authn: remove the local agent-token plane The agent_token table and everything that minted, verified, listed or revoked it. Agent credentials are tokens.sr.ht working tokens now: signed, expiring, owned by a meta.sr.ht account and carrying grants, verified locally by sr-ht-ecore's bearer package. One door, and nothing behind it — a credential the instance plane refuses is refused, where it used to be offered to a second store that might say yes. DEPLOY GATE: do not deploy this until every agent configured with the shared secret holds a tokens.sr.ht token with spec:propose (spec:read to read). Migration 0005 drops the table, migrate-on-upgrade runs it on deploy, and deploying early locks out every agent at once — including the SSH push path. hooks/ no longer reads agent_token directly. The push path goes through the same authn.Resolver the HTTP surfaces use and demands spec:propose, because a push by an agent is a proposal by another transport. The refs rule and the provenance requirement are untouched on both counts: a universal grant is still only an agent to the receive path, and X-Agent / X-Agent-Session are still mandatory on every agent write. bearer.ErrNotOurs is now a permanent refusal. A meta.sr.ht PAT used to fall through to the local store and miss there; with no store to fall through to it earns a 401 rather than the 503 an unclassified error would. [tokens.sr.ht] origin becomes a required config key: with no issuer there is no credential to check, so the daemon fails startup instead of serving reads and refusing every agent write one request at a time. /tokens redirects to the daemon that issues (tokens SPEC ch. 7).
feat: service — wiring, space lifecycle, read paths, push validation, reconciler Phase 1 of the implementation plan: the orchestration layer's read, validate and repair halves. The write plane (propose/merge) is Phase 3 and is absent. - Config/New assemble a Service from the shared config.ini, reporting every missing key in one message; TokenStore adapts db/ to authn.TokenStore, mapping db.ErrNotFound onto authn.ErrUnknownToken so an unknown credential is a 401 rather than a 503. - CreateSpace writes the repository first and the row second, removing the repository again if the insert fails; a crash between the two leaves content that is merely unlisted rather than a phantom space. - ReadDocument/ListDocuments/Policy/ResolveRev resolve the approved head or a pinned revision through one code path. - ValidatePush checks the refs rule first and unconditionally, then frontmatter and document-id uniqueness, which --push-option=skip-validation waives. The rejection is a structured, terminal-shaped message naming the document. - PlanRepairs is the repair table as a pure, table-tested function; Reconcile gathers the facts and applies them, listing stale-index spaces for Phase 2. Two departures from the design's repair table, both to stop the reconciler destroying live state, documented at their definitions: an open row with no branch is left alone inside a grace window (every propose passes through that state), and a branch still sitting on its recorded base is never treated as merged (its tip is trivially an ancestor of the approved head).