docs: D-1 remainder — stale Internal-ops framing and OQ list

Completes review 001 D-1 (vision.md's half landed with ADR-015):

- alk-stack.md gitea-lesson item 2: supersession note pointing at
  ADR-012 §3 / ADR-015 (repo ops are External, scope + manage grant —
  right mechanism, wrong axis).
- AGENTS.md lifecycle status: active OQ list updated (OQ-03
  partially resolved, OQ-05 deferred, OQ-16 deferred; OQ-04/06/08
  resolved via ADR-013/012/011).
- review 001: D-1 marked resolved.

All three stale statements were pre-decomposition landmines: research
docs are declared 'current source of truth' by AGENTS.md, so the
superseded admin-API design needed marking.
This commit is contained in:
glm-5.3-flash committed 2026-09-29 08:30:45 +00:00
1 parent 85bde4c241
commit 201c7a1fce
3 files changed
+12 -3

No files matched your search

+6 -2
View File
@@ -187,8 +187,12 @@ docs, branch dropped) or standalone mode (POC independent of repo code;
scratch project at `/workspace/<poc-name>`). POCs have relaxed
constraints (comments/unwrap acceptable) — they are exploration tools,
not production code. Open architecture questions live in
`docs/architecture/open-questions.md` (OQ-04 receive-pack, OQ-06
registry backing, OQ-08 identity model are the active ones).
`docs/architecture/open-questions.md` (the active set: OQ-03 —
partially resolved, the publish freeze inventory — and OQ-05 —
sha256 policy, deferred on ecosystem need; OQ-16 — grant-key identity
namespace, deferred on the distributed phase. OQ-04 receive-pack, OQ-06
registry backing, and OQ-08 identity model are resolved: ADR-013,
ADR-012, ADR-011).
## Architecture Context
+5
View File
@@ -46,6 +46,11 @@ unreachable from the wire. alkgit must extend the same philosophy:
call protocol as `Visibility::Internal` ops over the admin interface
(or via alkhttp with auth); there is no admin endpoint that exists on the
same unauthenticated surface as git traffic.
*(Superseded by ADR-012 §3 / ADR-015 for alkgit's repo ops: the ops are
`Visibility::External`, gated by scope + the per-repo `manage` grant —
the gitea lesson is served by the ACL (visible-surface =
authorized-surface), not by hiding the ops. "Right mechanism, wrong
axis.")*
3. **No plaintext secrets in the DB.** Credentials/tokens go through
alkvault; the metadata store holds references, not keys.
4. **Blast-radius thinking carries into the design**: single binary, no
@@ -764,7 +764,7 @@ criticals are ADR-writing work, not code):
| A-4 | done-round boundary set unverified | ADR-014 §2 + transport.md clause: boundary = `common_haves`-filtered haves | trivial | none | **resolved** — boundary set is the recognized subset (`common_haves`-filtered), amendment clause in ADR-014 §2 + transport.md §fetch |
| A-5 | consumer half unspecified | user scope decision, then amendment or small ADR (recommended: thin wrapper, deps carried with purpose) | small | scope | open |
| A-6 | trait execution model unspecified | backend.md paragraph + transport.md rephrase: async traits, wire-layer permit, impl-internal spawn_blocking | small | none | **resolved** — backend.md concurrency model: wire layer enforces the ADR-009 permit around gen/ingest trait calls; impls own internal `spawn_blocking` (ADR-009/ADR-013 aligned) |
| D-1 | stale Internal-ops + OQ-list text | supersession notes (vision, alk-stack, AGENTS) | trivial | none | open |
| D-1 | stale Internal-ops + OQ-list text | supersession notes (vision, alk-stack, AGENTS) | trivial | none | **resolved** — supersession notes in vision.md (with ADR-015) and alk-stack.md item 2; AGENTS.md active-OQ list updated to OQ-03/05/16 |
| D-2 | ADR-007 step-3 mechanism superseded | amendment note on ADR-007 | trivial | none | **resolved** — amendment note on ADR-007 step 3 (mechanism → ADR-011 `authorize`; step order unchanged) |
| D-3 | authorized-repo marker missing from tuples | add to transport.md tuples + backend.md API list | trivial | none | **resolved** — marker added to both substrate input tuples (transport.md) and backend.md public-API list |
| N-1 | ref-cap breach behavior | one fail-closed clause in transport.md | trivial | none | **resolved** — ref cap fail-closed clause in transport.md §Limits (breach is an error, never truncation) |