Problem
gf clone can read from a Hub, but nothing can write to one. Today only an operator with a control-plane token can publish a Project. Forks, Branches and owner-published Projects therefore can't appear on graphforge.sh, and the Hub's lineage connections stay empty.
Objective
Define and implement a Rust-owned, provider-neutral publish contract and gf publish command that uploads an exact Project Version or Branch head (including a Fork) to a conforming Hub.
Requirements
- The client derives the package and descriptors with the existing exporter and verifier. The Hub never re-derives semantics.
- Hand off authentication through a short-lived, scoped publish credential obtained by a browser/device flow. No long-lived secrets in project files, config participants or logs.
- Upload large objects directly to the data-plane location the Hub provides (resumable, digest- and length-verified, bounded), never through the control plane.
- Make publication idempotent: the operation identity and exact request commitment are retried safely; changed content under the same identity fails (
GF_IDEMPOTENCY_CONFLICT).
- Advance a ref only on an expected-revision precondition (no blind last-writer-wins). Treat Fork publication as a new repository identity that carries its origin citation.
- Specify stable errors for auth, quota/entitlement denial, conflict, unsupported version and integrity failure.
- Add conformance fixtures and a reference in-memory Hub for tests. Python, Node and the CLI expose the same Rust behavior.
Acceptance
- Publishing the same Version twice yields one Hub version and the original receipt.
- An interrupted upload resumes, and a corrupt object is refused before the ref moves.
- A published Fork clones back with its origin citation intact.
Non-goals
- Proposal submission into another owner's Project (needs Hub moderation design first).
- Private repositories, billing enforcement and Hub UI.
Related
#906, #1357, #1748; CurateLabs/graphforge-nextjs M3.
Problem
gf clonecan read from a Hub, but nothing can write to one. Today only an operator with a control-plane token can publish a Project. Forks, Branches and owner-published Projects therefore can't appear on graphforge.sh, and the Hub's lineage connections stay empty.Objective
Define and implement a Rust-owned, provider-neutral publish contract and
gf publishcommand that uploads an exact Project Version or Branch head (including a Fork) to a conforming Hub.Requirements
GF_IDEMPOTENCY_CONFLICT).Acceptance
Non-goals
Related
#906, #1357, #1748; CurateLabs/graphforge-nextjs M3.