 1 failed), the date requirement removed (loot-cli bin 0 passed and 1 failed, naming line 15 and 103 lines), that same defect with the new control stood down (1 passed and 0 failed, which is what shipped), the cut never leaving the quote (0 passed and 1 failed, naming line 197 and every guarded phrase the rows carry), the member list read short (store_rename_census 3 passed and 1 failed), a member declared outside the walk (3 passed and 1 failed), the empty-side carve-out removed from ends_clean (patch_trailing_newline 3 passed and 1 failed on the expect), and the marker withheld from a kept line (3 passed and 1 failed). ADR 0016 records the put-back in a new entry rather than rewriting the one that was wrong. the deploy sentence #2112 landed is narrower than that change, and that correction is a record posted on the ticket rather than code here. no migration, no wire or format byte moves and no relay or forge behaviour moves, so this owes no deploy, though the client rotation path moves and rides the next release. the workspace suite is green (4086 passed over 130 binaries, 8 ignored) (#2169)nothing readable · 10 sealed · 10 internal
- the relay mailbox takes the door the relay already writes objects through, and the keypair archive reports a held file rather than waiting it out: #2026 routed the object store loose rename through store::rename_retrying and left two sites its census named, and the question here was where that helper should live. it does not move. the mailbox needed no export at all, because store::atomic_write is already public and loot-net has called it for every loose object since storage::write_loose_object was written, so save_index and write_blob now stage through that door and both ends of their renames are waited out, the reader holding the index it replaces and the scanner holding the staging file, and the fixed index.tmp that two concurrent writers shared is gone with it. the wait is spent on the host too, where rename has no sharing window and the refusals that predicate answers to are permanent, and that is accepted rather than gated on cfg(windows): a second spelling of one predicate is the shape #565 is the record of, and the relay has paid this on every loose object all along. loot-identity cannot reach the helper and the helper cannot come to it, since that crate depends on no workspace crate but loot-codec, which is the no-fs wasm core a filesystem retry loop is defined not to live in, so the choice was a second copy or a report. it reports, and on its own terms: a store staging rename waits out a scanner passing over a file microseconds old, where what is held here is a long-lived keypair file whose holder no budget outlasts, and a rotation is one operator-driven act where a refusal costs a re-run. what makes that safe is the order, so id.pub now moves before id and a refusal leaves the private key in the active slot, where archiving id first left a repo whose key had moved and whose re-run met NoKeypair; the refusal names both paths. the census loses its two mailbox rows and its blind-instrument guard stops reading a file that renames today, asserting instead that every crate directory the tree declares is in the walk. red under mutation, counts read each time: the index save put back to a bare rename (loot-net mailbox 20 passed and 1 failed), the blob write put back (20 passed and 1 failed, refused with os error 32 on the source), the archive order restored (loot-identity 3 passed and 1 failed, the private key gone), the paths dropped from the refusal (3 passed and 1 failed), a retry loop given to the archive (3 passed and 1 failed, the rotation waiting the hold out and returning Ok), a bare rename put back where the census cannot see it (store_rename_census 3 passed and 1 failed) and the walk cut to three crates (2 passed and 2 failed). ADR 0016 records the archive decision and store.rs records where the helper stays. no migration, no wire or format byte moves and no schema moves, but the relay binary changes on its own write path, so this owes a relay redeploy. the workspace suite is green (4083 passed over 130 binaries, 8 ignored) (#2112)nothing readable · 6 sealed · 6 internal
- a modify stanza needs a preimage here, and a patch carries the ending of the line it shows: #2005 read a modify aimed at a path absent here as an empty file, so hunks that applied to nothing wrote a new file with not a line checked and hunks that did not reached the three-way against a base this tree never held, which format-patch never writes and git apply refuses by name, so the modify arm refuses naming the path and --check answers the same, both being one plan. the trailing newline is one cause seen from two ends: str::lines is not injective, so the seam gives the two sides a last line they can share while their endings differ, and the marker is a claim about one side, so a shared last line came out as context with nothing under it and the file was rebuilt with whatever ending the applier already had. format-patch now renders over a line space where an unterminated side carries the fact on its last line, render::patch_line_space, which is the git token of a line and its terminator, and takes the alignment again there, the same matcher on a different token and never a second differ, paid only where a side is unterminated; a last line whose ending changed then leaves as a removal and an addition, which is what git writes, and an ending that moved far from every other change gets a hunk at the end of the file. apply-patch reads an unmarked old-side last line as a claim of a trailing newline on a kept line as on a removed one, and takes the ending of the result from the last line it wrote, kept or inserted alike. a change with no line-level difference stays withheld, and its omitted row now carries the reason and the remedy: this body quotes exactly the rows the seam counted as disclosed, so minting a hunk for a row it counted as summarized is that safety claim coming apart, and emitting it means moving the seam and diff --content with it, which is the wider change to make if it is reopened. ADR 0082 section 3 records both decisions, section 4 states the rule the modify row now enforces, and CONTEXT.md says where the ending rides. red under mutation, counts read each time: the absent-path refusal removed (apply_patch_preimage 4 passed and 1 failed), the re-alignment dropped so the seam hunks are rendered over the marked lines (patch_trailing_newline 2 passed and 1 failed, the older marker pin still green at format_patch 12 passed), the mark itself removed (format_patch 11 passed and 1 failed), the ending check narrowed back to a removed line (2 passed and 1 failed), the kept line deciding the ending only when marked (2 passed and 1 failed, and uncaught at 3 passed and 0 failed until the shape whose result ends on a kept line was added), and the omitted row put back to its old words (2 passed and 1 failed). no migration and no store or wire byte moves, and the patch grammar is untouched with no row added or removed, so PATCH_FORMAT holds and this owes no deploy. the workspace suite is green (4066 passed over 130 binaries, 8 ignored) (#2005)
- ↳ supersedes
d3e1848b· not stored here - Kept, not rewritten: a carry replays a suffix as a new version and the one it replaced stays addressable. That is the difference between a carry and a rebase.
nothing readable · 7 sealed · 7 internal - ↳ supersedes
- the forge learns runners and jobs (#2157, ADR 0091, map #2099, first of three slices of #2129): migration 0018 adds the runner and job tables, both repo-scoped, so both join 0014 row-security set and take 0017 forge_is_bound_to_one_repo policy verbatim in shape, and tests/rls.rs ENABLED_TABLES names them, which is the set equality that forces the decision rather than a list nobody maintains. A runner is its OWN keypair under NO account and that is the security property expressed as schema: require_pusher and the proposal door both resolve a signer through account_key, so a runner key is refused at push and propose BY ABSENCE, where the same key on the owner account would have been a full pusher since require_pusher admits any live key of the account; the row is written from an envelope the namespace owner signed, which is a proof needing no browser session, so tests/account_tier.rs is green UNAMENDED. A job identity is the triple version, trigger, kind, so creation is idempotent by the primary key; member and approved are computed in at creation so a later membership change cannot re-authorize queued work; a claim is claimed_by plus a lease the CLAIMANT names, exclusive by FOR UPDATE SKIP LOCKED in the driver and one lock across find-and-write in the reference store; an expired lease returns the job by a READ-TIME predicate, so there is no reaper to fall behind; a verdict is accepted whatever the lease says, because the runner did the work and a bookkeeping deadline must not discard it; a job is born unclaimed and unfinished and a creation carrying either is refused, since those are the two writes that have to be exclusive. Trigger and Kind move from loot-cli to loot_net::pipeline, the one crate the forge and the CLI both already depend on, re-exported so every path reads unchanged: the forge stores what the CLI writes, and two copies of one vocabulary would be a list to keep in step. Capabilities is exactly Kind as a set, and a bit this build cannot name is REFUSED rather than dropped, because reading a newer runner row as covering less would hand it jobs it cannot do. Five conformance cases join the roll call, so both stores answer one contract and neither can name a subset. Measured: bash ci/local.sh green end to end against Postgres 18, 129 test binaries, 0 failed and 0 SKIPPED, which is what proves the driver, the migration and both policies rather than only the reference store; the claim exclusivity and the lease expiry are proved there on real Postgres, and an EXPLAIN plan under contention is NOT measured here and is owed to #2158 where the poll load is. Three refusals found by the run rather than by thought: the destination census flagged a fixture wake-up URL, allowlisted with the reason that it is a value the store round-trips and never an address anything dials, which took the allowlist to ten and moved ADR 0074 spelled count; the shipped-predicate pin read migration 17 alone, so it now reads the migration that CREATED each table rather than recording which came from where; and the binding fixture seeds a runner and a job row per repo, without which its controls were zero and the refusal below them would have passed for the wrong reason. Five pins each broken once by a named mutation, red at 1 failed then green at 0 failed with the count above zero: the claimable predicate widened, the lease made to hold forever, retirement re-dated, the born-claim refusal disabled, and an unknown capability bit accepted. No routes, no wire and no verb here; those are #2158 and #2159. No FORMAT_MAJOR move (#2157)
- ↳ supersedes
f7bc9065· not stored here - Kept, not rewritten: a carry replays a suffix as a new version and the one it replaced stays addressable. That is the difference between a carry and a rebase.
nothing readable · 17 sealed · 17 internal - ↳ supersedes
- the filter in front of the import resolver becomes part of what it refuses, and a dated amendment gets back the figure it landed with: #2148 made the branches of imported_names refuse by default and left a filter in front of them that kept only a line starting use, and a default a filter feeds is a default over what the filter let through, so a module named on a continuation line and a pub use re-export reached no branch at all and were skipped in silence, which is the #1946 under-count surviving the ticket that closed it and then the ticket that closed that, a third time. use_items reads items and not lines, a statement being the run between one semicolon and the next and a use item being the statement the keyword stands in, so a visibility, an attribute and where the lines break decide nothing, and what would make that wrong is a statement spelling the keyword without being one, which costs a refusal naming the line rather than a reach passed over. the call walk stops deciding the same question a second way and reads the code with those items blanked by without_use_items, so an import can never also be read as a call and the use and mod line prefixes it skipped by are gone, the declaration it does look for being found by what it declares. the re-export and the wrapped item are planted as outcomes, one resolving and one refusing, beside the alias #2148 planted, and the blanking is planted with them. the ASCII identifier reading in temp_root_census is gone for census_text is_ident_char, which whole_word_matches is now bounded by too, so where a name begins has one home and the wider letter a narrow reading lets answer as a whole word is planted where that census can see it. ADR 0066 #2127 amendment is restored to 82 in the dispatch table, which is what was true on its date, and the cause is named rather than the number: the_verb_counts_stated_in_prose_are_the_ones_usage_holds held every occurrence of its phrases to the count the code holds today, records included, so the cheapest green was to rewrite the record and #1976 rewrote it; claims_only takes the amendment entries out before that census reads, an entry stating what was true on the date it carries. emit.rs stops saying buoy is dispatched ahead of the table, ADR 0088 stops walking a buoy flags constant that has no references left, three plurals about verbs dispatched ahead of the table go singular where one verb is left, the telemetry pin reads the count instead of a substring of it, since buoy 1 stands inside buoy 10, and the glossary stops spelling the secret-shaped set with two env positions where #1930 made it three. red under mutation, counts read each time: the line shape deciding again which items are read (loot-cli lib 6 passed and 2 failed), an item ending where its line does (7 passed and 1 failed), the shared boundary widened to admit every character (loot-cli lib 4 passed and 4 failed, temp_root_census 1 passed and 2 failed) and narrowed back to ASCII, which nothing caught before this (temp_root_census 2 passed and 1 failed), the ADR records read as claims again (loot-cli bin 0 passed and 1 failed at the control, and with the control stood down 0 passed and 1 failed naming 82 where the code says 83), the cut widened to take every line (0 passed and 1 failed, the phrase it guards no longer stated), and the count reader stopping at the first digit (telemetry 3 passed and 1 failed). item 6 is a correction to two landed commit records and is reported rather than made. no migration, no wire or format byte moves and no host behaviour moves, so this owes no deploy. the workspace suite is green (4062 passed over 129 binaries, 8 ignored) (#2156)nothing readable · 11 sealed · 11 internal
- buoy joins the dispatch table and bisect is left alone on the early path with the only reason that is still its own: #1764 made an output shape able to carry its own exit code, which was the whole of why buoy was dispatched ahead of COMMANDS, so the arm is gone and cmd_buoy returns a shape like every other verb. emit::Buoy reads ADR 0025 exit codes off the BuoyVerdict it already holds, one arm per row of that table, so the rendered answer and the code are one decision and the empty porcelain of the none row cannot come apart from its 2; buoy --nearest carries its code as a value on the message instead, having collapsed to one token with no structure to read an outcome back off; and buoy_write is deleted rather than moved, because the dispatcher outcome was already byte-for-byte the same #870 rule about a reader that left early. everything that walked the table and the buoy spec separately now walks the table alone — the telemetry note_dispatched call, the machine-output census, the verb census, the documented-flag census, the template-flag census, help_for and the completion list — and nothing is counted twice: the telemetry report is asserted to say buoy once, the table is asserted to declare no name twice, the offered completion names are asserted to hold each name once, and the census sum is now an equality with the table rather than the table plus one. going through the argv door means declaring an arity, so exactly one invocation moved: loot buoy reviewed junk refuses by name and exits 1 where an open claim used to drop the word and resolve for reviewed, which is #1562 reaching a verb that had been standing outside the gate enforcing it. every code is pinned through the spawned binary in tests/buoy_exit.rs, each outcome in every rendering it accepts. red under mutation, counts read each time: the verdict codes flattened to zero (buoy_exit 4 passed and 2 failed, emit_snapshot 12 passed and 1 failed), Message::coded discarding the code it is handed (loot-cli lib 1334 passed and 1 failed, buoy_exit 5 passed and 1 failed), the early telemetry call put back beside the one in the table (telemetry 2 passed and 1 failed, reporting buoy three times for two runs), buoy pushed onto the completion list beside its own row (loot-cli bin 125 passed and 1 failed, buoy_exit 5 passed and 1 failed), the row declared twice (loot-cli bin 121 passed and 5 failed), the row declining its arity again (loot-cli bin 123 passed and 3 failed, buoy_exit 5 passed and 1 failed), and the census sum left at the table plus one (loot-cli bin 125 passed and 1 failed). ADR 0025 records where each code now comes from and the one that moved, ADR 0076 closes the open work it had recorded and narrows the early-dispatch path to bisect, ADR 0066 moves the split inside its dispatched total, and CONTEXT.md stops naming buoy beside bisect. no migration, no wire or format byte moves and no host behaviour moves, so this owes no deploy. the workspace suite is green (4058 passed over 129 binaries, 8 ignored) (#1976)nothing readable · 16 sealed · 16 internal
- a .env in the middle of a basename is secret-shaped too, and the backup written beside a sealed credential file is refused rather than sealed Internal: #1108 widened the mis-seal gate to the .env suffix and recorded one boundary as deliberately left open, that <name>.env.<suffix> answered to neither affix, on the argument that closing it with *.env.* would swallow the committed-template convention; that was an argument and not a measurement, so this measures it first. over every git-tracked basename in every git repo directly under this estate, 25 repos and 12,732 paths on 2026-09-20, the arm newly catches one path, the scripts repo .setup.env.example, and nothing else, which is the template class #1108 feared and also the one shape the arm cannot be narrowed away from by name, since a template and a backup differ only by the suffix the operator typed and a suffix allowlist would be a hand-maintained list of exactly the kind AGENTS.md names, guarding a credential. what bounds even that catch is the gate scoping rather than the pattern, first seal and Internal-by-fallthrough only, so a path already in the anchor or named by a rule of its own never trips and the template costs one .lootattributes line, once, against a false negative that loot burn can only bound. the case is this estate again: scripts seals .setup.env by exact basename, its gitignore covers the whole family since loot#1643, and a .setup.env.bak-v0420 sits in that working tree named by neither of the two loot policy files. reproduced through the spawned binary in a throwaway repo before and after, a .setup.env.bak-v0419 sibling beside a .setup.env restricted=connor rule captured and sealed internal with no refusal on 0.4.22 and refused by name on the lane binary, with one rule reaching the sibling sealing it restricted instead. ADR 0069 carries the measurement table and ADR 0038 section 1 closes the boundary it had recorded as open. red under mutation, counts read each time: the arm removed (0 passed and 2 failed, the gate handing back the old Ok with the sibling Internal), the arm widened to a boundary-free env substring (0 passed and 2 failed, on the negative controls both here and in the suffix pin), the refusal condition stripped of its tier and fallthrough halves so the sealed original is named beside the sibling (0 passed and 1 failed), and the arm narrowed to a suffix allowlist that spares the template (0 passed and 1 failed). the scripts .lootattributes half of the ticket is untouched and stays with the operator, being a visibility rule in another repo. no migration, no wire or format byte moves and no host behaviour moves, so this owes no deploy. the workspace suite is green (4051 passed over 128 binaries, 8 ignored) (#1930)nothing readable · 5 sealed · 5 internal
- the whole-word reading gets one home and a use this walk cannot follow is refused rather than skipped: #2126 landed census_text so that a .rs-text reading more than one census needs and none of them owns has one home, and the very doc saying the source_walk whole-word reader was shared rather than copied per census had a copy of it sitting in the temp-root census next door, drifted already, one asking char::is_alphanumeric and the other an ASCII byte test, so the sentence was false the day it was written. the reading moves into census_text as whole_word_matches, the offsets a word stands at as a whole identifier, with names_whole_word derived from it rather than written beside it, so the caller that wants the answer and the caller that wants the places cannot come to disagree about where a word begins, and the boundary is the Rust one and not the ASCII one, since a boundary that reads too narrowly lets a longer identifier answer as a whole word, which is a census reporting an offence that is not one. the copy the ticket found was not the only one: loot-first, loot-forge and loot-relayd each held the same closure inside the bare-flag census of its own crate, and each reads the shared file now through the same cross-package path attribute the other callers use, so one edit reddens every consumer of it. the docs stop naming callers and say instead what decides where a reading lives, which is the census_text admission rule, and the seam a reader arrives from now carries why the import reading stays in source_walk: it is keyed to that module own name and to what helpers_named can find afterwards, so it is not a flat question. that import reading also stops enumerating what it refuses, since the enumeration was already stale: a use item naming the module is the module under its own name, or names taken out of it, and everything else falls through to refuse_import, which is how use crate::source_walk as sw, outside both branches and skipped in silence, the under-count #1946 was filed on surviving the ticket that closed it, becomes a refusal without being named. the narrowing census in main.rs stops re-deciding which narrowing is in force and asks the door, since taking the first declared narrowing whose flag a shape requires and taking the narrowest part on a shape requiring two narrowing flags of different counts, latent while no verb writes that shape and now unreachable because the rule has one home, pinned where it lives. the forwarder that discards a door result is declined with the reason at sole_statement: a door too many is a site too many and the offenders are asserted empty, so it arrives red naming the call, while reading the discard would shrink the door set, which is the direction that loses a site in silence. one more of the same class was found beside the rest: code_mask said the two censuses that share this in the present tense, and it now speaks in the past about the two walks it replaced. red under mutation, counts read each time: the shared boundary widened to admit every character reddened all five consumers from the one edit (loot-cli lib 5 passed and 2 failed, loot-cli temp_root_census 1 passed and 2 failed, loot-first 0 passed and 1 failed, loot-forge 0 passed and 1 failed, loot-relayd 0 passed and 1 failed), the alias refusal put back to the silent skip (0 passed and 1 failed), the plain module import refused as well, which is the other direction (0 passed and 1 failed), and the door narrowing rule flipped from narrowest to widest (loot-core 0 passed and 1 failed, with the CLI census still green, which is the point of the move). no migration, no wire or format byte moves, and nothing outside test support and a doc comment moves, so this owes no deploy. the workspace suite is green (4049 passed over 129 binaries, 8 ignored) (#2148)
- ↳ supersedes
b26e0ebe· not stored here - Kept, not rewritten: a carry replays a suffix as a new version and the one it replaced stays addressable. That is the difference between a carry and a rebase.
nothing readable · 8 sealed · 8 internal - ↳ supersedes
- install.tsx RELEASE_TAG moves to v0.4.22: the release has reached dl.millerbyte.com, finalized from three of the five triples with the darwin pair carried on v0.4.14 as before (#1333), and the install page now names what the one-liner serves; the forge and the relay are on 0.4.22 and advertise fetch_depth, and the Known Issues page reviewed against v0.4.22 goes live with this deploy rather than before the binary it describes is installable (#2147)nothing readable · 2 sealed · 2 internal
- loot 0.4.22: loot-cli and loot-forge move to 0.4.22 with their two lock entries, the first public release since 0.4.21 and the one that carries the seek follow-ups, a fetch depth the hosts honour (#2123), the browser SDK bounded read (#2124) and the seek cache cap with --gc (#2125), beside the pipeline verb (#2127) and every land since 3039521e. format major stays at 14 and both live hosts already report 14, so ADR 0066 has nothing to sequence here, and the top forge migration is still 0017, so this release owes no schema step; the relay and the forge still deploy before the site, since #2123 is what the SDK bounded read refuses without. the Known Issues page is re-reviewed by running the 0.4.22 binary in a sandboxed home rather than by re-reading source: loot edit on an older change refuses with change tlqyroot has descendants, v1 edits only a tip (childless) change, word for word and exit 1, while on the tip it reopens the version as the working change, so the one entry stays as written; loot seek --gc --dry-run in that sandboxed home lists no positions and the defaults. REVIEWED_AGAINST moves to v0.4.22 and LAST_REVIEWED to 2026-09-20. RELEASE_TAG is deliberately NOT moved: it names what dl.millerbyte.com can serve, and this release has reached nothing yet. the site byte budget is re-recorded: NOT re-recorded, because no ceiling has to move: every one of the 62 surfaces is under its ceiling, and the uniform +150 to +170 B on every surface is #2127 CLI row in the shared docs chunk they all fetch, one growth and not sixty-two, and not this cut own; the site gate is green in the lane (669 passed and 62 skipped over 61 files). the workspace suite is green at the base (4023 passed over 126 binaries, 7 ignored, on the #2125 lane a commit below, and this land gate runs it again) and cargo build --release --locked validates the lock edit (loot 0.4.22 from the lane binary, and loot-forge 0.4.22 built beside it, refusing to open its storage without its URL, which is its answer outside a deploy)nothing readable · 5 sealed · 5 internal
- the seek cache home is bounded, and loot seek --gc tends it: every remote an agent touches leaves a position under the cache home and nothing bounded it, so the rule is now one function, seek::gc::plan, that the verb and the cap share and cannot disagree on, a position being a directory the two caches make, a .git holding a HEAD or a .loot holding a .loot, with its bytes on disk and the clock of its last refresh read off the #2108 record and never an mtime; a position whose record is older than the age asked for goes, then oldest first by that record positions go until the home is within the cap, and a position with no readable record is never removed by the cap because its age is not known and a cap is not a reason to guess, listed with a dash and removed only on the explicit ask, --older-than 0, which removes every position; a position another invocation is refreshing right now is busy and removed by nothing, since both caches write their record last and a position in use would otherwise be exactly the oldest candidate, so a refresh writes loot-seek-refreshing when it begins and removes it on every exit, a marker older than an hour reading as a crashed refresh; 0 is no cap. on every invocation that refreshed a position the home is measured against LOOT_SEEK_CACHE_CAP, 2 GiB when unset, and the oldest other positions go until it fits, said on stderr in one line, never the position just refreshed whatever its age, and a skipped refresh inside --fresh measures nothing, nor does the ambient repo; the environment cap is read before any target opens so a value that will not parse is bad_flag_value at no round trip, the just-refreshed position is matched on canonical paths so a URL spelled in another case still names its own, a removal that fails is said in the same line and never refuses the answer, and the measure is a walk of sizes and records only, targets read by --gc alone, paid once per refreshing invocation, 2 ms over this desktop cache of three positions and 217 files against the 30 ms process floor, which is the cost of having no size record to trust. loot seek --gc does the same on demand with --older-than <days> defaulting to 30, --cap <bytes> defaulting to the environment, and --dry-run deciding and removing nothing, printing one row per position with kind, bytes, refresh clock, what was done and why, and target, and the home bytes before and after, a failed removal a failed row with the error on the notice channel; beside any question it is refused by code as --schema is, its flags without it the same way, and a value that will not parse is bad_flag_value. its porcelain is two new marks, G and H, under a flag that did not exist before, in their own GC_COLUMNS table the mark census now reads beside MARK_COLUMNS, and --schema files the four flags under maintenance rather than among a question flags, since the SDK reads that set as the fields of a question, which its schema pin holds green unchanged; the shapes are frozen where every seek shape is, in an ADR 0023 amendment, and the one stderr line is recorded against its remote-answer sentence there. pinned pure on the rule, by age, no age, oldest first under the cap, the unrecorded position standing though the home is still over, the explicit ask, the kept position under both, the busy one under all three, a record ahead of the clock, and a tie on the clock going in path order; on the walk over a hand-made home with a bare git repo, a loot position, an unrecorded one, two directories that are not positions, a fresh marker and a stale one, canonical paths and the sizes-only walk; on a failed removal rendered failed with its bytes standing and the removals around it still done; on the schema census over both tables and the maintenance key; and through the spawned binary in the smoke suite over the relay and the git caches it already makes, the cap on an invocation removing the older git position and never the loot one just refreshed, a malformed cap variable refused by code before an unreachable host costs a round trip, the ambient repo measuring nothing, a skipped refresh measuring nothing, --dry-run in porcelain and JSON removing nothing with the H totals the sums of the G rows, a cap the two standing positions just fit removing the older git one in JSON, a cap of one byte unable to reach the unrecorded position, thirty-one days removing by age, a busy marker holding the unrecorded position against the explicit ask until it ages out, and the seven refusals by code. ADR 0090 and ADR 0023 amended, CONTEXT Seek, the usage line and the synopsis. red under mutation, counts read each time: age never removing (0 passed and 1 failed), the cap removing newest first (0 passed and 1 failed), the cap guessing at an unrecorded position (0 passed and 1 failed), the just-refreshed position going by cap (0 passed and 1 failed), the just-refreshed position going by age (0 passed and 1 failed), --older-than 0 not the explicit ask (0 passed and 1 failed), the walk skipping the loot kind (0 passed and 1 failed), the walk reading no record (0 passed and 1 failed), a loot target never read (0 passed and 1 failed), the gc flags landing among a question flags in the schema (0 passed and 1 failed), the H row losing its removed count (0 passed and 1 failed), --dry-run removing (0 passed and 1 failed), the cap on an invocation never running (0 passed and 1 failed), the cap on an invocation removing the just-refreshed position (0 passed and 1 failed), a skipped refresh measuring the home (0 passed and 1 failed), a gc flag beside a question admitted (0 passed and 1 failed), a question beside --gc admitted (0 passed and 1 failed), a busy position going (0 passed and 1 failed), a stale marker busy forever (0 passed and 1 failed), the walk reporting the spelled path rather than the canonical one (0 passed and 1 failed), a failed removal reported as removed (0 passed and 1 failed), the loot refresh writing no busy marker (0 passed and 1 failed), the git refresh writing no busy marker (0 passed and 1 failed), the guard never dropping the marker (0 passed and 1 failed), the busy marker surviving the refresh (0 passed and 1 failed), and the environment cap read after the target opens (0 passed and 1 failed). no migration, no wire or format byte moves, and no host behaviour moves, so this owes no deploy beyond the one #2123 already owes the release. the workspace suite is green (4023 passed over 126 binaries, 7 ignored) and the SDK seek suite is green in the lane (11 passed) (#2125)
- ↳ supersedes
b841de5e· not stored here - Kept, not rewritten: a carry replays a suffix as a new version and the one it replaced stays addressable. That is the difference between a carry and a rebase.
nothing readable · 7 sealed · 7 internal - ↳ supersedes
- a flag that puts a verb in a shorter shape declares the arity that shape takes, and the door refuses past it: #1928 gave every bounded verb one number, the widest shape its usage shows, so a flag selecting a narrower shape left the surplus word inside that number, admitted by the door and read around by the arm, which is the #1419 class one level down, since loot grant --relay origin a.txt bob junk sealed the grant for bob and never looked at junk. the declaration is Args::narrowed, a flag beside the arity its shape takes, and FlagSpec::arity_for reads a given one ahead of max_positionals rather than through it, which is what lets a shape carry an arity on a leaf that declares none: loot diff attaches the pathspec and counts nothing, while loot diff --conflict <path> reads no selector and no pathspec at all and its surplus word had no number to be past. the refusal is the door own sentence with the shape that was typed named in it, loot grant --relay takes 2 positional arguments, because loot grant really does take three and a refusal saying so would send the operator to check a count that is right; the narrowest declared narrowing wins when several are typed, since refusing against the wider would admit a token neither shape reads, and each is read through given rather than off raw argv, so a flag value spelled like another narrowing does not select it. the ticket offered a check inside the two arms it had found and made the declaration conditional on a third verb turning up in the census, so the census was written first and ran the decision: verbs did turn up beyond the two, one with two narrowed shapes of its own, one already carrying the check by hand, and one whose arity is None and for which a per-arm check would have had to invent a number, so the per-arm answer was a hand-written copy of the door sentence per shape and the declaration won. which shapes those are is the census answer and is in no list: forward, a documented shape typing a flag outside brackets and showing fewer positionals than the widest shape its own spec shows must declare a narrowing on one of those flags at its own count, and the door is then driven at an argv built from that shape and at one word past it; reverse, every declaration must name a flag the spec declares and carry a count some documented shape of that spec shows. a usage line is read against the spec whose arity the door actually enforces for it, the longest-named table row or family leaf its shape opens with, so loot id unlock --permanent is a statement about the arity of id unlock, which is zero and already refused, rather than about id. what the census cannot see is said where it lives: a mode flag documented as a bracketed option on the wide line rather than as a line of its own, which is loot apply --abort junk and loot archive --list junk, both measured still dropping the word, and closing those means splitting usage lines that README and the published CLI page are pinned to, so it is a ticket and not a clause. loot tag --retire gives up the surplus check it had written by hand and declares the narrowing at each spelling instead, and its pin loops the declared narrowings rather than the aliases typed out. the three readings of a usage line shape the censuses want, the positionals, the flags a shape requires and an argv in that shape, are one walk with three projections, because a copy of the bracket rule per reader is a copy that can come to disagree about which tokens a shape claims. red under mutation, counts read each time: the grant narrowing dropped (0 passed and 1 failed in the census, 0 passed and 1 failed at the process), the diff --conflict narrowing dropped (0 passed and 1 failed, 0 passed and 1 failed), both grants narrowings dropped (0 passed and 1 failed, 0 passed and 1 failed), resolve --tool declared to take a count no usage line shows (0 passed and 1 failed), a bracketed flag read as required by its shape (0 passed and 1 failed), no shape reading as requiring a flag at all (0 passed and 1 failed), the -d alias losing its narrowing (1 passed and 1 failed), arity_for ignoring the narrowings (1 passed and 2 failed in loot-core, 0 passed and 1 failed in the census), the refusal no longer naming the shape (1 passed and 2 failed, 0 passed and 1 failed), the narrowing read through max_positionals rather than ahead of it (2 passed and 1 failed, 0 passed and 1 failed), the widest narrowing winning over the narrowest (2 passed and 1 failed), and the check relaxed so a narrowing need not narrow (2 passed and 1 failed in the loot-core doctests). no migration, no wire or format byte moves and no host behaviour moves, since every byte of this is argv on the client side, so this owes no deploy. the workspace suite is green (4027 passed over 125 binaries, 7 ignored) (#1934)
- ↳ supersedes
4cb604a6· not stored here - Kept, not rewritten: a carry replays a suffix as a new version and the one it replaced stays addressable. That is the difference between a carry and a rebase.
nothing readable · 6 sealed · 6 internal - ↳ supersedes
- loot-hygiene (#2128, map #2099 ticket 4): the land text gates move from loot-first into a crate with no dependency that builds for wasm32, re-exported as loot_first::hygiene so every gate row, checkout test and AGENTS.md path reads unchanged; a new crate rather than loot-codec because three consumers now read it, loot-first, loot-cli and loot-wasm, and the wasm one is the fact ADR 0076 §2 no-new-crate reasoning did not have. Corpus::from_entries files an in-memory tree under exactly the allowlist the directory walk applies, top-level files plus SOURCE_ROOTS filtered by TEXT_EXTENSIONS minus SKIP_DIRS and SKIP_PATHS, through one filing rule both constructors share, and a link resolves against the entry set with dot and dotdot folded, so a Worker with no directory answers what the land answers. CORPUS_CHECKS is the table a .lootpipeline check step names, keyed by the land gate names and pinned to them, holding the floor-free halves: the land refusals still refuse a vacuous walk first because a mis-rooted land must not read as clean, but a three-file repo is not mis-rooted, so a check answers about the files it was handed. loot pipeline now runs check steps in-process over one corpus walk per run, a finding is failed and exits 2, an unknown name cannot start and names the set and exits 1, and the ? deferral #2127 shipped this morning is retired the same day with the ADR 0023 amendment saying so. loot-wasm links the crate and a wasm-bindgen test runs the three checks from entries under node. Measured: the site wasm is 475667 bytes before and after, unchanged, because nothing exported calls the crate; native the three checks over a 1120-file synthetic corpus take 0.8 ms in release and 28.0 ms under wasm in node; through the release binary on this repo, roughly 1355 covered files and 20 MB by an approximate count, the three checks cost 160 ms warm against a 73 ms listing and 6.5 s on a cold page cache. Two lands worth of censuses read off their refusals: the destination allowlist row for the moved file, and no other. Five pins broken once by a named mutation, red at 0 passed 1 failed then green at 1 passed: from_entries skipping widened, link resolution made true, the table key misspelled, a finding made a pass, an unknown check made a pass; the fifth sweep needed a second pass because its first restore string matched twice and left the mutation applied, caught by the full run that followed. 66 test binaries green across loot-hygiene, loot-cli and loot-first. No wire, format or store byte moves, no migration (#2128)nothing readable · 15 sealed · 15 internal
- loot pipeline (#2127, ADR 0091, map #2099 ticket 3): the tracked .lootpipeline at the repo root, in the .lootattributes grain with no dependency column, one step per line as name, trigger, kind and what, where the trigger names the tree a step judges, change or main, never the moment, and the kind is run, argv through the spawn seam with {message} and {paths} as gates reads them through one shared builder gates::spawnable, or check, a loot-native gate deferred naming #2128 until the checks live where the verb can reach them, and a deferred step is a refusal exiting 1, never a pass. loot pipeline lists and spawns nothing; run judges the working tree by default or, under --version, a scratch tree of a held version written by Workspace::scratch_tree from readable_tree_at so the readability decision precedes any file, holding the version own .lootpipeline, and removed on drop, with the hand-off from Workspace::version_handoff naming the paths whose readable content differs from the first parent; --only narrows to one step and an unknown name is refused naming the declared set; status reads the pipeline/TRIGGER/KIND passes and pipeline/approve admissions trusted keys signed on a version through attester_trust, passes only. A tracked file never runs implicitly: loot new with a run step declared and no .loot/gates line reaches no spawner, pinned. Frozen shapes in ADR 0023 amendment, exit code on the shape. Measured on the release binary: a two-step run 74 ms, run --version 47 ms and a listing 18 ms on a three-file repo; on this repo of 1452 tracked files, run --version HEAD materializes the whole readable tree in 1.2 s against a 0.15 s listing. Found by that measurement, not by thought: under load a Windows scanner held a freshly written scratch file, the one-shot remove_dir_all failed and its swallowed error left plaintext in the temp dir, so ScratchTree drop now retries over half a second and names the path on stderr if it still cannot remove it. Seven censuses moved, each read off its own refusal: the verb tier method count to 387, MACHINE_OUTPUT gains pipeline in sorted position, the usage spells the list leaf as an invocation line, README block and its all 84 verbs sentence, 133 verb lines in three places, the revset placeholder lists take <change|main>, <step> and <id> and SELECTOR_ONLY takes pipeline status, and the site CLI page names the verb; ADR 0066 counts 84 dispatched, 82 in the table, 32 emit machine output with an amendment. CONTEXT.md Pipeline entry says what is built. Nine unit pins plus two in change.rs, five broken once by a named mutation and confirmed red at 0 passed 1 failed then green at 1 passed: a check made a pass, the trigger filter widened, the scratch removal removed, the approval role made a job, and the tracked file run at a finalize. loot-cli and loot-first green across 64 binaries, 2162 passed; the site verb census green. No wire, format or store byte moves, no migration (#2127)
- ↳ supersedes
0320d317· not stored here - Kept, not rewritten: a carry replays a suffix as a new version and the one it replaced stays addressable. That is the difference between a carry and a rebase.
1 readable · 13 sealed · 14 internal - ↳ supersedes
- the source-walk consumer census sees a helper brought in by a use, and which methods the Admitted exceptions census watches is read off the marker on their own docs: the consumer walk keyed a reach on a call site spelled with the module path, so the spawn-seam census in main.rs, which calls the cut through an import, was counted by nobody and stood on no discrimination floor at all, and the src file walk #1944 added to flags.rs was invisible the same way, which is why #1944 reported the consumer count unchanged. a use item is resolved per file now, with a rename, a glob and an item that does not close on its line refused rather than read wrongly, and the floor is owed by the consumers that read the cut rather than by every consumer, derived from this module own source as the helpers that reach MARKER, the one spelling the cut keys on, so the file walks and the header readers owe it nothing while every census that cuts owes it as before. the derived header sentence is 15 consumers in 3 compilation units: 9 library, 5 binary, 1 integration test, and the paragraph that enumerated the censuses by name now says what a consumer is and leaves the files as an index the guard checks one way, saying which way. with_leading_word, which rewrites argv by position with no spec asked, was documented as doing so and was watched by nothing, so it carries the marker now and arrives in the roster with its one caller, bisect mark_by_term; whole-word matching moves into source_walk beside the walk, one spelling where flags.rs held the copy. red under mutation, counts read each time with the filter selecting the one test: the imported half of the reach dropped (0 passed and 1 failed), a planted use-imported bare call of the cut in main.rs (0 passed and 1 failed), the floor call removed from the spawn census (0 passed and 1 failed), the cut-reader derivation reduced to the direct namers of MARKER (0 passed and 1 failed), a renamed import planted (0 passed and 1 failed), the marker taken off with_leading_word (0 passed and 1 failed), and a planted with_leading_word caller in bisect dispatch (0 passed and 1 failed). item 3 of the ticket was already closed by #1974 and nothing there moved. no migration, no wire or format byte moves and nothing outside a test and a doc comment moves, so this owes no deploy. the workspace suite is green (4013 passed over 125 binaries, 7 ignored) (#1946)
- ↳ supersedes
01744a86· not stored here - Kept, not rewritten: a carry replays a suffix as a new version and the one it replaced stays addressable. That is the difference between a carry and a rebase.
nothing readable · 4 sealed · 4 internal - ↳ supersedes
- the browser SDK reads a relay at the heads generation and refuses a host that cannot give it one: connectRelay list() and read() open with a fetch carrying depth one, the heads nodes and nothing older with the whole manifest on each, and the object round is bounded the same way rather than paying the history a second time, since a want is answered by address across the cut, so a read is two bounded rounds where it was one unbounded and one that repeated it, against the 53 MB per call the map measured on this repo; the host is asked once per repo, on GET /info, which the transport seam gains as an optional get so a lane that never asks stays honest, and a host whose answer does not say fetch_depth, or answers with a non-2xx, or not JSON, or through a transport with no get, is read as one that did not say and is refused as a SetupError naming the host and the version line it reported, before any bytes are asked for, unless the caller passed unboundedRead, which accepts the cost on that host and asks a capable one for the bound all the same; a probe that could not reach the host is a TransportError and is asked again next time. heads() names the set the bounded read answered with, on a RelayLootRepo the connect door now returns, and several heads fold as they did, a later head write winning a shared path; push, status and grant ride the same bounded round because the parents a change builds on and the tree it carries are the heads own, which is all they ever read. pinned on a fake transport with the golden bundles, the request bytes bounded on the metadata and the object rounds, the old host refused by name on list and on read with nothing posted, the opt-in against it and not against a capable host, the probe asked once across list and read, the three did-not-say shapes each refused and each opted into, the unreachable probe re-asked, and heads() one; and over a spawned relay with two generations, the request four bytes longer than the unbounded one ending in one, the answer one node whose parent is the base change a whole fetch shows, every round of a read one node, the head named and then two after a fork the second session pushes off a replayed metadata answer, listed as the union, and the field stripped off the real /info refused by name and paid for on opt-in. README states the cost and the option, CONTEXT and ADR 0089 say the browser SDK refuses rather than is to. red under mutation, counts read each time: the depth never sent (21 passed and 5 failed), every host assumed to cut (21 passed and 5 failed), unboundedRead ignored (22 passed and 4 failed), the probe asked on every read (18 passed and 1 failed), a failed probe remembered (17 passed and 2 failed), heads() naming nothing (23 passed and 3 failed), the refusal not naming the host (24 passed and 2 failed), a transport without get reading as capable (18 passed and 1 failed), a 404 on /info reading as capable (18 passed and 1 failed), an error on /info remembered as a refusal (18 passed and 1 failed), an explicit false read as absent (18 passed and 1 failed), a JSON non-object left unclassified (18 passed and 1 failed), the head derivation skipping the parented filter (6 passed and 1 failed), and the object round unbounded (24 passed and 2 failed). no rust, no migration, no wire or format byte moves, and no host behaviour moves, so this owes no deploy beyond the one #2123 already owes the release; the SDK suite is green in the lane (126 passed over 11 files, against release binaries and sdk/wasm built in the lane) and the workspace suite is untouched by a TypeScript change and was green at the base (4017 passed over 126 binaries, 7 ignored, at 5a007435) (#2124)nothing readable · 11 sealed · 11 internal
- a fetch gains a depth the host honours: the request carries a trailing depth after its wants, written only above zero so a request at zero is byte for byte what every client sent before, and an old host decoder returns after the wants and never sees it, which is what makes it safe to send to any host; the relay and the forge confine the change lane to the nodes within that many generations of their live heads, one being the heads and nothing older, intersected with the delta past have and, on the forge, after the entitlement gate, so a caller refused metadata in a full bundle is refused it at any depth and a node the caller holds is never re-sent, while a want is answered by address whatever the depth, the lane walking the cut changes as it walks the held ones; the seeds are live heads and not childless ids, the forge reading the ref declared set a client computed with its retire applied and the engine excluding any version a node names as a predecessor, since on a host that ingests amends a superseded sibling stays childless and would otherwise seed a generation of its own, 213 such tips against 31 real on this repo; /info advertises it as fetch_depth, false when absent, so a caller that needs the bound refuses a host without it and a caller that can afford the fallback proceeds. the receiver still cuts and that stays the rule, ADR 0089 amended rather than overturned: pull_metadata_via and the depth round of a bounded pull ask the host for the depth they will keep, FromTips as its n and a deepen as zero since the frontier is this position own, and applies IngestDepth to whatever arrives, so a host that predates the field sends the history and the position is the same one generation deep, which the test relay pins both ways by playing a host that honours the depth and one that does not. the WASM core encodes the same bytes, frozen in the parity suite against the native vector at depth one. decided by a grill of six questions on 2026-09-20 and recorded on the ticket and in the ADR: bounded per invocation regardless of persistence, a depth on the existing fetch rather than a listing endpoint, counted from the host heads, search kept on the receiving side over bodies fetched by address, the host cut an optimisation the client never depends on, and the SDK and the cache cap to follow. this is the wire half of the browser SDK stopping its 53 MB stateless read and of the serverless runner per-job pull; measured against the live relay in the landing comment once the hosts are deployed. pinned on the same shapes at each host so the two walks are held to one answer, a chain at depths one, two and zero and past a have, a fork whose two heads are both seeds, a superseded sibling that never is, and depth zero byte-identical to the one-pass walk this walk replaced, the forge with a reader the gate refuses getting nothing at any depth; in loot-net on the field decoded both ways with an old body as zero, an odd remainder refused, a pre-field info as false and one frozen vector both encoders pin; over the wire on a spawned relay and a spawned forge each answering one node of two at depth one and advertising the cut, with a want riding across the cut; and in the CLI cache refresh asking depth one. a clone at a depth asks the host too, so its declined count is 0 under a host that cut, since nothing behind the cut arrives to be declined, and the frontier width is what says the position is bounded, which the shallow suite now pins against a host that honours the depth and one that predates it; the count stays exact on a deepen, which asks the host for no cut because the frontier it deepens from is this position own. red under mutation, counts read each time: the engine ignoring the depth (0 passed and 1 failed), the engine cut counting one generation too many (0 passed and 1 failed), the depth never written (1 passed and 1 failed), the depth never read (1 passed and 1 failed), the relay not advertising the cut (1 passed and 1 failed), the relay handler dropping the depth (0 passed and 1 failed), the forge ignoring the depth (0 passed and 1 failed), the forge cutting before the gate (0 passed and 1 failed), the forge not advertising the cut (0 passed and 1 failed), the cache refresh asking no depth (0 passed and 1 failed), the receiver stopping its own cut when the host cuts (0 passed and 1 failed), the wasm framing never writing the depth (0 passed and 1 failed), the forge handler dropping the depth (0 passed and 1 failed), the engine seeding from a superseded version (0 passed and 1 failed), the forge seeding from every childless id declared or not (0 passed and 1 failed), an odd remainder read as no depth (1 passed and 1 failed), and the wants lane skipping the cut changes (0 passed and 1 failed). no migration and no format major move: a trailing field the old side never reads is a minor move, and /info default false is the whole compatibility story; the relay and the forge owe a deploy, which the release cut carries. the workspace suite is green (4017 passed over 126 binaries, 7 ignored) (#2123)
- ↳ supersedes
28097b0b· not stored here - Kept, not rewritten: a carry replays a suffix as a new version and the one it replaced stays addressable. That is the difference between a carry and a rebase.
nothing readable · 19 sealed · 19 internal - ↳ supersedes