- new ADR-017: GitSession is a real typed client in v1 (ls_refs/fetch/
push), grounded in the two deployment use cases — the p2p replicator
is the named downstream and needs the client protocol layer; the
thin-wrapper reading is superseded
- fetch client reuses gix-protocol (async-client) over a custom
alkcall gix_transport::client::Transport impl (handshake writes the
ADR-016 request line on the direct path; the channels open-op params
carry it otherwise); push hand-rolled to ADR-013's shapes (gitoxide
has no send-pack client)
- storage-agnostic: packs stream both ways to caller-owned consumers;
no in-session credentials (alkcall transport authenticates); client
sessions carry ADR-009 Limits (client is also internet-facing)
- manifest: gix-protocol/gix-transport gain async-client features
(verified against published tree, MSRV 1.88)
- amend ADR-010 (consumer-half bullet) and ADR-012 §4 (the deferred
gix-protocol call — resolved; rider superseded); backend/transport/
overview/doors wording; review 001 A-5 marked resolved
verification: cargo check (default, --all-features, --no-default-features,
--features sha256), cargo +1.88 check, cargo test, clippy
-D warnings, fmt --check — clean across the matrix
Resolves review 001 findings A-2 (critical) and A-6 (major) — the same
signature surface:
- ADR-012 §1: registry traits amended to #[async_trait] (bare async fn
in traits is not dyn-compatible, E0038; ops sit behind Arc<dyn
GitRegistryStore>). Desugared boxed Future form pinned in OQ-03's
freeze inventory. async-trait = "0.1" added to the manifest.
- backend.md concurrency model: the five-trait family is
#[async_trait] Send + Sync dyn-compatible; the wire layer enforces
ADR-009's pipeline-concurrency budget itself (permit acquired around
each GitPackGen/GitPackIngest call — the concrete admission point);
impls must not block the async executor and own their internal
threading (gix impls run spawn_blocking inside the impl — POC-2's
shape restated at its true layer).
- transport.md §fetch: spawn_blocking sentence rephrased to the
trait-contract version (the wire spec stops speaking gix).
- ADR-009: enforcement point of the blocking-pool budget made concrete.
- ADR-013 §6: ingestion spawn_blocking line aligned.
- review 001: A-2, A-6 marked resolved.
Verification: cargo test, clippy -D warnings, fmt --check, doc
--no-deps, check --no-default-features, check --all-features — all
clean.
Resolves review 001 finding A-1 (critical): ADR-012 §3's "scope
git:admin OR ownership" gate is not expressible in alkcall's
AccessControl (AND-composition). Resolution is the review's option (a)
shape with the OR-term generalized: the per-repo grant action set gains
manage, authorize(record, identity, read|write|manage) becomes the
single policy function for git access and repo administration, and the
delete/update/get gate is admin scope OR manage grant (handler-side,
generic FORBIDDEN, unknown-repo = unauthorized per ADR-008). Repo
create seeds the creator's {read, write, manage} grants —
administration is grantable, so collaborators/bots/app-compiled roles
work without global scopes. Ownership stays as alkcall spawn-tracking
(mint at create unchanged); "ownership never implies git access" is
superseded.
- ADR-015 (new): manage grant tier, op gate, flat-grants-as-replication-
substrate, opaque grant-key rule
- ADR-011: action set + policy domain amended, references updated
- ADR-012 §3: gate table replaced, two-tier paragraph superseded
- backend.md/doors.md/overview.md: gate + grant restatements, ADR tables
- OQ-16 (new, deferred(scope)): grant-key identity namespace —
globally-comparable ids for cross-assembly/replicator grant state;
tracker task tasks/architecture/oq-16-grant-identity-namespace.md
- review 001: A-1 marked resolved (ADR-015)
- vision.md: supersession notes (Internal-ops framing, v1 grant set)
Verification: cargo test, clippy -D warnings, fmt --check, doc --no-deps
all clean.