docs(v4.0.0): ACL intent -- a runtime check of a word; TTL is how often

Captain Bob, 2026-10-05.  The countdown runs on every execution; the
permission check only when it reaches zero.  A compile-time check does not
meet the intent, so a word that is to be checked must be called.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
rajames
2026-10-05 17:46:04 -04:00
co-authored by Claude Opus 5.5
parent c80b4c8ed7
commit 0273308b78
+16
View File
@@ -290,6 +290,22 @@ check it.
give headers to. The node must be able to tell, at the call, whether the
target has the three cells of an entry before it.
**Intent, stated by Captain Bob 2026-10-05:** "Intent is for a runtime
check of a word. And the way we were originally doing it is the TTL was how
often the check would be performed. If the TTL was still valid, the word
would not get checked, in order to save the overhead of checking for
permissions every time."
So: the check is at run time, per word, at the hook. The countdown is the
cheap part, done on every execution; the permission check itself is done
only when the countdown reaches zero. A check made only when a definition
is compiled does not meet the intent.
What follows for the in-line words: to be checked at run time a word has
to pass through the hook, so it has to be called. The six that cannot be
called (`>R R> R@ I J LEAVE`) are the residue: they can only appear inside
a definition, and can only be checked when it is compiled.
**And what v3 measures.** v3 works a word's TTL out from that word's heat
(`heat/4 + 256`). Section 2.7 rules heat per opcode. A word card exactly as
v3's needs a count per word, which the same hook could take; whether it