Full-corpus gate review between the completed OQ cycle (ADR-013/014)
and phase-2 decomposition. Verified external API claims against real
sources (alkcall AccessControl/OwnershipStore semantics, alktty
template, gitoxide pins), probed the feature matrix (all four configs
compile) and the trait dyn-compatibility claim (E0038 repro on 1.88
and 1.94).
Findings:
- A-1 (critical): ADR-012 §3's scope-OR-ownership op gate is not
expressible in alkcall's AccessControl (restrictions compose as
AND) — handler-side two-tier check recommended
- A-2 (critical): bare async fn traits are not dyn-compatible
(E0038) — ADR-012 §1 signatures need #[async_trait] + dep
- A-3 (critical): native path has no pinned session preamble —
open-op params carry no service, so the open-time ACL point cannot
run the write-tier check and push is unservable over alk/git
- A-4..A-6 (major): done-round boundary set should be the
common_haves-filtered subset; consumer half (GitSession) named in
five docs, specified in none; backend trait execution model
unspecified
- D-1..D-3 (minor): stale superseded text (vision/alk-stack
Internal-ops framing, AGENTS.md OQ list, ADR-007 step-3 mechanism)
- N-1..N-5: ref-cap breach rule, error-indistinguishability at the
wire mapping, freeze-inventory schemas, push-options seam,
ls-refs=unborn never capture-verified
Non-findings record what verified sound (feature story, gitoxide API
pins, deferral hygiene, cross-reference integrity). Remediation table
proposes six fix-round batches; A-5 needs a user scope decision.
Verification: cargo test/clippy/fmt/doc clean; check under
default/no-default/sha256/all-features and MSRV 1.88 all clean;
publish dry-run completes; git 2.43.0 present for integration tests.