docs: hash simplification — canonical git-family hash resolves BLAKE3

- OQ-BL-03 RESOLVED: BLAKE3's presence traced to pure iroh-blobs
  inheritance; with that rejected the multi-hash framing dissolves.
  Three tiers: canonical git-blob-sha-256 (git oids + every other
  consumer share one address domain — cross-consumer dedup free),
  tolerated git-blob-sha-1 (protocol necessity, git's hardened-SHA-1
  threat model), conditional BLAKE3 (only if a bao-like chunk-tree
  encoding is ever adopted; confined to that encoding layer)
- Principle 2 rewritten (one canonical hash, git-family derivation);
  alkgit consumer entry updated (the 'hash conflict' was an artifact
  of the BLAKE3 inheritance); p2p section notes strengthened dedup
- OQ-BL-04: verification options no longer BLAKE3-mandatory; chunk-
  tree encoding note — verified wholes register under the canonical
  hash so chunked and whole-file paths dedup together
- POC register: #2 absorbed into #1 (postamble abstraction + SHA-1
  tolerance are #1's trait work); #3 gains the sqlite-vs-fs
  micro-benchmark pull-out
- AGENTS.md convention 5 aligned (canonical git-family derivation)
This commit is contained in:
glm-5.3-flash committed 2026-10-01 06:33:59 +00:00
1 parent 55450d6bf0
commit cde279b76d
2 files changed
+163 -97

No files matched your search

+9 -5
View File
@@ -86,11 +86,15 @@ are repeated here so they apply to every session.
feature-gated modules. This is the same inversion-point pattern as
the alk* family (alktty `TtyBackend`, alktunnels pump halves).
5. **Hashes are data, not identity of transport** — the crate must
tolerate multiple hash algorithms (the alkgit conflict: git's SHA-1/
SHA-256 object hashes vs iroh-blobs' BLAKE3). How the hash algorithm
is abstracted (trait, enum, per-backend configuration) is a Phase 0/
1 decision, not yet pinned. Do not hardcode a single algorithm.
5. **Canonical hash is the git-family derivation** — the store keys
entries under git's oid derivation (`"blob <len>\0" + content`),
SHA-256 canonically, SHA-1 tolerated (existing repos; git's own
hardened-SHA-1 threat model inherited). The hash-conflict framing
dissolved 2026-10-01: BLAKE3's presence was an iroh-blobs
inheritance, not a requirement — it is demoted to a conditional
large-blob encoding consideration (docs/research/phase-0.md
OQ-BL-03). Do not hardcode beyond the small enum abstraction: the
key encoding is a one-way door.
6. **Auth-gated operations ride the alkcall authorization seam** — when
network-facing operations exist, authorization happens via alkcall's