Amendment batch (no new decisions, all doc-level):
- A-4: done-round boundary set is the recognized subset — request
haves filtered through common_haves, the same honest-boundary rule
as the ack rounds (never honor an unverified have); amendment clause
in ADR-014 §2, same rule restated in transport.md §fetch.
- D-2: amendment note on ADR-007 step 3 — the per-repo check is
ADR-011's authorize policy function (static ACL engine fails closed
on None identity); step order unchanged.
- D-3: authorized-repo marker added to both substrate input tuples in
transport.md and to backend.md's public-API list (ADR-007's
type-level enforcement promise is now findable from the transport
spec).
- N-1: advertisement ref cap is fail-closed (breach is an error, never
a silent truncation) — transport.md §Limits.
- N-2: RegistryError::NotFound and authorization failure collapse to
the same wire error at the variant→wire mapping — transport.md
§error taxonomy.
- review 001: A-4/D-2/D-3/N-1/N-2 marked resolved.
Verification: cargo doc --no-deps, cargo test — clean.
- ADR-014: the multi-round ack loop, grounded in duplex git 2.43.0
captures cross-checked against fetch-pack.c: no-done rounds get
acknowledgments (ACK <oid> per recognized have, NAK when none, flush;
never ready so FLUSH is always the terminator), the done round
generates closure(wants) - closure(haves) with no cross-round server
state (clients re-send wants + commons every round), wait-for-done
stays (no capability change), want-less rounds answered empty, the
ack check is a new GitPackGen::common_haves seam (honest boundary at
the trait), budgets unchanged kinds
- docs/research/negotiation-captures.md: the normative negotiation
record (grammar, client behavior, malformed-section failure modes)
- transport.md: fetch section rewritten to the decided loop; references
updated
- OQ-02 resolved
Verification: cargo test / clippy -D warnings / fmt --check / doc pass