feat: nothing written from the fence onward is taken on trust - #104
Merged
rgdevment merged 1 commit intoOct 1, 2026
Merged
Conversation
The schema that introduced signing is the one from which a history has to answer for itself. A folder whose copy of a machine was written at that schema or later owes a signature, whatever else is known about that machine — and one written before it owes nothing, because it never could have carried one. This was built once before and withdrawn, on the grounds that it broke forty-one tests. It did, and the tests were the thing that was wrong: the round's own suite was modelling a fleet that does not sign. Its helpers opened a store with no key, never answered for their own, and one of them copied segments into the folder while leaving the signatures behind. None of that is what a machine does — opening one mints a key, signs, and answers for its own — and with the suite modelling that, the rule costs nothing. The two arguments that remained do not survive either. A machine that cannot read its own history stops signing and keeps writing, but it has published a key, so it was already turned away by what that key demands. And a folder written by this build is at this schema, so it has no claim to being a history from before signing; one that really is reads below the fence and is let in. Which left a hole of this branch's own making: with the helpers signing, the test that said a pre-key folder is not a stripped one no longer meant it, because its machine now signs from the first line. A history below the fence is something this build cannot write, so that test now builds one by hand, and its opposite stands beside it.
rgdevment
deleted the
rgdevment/nothing-after-the-fence-is-taken-on-trust
branch
October 1, 2026 21:58
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The schema that introduced signing is the one from which a history has to answer for itself: a folder whose copy of a machine was written at that schema or later owes a signature, and one written before it owes nothing because it never could have
carried one. This was built once before and withdrawn on the grounds that it broke forty-one tests. It did, and the tests were what was wrong — the round's suite was modelling a fleet that does not sign: helpers opened a store with no key, never answered for their own, and one copied segments into the folder while leaving the signatures
behind. With the suite modelling what a machine actually does, the rule costs nothing. The two remaining arguments do not survive either: a machine that cannot read its own history was already turned away by the key it published, and a folder written by this build has no claim to being a history from before signing. The test that said a
pre-key folder is not a stripped one stopped meaning it once the helpers signed, so it now builds a pre-fence history by hand, with its opposite beside it.