- Pin the object-storage trait signatures (GitRefs.list_refs/apply_updates,
GitPackGen.generate/common_haves, GitPackIngest.prepare) — the A-2
amendment's unfinished half (review 001 pinned only the registry pair)
- repo parameter is &RepoRecord (record carries storage_root; no handle
type, no second lookup)
- Shared seam types pinned: RefLine (unborn-symref shape for the N-5
rider), RefUpdate, RefOutcome, PreparedPush, PushOptions
- StorageError for traits 3-5; RegistryError re-scoped to the registry
family (the 'every failure the trait family can produce' claim corrected)
- backend.md: pinned-signatures mirror section, concurrency-model
ownership bridge, boxed-stream parameter-ownership rule
Verification: cargo doc/test/clippy/fmt clean (docs-only change)
- new backend.md §"Registry types and schemas": RepoRecord serde shape
(three-action grants per ADR-015, opaque grant keys, storage_root
omitted from all op responses per ADR-008); the five-variant
RegistryError set with wire mappings; the four git/repo/* op
request/response schemas with additionalProperties: false inputs and
the git:repo:* error-code namespace
- the not_found/forbidden collapse carries one wire code ('unauthorized')
per N-2's rule; AlreadyExists is create-side only (no existence oracle)
- OQ-03 inventory note + review 001 N-3 marked resolved — review 001 is
now 14/14
verification: cargo test, clippy -D warnings, fmt --check, doc,
publish --dry-run — clean
- N-4: GitPackIngest's prepare binding carries push_options:
Option<&PushOptions> (parsed (key, value) pairs, verbatim and
un-interpreted; None until the config gate opens) — pinned in
ADR-013 §11 and backend.md's trait description so opening the
config gate later is value-additive, not a trait redesign
- N-5: ls-refs=unborn verification recorded as a rider in
transport.md §ls-refs + tracker task tasks/architecture/
n5-unborn-head-rider.md (unborn fixture, real client, both
substrates; drop the token if it cannot be served — ADR-003)
- review 001: N-4, N-5 marked resolved
verification: cargo test, clippy -D warnings, fmt --check, doc — clean
- new ADR-017: GitSession is a real typed client in v1 (ls_refs/fetch/
push), grounded in the two deployment use cases — the p2p replicator
is the named downstream and needs the client protocol layer; the
thin-wrapper reading is superseded
- fetch client reuses gix-protocol (async-client) over a custom
alkcall gix_transport::client::Transport impl (handshake writes the
ADR-016 request line on the direct path; the channels open-op params
carry it otherwise); push hand-rolled to ADR-013's shapes (gitoxide
has no send-pack client)
- storage-agnostic: packs stream both ways to caller-owned consumers;
no in-session credentials (alkcall transport authenticates); client
sessions carry ADR-009 Limits (client is also internet-facing)
- manifest: gix-protocol/gix-transport gain async-client features
(verified against published tree, MSRV 1.88)
- amend ADR-010 (consumer-half bullet) and ADR-012 §4 (the deferred
gix-protocol call — resolved; rider superseded); backend/transport/
overview/doors wording; review 001 A-5 marked resolved
verification: cargo check (default, --all-features, --no-default-features,
--features sha256), cargo +1.88 check, cargo test, clippy
-D warnings, fmt --check — clean across the matrix
- new ADR-016: channels open-op params pinned as {repo, service}
(channels/git/sub, additionalProperties: false); direct-ALPN GitAdapter
parses the git-daemon request line (POC-1-verbatim grammar, capture-
backed); session tuple gains the service dimension on both substrates;
GitSession mirrors the shapes; version deliberately stays out of the
preamble (service fully determines the state machine)
- amend ADR-002/005/010 (tuple, substrate inputs, open-op params pin) and
transport.md/doors.md/overview.md/backend.md accordingly
- add the ADR-016 wire shapes to OQ-03's freeze inventory; note in
AGENTS.md convention 9 that the alkgit-specific framing now exists and
is pinned
- review 001: A-3 marked resolved
verification: cargo test, clippy -D warnings, fmt --check, doc — clean
Completes review 001 D-1 (vision.md's half landed with ADR-015):
- alk-stack.md gitea-lesson item 2: supersession note pointing at
ADR-012 §3 / ADR-015 (repo ops are External, scope + manage grant —
right mechanism, wrong axis).
- AGENTS.md lifecycle status: active OQ list updated (OQ-03
partially resolved, OQ-05 deferred, OQ-16 deferred; OQ-04/06/08
resolved via ADR-013/012/011).
- review 001: D-1 marked resolved.
All three stale statements were pre-decomposition landmines: research
docs are declared 'current source of truth' by AGENTS.md, so the
superseded admin-API design needed marking.
Amendment batch (no new decisions, all doc-level):
- A-4: done-round boundary set is the recognized subset — request
haves filtered through common_haves, the same honest-boundary rule
as the ack rounds (never honor an unverified have); amendment clause
in ADR-014 §2, same rule restated in transport.md §fetch.
- D-2: amendment note on ADR-007 step 3 — the per-repo check is
ADR-011's authorize policy function (static ACL engine fails closed
on None identity); step order unchanged.
- D-3: authorized-repo marker added to both substrate input tuples in
transport.md and to backend.md's public-API list (ADR-007's
type-level enforcement promise is now findable from the transport
spec).
- N-1: advertisement ref cap is fail-closed (breach is an error, never
a silent truncation) — transport.md §Limits.
- N-2: RegistryError::NotFound and authorization failure collapse to
the same wire error at the variant→wire mapping — transport.md
§error taxonomy.
- review 001: A-4/D-2/D-3/N-1/N-2 marked resolved.
Verification: cargo doc --no-deps, cargo test — clean.
Resolves review 001 findings A-2 (critical) and A-6 (major) — the same
signature surface:
- ADR-012 §1: registry traits amended to #[async_trait] (bare async fn
in traits is not dyn-compatible, E0038; ops sit behind Arc<dyn
GitRegistryStore>). Desugared boxed Future form pinned in OQ-03's
freeze inventory. async-trait = "0.1" added to the manifest.
- backend.md concurrency model: the five-trait family is
#[async_trait] Send + Sync dyn-compatible; the wire layer enforces
ADR-009's pipeline-concurrency budget itself (permit acquired around
each GitPackGen/GitPackIngest call — the concrete admission point);
impls must not block the async executor and own their internal
threading (gix impls run spawn_blocking inside the impl — POC-2's
shape restated at its true layer).
- transport.md §fetch: spawn_blocking sentence rephrased to the
trait-contract version (the wire spec stops speaking gix).
- ADR-009: enforcement point of the blocking-pool budget made concrete.
- ADR-013 §6: ingestion spawn_blocking line aligned.
- review 001: A-2, A-6 marked resolved.
Verification: cargo test, clippy -D warnings, fmt --check, doc
--no-deps, check --no-default-features, check --all-features — all
clean.
Resolves review 001 finding A-1 (critical): ADR-012 §3's "scope
git:admin OR ownership" gate is not expressible in alkcall's
AccessControl (AND-composition). Resolution is the review's option (a)
shape with the OR-term generalized: the per-repo grant action set gains
manage, authorize(record, identity, read|write|manage) becomes the
single policy function for git access and repo administration, and the
delete/update/get gate is admin scope OR manage grant (handler-side,
generic FORBIDDEN, unknown-repo = unauthorized per ADR-008). Repo
create seeds the creator's {read, write, manage} grants —
administration is grantable, so collaborators/bots/app-compiled roles
work without global scopes. Ownership stays as alkcall spawn-tracking
(mint at create unchanged); "ownership never implies git access" is
superseded.
- ADR-015 (new): manage grant tier, op gate, flat-grants-as-replication-
substrate, opaque grant-key rule
- ADR-011: action set + policy domain amended, references updated
- ADR-012 §3: gate table replaced, two-tier paragraph superseded
- backend.md/doors.md/overview.md: gate + grant restatements, ADR tables
- OQ-16 (new, deferred(scope)): grant-key identity namespace —
globally-comparable ids for cross-assembly/replicator grant state;
tracker task tasks/architecture/oq-16-grant-identity-namespace.md
- review 001: A-1 marked resolved (ADR-015)
- vision.md: supersession notes (Internal-ops framing, v1 grant set)
Verification: cargo test, clippy -D warnings, fmt --check, doc --no-deps
all clean.
Full-corpus gate review between the completed OQ cycle (ADR-013/014)
and phase-2 decomposition. Verified external API claims against real
sources (alkcall AccessControl/OwnershipStore semantics, alktty
template, gitoxide pins), probed the feature matrix (all four configs
compile) and the trait dyn-compatibility claim (E0038 repro on 1.88
and 1.94).
Findings:
- A-1 (critical): ADR-012 §3's scope-OR-ownership op gate is not
expressible in alkcall's AccessControl (restrictions compose as
AND) — handler-side two-tier check recommended
- A-2 (critical): bare async fn traits are not dyn-compatible
(E0038) — ADR-012 §1 signatures need #[async_trait] + dep
- A-3 (critical): native path has no pinned session preamble —
open-op params carry no service, so the open-time ACL point cannot
run the write-tier check and push is unservable over alk/git
- A-4..A-6 (major): done-round boundary set should be the
common_haves-filtered subset; consumer half (GitSession) named in
five docs, specified in none; backend trait execution model
unspecified
- D-1..D-3 (minor): stale superseded text (vision/alk-stack
Internal-ops framing, AGENTS.md OQ list, ADR-007 step-3 mechanism)
- N-1..N-5: ref-cap breach rule, error-indistinguishability at the
wire mapping, freeze-inventory schemas, push-options seam,
ls-refs=unborn never capture-verified
Non-findings record what verified sound (feature story, gitoxide API
pins, deferral hygiene, cross-reference integrity). Remediation table
proposes six fix-round batches; A-5 needs a user scope decision.
Verification: cargo test/clippy/fmt/doc clean; check under
default/no-default/sha256/all-features and MSRV 1.88 all clean;
publish dry-run completes; git 2.43.0 present for integration tests.
- ADR-014: the multi-round ack loop, grounded in duplex git 2.43.0
captures cross-checked against fetch-pack.c: no-done rounds get
acknowledgments (ACK <oid> per recognized have, NAK when none, flush;
never ready so FLUSH is always the terminator), the done round
generates closure(wants) - closure(haves) with no cross-round server
state (clients re-send wants + commons every round), wait-for-done
stays (no capability change), want-less rounds answered empty, the
ack check is a new GitPackGen::common_haves seam (honest boundary at
the trait), budgets unchanged kinds
- docs/research/negotiation-captures.md: the normative negotiation
record (grammar, client behavior, malformed-section failure modes)
- transport.md: fetch section rewritten to the decided loop; references
updated
- OQ-02 resolved
Verification: cargo test / clippy -D warnings / fmt --check / doc pass
Per ADR-012 §4: the gix feature now gates only the engine component
crates (odb/pack/ref/object/fsck); the gix facade crate (client
entry point) is removed — the impls drive components directly
(POC-2's shape). registry-file added as an independent default-on
seam (file-backed registry + record ops, no gitoxide). Both
default-on preserves the batteries-included story; --no-default-
features remains the wire-only embed.
Verification: cargo test (default + --no-default-features), clippy
--all-targets -D warnings, fmt --check.
Structural decision (OQ-09 resolved): alkgit follows the alktty/
alktunnels template — a single published protocol crate on alkcall
channels, no binary, no front doors.
- ADR-010 supersedes ADR-001 (crate decomposition) and ADR-006
(http router factory); both marked Superseded
- Single crate at repo root: Cargo.toml with gix feature (default-on
backend implementations; wire layer compiles without it —
gix-hash always-on with sha1 per the compile-time-rejected
invariant), crates/ workspace deleted, src/lib.rs stub in place
- doors.md replaces http.md/ssh.md/alkgitd.md: alkhttp git-feature
sequencing (after first publish), alkssh requirement (fixed-grammar
exec dispatch), native alk/git path, downstream assembly
- backend.md replaces storage.md: GitRegistry/GitRefs/GitPackGen/
GitPackIngest traits (ingest validates, refs commits — single CAS
home), gix feature encodes POC-2 prerequisites
- transport.md reframed for the single crate; backend traits replace
hook traits in the public API
- OQ-09 resolved (all five sub-decisions in ADR-010), OQ-01 resolved
(subsumed), OQ-03 narrowed to publish-freeze, OQ-08 narrowed to
registry identity + vault placement, OQ-07 rescoped to the gix
feature's registry impl
- vision.md v2: single-binary/monorepo framing corrected as
init-agent artifact; POC checklist marked complete
- AGENTS.md + .opencode agent specs updated to the new shape
Verification: cargo build (default + no-default-features), cargo test
--all-features, clippy --all-features -D warnings, fmt --check all
pass. Third review round: zero critical, all warnings/suggestions
addressed (GitPackGen signature amended in ADR-004, stale anchors
fixed, ADR-006 body tense normalized, CAS split stated, vision
residuals cleaned).
New open question capturing the doors-as-family-infrastructure
direction: alkssh (planned) becomes the ssh door for git, git is a
payload service exposed by downstream doors (alkhttp, alkssh, alknet),
and the crate set may slim to protocol crates + http adapter (kept in
alkgit, Slim-A, or promoted to an alkhttp git feature, Slim-B).
OQ-09 carries the three sub-decisions (alkgit-ssh deletion vs
temporary russh scaffolding; http adapter home; alkgitd consumption
path) and cross-references ADR-006 (now flagged as possibly superseded
before finalization) and OQ-01. Deferred summary table updated.
- real git 2.43 clones/fetches/tag-checkouts over http:// through the full
alkcall -> alkhttp path (Connection::from_bidi(http/1.1) -> HttpAdapter ->
axum custom routes); h2c clone also verified
- request bodies stream (measured): BodyDataStream yields one hyper-read
chunk per poll_next; dribble probe + git's forced-chunked POST path
- pack responses stream under back pressure: bounded mpsc -> Body::from_stream,
O(counts) RSS on a 60k-object clone (peak ~8 MB above idle at 5.33 MB pack)
- protocol correction for git-protocol.md: http V2 responses end at the
flush; the 0002 response-end pkt is synthesized by remote-curl, never on
the wire; first POST carries the cached capability dump; flush-only POST
(probe_rpc) wants 200 + empty body
- POC-3 outcome recorded in pocs.md; alk-stack.md item 2 resolved
Verification: cargo test / clippy -D warnings / fmt --check clean
- pocs.md: define both modes + per-POC assignment (POC-1/2 standalone at
/workspace/alkgit-pocN, POC-3 branch mode); findings are the
deliverable, POC source never merges to main
- sdd_process.md: phase 0 + POC Specialist sections cover both modes
- poc-specialist.md: mode determination up front, standalone environment
section, 'stay in your lane' principle updated
- AGENTS.md: lifecycle status describes the two modes
Verified: none needed (markdown only)