Skip to main content

Open Decisions

Updated: 2026-10-05 (Asia/Shanghai). The first-release product decisions below were confirmed by the user on 2026-09-13 and are now delivered as Suite v4 (BYOS): the successor suite is deployed on Injective testnet, CLI/Web dispatch by version, and real R2 end-to-end flows pass. What remains open is listed below (real AWS canary, successor publication evidence, mainnet governance). See ADR 0004 and the BYOS specification.

Already Decided — Do Not Reopen For The First Release​

  • Object storage is a first mainnet requirement: directly target a storage-neutral successor, not an IPFS-only v3 mainnet intermediate release.
  • Only user-owned Amazon S3 and Cloudflare R2 buckets. No MinIO, self-hosted object stores, other clouds or arbitrary S3-compatible write endpoint.
  • Public repositories first; private repositories, E2EE and key distribution are later work. Private bucket access alone is not a privacy guarantee.
  • Users pay their cloud costs. One verified object location suffices; dual replicas and managed public storage are not mandatory release conditions.
  • Authenticated readers use independent user-owned configuration; no managed GET broker or writer-secret sharing. Anonymous Web access requires public read configuration/CORS and cannot be inferred from authenticated CLI tests.
  • Canonical JSON, using RFC 8785 JCS as the implementation baseline, not CBOR.

Engineering Decisions Frozen Through S01–S05 (Delivered As Suite v4)​

These decisions were frozen during S01–S05 and are now implemented and tested in the delivered v4 suite; do not reopen them without a new successor version. The specification's recommended defaults were applied, local fixtures were implemented, and justified deviations were recorded before freezing the wire protocol.

  • Manifest schema 1/canonical bytes/context binding and local limits are now tested and frozen in BYOS section 9: SHA-1, pack v2, full non-thin history. Other Git formats and incremental dependency optimization remain separate work. Incremental dependency packs were approved by the user on 2026-10-05 and scheduled as S08: manifest schemaVersion 2 on the existing Suite v4, no contract change; schema 1 manifests stay valid.
  • Successor version, bounded bootstrap locator/state layout, same-commit manifest changes, CAS revision/tombstones, ref deletion/recreation, fork and import semantics, event ABI and backwards-compatible client dispatch.
  • Provider/credential reference UX and safe endpoint validation; exact cloud region/account constraints and public read domain rules. No generic endpoint escape hatch to make local mocks easier.
  • Local provider limits are frozen: 16 MiB single PUT for AWS/R2, AWS-only 8 MiB multipart parts up to 512 MiB, full readback and directed recovery. Real R2 conditional completion and full-chain Git evidence are now PASS; the real AWS S3 canary and its cost/interruption evidence remain NOT PROVEN. Missing real evidence results in explicit feature/size limits, not an assumed compatibility claim.
  • Resource policy documentation: least-privilege writer/reader identities, stable public GET/CORS, secret redaction, safe lifecycle warnings and optional retention/versioning. Do not make a feature unavailable on one provider an unreviewed common requirement.
  • Versioned successor indexer/evidence gate support. Existing scripts marked FAIL and v3-only release gates cannot silently authorize successor use.

Decisions Requiring User Resources Or Separate Scope​

  • Which disposable AWS/R2 test buckets/prefixes, public domains/origins, permissions, cost limits and upload ranges may be used for real canaries? Credentials must be configured by the user through a secure local channel, never pasted into chat or recovered from existing secret files.
  • Whether any existing v3 testnet history should be imported into a new successor. Default recommendation: validate a fresh successor first. This is separate from the already-decided mainnet successor target; V1 remains read-only archive preview and is not automatically imported.
  • Scope of any real testnet deployments/transactions, signing environment and funds. Funds have not been checked; do not assert insufficiency. This documentation/prompt grants no such authorization.
  • Any future object deletion, incomplete-upload abort, lifecycle cleanup or historical unpin needs an explicit inventory/scope, recovery policy and authorization, not an implicit step after a successful ref update.

Production Governance And Evidence Gates​

  • Define multisig membership, quorum, emergency powers and timelock policy.
  • Approve INJ platform fee and treasury policy from reviewed constructor evidence.
  • Approve username original-owner claim duration and public communication only with the required escrow/non-liability evidence for the selected scope.
  • Select finality depth, RPC/reorg thresholds and recovery procedures.
  • Establish key rotation, offline backup and deployment/operator separation.
  • Define evidence retention and independent reviewers authorized to sign the exact commit/hash-bound release approval.
  • Complete successor security review and both providers' native Git/Web acceptance before publishing a mainnet or successor public profile.

Later Product Work — Not First-Release BYOS Blockers​

  • Optional dual replicas, managed public profiles, provider failover and who pays for any platform-operated copy/bandwidth.
  • Private repositories, E2EE, per-reader key distribution/revocation, metadata leakage and private Web access. The choice of independent readers does not itself solve those problems.
  • Additional cloud providers or self-hosted services, each with independent capability/security acceptance.
  • Incremental pack dependencies moved to scheduled work on 2026-10-05 (S08, user decision: manifest schemaVersion 2 on the existing Suite v4, no contract change). Still later work: chain compaction/merging, safe inventory-based orphan cleanup, retention/disaster-recovery service commitments.
  • Whether ZKP remains an isolated testnet experiment or becomes a separately reviewed successor requirement, with root governance, setup, verifier/circuit audits, privacy and replay/front-running controls.

No fixture, previous deployment or document checkbox can decide these matters or prove their implementation. See the roadmap and S01–S07 backlog for actual exit conditions.