Amendment batch (no new decisions, all doc-level):
- A-4: done-round boundary set is the recognized subset — request
haves filtered through common_haves, the same honest-boundary rule
as the ack rounds (never honor an unverified have); amendment clause
in ADR-014 §2, same rule restated in transport.md §fetch.
- D-2: amendment note on ADR-007 step 3 — the per-repo check is
ADR-011's authorize policy function (static ACL engine fails closed
on None identity); step order unchanged.
- D-3: authorized-repo marker added to both substrate input tuples in
transport.md and to backend.md's public-API list (ADR-007's
type-level enforcement promise is now findable from the transport
spec).
- N-1: advertisement ref cap is fail-closed (breach is an error, never
a silent truncation) — transport.md §Limits.
- N-2: RegistryError::NotFound and authorization failure collapse to
the same wire error at the variant→wire mapping — transport.md
§error taxonomy.
- review 001: A-4/D-2/D-3/N-1/N-2 marked resolved.
Verification: cargo doc --no-deps, cargo test — clean.
Phase 1 (SDD) output for alkgit — the git payload service of the alk
family: a pure protocol crate on alkcall channels (the alk/git ALPN),
following the alktty/alktunnels template (ADR-010). Phase 0 research lives
in docs/research/; every design claim here traces
to a POC finding or research doc, or is flagged as an open question.
Current State
Phase 1, architecture committed to the pure-protocol-crate shape (ADR-010;
OQ-09 resolved). POC-1/2/3 validated the git protocol half end-to-end
against real git 2.43. Previous cycles settled the auth/backend theme
(ADR-011, ADR-012). This cycle settled the wire surface against
real-client captures: the receive-pack push state machine (ADR-013,
OQ-04) and the V2 multi-round negotiation ack loop (ADR-014, OQ-02). All
wire-layer design is now capture-grounded; the remaining open questions
are the publish-freeze timing (OQ-03, a release decision), sha256
policy (OQ-05, deferred on ecosystem need), and the grant-key identity
namespace (OQ-16, deferred on the first cross-assembly deployment —
blocks nothing in v1). ADR-015 resolved
review 001's A-1 (the repo-op gate) with the manage grant tier.
Manage grant tier + repo-op gate (admin scope OR manage grant)
Accepted
Open Questions
All unresolved questions are tracked in open-questions.md
with stable OQ-IDs, priorities, and cross-references. Remaining: OQ-03
(publish freeze inventory — partially resolved, blocked on first-publish
timing), OQ-05 (sha256, deferred on ecosystem need), and OQ-16 (grant-key
identity namespace, deferred on the first cross-assembly record-sharing
deployment). The wire-layer
questions (OQ-02, OQ-04) resolved this cycle with ADR-014/ADR-013.
Document Lifecycle
Status
Meaning
Transitions
draft
Under active development; may change significantly
→ reviewed when its OQs are resolved
reviewed
Architecture final; implementation may begin; changes need review
→ stable when implementation verified
stable
Locked; changes require review, may warrant an ADR