docs(architecture): resolve OQ-06/07/08 — per-repo authz, registry backing, CRUD ops

ADR-011 (resolves OQ-08): per-repo authorization — grants live in repo
records keyed on the stable logical identity id (alkcall ADR-025,
referenced); policy is alkgit-core's authorize() function (public+read
anonymous-first-class, write always authenticated+granted); alkgit
stores no identity records; vault placement resolved as nothing to
place in v1.

ADR-012 (resolves OQ-06/OQ-07): registry backing + write surface —
GitRegistryStore write supertrait (alknet ADR-035 read/write split
shape); registry-file default (per-repo record files + in-memory
index, config-seeded, op-mutable, no gitoxide); git/repo/* CRUD ops
shipped External with scope+ownership ACL (create mints ownership and
seeds creator grants; ownership never implies git access); the
two-op-kind classification recorded (open op + call ops from one
crate, per alkcall ADR-047); recorded split trigger for a downstream
platform crate.

Doc sync: backend.md (five-trait family, feature model split,
two-op-kinds), doors.md + overview.md (authorize policy, dual-kind
crate map), open-questions.md (OQ-06/07/08 resolved), README (ADR
table, current state), oq-06 tracker task closed (resolved early).

Verification: cargo test (default + --no-default-features), clippy
-D warnings, fmt --check.
This commit is contained in:
glm-5.3-flash committed 2026-09-21 16:26:59 +00:00
1 parent 86bf5a0cf0
commit addc874667
8 files changed
+492 -104

No files matched your search

+21 -8
View File
@@ -32,10 +32,13 @@ Single crate `alkgit`:
| Producer | `GitAdapter` (`alk/git` ALPN via alkcall `ProtocolHandler`), channels `register_openable` (repo id in open-op params — the negotiation + ACL point) | POC-1 verbatim |
| Consumer | `GitSession` typed client (`connect_direct`, `open_via_channels`) — the replication/mirroring primitive for alknet | new, small (TtySession analog) |
| Substrate | duplex session + stateless request/response layer (ADR-005); wire framing, V2 state machines (ADR-003) | POC-1, POC-3 |
| Backends | `GitRegistry`, `GitRefs`, `GitPackGen`, `GitPackIngest` traits; gix impl behind the default-on `gix` feature | POC-2 (gix impl) |
| Backends | `GitRegistry` (+ write supertrait), `GitRefs`, `GitPackGen`, `GitPackIngest` traits; impls behind the default-on `gix` (engine) and `registry-file` (records) features | POC-2 (gix impl) |
| Management ops | `git/repo/*` call ops over `GitRegistryStore` (ADR-012 §3) — the JSON half alongside the `alk/git` open op (first dual-kind payload; ADR-012 §5) | thin over the store trait |
Feature model: `default-features = false` gives the wire/protocol layer
without gix (wasm-clean as a side effect, not a goal); the `sha256`
Feature model: `gix` (engine impls) and `registry-file` (record store +
ops) are independent default-on seams (ADR-012 §4);
`default-features = false` gives the wire/protocol layer without either
(wasm-clean as a side effect, not a goal); the `sha256`
passthrough and (eventually, in alkhttp) the `git` door feature ride the
same pattern. Doors live in the door crates — see [doors.md](doors.md).
@@ -51,7 +54,9 @@ same pattern. Doors live in the door crates — see [doors.md](doors.md).
4. **Registry-resolved repo identity** — wire names are ids, never paths
(ADR-008).
5. **No secret material on the wire or at rest outside alkvault** —
metadata holds vault references; no env-var credential reads.
metadata holds vault references; no env-var credential reads. (In v1
alkgit's metadata holds no credential-shaped material at all, so
nothing is vault-placed — ADR-011 §5.)
6. **No shelling out to `git`** — pure Rust on gix primitives.
7. **Bounded resources** — every session carries `Limits` (ADR-009).
8. **Honest capability advertisement** — advertise exactly what we serve
@@ -82,6 +87,8 @@ designed but not yet exercised (OQ-04).
| [008](decisions/008-registry-resolved-repo-identity.md) | Repo identity | wire names are registry IDs |
| [009](decisions/009-bounded-resources-budget.md) | Budgets | every session carries limits |
| [010](decisions/010-pure-protocol-crate.md) | Pure protocol crate | single crate, producer/consumer halves, no doors/binary |
| [011](decisions/011-per-repo-authorization.md) | Per-repo authorization | grants in repo records, policy in core, vault-nil |
| [012](decisions/012-registry-backing-and-ops.md) | Registry + ops | read/write split, file default, CRUD ops, feature split |
## Open Questions
@@ -89,7 +96,13 @@ Key questions tracked in [open-questions.md](open-questions.md):
- **OQ-04**: receive-pack (push) validation gap (high — the
always-authenticated half of the wire surface).
- **OQ-06**: registry backing store for the gix feature (deferred on
scale requirements).
- **OQ-08**: registry identity space + vault placement (narrowed by
ADR-010).
- **OQ-02**: V2 multi-round negotiation (medium — efficiency, not
correctness).
- **OQ-03**: publish-time API freeze inventory (the `git/repo/*` op
set enters it; ADR-012).
- **OQ-05**: sha256 policy (deferred(scope), low).
Resolved this cycle: OQ-08 (ADR-011 — per-repo authorization, grants in
records, vault-nil), OQ-06 (ADR-012 — `registry-file` default,
persistence adapters additive), OQ-07 (ADR-012 — CRUD ops shipped
External with scope+ownership ACL).