docs(arch): review-001 doc batch — A-4, D-2, D-3, N-1, N-2

Amendment batch (no new decisions, all doc-level):

- A-4: done-round boundary set is the recognized subset — request
  haves filtered through common_haves, the same honest-boundary rule
  as the ack rounds (never honor an unverified have); amendment clause
  in ADR-014 §2, same rule restated in transport.md §fetch.
- D-2: amendment note on ADR-007 step 3 — the per-repo check is
  ADR-011's authorize policy function (static ACL engine fails closed
  on None identity); step order unchanged.
- D-3: authorized-repo marker added to both substrate input tuples in
  transport.md and to backend.md's public-API list (ADR-007's
  type-level enforcement promise is now findable from the transport
  spec).
- N-1: advertisement ref cap is fail-closed (breach is an error, never
  a silent truncation) — transport.md §Limits.
- N-2: RegistryError::NotFound and authorization failure collapse to
  the same wire error at the variant→wire mapping — transport.md
  §error taxonomy.
- review 001: A-4/D-2/D-3/N-1/N-2 marked resolved.

Verification: cargo doc --no-deps, cargo test — clean.
This commit is contained in:
glm-5.3-flash committed 2026-09-29 08:30:26 +00:00
1 parent d067cf558a
commit 85bde4c241
5 files changed
+52 -11

No files matched your search

@@ -36,6 +36,13 @@ Every session/request performs, in order, before any protocol output:
the "advertisement is the only anonymous surface" line in the same
doc's principle 1 is read as the *minimum* boundary, and this decision
sets the operative rule).
*(Mechanism amended by ADR-011 §3 (review 001 D-2): the static ACL
engine fails closed on `identity: None`, so it cannot express
anonymous-public fetch. The per-repo check is alkgit-core's
`authorize` policy function evaluated on the registry record; the
alkcall registry gate still applies where the op has scopes. The
step *order* — resolve, then authorize, before any protocol output —
is unchanged.)*
4. Only then hand the session to transport.
Adapters embed this sequence; transport asserts it (the session entry