Commit Graph
10 Commits
Author SHA1 Message Date
glm-5.3-flash 18106f461c docs(reviews): post-remediation re-review — gate passed, specs to reviewed
- docs/reviews/002-post-remediation-review.md: verifies all 14 review-001
  findings landed faithfully (sibling-source re-verification + gix-transport
  async_trait(?Send) check + four-config/MSRV probes), records the eight
  residual findings (R-1..R-8) and their resolutions (ADR-018 + doc batch)
- README lifecycle: draft→reviewed allows properly-tracked non-circular
  OQ deferrals (release-timing OQ-03 no longer blocks the transition) — R-7
- overview/transport/backend/doors/open-questions: frontmatter flipped to
  reviewed, timestamps refreshed; ADR-018 added to all ADR tables and the
  OQ-03 freeze-inventory narrative

Phase-1 gate verdict: decomposition may begin
Verification: cargo doc/test/clippy/fmt clean; four feature configs +
MSRV 1.88 check/clippy clean
2026-09-30 05:30:16 +00:00
glm-5.3-flash b6040d36a9 docs(architecture): N-3 — registry types/schemas pinned (freeze-inventory draft)
- new backend.md §"Registry types and schemas": RepoRecord serde shape
  (three-action grants per ADR-015, opaque grant keys, storage_root
  omitted from all op responses per ADR-008); the five-variant
  RegistryError set with wire mappings; the four git/repo/* op
  request/response schemas with additionalProperties: false inputs and
  the git:repo:* error-code namespace
- the not_found/forbidden collapse carries one wire code ('unauthorized')
  per N-2's rule; AlreadyExists is create-side only (no existence oracle)
- OQ-03 inventory note + review 001 N-3 marked resolved — review 001 is
  now 14/14

verification: cargo test, clippy -D warnings, fmt --check, doc,
publish --dry-run — clean
2026-09-30 04:21:03 +00:00
glm-5.3-flash 11ceead6fd docs(architecture): N-4 + N-5 — push-options trait param, unborn-HEAD rider
- N-4: GitPackIngest's prepare binding carries push_options:
  Option<&PushOptions> (parsed (key, value) pairs, verbatim and
  un-interpreted; None until the config gate opens) — pinned in
  ADR-013 §11 and backend.md's trait description so opening the
  config gate later is value-additive, not a trait redesign
- N-5: ls-refs=unborn verification recorded as a rider in
  transport.md §ls-refs + tracker task tasks/architecture/
  n5-unborn-head-rider.md (unborn fixture, real client, both
  substrates; drop the token if it cannot be served — ADR-003)
- review 001: N-4, N-5 marked resolved

verification: cargo test, clippy -D warnings, fmt --check, doc — clean
2026-09-30 04:19:37 +00:00
glm-5.3-flash 82653c31b6 docs(architecture): ADR-017 — consumer half, GitSession as typed client (review 001 A-5)
- new ADR-017: GitSession is a real typed client in v1 (ls_refs/fetch/
  push), grounded in the two deployment use cases — the p2p replicator
  is the named downstream and needs the client protocol layer; the
  thin-wrapper reading is superseded
- fetch client reuses gix-protocol (async-client) over a custom
  alkcall gix_transport::client::Transport impl (handshake writes the
  ADR-016 request line on the direct path; the channels open-op params
  carry it otherwise); push hand-rolled to ADR-013's shapes (gitoxide
  has no send-pack client)
- storage-agnostic: packs stream both ways to caller-owned consumers;
  no in-session credentials (alkcall transport authenticates); client
  sessions carry ADR-009 Limits (client is also internet-facing)
- manifest: gix-protocol/gix-transport gain async-client features
  (verified against published tree, MSRV 1.88)
- amend ADR-010 (consumer-half bullet) and ADR-012 §4 (the deferred
  gix-protocol call — resolved; rider superseded); backend/transport/
  overview/doors wording; review 001 A-5 marked resolved

verification: cargo check (default, --all-features, --no-default-features,
--features sha256), cargo +1.88 check, cargo test, clippy
-D warnings, fmt --check — clean across the matrix
2026-09-29 09:24:47 +00:00
glm-5.3-flash 41b0894740 docs(architecture): ADR-016 — native session preamble (review 001 A-3)
- new ADR-016: channels open-op params pinned as {repo, service}
  (channels/git/sub, additionalProperties: false); direct-ALPN GitAdapter
  parses the git-daemon request line (POC-1-verbatim grammar, capture-
  backed); session tuple gains the service dimension on both substrates;
  GitSession mirrors the shapes; version deliberately stays out of the
  preamble (service fully determines the state machine)
- amend ADR-002/005/010 (tuple, substrate inputs, open-op params pin) and
  transport.md/doors.md/overview.md/backend.md accordingly
- add the ADR-016 wire shapes to OQ-03's freeze inventory; note in
  AGENTS.md convention 9 that the alkgit-specific framing now exists and
  is pinned
- review 001: A-3 marked resolved

verification: cargo test, clippy -D warnings, fmt --check, doc — clean
2026-09-29 08:50:54 +00:00
glm-5.3-flash 201c7a1fce docs: D-1 remainder — stale Internal-ops framing and OQ list
Completes review 001 D-1 (vision.md's half landed with ADR-015):

- alk-stack.md gitea-lesson item 2: supersession note pointing at
  ADR-012 §3 / ADR-015 (repo ops are External, scope + manage grant —
  right mechanism, wrong axis).
- AGENTS.md lifecycle status: active OQ list updated (OQ-03
  partially resolved, OQ-05 deferred, OQ-16 deferred; OQ-04/06/08
  resolved via ADR-013/012/011).
- review 001: D-1 marked resolved.

All three stale statements were pre-decomposition landmines: research
docs are declared 'current source of truth' by AGENTS.md, so the
superseded admin-API design needed marking.
2026-09-29 08:30:45 +00:00
glm-5.3-flash 85bde4c241 docs(arch): review-001 doc batch — A-4, D-2, D-3, N-1, N-2
Amendment batch (no new decisions, all doc-level):

- A-4: done-round boundary set is the recognized subset — request
  haves filtered through common_haves, the same honest-boundary rule
  as the ack rounds (never honor an unverified have); amendment clause
  in ADR-014 §2, same rule restated in transport.md §fetch.
- D-2: amendment note on ADR-007 step 3 — the per-repo check is
  ADR-011's authorize policy function (static ACL engine fails closed
  on None identity); step order unchanged.
- D-3: authorized-repo marker added to both substrate input tuples in
  transport.md and to backend.md's public-API list (ADR-007's
  type-level enforcement promise is now findable from the transport
  spec).
- N-1: advertisement ref cap is fail-closed (breach is an error, never
  a silent truncation) — transport.md §Limits.
- N-2: RegistryError::NotFound and authorization failure collapse to
  the same wire error at the variant→wire mapping — transport.md
  §error taxonomy.
- review 001: A-4/D-2/D-3/N-1/N-2 marked resolved.

Verification: cargo doc --no-deps, cargo test — clean.
2026-09-29 08:30:26 +00:00
glm-5.3-flash d067cf558a docs(arch): A-2 + A-6 — async-trait trait family, pinned execution model
Resolves review 001 findings A-2 (critical) and A-6 (major) — the same
signature surface:

- ADR-012 §1: registry traits amended to #[async_trait] (bare async fn
  in traits is not dyn-compatible, E0038; ops sit behind Arc<dyn
  GitRegistryStore>). Desugared boxed Future form pinned in OQ-03's
  freeze inventory. async-trait = "0.1" added to the manifest.
- backend.md concurrency model: the five-trait family is
  #[async_trait] Send + Sync dyn-compatible; the wire layer enforces
  ADR-009's pipeline-concurrency budget itself (permit acquired around
  each GitPackGen/GitPackIngest call — the concrete admission point);
  impls must not block the async executor and own their internal
  threading (gix impls run spawn_blocking inside the impl — POC-2's
  shape restated at its true layer).
- transport.md §fetch: spawn_blocking sentence rephrased to the
  trait-contract version (the wire spec stops speaking gix).
- ADR-009: enforcement point of the blocking-pool budget made concrete.
- ADR-013 §6: ingestion spawn_blocking line aligned.
- review 001: A-2, A-6 marked resolved.

Verification: cargo test, clippy -D warnings, fmt --check, doc
--no-deps, check --no-default-features, check --all-features — all
clean.
2026-09-29 08:29:46 +00:00
glm-5.3-flash c4b9c53674 docs(architecture): ADR-015 — manage grant tier + repo-op gate, OQ-16 identity namespace
Resolves review 001 finding A-1 (critical): ADR-012 §3's "scope
git:admin OR ownership" gate is not expressible in alkcall's
AccessControl (AND-composition). Resolution is the review's option (a)
shape with the OR-term generalized: the per-repo grant action set gains
manage, authorize(record, identity, read|write|manage) becomes the
single policy function for git access and repo administration, and the
delete/update/get gate is admin scope OR manage grant (handler-side,
generic FORBIDDEN, unknown-repo = unauthorized per ADR-008). Repo
create seeds the creator's {read, write, manage} grants —
administration is grantable, so collaborators/bots/app-compiled roles
work without global scopes. Ownership stays as alkcall spawn-tracking
(mint at create unchanged); "ownership never implies git access" is
superseded.

- ADR-015 (new): manage grant tier, op gate, flat-grants-as-replication-
  substrate, opaque grant-key rule
- ADR-011: action set + policy domain amended, references updated
- ADR-012 §3: gate table replaced, two-tier paragraph superseded
- backend.md/doors.md/overview.md: gate + grant restatements, ADR tables
- OQ-16 (new, deferred(scope)): grant-key identity namespace —
  globally-comparable ids for cross-assembly/replicator grant state;
  tracker task tasks/architecture/oq-16-grant-identity-namespace.md
- review 001: A-1 marked resolved (ADR-015)
- vision.md: supersession notes (Internal-ops framing, v1 grant set)

Verification: cargo test, clippy -D warnings, fmt --check, doc --no-deps
all clean.
2026-09-26 11:50:25 +00:00
glm-5.3-flash d478361a15 docs(reviews): architecture pre-decomposition review — 3 critical spec gaps
Full-corpus gate review between the completed OQ cycle (ADR-013/014)
and phase-2 decomposition. Verified external API claims against real
sources (alkcall AccessControl/OwnershipStore semantics, alktty
template, gitoxide pins), probed the feature matrix (all four configs
compile) and the trait dyn-compatibility claim (E0038 repro on 1.88
and 1.94).

Findings:
- A-1 (critical): ADR-012 §3's scope-OR-ownership op gate is not
  expressible in alkcall's AccessControl (restrictions compose as
  AND) — handler-side two-tier check recommended
- A-2 (critical): bare async fn traits are not dyn-compatible
  (E0038) — ADR-012 §1 signatures need #[async_trait] + dep
- A-3 (critical): native path has no pinned session preamble —
  open-op params carry no service, so the open-time ACL point cannot
  run the write-tier check and push is unservable over alk/git
- A-4..A-6 (major): done-round boundary set should be the
  common_haves-filtered subset; consumer half (GitSession) named in
  five docs, specified in none; backend trait execution model
  unspecified
- D-1..D-3 (minor): stale superseded text (vision/alk-stack
  Internal-ops framing, AGENTS.md OQ list, ADR-007 step-3 mechanism)
- N-1..N-5: ref-cap breach rule, error-indistinguishability at the
  wire mapping, freeze-inventory schemas, push-options seam,
  ls-refs=unborn never capture-verified

Non-findings record what verified sound (feature story, gitoxide API
pins, deferral hygiene, cross-reference integrity). Remediation table
proposes six fix-round batches; A-5 needs a user scope decision.

Verification: cargo test/clippy/fmt/doc clean; check under
default/no-default/sha256/all-features and MSRV 1.88 all clean;
publish dry-run completes; git 2.43.0 present for integration tests.
2026-09-25 15:36:16 +00:00