opencode auto-loads AGENTS.md as instructions, overriding the built-in
default of 'only commit when explicitly asked.' This repo's stance is
the opposite — commit and push when reasonable — which already matches
the custom agents in .opencode/agents/ (coordinator.md §5 'Push Main
After Every Merge', implementation-specialist.md §5 'Push immediately').
The file also surfaces the project conventions (no comments, OsRng for
nonces, zeroize-on-drop, thiserror/anyhow, no async, frozen wire format)
so they apply to all sessions, not just spawned implementation agents.
No code change. Restart opencode to load the new instructions.
The 'TODO(Phase B): Use salt in HKDF-based key derivation' at
src/encryption.rs:169 described a design direction that ADR-021
(Accepted) explicitly decided against — key rotation uses
version-indexed HD paths (m/74'/2'/0'/{version-2}'), not a KDF over
the salt. ADR-020 §6 W6 confirms v2 data's salt is permanently unused.
The salt field stays populated because ADR-018 locks the wire format.
No behavior or wire-format change. The implementation was already
correct per the ADRs; only the comments and TODO had drifted toward a
rejected design.
Changes (src/encryption.rs, comments/docs only):
- Module 'Salt Field' section: rewritten to match encryption.md and
ADR-020/021/018
- EncryptedData.salt field doc: removed Phase B framing, added ADR
references and pointer to encryption.md
- encrypt() doc: removed false claim 'salt allows key rotation'; now
states IV/salt roles and ADR pointers
- TODO(Phase B) line: removed, replaced with a one-line rationale
comment matching the neighboring IV comment's style
- Drive-by: fixed stale 'OQ-SVC-03' reference -> 'OQ-20' (the actual
OQ file; OQ-SVC-03 appears nowhere else in the repo)
Verification (matches 0.1.0 publish baseline):
- cargo test --all-features: 108 passed
- cargo test (default): 101 passed
- cargo clippy --all-features --all-targets: clean
- cargo doc --no-deps --all-features: clean
- cargo publish --dry-run --all-features --allow-dirty: 44 files packaged
Add dual MIT/Apache-2.0 license files and a crates.io README.
Bump dependencies to current: rand 0.8->0.10, aes-gcm 0.10->0.11,
base64 0.22->0.23. Add keywords, categories, readme, rust-version
fields to Cargo.toml. Migrate encryption.rs and test_vectors.rs to
the new rand/aes-gcm/base64 APIs.
Rename the crate from alknet-vault to alkvault across source and docs:
- Cargo.toml: package name and lib name (alknet_vault -> alkvault)
- src/ doc comments and doc-test use statements
- tests/ use statements and one string literal
Convert references to non-vault alknet ADRs (003, 005, 008, 010, 014,
064) that were broken local links into @alkdev/alknet: cross-repo
references, matching the alktype sibling pattern. Local ADR/OQ
references are now proper links. Rewrote monorepo path references
(crates/alknet-vault/src/...) to the flat layout (src/...). Fixed
sdd_process.md package name (@alkdev/storage -> @alkdev/alkvault).
ADR/OQ renumbering is deferred to a subsequent pass per the alknet-
origin numbering convention. Generic prose 'vault' and type names
(VaultServiceHandle, VaultServiceError, etc.) are unchanged.
Build, 108 tests, and clippy all pass clean.
Copy the local key vault (src/, tests/) verbatim from
alknet/crates/alknet-vault and create a standalone Cargo.toml
(workspace-inherited fields inlined). Port the architecture docs
(specs, ADRs 018-026, OQs 020-022) from alknet's nested multi-crate
layout to a flat single-crate layout, fixing relative link paths.
ADR and OQ numbers are preserved from alknet; a subsequent pass will
renumber them to a per-project sequence (001, 002, ...) and rebrand
alknet-vault -> alkvault (crate name, lib name, prose), updating the
cross-references to non-vault alknet ADRs (003, 005, 008, 010, 014,
064) that are referenced in the copied docs but not copied over.
Build, 108 tests, and clippy all pass clean.