diff --git a/AGENTS.md b/AGENTS.md index 9c0c1cb..23aa42f 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -193,7 +193,10 @@ partially resolved, the publish freeze inventory — and OQ-05 — sha256 policy, deferred on ecosystem need; OQ-16 — grant-key identity namespace, deferred on the distributed phase. OQ-04 receive-pack, OQ-06 registry backing, and OQ-08 identity model are resolved: ADR-013, -ADR-012, ADR-011). +ADR-012, ADR-011). Both gate reviews (001 pre-decomposition, 002 +post-remediation) are complete and all their findings are resolved +(resolutions: ADR-015/016/017/018); the specs are in `reviewed` status +and decomposition into implementation tasks may begin. ## Architecture Context diff --git a/docs/architecture/decisions/016-native-session-preamble.md b/docs/architecture/decisions/016-native-session-preamble.md index c8066f2..91a751b 100644 --- a/docs/architecture/decisions/016-native-session-preamble.md +++ b/docs/architecture/decisions/016-native-session-preamble.md @@ -102,7 +102,7 @@ the session tuple gains the service dimension.** fail before any advertisement; repo resolution and authorization failures collapse per ADR-008 (unknown ≡ unauthorized). This is alkgit-specific wire format on a published ALPN — it enters OQ-03's - freeze inventory (one-way). The grammar is also the one a git://-to- + freeze inventory (one-way). The grammar is also the one a git://-to- `alk/git` bridge would need anyway, and it is the framing `GitSession::connect_direct` sends — the two native paths speak one preamble dialect. @@ -120,8 +120,8 @@ the session tuple gains the service dimension.** above). 4. **`GitSession` mirrors the same shapes**: `connect_direct` sends the - request-line preamble before waiting for the server; `open_via_ - channels` sends the same `{repo, service}` params schema. + request-line preamble before waiting for the server; `open_via_channels` + sends the same `{repo, service}` params schema. 5. **Rejected alternatives** (recorded so the decomposer does not reinvent them): diff --git a/docs/architecture/doors.md b/docs/architecture/doors.md index 30a5f7d..04809c0 100644 --- a/docs/architecture/doors.md +++ b/docs/architecture/doors.md @@ -1,6 +1,6 @@ --- -status: draft -last_updated: 2026-09-25 +status: reviewed +last_updated: 2026-09-30 --- # Doors: how alkgit is exposed @@ -74,10 +74,12 @@ exists): parse the exec-request string with a fixed grammar — `git-upload-pack ''` / `git-receive-pack ''` — never shell- interpret it (ADR-008's never-execute rule), map the door's key-based identity to the alkcall identity space, resolve the repo id against the -registry, run ACL, and hand (identity, repo, post-auth stream, limits) -to alkgit's duplex session. `git-upload-archive` gets a fixed refusal. -V2 is expected (ADR-003); `GIT_PROTOCOL=version=2` rides the ssh env -mechanism. +registry, run ACL, and hand the ADR-002 duplex tuple — `(identity, repo, +service, authorized-repo marker, post-auth stream, limits)` — to +alkgit's duplex session; the exec command is the service selector +(ADR-016's per-path service-establishment rule). `git-upload-archive` +gets a fixed refusal. V2 is expected (ADR-003); `GIT_PROTOCOL=version=2` +rides the ssh env mechanism. **Interim**: no git-over-ssh path ships with alkgit. A downstream that needs it before alkssh lands can terminate wire-ssh itself (russh or @@ -127,6 +129,7 @@ deployment's docs, not here. | [015](decisions/015-manage-grant-and-op-gate.md) | Manage grant + op gate | `manage` tier, admin-OR-manage op gate | | [016](decisions/016-native-session-preamble.md) | Native session preamble | `{repo, service}` open-op params, request-line preamble, service in the tuple | | [017](decisions/017-consumer-half-git-session.md) | Consumer half | `GitSession` typed client — the direct-connection push/pull primitive | +| [018](decisions/018-backend-trait-signatures-and-storage-error-model.md) | Trait signatures + storage errors | backend-seam shapes pinned (the door-blind object-storage family) | ## Open Questions