docs(architecture): resolve OQ-06/07/08 — per-repo authz, registry backing, CRUD ops

ADR-011 (resolves OQ-08): per-repo authorization — grants live in repo
records keyed on the stable logical identity id (alkcall ADR-025,
referenced); policy is alkgit-core's authorize() function (public+read
anonymous-first-class, write always authenticated+granted); alkgit
stores no identity records; vault placement resolved as nothing to
place in v1.

ADR-012 (resolves OQ-06/OQ-07): registry backing + write surface —
GitRegistryStore write supertrait (alknet ADR-035 read/write split
shape); registry-file default (per-repo record files + in-memory
index, config-seeded, op-mutable, no gitoxide); git/repo/* CRUD ops
shipped External with scope+ownership ACL (create mints ownership and
seeds creator grants; ownership never implies git access); the
two-op-kind classification recorded (open op + call ops from one
crate, per alkcall ADR-047); recorded split trigger for a downstream
platform crate.

Doc sync: backend.md (five-trait family, feature model split,
two-op-kinds), doors.md + overview.md (authorize policy, dual-kind
crate map), open-questions.md (OQ-06/07/08 resolved), README (ADR
table, current state), oq-06 tracker task closed (resolved early).

Verification: cargo test (default + --no-default-features), clippy
-D warnings, fmt --check.
This commit is contained in:
glm-5.3-flash committed 2026-09-21 16:26:59 +00:00
1 parent 86bf5a0cf0
commit addc874667
8 files changed
+492 -104

No files matched your search

+10 -5
View File
@@ -16,8 +16,10 @@ to a POC finding or research doc, or is flagged as an open question.
Phase 1, architecture committed to the pure-protocol-crate shape (ADR-010;
OQ-09 resolved). All docs below are `draft` except the superseded ADRs.
POC-1/2/3 validated the git protocol half end-to-end against real git
2.43; the remaining design work is the receive-pack state machine (OQ-04)
and backend/identity decisions (OQ-06, OQ-08).
2.43. This cycle settled the auth/backend theme: per-repo authorization
(ADR-011, OQ-08), registry backing + write surface + CRUD ops (ADR-012,
OQ-06/OQ-07). The remaining design work is the receive-pack state machine
(OQ-04) and V2 multi-round negotiation (OQ-02).
## Architecture Documents
@@ -43,13 +45,16 @@ and backend/identity decisions (OQ-06, OQ-08).
| [008](decisions/008-registry-resolved-repo-identity.md) | Wire repo names are registry IDs, never paths | Accepted |
| [009](decisions/009-bounded-resources-budget.md) | Bounded-resources budget model | Accepted |
| [010](decisions/010-pure-protocol-crate.md) | Pure protocol crate (alktty/alktunnels template) | Accepted |
| [011](decisions/011-per-repo-authorization.md) | Per-repo authorization (grants in records, policy in core) | Accepted |
| [012](decisions/012-registry-backing-and-ops.md) | Registry backing, write surface, CRUD ops, feature split | Accepted |
## Open Questions
All unresolved questions are tracked in [open-questions.md](open-questions.md)
with stable OQ-IDs, priorities, and cross-references. Highest-priority opens:
OQ-04 (receive-pack validation), OQ-06 (registry backing), OQ-08 (registry
identity space + vault placement).
with stable OQ-IDs, priorities, and cross-references. Highest-priority
open: OQ-04 (receive-pack validation). Also open: OQ-02 (multi-round
negotiation), OQ-03 (publish freeze inventory), OQ-05 (sha256,
deferred).
## Document Lifecycle