docs(architecture): OQ-09 gains Option C — pure protocol crate (alktty template)

This commit is contained in:
glm-5.3-flash committed 2026-09-21 04:42:37 +00:00
1 parent 74029207e6
commit de922253a4
1 file changed
+25 -9
+25 -9
View File
@@ -194,20 +194,36 @@ when their impacts say so; it records how careful the resolution must be.
planned (after alksocks), alknet rewrite coming. Doors wrap alkcall
producer/consumer in their wire protocol; services (git, tty, tunnels,
socks) are payloads doors optionally expose. git should be a service
exposed by downstream consumers rather than owning its own doors:
candidate end-state is protocol crates (core + transport) + http adapter
either in alkgit or as an alkhttp `git` feature (Slim-B) or kept as
alkgit-http (Slim-A). alkssh is where git-over-ssh belongs when it
exists — the temporary russh-in-alkgitd decision (ssh.md) is scaffolding
either way.
exposed by downstream consumers rather than owning its own doors.
Candidate end-states: **Slim-A** — keep alkgit-http factory, 5-crate
layout, ADR-006 Option A as written; **Slim-B** — protocol crates +
alkhttp `git` feature for smart-http (requires alkgit published first);
**Option C (pure protocol crate)** — follow the alktty/alktunnels
template exactly: single `alkgit` crate, producer half (`GitAdapter`
for `alk/git` ALPN + channels `register_openable`, POC-1 substrate),
consumer half (typed `GitSession` — the replication/mirroring
primitive), backend traits (registry/refs/pack-gen/pack-ingest) with
the gix implementation feature-gated (mirrors alktty's `local`; NOT a
wasm goal, the cleanliness just falls out), smart-http stateless
substrate stays in-crate while the http mounting becomes alkhttp's
`git` feature. No binary; assembly is downstream's. Consequences to
record on commitment: vision.md's "single-binary git server" framing
is amended (assembly belongs to downstream consumers); ADR-001/006
superseded by a new ADR; ssh.md defers entirely to alkssh (the
temporary russh scaffolding decision is dropped, not shipped); OQ-08
narrows to the registry identity space + vault placement.
- **Sub-decisions**: (1) delete `alkgit-ssh` now and defer git-over-ssh to
alkssh, or keep temporary russh scaffolding in alkgitd until then
(hinges on whether our deployment needs git-over-ssh before alkssh
lands); (2) http adapter home — Slim-A (keep alkgit-http, ADR-006
Option A as written) vs Slim-B (alkhttp 0.6 `git` feature; requires
alkgit published first); (3) if Slim-B, whether `alkgitd` keeps an
internal factory consumption path or consumes the alkhttp feature like
any downstream.
alkgit published first); (3) crate granularity — keep core+transport
split (embedders wanting storage-only) vs merge into one `alkgit`
(Option C's shape); (4) under Option C, backend-trait surface: full
family (registry, refs, pack-gen, pack-ingest) vs minimal (pack +
registry, refs ride the registry trait); (5) alkgitd's fate — deleted,
or kept as a thin reference assembly once doors exist to assemble
against.
- **Resolution path**: dedicated discussion session; decide the three
sub-decisions, then rewrite ADR-001/006 and ssh.md (a new ADR superseding
the affected parts, per ADR stability rules), and re-scope OQ-08.