- N-4: GitPackIngest's prepare binding carries push_options:
Option<&PushOptions> (parsed (key, value) pairs, verbatim and
un-interpreted; None until the config gate opens) — pinned in
ADR-013 §11 and backend.md's trait description so opening the
config gate later is value-additive, not a trait redesign
- N-5: ls-refs=unborn verification recorded as a rider in
transport.md §ls-refs + tracker task tasks/architecture/
n5-unborn-head-rider.md (unborn fixture, real client, both
substrates; drop the token if it cannot be served — ADR-003)
- review 001: N-4, N-5 marked resolved
verification: cargo test, clippy -D warnings, fmt --check, doc — clean
Resolves review 001 finding A-1 (critical): ADR-012 §3's "scope
git:admin OR ownership" gate is not expressible in alkcall's
AccessControl (AND-composition). Resolution is the review's option (a)
shape with the OR-term generalized: the per-repo grant action set gains
manage, authorize(record, identity, read|write|manage) becomes the
single policy function for git access and repo administration, and the
delete/update/get gate is admin scope OR manage grant (handler-side,
generic FORBIDDEN, unknown-repo = unauthorized per ADR-008). Repo
create seeds the creator's {read, write, manage} grants —
administration is grantable, so collaborators/bots/app-compiled roles
work without global scopes. Ownership stays as alkcall spawn-tracking
(mint at create unchanged); "ownership never implies git access" is
superseded.
- ADR-015 (new): manage grant tier, op gate, flat-grants-as-replication-
substrate, opaque grant-key rule
- ADR-011: action set + policy domain amended, references updated
- ADR-012 §3: gate table replaced, two-tier paragraph superseded
- backend.md/doors.md/overview.md: gate + grant restatements, ADR tables
- OQ-16 (new, deferred(scope)): grant-key identity namespace —
globally-comparable ids for cross-assembly/replicator grant state;
tracker task tasks/architecture/oq-16-grant-identity-namespace.md
- review 001: A-1 marked resolved (ADR-015)
- vision.md: supersession notes (Internal-ops framing, v1 grant set)
Verification: cargo test, clippy -D warnings, fmt --check, doc --no-deps
all clean.