Review gate — wave-5 suite passed (task review-wave-5): the suite stands as the compatibility instrument and the engine specs flip to stable. All 25 mechanism rows per engine column read in full and verified against core-contract.md §Verification backlog item by item (the appendix map's every claim confirmed by the pinning row/text, incl. the combined-coverage claim for save_offset_tx exactly-once and the five engine-side pins — SQLite open row, watcher-cadence knob, M-1 sweep-rollback: SQLite trigger seam live + the pg frame's in_tx structure code-read; beyond-64 skip-forward; cap-curve); all 25 'Contract stamp:' markers checked against the cited ADR § bodies (ADR-008 §3/§5/§7/§8, 009 §1/§3/§4/§6, 010 §1-§5, 014 §1, 015 §1-§5, 016 §5, 020 §1-§4, 021 §1/§3/§4/§5, 023 §1/§2, 012 §2, 019, 007, 006) — the enqueue_opts_resolution amendment accumulation rides ADR-023 §2 per the convention; all six parked dispositions audited and recorded (M-1 engine-side, skip-forward engine-side twins, cap engine-side, fire-wake parity not demanded, lock busy-path no divergence, reconnect-success test taken); conformance spot-checks clean (no row pins beyond ADR text, determinism posture holds incl. the two documented extensions, cross-references not duplication). Green on both engines this session: workspace build/test/clippy -D warnings/fmt; SQLite column 25/25 server-less twice (isolated + concurrent); pg column 25/25 vs the harness server three full runs (two consecutive + one concurrent with the SQLite column) plus 6 focused --test-threads=6 stress runs of the two development-time flake rows — all clean, the two unreproducible pg failures recorded with the bounded investigation and a wave-6 watch flag in the task's Notes. Docs: engine-sqlite.md and engine-postgres.md frontmatter status draft → stable with dated annotations citing this gate; implementation.md wave-table row 5 and review-rounds entry; suite-opts-backoff-rows.md placeholder remnants removed. Wave 6 (release readiness) decomposition may proceed

This commit is contained in:
glm-5.3-flash committed 2026-10-10 08:13:17 +00:00
1 parent 5c03fb2130
commit 21074bbcdb
5 files changed
+198 -18

No files matched your search

+174 -9
View File
@@ -1,7 +1,7 @@
---
id: review-wave-5
name: Wave 5 review gate — the suite as compatibility instrument
status: pending
status: completed
depends_on: [suite-queue-depth-rows, suite-scheduler-rows, suite-tx-commit-atomicity-rows, suite-stream-rows, suite-lock-rows, suite-wake-rows, suite-opts-backoff-rows, sqlite-commit-error-arm, pg-suite-infra-hardening]
scope: broad
risk: low
@@ -57,17 +57,17 @@ Primary lenses:
## Acceptance Criteria
- [ ] Backlog discharge map recorded (every §Verification backlog item
- [x] Backlog discharge map recorded (every §Verification backlog item
→ its pinning row/test or an explicit gap with a disposition)
- [ ] Every row version-stamped per convention; amendment stamps
- [x] Every row version-stamped per convention; amendment stamps
accumulated; stamps verified against the cited ADR text
- [ ] Suite green on both engines (SQLite server-less; pg vs harness,
- [x] Suite green on both engines (SQLite server-less; pg vs harness,
two consecutive full runs); workspace gates green
- [ ] All parked dispositions from the wave-5 tasks audited and
- [x] All parked dispositions from the wave-5 tasks audited and
recorded
- [ ] Engine specs flipped to `stable` with dated annotations;
- [x] Engine specs flipped to `stable` with dated annotations;
implementation.md updated (wave table + review rounds)
- [ ] Findings recorded; wave 6 decomposition may proceed
- [x] Findings recorded; wave 6 decomposition may proceed
## References
@@ -79,11 +79,176 @@ Primary lenses:
## Notes
> To be filled by implementation agent
> Audit of record for the gate (2026-10-10). Every claim below was
> verified by reading the pinning row/test, not by trusting the
> appendix map or the implementing tasks' self-reports.
**1. Backlog audit — the discharge map, verified.** All 25 mechanism
rows per engine column were read in full
(`alkstore-contract-suite/src/properties.rs`, 3344 lines) against the
backlog text in `core-contract.md` §Verification backlog. Findings:
- Every row of the appendix's first table is genuinely discharged by
the named row: name validation + `schedule()` queue argument + the
keyed `publish_with_key_tx` empty-`Some` rule (exemplar covers all
three, tx twins included and `with_tx`-driven); numeric domains
(`extent_clamp_semantics` + `duration_refusal_on_non_positive_ttl`);
`encode_payload` typed failure + round-trip; the `PayloadTooLarge`
asymmetry (both engine-scoped rows, the pg one reading the limit
from the produced variant); drop = rollback no-ghosts;
read-your-own-writes; receiver arms + monotone save composition.
- The combined-coverage claim for `save_offset_tx` exactly-once
(in-tx-ryow's own-save visibility + drop-rollback's save-never-lands)
holds: together they pin (a) the save is visible inside the tx,
(b) the saved checkpoint survives commit semantics exactly when the
business tx commits, (c) rollback deletes it. No gap.
- The engine-side pins the map claims exist and are real:
`uri_shaped_open_path_is_a_literal_filename` and
`poll_interval_flows_to_the_watcher_config`
(`alkstore-sqlite/src/store/open_tests.rs`);
`sweep_rolls_back_the_retention_half_with_the_move`
(SQLite substrate trigger seam — M-1's live pin) and the pg twin's
structural guarantee confirmed by code-read of
`alkstore-postgres/src/queue.rs::sweep_expired` (move + retention
DELETE inside one `in_tx` `BEGIN…COMMIT/ROLLBACK` frame — a
retention-DELETE failure rolls the move back via the frame's error
arm);
`receiver_stays_open_across_reconnects_closes_at_shutdown` (pg
notify tests) + `subscriber_survives_reconnect_and_heals_gap_by_redrain`
(pg stream tests) — the reconnect-stays-open pin the receiver-arms
row cross-references; and the pg receiver error/close arms it pins
inside the shared row body.
- Every row of the second table (wave-5 tasks) is present and stamped:
the three queue-depth rows, three scheduler rows, three tx-seam rows
(N-5's panic probe included), two stream rows, two lock rows (the
SQLite busy-path open question answered in-row: losers get the clean
`None` value — no divergence), `wake_receiver_shapes`,
`backoff_curve_equivalence`, and the two extended
`enqueue_opts_resolution` clock legs. The two engine-side hardening
deliverables landed (`failed_commit_replenishes_the_writer_slot` —
replay-proofed per its task; `reconnect_success_resumes_wake_delivery`;
the pg `must_recv_event` parked-recv re-shape with the
self-diagnosing deadline panic).
**2. Stamp audit — verified against the cited ADR text.** `grep
"Contract stamp:"` yields exactly 25 markers for 25 rows (one per
row; multi-stamp rows cite several ADRs on one marker). Every cited §
exists in its ADR and pins the behavior the row tests — verified
against the ADR bodies for the load-bearing citations: ADR-008 §3
(wake type + recv forms, `Ok(None)` idle arm), §5 (error taxonomy /
value-not-error), §7 (locks guarantee row), §8 (explicit saves only);
ADR-009 §1/§3/§4/§6 (runner shape, boundary fires, the 64-cap,
`LeadershipLost`); ADR-010 §1 (delete-on-ack, per-id `ack_batch`
predicate — pinned in ADR-021-era §1 annotation), §2 (validity
predicate, reclaim-eats-attempt), §3/§3a, §4 (strings, get_job-sees-dead,
retention default), §5 (no-stranded-rows, retention); ADR-014 §1 (60/5/5
derived stamp set); ADR-015 §1–§5 (key semantics, tx seam, `StreamEvent`
shape, ordering row, `trim_to` — the row texts quote the ADR's
"silent-loss / resume-at-horizon / no-dedicated-wake" semantics
verbatim); ADR-016 §5; ADR-020 §1/§2/§3/§4; ADR-021 §1/§3/§4/§5;
ADR-023 §1/§2 (the domain-rule table); ADR-012 §2 (one-owner
arithmetic, suite-pinned identical); ADR-019 §1/§3/§4/§6; ADR-007;
ADR-006. The amendment case checks: `enqueue_opts_resolution`'s stamp
list accumulated ADR-023 §2 when the wave-5 clock legs landed, on top
of its ADR-020 stamps — the deferral note replaced by the completion
statement, per the convention. No stamp cites an ADR § that doesn't
pin the tested behavior; no tested behavior lacks a stamp.
**3. Green on both engines — verified this session.** Workspace gates
green: `cargo build`, `cargo test` (12 binaries — core 25; suite
harness 3; pg 121 lib + 25 suite + 9 schema against the harness
server; SQLite 191 lib + 25 suite), `cargo clippy --all-targets --
-D warnings`, `cargo fmt --check`. Dedicated suite runs: pg column
vs the harness server three full runs (two consecutive + one concurrent
with the SQLite column, the wave-4 gate's posture plus), 25/25 each;
SQLite column green server-less twice (isolated + concurrent), 25/25.
Focused stress: 6 consecutive `--test-threads=6` runs of
`row_trim_to_semantics` + `row_lock_ttl` on pg — green throughout.
**4. Parked dispositions audited — all six made and recorded.**
| Disposition | Where recorded | Audit verdict |
|---|---|---|
| M-1 retention-failure pin's location | `suite-queue-depth-rows` Notes | Engine-side (SQLite trigger seam; pg by frame structure) — sound; the pg leg rests on code-read, accepted with the row's doc text recording it |
| Beyond-64 skip-forward leg | `suite-scheduler-rows` Notes | Engine-side twins exist on both engines (`catch_up_replays_up_to_the_cap_then_skips_forward`); suite pins the ≤64 in-band leg; row doc states it |
| Backoff cap leg | `suite-opts-backoff-rows` Notes | Engine-side pins verified present (both engines' unit tests); row doc records the disposition |
| Scheduler fire-wake parity | `suite-scheduler-rows` Notes | Not demanded by the row shapes (claim-polling observation only); the recorded gap stands for a later task; accepted as-is |
| Lock-row divergence call | `suite-lock-rows` Notes | No divergence found — the row pins the convergence; nothing to fix |
| SQLite reconnect-success test | `sqlite-commit-error-arm` Notes | Taken — `reconnect_success_resumes_wake_delivery` exists and pins the success arm's re-baseline + restored delivery |
**5. Conformance spot-checks — clean.** No row pins beyond ADR text
(a row that would fail a correct engine was not found); the
determinism posture holds throughout — state-outcome assertions,
bounded waits, tolerance bands on stamps (`abs_diff <= 5`, ±10 s
informational `created_at`, one-second straddle on the curve upper
bounds), sleeps bounded well past second-resolution stamps; the two
documented posture extensions (runner-driving rows; the N-5 panic
probe) are admitted in the module doc as ADR-017 §2 class-4
suite-side posture notes and are implemented as described; no leg
duplication — cross-references instead (duration guards →
`duration_refusal_on_non_positive_ttl`; close arms →
`receiver_close_and_save_arms`; byte-exactness →
`payload_round_trip_stores_exact_encoding`; negative-horizon →
`extent_clamp_semantics`).
**6. Flaky-test ledger — the two unreproducible pg failures.** Two
single-occurrence failures were recorded honestly during development:
`row_trim_to_semantics` (stream-rows, 1/14 under the concurrent
SQLite+pg condition) and `row_lock_ttl_expiry_and_reacquisition`
(lock-rows, first cold pg run, message lost to truncation). Bounded
review investigation this session: three full pg suite runs (one under
the replayed concurrent SQLite+pg condition), six focused
`--test-threads=6` runs of both rows, and the workspace's own full pg
runs — all green; no divergence, no repro. Both rows' windows assert
state outcomes only (delivered events / post-sleep lock state), so a
timing-value failure mode is not available; the lock row's lapse
assertions are post-sleep states that a slower clock can only delay,
never un-lapse. One residual observation recorded for the future: the
trim row's pg-side failure shape would have been an event delivered to
the subscriber beyond its checkpoint in the post-trim absence window —
under pg's cross-database LISTEN the wakes are mechanism-named, and
the row's re-drain safety argument (own-schema storage yields nothing)
is the by-construction defense; if either row fails again, it should
get a dedicated investigative session (instrumentation + focused
repro loop) *before* any postulate-and-fix — per the user's ledger
the pattern (a prior unreproducible flake hinting at a real engine
issue) deserves that attention. Not blocking this gate: 13+ subsequent
clean pg runs across both rows since the failures, all conditions
covered. **Flagged for watch in wave 6's window.**
**7. Findings.** No code, suite-row, or stamp defects requiring change
were found at gate time; all changes this gate made are doc-side
(engine specs `draft` → `stable` with dated gate annotations;
`docs/plans/implementation.md` wave table + review-rounds entry) and
task-file hygiene (`suite-opts-backoff-rows` had the placeholder
"To be filled" lines left in its Notes/Summary headers above real
content — removed the placeholders). Wave 6 decomposition may proceed.
## Summary
> To be filled on completion
> Filled by the review agent (2026-10-10):
The wave-5 review gate passed. The suite is the compatibility
instrument the plan called for: **all 25 mechanism rows per engine
column present, version-stamped per `version_stamp.rs`'s convention
(greppable via `STAMP_MARKER`), green on both engines.** Verified by
direct read of every row and both engines' wiring, cross-checked
against `core-contract.md` §Verification backlog item by item (the
verified discharge map is in Notes §1), every `Contract stamp:` against
its cited ADR § text (Notes §2; the `enqueue_opts_resolution`
amendment accumulation checked), all six parked dispositions
audited (Notes §4, table), and the determinism/conformance postures
spot-checked (Notes §5). Suite green on both engines with the gate
posture exceeded (three full pg runs against the harness, one
concurrent with the SQLite column; SQLite green server-less twice),
plus focused stress on the two development-time flake rows; workspace
build/test/clippy/fmt green. Engine specs flipped to `stable`
(`docs/architecture/engine-sqlite.md`, `docs/architecture/engine-postgres.md`,
dated annotations citing this gate); `docs/plans/implementation.md`
wave table and review-rounds updated. The two unreproducible pg
failures from development are recorded with the bounded investigation
and a watch flag (Notes §6) — if either reproduces, a dedicated
session follows. Wave 6 (release readiness) decomposition may proceed.
## Appendix — the decomposition's backlog audit (verify, don't trust)
-3
View File
@@ -74,7 +74,6 @@ Work:
## Notes
> To be filled by implementation agent
- **The 1-hour cap leg is not suite-pinned** (as pre-decided): reaching
capped attempts requires waiting out minute-scale delays. The cap
@@ -124,8 +123,6 @@ Work:
## Summary
> To be filled on completion
`enqueue_opts_resolution` extended in place with the wave-5
completion legs (its deferral note replaced by the completion
statement, ADR-023 §2 stamp accumulated): the `run_at`-alone literal