Design session outcome for the relay unit. The hub/spoke family (hub
or spoke may relay; the hub re-exposes spoke services by ACL without
binding ports) needs the call-half support too, so the unit's scope
grew beyond the as-pinned sketch and is now three sub-units.
- ADR-051 (new): the relay is the wrapper composition — translate hop
= the ADR-049 establisher shape, byte-forward hop = pump_bidi per
ADR-050; the relay holds Arc<CallConnection> + ChannelManager per
producer leg (not a ChannelClient — take_call_connection's detach
is wrong for a hub with three CallConnection claimants); the reason
mapping preserves the spoke's code+message (timeout is the one
non-1:1 case, mapping to dial_failed); the registration seam is
two-phase (discover/stash → per-connection fork-register — the
ADR-047 §4 fork mechanism makes a one-call import impossible); the
ADR-042 relay map dissolves (implicit per-channel mapping) and
channel/close needs no translation surface (EOF cascade propagates
with correct ledger accounting on both legs); Pub-typed marked
specs are a loud assembly error; establishment bounds compound per
hop (noted, no fix); the ACL layering note is pinned (the spoke's
AccessControl sees only the hub identity; forwarded_for is never
checked).
- ADR-042 amended: the §Scope note is revised (implementation is an
alkcall export; hub crates compose it) and the two mechanism
supersessions are recorded — the contract and auth-model rationale
unchanged.
- ADR-047 amendment 3's forward reference and the README ADR index
updated (001..051).
- Review 008 remediation plan: Unit 3 split into 3a (ChannelRelay
component + gates), 3b (hub-leg install template — the call-half
support), 3c (gate-2 e2e incl. the mid-establishment disconnect
window); sequencing note updated; adoption note records the
session's decisions.
Verified: cargo doc --no-deps (markdown-only change).