- residency-accept.sh section 7, six checks: the refusal names the class
and all three ways forward (exit 2); WO_EPHEMERAL=1 runs from RAM with
the boot notice and a write round-trips; WO_EPHEMERAL with WO_DATA
refuses; WO_EPHEMERAL=2 refuses naming the accepted value; keys-resident
still refuses under the hatch; a plain class (the corpus `methods`
fixture) runs with no WO_DATA, rc 0, nothing on stderr
- blast radius measured gate by gate — each run without the export first,
kept only where the program refused: oop-e2e (fixtures declare tables);
db-bench.py's ram/msgrate/growth/randread legs (the durable legs drop it,
so a WO_DATA in the caller's shell now refuses loudly instead of silently
turning a RAM leg durable); db-actor per run (its restart pair sets
WO_DATA); chat (porch's store declares RateLimitCounter default-durable —
a library's table binds the consumer); wmux client legs (same image as
the server, no WO_DATA; servers and the WO_DATA-carrying r11cli `env -u`)
- byte-exact compares (db-actor single-shard, wmux client) drop the one
notice line; fibers, subprocess, log-watcher declare no table — untouched
- db-bench.py ceiling note: the checked refusal is databasev2 5's now
- residency 32/0, oop-e2e 131/0 with this tree
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
(cherry picked from commit 4553ca15da235c155b7ad31bbb077c3ad8e88fee)