Commit Graph
2 Commits
Author SHA1 Message Date
glm-5.3-flash c4b9c53674 docs(architecture): ADR-015 — manage grant tier + repo-op gate, OQ-16 identity namespace
Resolves review 001 finding A-1 (critical): ADR-012 §3's "scope
git:admin OR ownership" gate is not expressible in alkcall's
AccessControl (AND-composition). Resolution is the review's option (a)
shape with the OR-term generalized: the per-repo grant action set gains
manage, authorize(record, identity, read|write|manage) becomes the
single policy function for git access and repo administration, and the
delete/update/get gate is admin scope OR manage grant (handler-side,
generic FORBIDDEN, unknown-repo = unauthorized per ADR-008). Repo
create seeds the creator's {read, write, manage} grants —
administration is grantable, so collaborators/bots/app-compiled roles
work without global scopes. Ownership stays as alkcall spawn-tracking
(mint at create unchanged); "ownership never implies git access" is
superseded.

- ADR-015 (new): manage grant tier, op gate, flat-grants-as-replication-
  substrate, opaque grant-key rule
- ADR-011: action set + policy domain amended, references updated
- ADR-012 §3: gate table replaced, two-tier paragraph superseded
- backend.md/doors.md/overview.md: gate + grant restatements, ADR tables
- OQ-16 (new, deferred(scope)): grant-key identity namespace —
  globally-comparable ids for cross-assembly/replicator grant state;
  tracker task tasks/architecture/oq-16-grant-identity-namespace.md
- review 001: A-1 marked resolved (ADR-015)
- vision.md: supersession notes (Internal-ops framing, v1 grant set)

Verification: cargo test, clippy -D warnings, fmt --check, doc --no-deps
all clean.
2026-09-26 11:50:25 +00:00
glm-5.3-flash d478361a15 docs(reviews): architecture pre-decomposition review — 3 critical spec gaps
Full-corpus gate review between the completed OQ cycle (ADR-013/014)
and phase-2 decomposition. Verified external API claims against real
sources (alkcall AccessControl/OwnershipStore semantics, alktty
template, gitoxide pins), probed the feature matrix (all four configs
compile) and the trait dyn-compatibility claim (E0038 repro on 1.88
and 1.94).

Findings:
- A-1 (critical): ADR-012 §3's scope-OR-ownership op gate is not
  expressible in alkcall's AccessControl (restrictions compose as
  AND) — handler-side two-tier check recommended
- A-2 (critical): bare async fn traits are not dyn-compatible
  (E0038) — ADR-012 §1 signatures need #[async_trait] + dep
- A-3 (critical): native path has no pinned session preamble —
  open-op params carry no service, so the open-time ACL point cannot
  run the write-tier check and push is unservable over alk/git
- A-4..A-6 (major): done-round boundary set should be the
  common_haves-filtered subset; consumer half (GitSession) named in
  five docs, specified in none; backend trait execution model
  unspecified
- D-1..D-3 (minor): stale superseded text (vision/alk-stack
  Internal-ops framing, AGENTS.md OQ list, ADR-007 step-3 mechanism)
- N-1..N-5: ref-cap breach rule, error-indistinguishability at the
  wire mapping, freeze-inventory schemas, push-options seam,
  ls-refs=unborn never capture-verified

Non-findings record what verified sound (feature story, gitoxide API
pins, deferral hygiene, cross-reference integrity). Remediation table
proposes six fix-round batches; A-5 needs a user scope decision.

Verification: cargo test/clippy/fmt/doc clean; check under
default/no-default/sha256/all-features and MSRV 1.88 all clean;
publish dry-run completes; git 2.43.0 present for integration tests.
2026-09-25 15:36:16 +00:00