p = r'C:\Users\decid\Documents\projects\spt-core\.worktrees\351-w5\docs-site\src\networking\monics.md'
s = open(p, encoding='utf-8', newline='').read()
N = '\r\n' if '\r\n' in s else '\n'


def rep(old, new):
    global s
    old = old.replace('\n', N)
    new = new.replace('\n', N)
    assert s.count(old) == 1, (old[:70], s.count(old))
    s = s.replace(old, new)


rep('''what a stranger would forge. It rides the message's own envelope instead — see
[the warning rides the message](#the-warning-rides-the-message) below.''',
    '''what a stranger would forge. It reaches you in the now-signal instead — see
[the warning reaches you in the now-signal](#the-warning-reaches-you-in-the-now-signal)
below.''')

a = s.index('## The warning rides the message')
b = s.index('**Anything a sender writes into this attribute is inert.**')
new = '''## The warning reaches you in the now-signal

<!-- [doc->REQ-TRUST-WARNING-NOW-SIGNAL] -->

The warning arrives as a `TRUST_WARNINGS` entry in your
[now-signal](../harness-contract/api.md), not on the message. Your node — the one
that received the message — records it, and your next poll shows it:

```text
<TRUST_WARNINGS>
wanda — msg BCDFGH23 (+2 more): TRUST WARNING — this message is from wanda, … / Until you have decided … / Once you have decided …
</TRUST_WARNINGS>
```

- **One line per peer.** It names the peer and the newest message it concerns,
  and counts the rest (`+2 more`) when several arrived before you polled. The
  warning block follows on the same line, its line breaks shown as ` / `.
- **Your override is never cut.** Its length is bounded when you set it, so the
  line carries all of it.
- **Showing it is what counts.** The warning is claimed for the session the
  first time a poll shows it, so a warning you never saw is still owed. A burst
  that arrived while you were away shows once, in the session you come back
  with, and never again after that.
- **No adapter setting can hide it.** A now-signal spec can narrow every other
  category, but not this one: when the warning rode the message, no adapter
  configuration could drop it, and moving it must not change that.
- **It stays on the node that received the message.** Your other instances do
  not see it.

> **For adapter authors: polling the now-signal is REQUIRED to receive trust
> warnings.** The `trust-warning` envelope attribute is gone, and so is the
> standalone system-authored delivery. An adapter that never polls the
> now-signal never shows the caution.

'''.replace('\n', N)
s = s[:a] + new + s[b:]
rep('''**Anything a sender writes into this attribute is inert.** A typed envelope rides
verbatim from the wire to your context, so a peer *can* put a `trust-warning`
into one and hand it over.''', '''**A `trust-warning` attribute a sender writes is inert.** No node composes one any
more, but a typed envelope rides verbatim from the wire to your context, so a
peer *can* put one into an envelope and hand it over.''')
open(p, 'w', encoding='utf-8', newline='').write(s)
print('ok')
