diff --git a/docs/architecture/open-questions.md b/docs/architecture/open-questions.md index a4def50..8afe01b 100644 --- a/docs/architecture/open-questions.md +++ b/docs/architecture/open-questions.md @@ -194,20 +194,36 @@ when their impacts say so; it records how careful the resolution must be. planned (after alksocks), alknet rewrite coming. Doors wrap alkcall producer/consumer in their wire protocol; services (git, tty, tunnels, socks) are payloads doors optionally expose. git should be a service - exposed by downstream consumers rather than owning its own doors: - candidate end-state is protocol crates (core + transport) + http adapter - either in alkgit or as an alkhttp `git` feature (Slim-B) or kept as - alkgit-http (Slim-A). alkssh is where git-over-ssh belongs when it - exists — the temporary russh-in-alkgitd decision (ssh.md) is scaffolding - either way. + exposed by downstream consumers rather than owning its own doors. + Candidate end-states: **Slim-A** — keep alkgit-http factory, 5-crate + layout, ADR-006 Option A as written; **Slim-B** — protocol crates + + alkhttp `git` feature for smart-http (requires alkgit published first); + **Option C (pure protocol crate)** — follow the alktty/alktunnels + template exactly: single `alkgit` crate, producer half (`GitAdapter` + for `alk/git` ALPN + channels `register_openable`, POC-1 substrate), + consumer half (typed `GitSession` — the replication/mirroring + primitive), backend traits (registry/refs/pack-gen/pack-ingest) with + the gix implementation feature-gated (mirrors alktty's `local`; NOT a + wasm goal, the cleanliness just falls out), smart-http stateless + substrate stays in-crate while the http mounting becomes alkhttp's + `git` feature. No binary; assembly is downstream's. Consequences to + record on commitment: vision.md's "single-binary git server" framing + is amended (assembly belongs to downstream consumers); ADR-001/006 + superseded by a new ADR; ssh.md defers entirely to alkssh (the + temporary russh scaffolding decision is dropped, not shipped); OQ-08 + narrows to the registry identity space + vault placement. - **Sub-decisions**: (1) delete `alkgit-ssh` now and defer git-over-ssh to alkssh, or keep temporary russh scaffolding in alkgitd until then (hinges on whether our deployment needs git-over-ssh before alkssh lands); (2) http adapter home — Slim-A (keep alkgit-http, ADR-006 Option A as written) vs Slim-B (alkhttp 0.6 `git` feature; requires - alkgit published first); (3) if Slim-B, whether `alkgitd` keeps an - internal factory consumption path or consumes the alkhttp feature like - any downstream. + alkgit published first); (3) crate granularity — keep core+transport + split (embedders wanting storage-only) vs merge into one `alkgit` + (Option C's shape); (4) under Option C, backend-trait surface: full + family (registry, refs, pack-gen, pack-ingest) vs minimal (pack + + registry, refs ride the registry trait); (5) alkgitd's fate — deleted, + or kept as a thin reference assembly once doors exist to assemble + against. - **Resolution path**: dedicated discussion session; decide the three sub-decisions, then rewrite ADR-001/006 and ssh.md (a new ADR superseding the affected parts, per ADR stability rules), and re-scope OQ-08.