Files
alkgit/docs/architecture/decisions/008-registry-resolved-repo-identity.md
T
glm-5.3-flash 86bf5a0cf0 refactor(architecture): ADR-010 — pure protocol crate (alktty template)
Structural decision (OQ-09 resolved): alkgit follows the alktty/
alktunnels template — a single published protocol crate on alkcall
channels, no binary, no front doors.

- ADR-010 supersedes ADR-001 (crate decomposition) and ADR-006
  (http router factory); both marked Superseded
- Single crate at repo root: Cargo.toml with gix feature (default-on
  backend implementations; wire layer compiles without it —
  gix-hash always-on with sha1 per the compile-time-rejected
  invariant), crates/ workspace deleted, src/lib.rs stub in place
- doors.md replaces http.md/ssh.md/alkgitd.md: alkhttp git-feature
  sequencing (after first publish), alkssh requirement (fixed-grammar
  exec dispatch), native alk/git path, downstream assembly
- backend.md replaces storage.md: GitRegistry/GitRefs/GitPackGen/
  GitPackIngest traits (ingest validates, refs commits — single CAS
  home), gix feature encodes POC-2 prerequisites
- transport.md reframed for the single crate; backend traits replace
  hook traits in the public API
- OQ-09 resolved (all five sub-decisions in ADR-010), OQ-01 resolved
  (subsumed), OQ-03 narrowed to publish-freeze, OQ-08 narrowed to
  registry identity + vault placement, OQ-07 rescoped to the gix
  feature's registry impl
- vision.md v2: single-binary/monorepo framing corrected as
  init-agent artifact; POC checklist marked complete
- AGENTS.md + .opencode agent specs updated to the new shape

Verification: cargo build (default + no-default-features), cargo test
--all-features, clippy --all-features -D warnings, fmt --check all
pass. Third review round: zero critical, all warnings/suggestions
addressed (GitPackGen signature amended in ADR-004, stale anchors
fixed, ADR-006 body tense normalized, CAS split stated, vision
residuals cleaned).
2026-09-21 10:54:03 +00:00

2.0 KiB

ADR-008: Wire repo names are registry IDs, never paths

Status

Accepted

Context

Repo names arrive on the wire in three shapes: the git:// first-request line (git-upload-pack '<repo>'\0host=…), the ssh exec command string (git-upload-pack '<repo>'), and the http path segment (/<repo>/info/refs). All three are attacker-controlled. Treating them as filesystem paths (even with ad-hoc sanitization) is the classic git-server traversal bug — and docs/research/git-protocol.md §"Security-relevant protocol notes" flags exactly this.

Decision

Wire-supplied repo names are IDs: opaque registry keys resolved server-side to configured storage roots.

  • The registry is alkgit's authoritative (repo id → storage root + visibility + ACL scope) mapping, owned by the GitRegistry backend trait.
  • Resolution failure and authorization failure are indistinguishable to the caller (ADR-007 step 2's no-existence-oracle rule).
  • Wire names are never joined, normalized, or canonicalized into paths. Path construction happens only from registry-resolved roots.
  • The same never-execute rule covers the ssh exec command string: it is parsed (fixed grammar: service name + quoted repo argument), never interpreted by a shell and never passed to a subprocess (convention 6's no-shelling-out invariant). Unknown commands get a fixed refusal.
  • The registry's own backing store is a separate decision (OQ-06).

Consequences

  • Path traversal is structurally impossible on the serving path.
  • Repo renames/migrations are registry edits, not filesystem moves (the storage root indirection absorbs them).
  • The registry must be available (or cached) at session start; its unavailability is a config/ops error surfaced as session failure, never a path-guessing fallback.

References

  • docs/research/git-protocol.md §"Security-relevant protocol notes"
  • docs/research/vision.md §"Immediate threat-model notes"
  • ADR-007 (the resolve-then-authorize order)
  • backend.md §"The trait family" (GitRegistry), OQ-06 (registry backing)