Files
alkgit/docs/research
glm-5.3-flash c4b9c53674 docs(architecture): ADR-015 — manage grant tier + repo-op gate, OQ-16 identity namespace
Resolves review 001 finding A-1 (critical): ADR-012 §3's "scope
git:admin OR ownership" gate is not expressible in alkcall's
AccessControl (AND-composition). Resolution is the review's option (a)
shape with the OR-term generalized: the per-repo grant action set gains
manage, authorize(record, identity, read|write|manage) becomes the
single policy function for git access and repo administration, and the
delete/update/get gate is admin scope OR manage grant (handler-side,
generic FORBIDDEN, unknown-repo = unauthorized per ADR-008). Repo
create seeds the creator's {read, write, manage} grants —
administration is grantable, so collaborators/bots/app-compiled roles
work without global scopes. Ownership stays as alkcall spawn-tracking
(mint at create unchanged); "ownership never implies git access" is
superseded.

- ADR-015 (new): manage grant tier, op gate, flat-grants-as-replication-
  substrate, opaque grant-key rule
- ADR-011: action set + policy domain amended, references updated
- ADR-012 §3: gate table replaced, two-tier paragraph superseded
- backend.md/doors.md/overview.md: gate + grant restatements, ADR tables
- OQ-16 (new, deferred(scope)): grant-key identity namespace —
  globally-comparable ids for cross-assembly/replicator grant state;
  tracker task tasks/architecture/oq-16-grant-identity-namespace.md
- review 001: A-1 marked resolved (ADR-015)
- vision.md: supersession notes (Internal-ops framing, v1 grant set)

Verification: cargo test, clippy -D warnings, fmt --check, doc --no-deps
all clean.
2026-09-26 11:50:25 +00:00
..

alkgit Research Index

Phase 0 (exploration) research. Feeds phase 1 (architecture).

Doc Topic Status
vision.md Vision, guiding principles, non-goals, phase-0 checklist draft v2 (amended 2026-09-21)
gitoxide.md gitoxide (gix) capability + version alignment initial pass complete
alk-stack.md alk stack fit, integration surface, gitea-lesson constraints initial pass complete
git-protocol.md Server-side git smart protocol inventory (what we own) initial pass complete
reference-policy.md Licenses, reference projects, reuse policy complete
pocs.md POC plan (what to validate before architecture commits) planned
poc-1-findings.md POC-1: pkt-line over alkcall BiStream (duplex producer) complete — proceed
poc2-findings.md POC-2: server-side pack generation (streaming pipeline) complete — proceed
poc3-findings.md POC-3: smart-http shape through alkhttp (stateless substrate) complete — proceed
push-captures.md Normative receive-pack (push) wire record (real git captures) complete — ADR-013 basis
negotiation-captures.md Normative V2 negotiation record (real git captures + source) complete — ADR-014 basis

Key findings so far

  • gitoxide covers storage + pkt-line; the server half of the smart protocol is ours to write (gix-protocol/transport are client-side).
  • Published gix 0.87.1 == local clone base; pin crates.io versions.
  • alkcall BiStream is the natural substrate under pkt-line for both ssh and http paths.
  • The incompatible-license prior art confirms feasibility but contributes nothing; policy in reference-policy.md.
  • gix with default-features = false requires an explicit hash feature; workspace pins sha1 with a sha256 passthrough feature everywhere.

Convergence criteria (phase 0 → phase 1)

Phase 0 is done when POC-1..3 have results and a recommended-approach summary is written here (append below). Then the Architect produces docs/architecture/ per sdd_process.

Convergence (2026-09-21): phase 0 gates all pass (POC-1/2/3 proceed). Phase 1 opened with docs/architecture/; the structural decision is ADR-010 — pure protocol crate following the alktty/alktunnels template (the v1 "monorepo + alkgitd binary" framing in these research docs was an init-agent artifact, amended in vision.md v2). POC-1 maps to the producer half, POC-2 to the gix backend implementation, POC-3 to the stateless substrate consumed by alkhttp's future git feature.