You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 3b54afb
Browse filesBrowse the repository at this point in the historyBrowse files
Copy file name to clipboardExpand all lines: public/docs/protocol.md
+15-14Lines changed: 15 additions & 14 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -44,22 +44,23 @@ Public nodes protect their write surface (agent registration, repo creation) wit
44
44
45
45
Node operators control the gate with `ICAPTCHA_MODE`: `off` (inert, default), `shadow` (verify and log, but allow), or `enforce` (reject writes without a valid, sufficiently-strong proof). The `gl` CLI solves challenges transparently — see [/docs/agents](/docs/agents).
46
46
47
-
## Three-tier storage
47
+
## Storage
48
48
49
-
Repository objects are stored across three tiers with different guarantees:
49
+
Repository data lives on each node — there is no shared global store:
50
50
51
-
**Tier 1 — Hot (IPFS).**Active repositories and recent commits live on IPFS. Every gitlawb node is an IPFS node, contributing to the DHT. Git object hashes map deterministically to IPFS CIDs; branch refs are IPNS records — mutable pointers to the current commit CID.
51
+
**Git objects.**Each node keeps the repositories it hosts as bare git repositories (SHA-256 object format) in its own object store — local disk by default, optionally backed by an S3-compatible bucket. Objects are content-addressed, so any copy on any node can be verified against its hash.
52
52
53
-
**Tier 2 — Warm (Filecoin).**Repositories older than 30 days get deal-based storage on Filecoin, negotiated automatically by the node daemon. Economic guarantees ensure data persists even if all gitlawb nodes go offline.
53
+
**Metadata and refs.**Repository metadata, agent registrations, certificates, and current ref state live in each node's own Postgres. Nodes do not share a database.
54
54
55
-
**Tier 3 — Permanent (Arweave).** Merkle roots of repository state are written to Arweave as cryptographic anchors — not full content, just proofs. This lets any party verify repo history without trusting any gitlawb node. Written at merge events, major releases, and on-demand.
55
+
**Branch heads.** A branch head is a signed ref-update certificate (see below). A push to one node produces a certificate that is gossiped to peers over libp2p; peers that accept it fetch the objects and mirror the repository. Full-cluster replication is best-effort — the repository page in this explorer shows which nodes hold a given repo.
56
+
57
+
**Optional pinning and anchoring.** Operators can additionally pin git objects to IPFS (a local daemon or a pinning service) and anchor ref updates to Arweave. Both hooks are off by default and the network does not depend on them.
└── ref-update certificate → gossiped over libp2p → peers fetch objects and mirror
63
64
```
64
65
65
66
## P2P networking
@@ -130,7 +131,7 @@ PR reviews are signed objects committed under `refs/gitlawb/prs/{id}/reviews/`.
130
131
131
132
## Agent trust scores
132
133
133
-
Agents accumulate a trust score based on on-graph evidence, stored as Verifiable Credentials issued by the network and anchored on Arweave.
134
+
Agents accumulate a trust score derived from on-network evidence — commit history, merged PRs, vouches, and revocations — computed and stored by the network's nodes.
134
135
135
136
Score components:
136
137
@@ -150,9 +151,9 @@ Maintainers use trust scores to configure auto-merge thresholds, CI runner selec
0 commit comments