Resolves review 001 finding A-1 (critical): ADR-012 §3's "scope
git:admin OR ownership" gate is not expressible in alkcall's
AccessControl (AND-composition). Resolution is the review's option (a)
shape with the OR-term generalized: the per-repo grant action set gains
manage, authorize(record, identity, read|write|manage) becomes the
single policy function for git access and repo administration, and the
delete/update/get gate is admin scope OR manage grant (handler-side,
generic FORBIDDEN, unknown-repo = unauthorized per ADR-008). Repo
create seeds the creator's {read, write, manage} grants —
administration is grantable, so collaborators/bots/app-compiled roles
work without global scopes. Ownership stays as alkcall spawn-tracking
(mint at create unchanged); "ownership never implies git access" is
superseded.
- ADR-015 (new): manage grant tier, op gate, flat-grants-as-replication-
substrate, opaque grant-key rule
- ADR-011: action set + policy domain amended, references updated
- ADR-012 §3: gate table replaced, two-tier paragraph superseded
- backend.md/doors.md/overview.md: gate + grant restatements, ADR tables
- OQ-16 (new, deferred(scope)): grant-key identity namespace —
globally-comparable ids for cross-assembly/replicator grant state;
tracker task tasks/architecture/oq-16-grant-identity-namespace.md
- review 001: A-1 marked resolved (ADR-015)
- vision.md: supersession notes (Internal-ops framing, v1 grant set)
Verification: cargo test, clippy -D warnings, fmt --check, doc --no-deps
all clean.
alkgit Research Index
Phase 0 (exploration) research. Feeds phase 1 (architecture).
| Doc | Topic | Status |
|---|---|---|
| vision.md | Vision, guiding principles, non-goals, phase-0 checklist | draft v2 (amended 2026-09-21) |
| gitoxide.md | gitoxide (gix) capability + version alignment | initial pass complete |
| alk-stack.md | alk stack fit, integration surface, gitea-lesson constraints | initial pass complete |
| git-protocol.md | Server-side git smart protocol inventory (what we own) | initial pass complete |
| reference-policy.md | Licenses, reference projects, reuse policy | complete |
| pocs.md | POC plan (what to validate before architecture commits) | planned |
| poc-1-findings.md | POC-1: pkt-line over alkcall BiStream (duplex producer) | complete — proceed |
| poc2-findings.md | POC-2: server-side pack generation (streaming pipeline) | complete — proceed |
| poc3-findings.md | POC-3: smart-http shape through alkhttp (stateless substrate) | complete — proceed |
| push-captures.md | Normative receive-pack (push) wire record (real git captures) | complete — ADR-013 basis |
| negotiation-captures.md | Normative V2 negotiation record (real git captures + source) | complete — ADR-014 basis |
Key findings so far
- gitoxide covers storage + pkt-line; the server half of the smart protocol is ours to write (gix-protocol/transport are client-side).
- Published gix 0.87.1 == local clone base; pin crates.io versions.
- alkcall
BiStreamis the natural substrate under pkt-line for both ssh and http paths. - The incompatible-license prior art confirms feasibility but contributes nothing; policy in reference-policy.md.
gixwithdefault-features = falserequires an explicit hash feature; workspace pinssha1with asha256passthrough feature everywhere.
Convergence criteria (phase 0 → phase 1)
Phase 0 is done when POC-1..3 have results and a recommended-approach
summary is written here (append below). Then the Architect produces
docs/architecture/ per sdd_process.
Convergence (2026-09-21): phase 0 gates all pass (POC-1/2/3 proceed).
Phase 1 opened with docs/architecture/; the structural decision is
ADR-010 — pure protocol crate following the alktty/alktunnels template
(the v1 "monorepo + alkgitd binary" framing in these research docs was an
init-agent artifact, amended in vision.md v2). POC-1 maps to the producer
half, POC-2 to the gix backend implementation, POC-3 to the stateless
substrate consumed by alkhttp's future git feature.