docs(review 007 Unit 2): WS-31 discovery-shadowing note + record corrections

- WS-31: websocket.md §"Data channels for browsers" + ADR-067's landed
  note record that WS-session discovery is the bootstrap set — the
  hook's bootstrap `services/*` registrations overwrite a
  base-registry `services/*` registration on the WS path by design
  (a deployment's custom `services/list` is shadowed on WS sessions
  only).
- ADR-048's landed note: correction + completion — the WS-26
  retention sentence was aspirational at the landed commit (WS-28) and
  is now real; the UP-02 posture's override half is now an explicit
  surface (`with_ws_op_register_acl` / `OpRegisterAcl`), with the
  note that `ChannelsPolicy` could not carry an op ACL.
- ADR-067's landed note: review-007 notes (WS-28 fix + gate, WS-29
  surface, WS-31 record).
- OQ-05 resolution: the retention claim carries the WS-28 correction.
- review-006 UP-02 log + WS-26 paragraph: corrections marking what the
  pre-fix tree did not have, with the landed remediation named.
- review-002 WS-17: the "bounded at 64 sessions" claim corrected —
  the bare-registry semaphore was per-request and bounded nothing;
  `SessionSlots` is the shared-cap surface.
- review-007 status: open for remediation → remediated, with the
  decisions taken (both "implement" options) and the gate names.

Verification: cargo test 454 passed / 0 failed; cargo doc --no-deps
clean (6 pre-existing warnings, identical at baseline).

Review: docs/reviews/007-ws-data-channel-surface-review.md
This commit is contained in:
2026-09-05 05:45:31 +00:00
parent 24c2e9a224
commit 802d94ec07
7 changed files with 87 additions and 4 deletions
@@ -191,6 +191,15 @@ long-lived silent subscription deployment needs `None` and cannot get
it. **Fix:** a `WsIdleTimeout`/`WsSessions` request extension mirroring
`ChannelsPolicy`, or document the fixed values.
*(Correction, review 007 WS-30: the "bounded at 64 sessions" half was
wrong — the bare-registry `SessionState` is built by `FromRef` per
request, so its 64-permit semaphore is fresh per request and bounds
nothing across requests. The idle-timeout half above was the real
finding and landed as the `WsTimeouts` extension (WS-17's acceptance
gate). The session-cap half landed later as the `SessionSlots`
extension — the shared-cap surface a custom route inserts for an
effective bound.)*
## WS-18 [minor] — Write-side stall is unbounded: a peer that stops reading parks the mux indefinitely
**Verified:** YES. `byte_adapter.rs:584-597` — the idle knob covers