--- id: ws-overlay-ops name: Browser-registered ops — connection-local overlay tests status: pending depends_on: [ws-upgrade-session] scope: narrow risk: medium impact: component level: implementation tags: [websocket, phase-2] --- ## Description Port the connection-local Layer 2 overlay verification from `/workspace/@alkdev/alknet/crates/alknet-http/src/websocket/overlay.rs` to the channels-over-WS session: a WS client registers ops (via call-protocol registration on channel 0), the hub reaches them through the live connection handle's `overlay_env()` — not PeerRef. Tests: hub→browser call over the same session; overlay ops die on disconnect; AccessControl gating on browser ops; bidirectional concurrent calls (both sides initiating on channel 0). ## Acceptance Criteria - [ ] Hub→browser call test passes (browser registered an op, hub invokes it) - [ ] Disconnect drops overlay; subsequent reach attempts fail cleanly - [ ] Concurrent bidirectional calls don't deadlock or cross-correlate - [ ] `cargo test` passes ## References - docs/architecture/websocket.md (§Connection-local overlay, §Bidirectionality) - docs/architecture/decisions/034-outgoing-only-x509-and-three-peer-roles.md (§4) - alkcall ADR-019 (registry layering) - Old source: `/workspace/@alkdev/alknet/crates/alknet-http/src/websocket/overlay.rs` ## Notes > Agent fills during implementation. ## Summary > Agent fills on completion.