docs: review-002 minor fixes — op PATCH semantics, repo-id grammar, ssh tuple, ADR-016 glitches

- backend.md: git/repo/update pinned as PATCH (omitted fields unchanged;
  present fields replaced wholesale) — R-3; 'already_exists' disclosure
  posture recorded (accepted create-scope oracle; resolve-side stays
  collapsed) — R-6; repo-id grammar pinned (owner/name segments, rejection-
  only parsing, percent-encoded flat record-file naming, two-placeholder
  http-route note) — R-5
- doors.md: alkssh hand-off tuple gains service + authorized-repo marker
  (ADR-016/D-3 amendment rounds missed this third tuple site) — R-4
- ADR-016: collapsed-space and broken code-span glitches — R-8
- AGENTS.md: lifecycle paragraph records both gate reviews complete and
  decomposition unblocked

Verification: docs-only; cargo doc/test/clippy/fmt clean
This commit is contained in:
glm-5.3-flash committed 2026-09-30 05:30:12 +00:00
1 parent 0f7d5c7309
commit 666abd1da4
3 files changed
+16 -10

No files matched your search

+4 -1
View File
@@ -193,7 +193,10 @@ partially resolved, the publish freeze inventory — and OQ-05 —
sha256 policy, deferred on ecosystem need; OQ-16 — grant-key identity
namespace, deferred on the distributed phase. OQ-04 receive-pack, OQ-06
registry backing, and OQ-08 identity model are resolved: ADR-013,
ADR-012, ADR-011).
ADR-012, ADR-011). Both gate reviews (001 pre-decomposition, 002
post-remediation) are complete and all their findings are resolved
(resolutions: ADR-015/016/017/018); the specs are in `reviewed` status
and decomposition into implementation tasks may begin.
## Architecture Context
@@ -102,7 +102,7 @@ the session tuple gains the service dimension.**
fail before any advertisement; repo resolution and authorization
failures collapse per ADR-008 (unknown ≡ unauthorized). This is
alkgit-specific wire format on a published ALPN — it enters OQ-03's
freeze inventory (one-way). The grammar is also the one a git://-to-
freeze inventory (one-way). The grammar is also the one a git://-to-
`alk/git` bridge would need anyway, and it is the framing
`GitSession::connect_direct` sends — the two native paths speak one
preamble dialect.
@@ -120,8 +120,8 @@ the session tuple gains the service dimension.**
above).
4. **`GitSession` mirrors the same shapes**: `connect_direct` sends the
request-line preamble before waiting for the server; `open_via_
channels` sends the same `{repo, service}` params schema.
request-line preamble before waiting for the server; `open_via_channels`
sends the same `{repo, service}` params schema.
5. **Rejected alternatives** (recorded so the decomposer does not
reinvent them):
+9 -6
View File
@@ -1,6 +1,6 @@
---
status: draft
last_updated: 2026-09-25
status: reviewed
last_updated: 2026-09-30
---
# Doors: how alkgit is exposed
@@ -74,10 +74,12 @@ exists): parse the exec-request string with a fixed grammar —
`git-upload-pack '<repo>'` / `git-receive-pack '<repo>'` — never shell-
interpret it (ADR-008's never-execute rule), map the door's key-based
identity to the alkcall identity space, resolve the repo id against the
registry, run ACL, and hand (identity, repo, post-auth stream, limits)
to alkgit's duplex session. `git-upload-archive` gets a fixed refusal.
V2 is expected (ADR-003); `GIT_PROTOCOL=version=2` rides the ssh env
mechanism.
registry, run ACL, and hand the ADR-002 duplex tuple — `(identity, repo,
service, authorized-repo marker, post-auth stream, limits)` — to
alkgit's duplex session; the exec command is the service selector
(ADR-016's per-path service-establishment rule). `git-upload-archive`
gets a fixed refusal. V2 is expected (ADR-003); `GIT_PROTOCOL=version=2`
rides the ssh env mechanism.
**Interim**: no git-over-ssh path ships with alkgit. A downstream that
needs it before alkssh lands can terminate wire-ssh itself (russh or
@@ -127,6 +129,7 @@ deployment's docs, not here.
| [015](decisions/015-manage-grant-and-op-gate.md) | Manage grant + op gate | `manage` tier, admin-OR-manage op gate |
| [016](decisions/016-native-session-preamble.md) | Native session preamble | `{repo, service}` open-op params, request-line preamble, service in the tuple |
| [017](decisions/017-consumer-half-git-session.md) | Consumer half | `GitSession` typed client — the direct-connection push/pull primitive |
| [018](decisions/018-backend-trait-signatures-and-storage-error-model.md) | Trait signatures + storage errors | backend-seam shapes pinned (the door-blind object-storage family) |
## Open Questions