From 5c2e4570b49c543c62ae47262bc27220771d1f01 Mon Sep 17 00:00:00 2001 From: zzstoatzz Date: Tue, 18 Aug 2026 03:21:35 -0500 Subject: [PATCH] docs: move the MST inversion report out of the repo root It sat at top level while every other doc lives in docs/ or devlog/. Updates the 0.3.19 changelog entry that references it by path. Co-Authored-By: Claude Opus 5 (1M context) --- CHANGELOG.md | 2 +- .../mst-inversion-prevdata.md | 0 2 files changed, 1 insertion(+), 1 deletion(-) rename REPORT-mst-inversion-prevdata.md => docs/mst-inversion-prevdata.md (100%) diff --git a/CHANGELOG.md b/CHANGELOG.md index 50ab8d2..95f34f0 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -282,7 +282,7 @@ Still absent, and deliberately so until something downstream demands them: dial ## 0.3.19 -- **fix**: `Mst` delete now prunes subtree nodes it empties. `deleteFromNode` recursed into a child and marked the parent dirty but never dropped the child when the delete emptied it; MST nodes are content-addressed, so the emptied node serialized as a real block and changed every ancestor CID. The tree therefore no longer equalled the tree that never contained the key — the equality commit-proof inversion depends on. `verifyCommitDiff` consequently returned `PrevDataMismatch` for valid second commits from a real PDS; any repo with two records whose keys differ in height hits it, since the lower key lives alone in a subtree. We only trimmed at the root; the TS reference and atmos both prune here (atmos cites indigo's `removeChild`/`IsEmpty` invariant). Found downstream in zlay via the atmoq relay-conformance corpus, where the `sync11/commit2-valid` control was being dropped. Post-delete roots now match atmos byte-for-byte over 25,000 deletes in atproto-bench; costs ~3% on a pure-delete microbenchmark. New coverage: a pure-MST prune test, a golden `@atproto/repo` partial-proof fixture through `verifyCommitDiff`, plus canonicality and lazy-stub guards ported from atmos. See `REPORT-mst-inversion-prevdata.md`. +- **fix**: `Mst` delete now prunes subtree nodes it empties. `deleteFromNode` recursed into a child and marked the parent dirty but never dropped the child when the delete emptied it; MST nodes are content-addressed, so the emptied node serialized as a real block and changed every ancestor CID. The tree therefore no longer equalled the tree that never contained the key — the equality commit-proof inversion depends on. `verifyCommitDiff` consequently returned `PrevDataMismatch` for valid second commits from a real PDS; any repo with two records whose keys differ in height hits it, since the lower key lives alone in a subtree. We only trimmed at the root; the TS reference and atmos both prune here (atmos cites indigo's `removeChild`/`IsEmpty` invariant). Found downstream in zlay via the atmoq relay-conformance corpus, where the `sync11/commit2-valid` control was being dropped. Post-delete roots now match atmos byte-for-byte over 25,000 deletes in atproto-bench; costs ~3% on a pure-delete microbenchmark. New coverage: a pure-MST prune test, a golden `@atproto/repo` partial-proof fixture through `verifyCommitDiff`, plus canonicality and lazy-stub guards ported from atmos. See `docs/mst-inversion-prevdata.md`. ## 0.3.18 diff --git a/REPORT-mst-inversion-prevdata.md b/docs/mst-inversion-prevdata.md similarity index 100% rename from REPORT-mst-inversion-prevdata.md rename to docs/mst-inversion-prevdata.md -- 2.51.2