Files
amethyst/commons
Claude f60d96e00a feat(cordn): mark the searched people a coordinator can actually reach
Inviting failed only at the tap: cordn adds a member by spending a KeyPackage
they published to this coordinator, and the search offered everyone in the
address book with no hint which of them qualified.

`kp_list` is the only non-destructive way to learn who did -- `kp_take` by
stable identity consumes one of their single-use packages (spec/00.md,
coordinator retrieval behavior), so it can never be a probe. It takes no
arguments and answers with every identity the coordinator holds a package for,
which means one call covers everybody and per-person probing would be the same
download repeated. So CordnKeyPackages now keeps that response as a snapshot:
identities for everyone, full entries for us, reused for a minute.

Cost is unchanged. topUp/ensureLastResort/listPublished already made this exact
call and discarded everyone else's rows; they now go through refresh(), which
warms the snapshot on the way past. The badge is fetched only once the field is
in use, so opening group info downloads nothing.

Publish decisions never read the reused copy. Minting against a stale listing
is the one place staleness does damage -- the coordinator keeps one last-resort
package per identity, so a second publish silently evicts the first and strands
every invite that referenced it. publishNew/withdraw drop the snapshot.

Only identities are retained for other accounts, not their kp_refs: a Welcome
is addressed to a ref obtained by taking the package, never to one read out of
a listing, and on a busy coordinator those refs are the bulk of an unpaginated
response.

The badge marks the yes and says nothing about the no, because the answer has
three states: published here, not published here, and a lookup that never came
back. Only membership was something we were told, so an unmarked row asserts
nothing and stays fully tappable -- a "cannot be added" marker would turn an
unreachable coordinator into a claim about a person.

Not exercised on a device.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012BfD4txdnsaPRXmNXbup9n
2026-09-25 20:08:46 +00:00
..