- BREAKING (ecosystem-coordination): alkcall bumped to 0.8.0. No type
alktty touches changed shape (ChannelCore/openable machinery,
OpenEstablisher/OpenHandler/Establishment/ChannelPlan,
ChannelClient::open_channel, ChannelOpenError::CallFailed are
identical to 0.7.1); the new reply-projection / relay / hub-leg
surfaces are additive and alktty exercises none of them. alktty's own
open op is the standard-shape name channels/tty/sub, so the new
flavor-form discovery path stays on the byte-stable standard
derivation, and with no establisher reply-fields configured the open
reply is byte-identical to pre-0.8.0. The minor bump is for
downstream lockstep, since alktty's public signatures reference
alkcall types.
- Verification counts unchanged from the 0.7.1 baseline (113 default /
156 all-features); the adoption required no source change in alktty.
Verification:
- cargo test: 113 passed (default), 156 passed (--all-features)
- cargo clippy --all-targets -- -D warnings: clean
- cargo fmt --check: clean
- cargo doc --no-deps: clean
- cargo check/clippy --target wasm32-unknown-unknown -D warnings: clean
- cargo publish --dry-run --allow-dirty: clean
- BREAKING (ecosystem-coordination): alkcall bumped to 0.7.0. No type
alktty touches changed shape (OpenEstablisher/OpenHandler/
Establishment/ChannelPlan identical to 0.6.0); the minor bump is for
downstream lockstep, since alktty's public signatures reference
alkcall types.
- CF-006 alignment: the channels establisher and pump handler now take
their identity from the per-call auth (alkcall 0.7 derives the
dispatch-resolved opener — the same identity view the registry's ACL
gate checked) instead of the captured install-time override.
Behavior-identical in the per-connection-registry deployment; the
ownership check and the ACL gate see the same subject in every
deployment. make_tty_establisher / make_tty_open_handler drop their
captured-identity parameter (both private).
Verification:
- cargo test: 113 passed (default), 156 passed (--all-features)
- cargo clippy --all-targets -- -D warnings: clean
- cargo fmt --check: clean
- cargo doc --no-deps: clean
- cargo check/clippy --target wasm32-unknown-unknown -D warnings: clean
- cargo publish --dry-run --allow-dirty: clean
- Bump alkcall 0.5.0 -> 0.6.0 (Establishment plan payload, ADR-049
amendment 2); alktty 0.2.0 -> 0.3.0 (breaking channels-path
allocation-failure shape)
- make_tty_establisher runs backend.allocate; failure maps to
EstablishmentError::DialFailed (channel:open_failed reason
dial_failed); the TtyHandle crosses to the pump handler via a
private per-open AllocatedHandle one-shot slot (the handle is not
Sync — it cannot be the ChannelPlan directly)
- make_tty_open_handler gains the Option<ChannelPlan> parameter; a
plan drives the new drive_session_pre_allocated (pumps only), a
None plan falls back to drive_session_pre_negotiated (inline
validate-and-allocate — defense-in-depth for no-establisher
registrations)
- tty_open_spec's channel:open_failed ErrorDefinition declares
dial_failed (four reachable reasons)
- Pinned in-band allocate test flipped:
allocate_failure_fails_open_as_dial_failed (end-to-end, no channel
survives); establisher unit gate for the plan slot + failure
mapping
- ADR-010 amended (§2A; §2 kept as historical record), tty-adapter.md,
session/channels/adapter docs, CHANGELOG, AGENTS.md alkcall pin
updated
Verification: cargo test (113) + --all-features (137), clippy
-D warnings (native + wasm32, default + all-features), fmt, doc,
wasm32 check — all clean
Adopt alkcall 0.5.0's channel-open establishment phase (ADR-049 —
review 006 E-01 + N-1) and migrate the channels-path semantic failures
per its §5 sequencing (alktty ADR-010).
- `register_openable` registers `channels/tty/sub` with an establisher
(`register_openable_with_establisher`): full `NegotiateRequest`
parse of schema-valid `input`, `carriage == "raw"`, non-empty `cmd`,
backend lookup, and the ADR-050 ownership check run before the open
reply; rejections are `channel:open_failed` with `details.reason`
(`unknown_resource` / `handler_error` / `timeout`) — no phantom
channel (the SSH contract holds consumer-visibly)
- `backend.allocate` deliberately stays in the pump handler:
`Establishment` is payloadless so the `TtyHandle` cannot cross the
establisher→handler boundary, and re-allocating would violate
ADR-005's kill-on-Drop contract — `allocate_failed` remains the one
in-band failure class on the channels path (pinned by test)
- `TtySessionError::ChannelsOpen` carries alkcall's typed
`ChannelOpenError` (`#[from]`) instead of a flattened `String` —
the N-1 fix at alktty's layer (breaking)
- channels-path semantic failures change shape from
`NegotiationRejected` in-band frames to `channel:open_failed` call
errors (breaking); the direct-ALPN path is unchanged
- `tty_open_spec()` gains a `description` (review 006 E-02) and an
ErrorDefinition for `channel:open_failed` (ADR-016 — disclosed via
services/schema)
- alkcall = "0.5.0"; version 0.2.0; ADR-010 + ADR-009 amendment +
tty-adapter.md + CHANGELOG
Verification: cargo test (112 lib + integration), cargo test
--all-features (136), clippy --all-targets -D warnings (host + wasm),
fmt --check, cargo doc --no-deps clean; wasm32-unknown-unknown check
confirms the default crate stays wasm-clean.
Closes review #003 (prepublish review for v0.1.0).
- P8: StdinSink::poll_shutdown parks an inflight reserve+send on a
full channel (waker registered) — a stdin blast followed by EOF
delivers the EOF instead of stranding it
- P9: five poisoned-lock .expect() sites -> unwrap_or_else(into_inner)
- P10: three thread-spawn .expect() sites -> TtyError::AllocFailed
- P5: tty:open scope gate runs before carriage/cmd/backend-lookup
checks (no backend-name enumeration differential for unscoped ids)
- P11: recv_stdout terminates on the zero-length drained sentinel;
the sentinel is no longer yielded as an item (doc was already the
contract); stderr has no sentinel (doc noted)
- P2: exclude AGENTS.md + docs/plans/, drop dead Cargo.lock and
docs/research/ entries (package list: 42 files, 659.2KiB)
- P3: AGENTS.md phase status (all five landed), ADR range 001..009
(+ alktty-native ADR-009 in the mapping), alkcall guidance
corrected to v0.4.x / pin "0.4.0"; architecture README ADR-009 row
+ landed-phase status
- P15: backend.rs doc typo; redundant tokio-stream dev-dep removed;
NegotiationError::Io arm logs; set_identity failure logs;
input_pump.abort() at session end; TtySessionError::Open carries
the accept_bi StreamError (no io::Error flattening); borrowing
deserialize in open_via_channels (no params.clone());
error_response_bytes guards an "error" key in fields; trivial
inline comments promoted/removed; plan-doc test counts + doc
front-matter refreshed; session tests that raced session teardown
under the abort change use a GatedBackend (exit held until
released)
Verification: cargo test 104 lib / --all-features 147; clippy
(all-targets + wasm32) -D warnings; fmt; wasm check; doc 0 warnings;
publish dry-run OK.
Review #003 Session 2 (P12 + P6 + P7 + P4 + P16):
- P12: primary types re-exported at the crate root (TtyAdapter,
TtySession, TtyBackend/TtyHandle/TtyParams, Chunk codec, wire
constants, ControlMessage, negotiation types, channels helpers;
LocalTtyBackend under `local`). signal_from_name re-export is
#[cfg(unix)]-gated to match its definition (wasm check caught it).
- P6: ChunkWriter validates before writing — stream_type > 4 or
payload > MAX_CHUNK_LEN fails locally (RawError) instead of
corrupting the peer's framing; length validated as u64 before the
u32 cast so oversized payloads cannot wrap past the check.
Empty-payload shape unified via a single write_validated helper.
- P7: ChunkReader tracks peeked state — read_chunk() after
peek_stream_type() completes the peeked chunk instead of consuming
a second header byte; second peek is idempotent;
read_chunk_after_peek debug-asserts a peek. Session read pump drops
its manual first_byte_peeked threading.
- P4: README.md (alkcall structure; quick-start examples per role
using the new root paths) + readme = "README.md" in [package].
- P16: CHANGELOG.md with the full [0.1.0] entry and tag link.
Verification: cargo test 104 lib (default) / 147 (--all-features);
clippy all-targets + wasm32 -D warnings; fmt; wasm check; doc 0
warnings; publish dry-run 44 files OK.