docs(architecture): ADR-009 — pg-lo admitted as the fs tier's second engine on POC #7
- ADR-009 (new): postgres Large Objects ship as the fs tier's second
engine (feature pg-lo, default-off), admitted on POC #7's passed
gate (contract 10/10, durable put ~= fs at >=1 MiB, lo_get window
gets, transactional LO lifecycle = zero crash orphans). Engine
shape: companion table (lo_entries) is the contract authority; put =
one tx (lo_create + lowrite + row + pin); get = descriptorless
lo_get windows (lo_*64 discipline); named operator deltas (catalog
space never returned / autovacuum inherited / sweep for the legacy
bypass class only) and named performance deltas (cached-get 20-50x
behind page-cache fs single-stream, ~700 MB/s aggregate at 16
readers = the fleet serving picture).
- Ripple: backends-and-dispatch (pg-lo shipped; fleet locality
contract gains the whole-fleet-pg-lo option), overview (layer map,
feature table + pg-lo row, OQ -> shipped pointer), requirements
(engine def + REQ-2 note updated), README (current-state + ADR
table), store-api (invariant 1/6 engine lists), ADR-008 Status
amendment (pg-lo posture superseded by ADR-009), open-questions
(audit trail completed: decided -> sequenced -> completed).
Verification: docs-only; all cross-references resolve (ADR/REQ/POC);
register, findings, spec, and both engine-ADR status lines agree.