The two dated log sections had never been split, so every one of their 29 entries sat inline and the startup index had grown to 372 lines — which is the cost the two-tier scheme exists to remove, paid on every session that reads the file. 27 entries were over threshold. All 29 now have a detail file under persistent-memory.d/ and a one-line index entry that routes rather than restates. Index: 372 -> 93 lines. No archival. The soft cap fired, but every entry in this repo is dated 2026-09-21 or later, so the under-14-days guard held all of them back — and the split alone took the index well under the target without moving anything out of the active file. The in-flight section is rewritten for the post-release state: nothing is in flight, no gate is outstanding, and the next unit is explicitly recorded as the operator's undecided call rather than as a plan. The session's recommendation (U4, on three grounds) is written down so it does not have to be re-derived, alongside the two alternatives and why they are alternatives. Two dated predictions are carried forward with their dates and their instruments: the U5 adoption re-measure on 2026-09-29, which already reads 3 of 24 announced and 2 with a why from peers told nothing, and the .forever re-count a fortnight AFTER U4 lands, which is U4's own success criterion and is destroyed by running it early.
16 lines
893 B
Markdown
16 lines
893 B
Markdown
# The lenient reader's blast radius was the whole service
|
|
|
|
_2026-09-22 · booth_
|
|
|
|
**The lenient reader's blast radius was the whole service, not
|
|
one booth.** `_clean_text` did `(text or "").replace(...)` and `marks_for`
|
|
sorts on `(created, id)`, so a stored `text` that was a dict or a `created`
|
|
that was a number raised out of the READ path — and `list_booths` reads every
|
|
booth's marks on every index load. One hand-edited file 500'd `/` and
|
|
`/healthz` for all 25 booths. Fixed in two layers, matching the house posture:
|
|
a named type check (`_entry_type_error`) plus a `_hydrate_safe` backstop that
|
|
cannot raise, and the panel now RENDERS an unreadable mark as ⚠ broken instead
|
|
of as an empty note. **The general shape: a lenient reader is only lenient if
|
|
the leniency is bounded by where it runs.** `marks_for` was written for one
|
|
booth's page and is called in a loop over every booth.
|