Why is renaming a protobuf field's Java-facing name always safe, while renumbering it — keeping the name, changing the field number — silently corrupts already-stored or already-in-flight data? What's actually on the wire?
A serialized protobuf message carries no field names at all — every field on the wire is a (tag, value) pair where the tag encodes the field number, never the name. A decoder reads that number and looks it up in its own copy of the schema to know what the value means; the name was only ever a source-code label the compiler used to generate a getter, and it never crossed the wire in the first place. That's why renaming total_paise to total_cents is completely free at the wire level — every already-deployed reader keeps decoding field 2 exactly as before, because field 2 is still field 2. Renumbering is the opposite: it changes the one thing that is on the wire, so an old reader that still expects field 2 to mean the old thing will silently decode new data under the old meaning, or vice versa, with nothing on the wire to say the schema changed.