phase 1: architecture spec — overview, server/client, ADR-001..006
- ADR-001: inherit the alknet TLS design as the baseline; deviations
recorded as alktls ADRs
- ADR-002: TlsError ships the ADR-088 six-variant shape from day one
(typed #[from] sources; NoqWrap; no string catch-all)
- ADR-003: the QUIC feature is noq (iroh's extracted fork), pre-
consumer rename; default = [] per the lean-crate convention
(corrects the extracted code's default = ["quinn"])
- ADR-004: complete accessors — for_tcp_tls() adopted, rustls_config()
adopted; server accessors borrow (&self), client accessors consume
- ADR-005: identity + credentials + fingerprint types move into
alktls; auth layer stays out
- ADR-006: eight-module layout; seed tests + integration invariant
pins (exact nine-scheme list, client enable_early_data)
- specs: overview (transport picture, terminology), server.md (ACME
lifecycle, invariants), client.md (verifier selection matrix, root-
store fallback); open-questions.md promotes OQ-TLS-01..08 (all
resolved at entry)
- Cargo.toml: quinn feature -> noq (per ADR-003); AGENTS.md aligned
Architecture review pass done: 0 critical, 2 major (ADR-002 AcmeConfig
doc comment contradiction; ADR-003 unrecorded default deviation) and
8 minors all addressed; cross-references verified against alknet ADRs,
rustls/noq/iroh sources.
Verified: cargo test, test --all-features, clippy -D warnings,
fmt --check, doc --no-deps