wintercount 0.1.1

Temporal policy provenance: pin the policy hash in force at every event, then answer 'what rules governed at time T' forever — named for the painted buffalo robes that recorded each year's defining event
Documentation
# Threat model

wintercount answers one question verifiably: *which rules governed at
time T?* It assumes events faithfully pin the hash that was in force —
the crate preserves and queries that record.

## What it defends against

- **Retroactive governance claims.** Once marks are painted, "the
  policy at time T" is a query over committed history, not a memory.
- **Rejection laundering.** A policy that failed verification still
  has its hash pinned — `foreign_marks` surfaces events governed by
  bytes that were never accepted.
- **Silent defaults.** `builtin` is explicit — "ran on compiled-in
  defaults" can't be confused with "hash unavailable."

## What it does not defend against

- **A ledger that pins the wrong hash.** If the writer lies at paint
  time, the count faithfully preserves the lie. Provenance integrity
  depends on the writer pinning the actual in-force bytes — anchor the
  count in a hash-chained ledger so post-hoc edits break the chain.
- **Unhashed events.** Events without a pinned hash create gaps in the
  robe — `from_ledger` skips them silently, so coverage is the
  integrator's job.
- **Policy bytes lost.** `foreign_marks` flags hashes the registry
  can't resolve; if the document itself is gone, the mark survives but
  the rules don't. Keep a `PolicySet` archive.

## Design posture

Paint what governed, keep the paint permanent, never fabricate a
missing mark.