decompose wave 5 — contract suite: audit-first split of the verification backlog (engines' columns already discharge most rows; map in review-wave-5's appendix), seven mechanism-grouped suite-row tasks (queue depth, scheduler, tx commit-atomicity, streams, locks, wakes, opts/backoff equivalence), two engine-side hardening tasks (sqlite commit-error arm, pg F-1 defense-in-depth), and the review-wave-5 gate that flips the engine specs to stable

This commit is contained in:
glm-5.3-flash committed 2026-10-10 05:37:53 +00:00
1 parent 9a00fb8a7e
commit 250511d480
11 files changed
+911 -2

No files matched your search

+68
View File
@@ -0,0 +1,68 @@
---
id: sqlite-commit-error-arm
name: SQLite engine — commit-error-arm coverage (wave-3 review's deferred test)
status: pending
depends_on: []
scope: narrow
risk: medium
impact: isolated
level: implementation
tags: [wave-5, sqlite-engine, tests]
---
## Description
Land the wave-3 review gate's deferred coverage item
(`tasks/review-wave-3.md` Notes: "Coverage of the commit-error arm —
no test induces a failing `COMMIT` ... natural home is wave 5's suite
hardening"): a test that drives a failing `COMMIT` through the SQLite
engine's `commit` path and pins the fix the review verified by
code-read — the writer slot is replenished via the `reopen` closure on
the failed `COMMIT` (no stranding), the error surfaces as the opaque
`Database`, and the store remains fully usable afterward (subsequent
`begin_tx`/auto-commit ops work).
The injection mechanism is this task's to find — candidates: a
`PRAGMA max_page_count` squeeze forcing `SQLITE_FULL` on a
space-consuming commit, or a `cfg(test)` fault seam in the seam layer
if the PRAGMA route cannot hit the COMMIT arm deterministically. The
wave-4 fix batch's `cfg(test)` config-seam precedent
(`pg-fix-forwarder-reconnect`) is the house pattern if a seam is
needed. Prefer the least-invasive mechanism that deterministically
reaches the arm; document the choice.
If the same session has cheap room for it, the waves-1–2 review's
optional add — the watcher reconnect-*success* path test (upstream's
W-1 test drives only the failure path; "a reconnect success test would
require a file appearing mid-run") — rides here **only if** the
engine kept the current watcher shape and the test is genuinely cheap;
otherwise leave it recorded as not-taken in Notes (it was a
suggestion, not an order).
## Acceptance Criteria
- [ ] A test induces a failing `COMMIT` on the SQLite engine and pins:
error surfaces (`Database`), writer slot replenished (a
subsequent `begin_tx` succeeds), no partial-commit residue
- [ ] The injection mechanism documented in Notes (PRAGMA vs seam, and
why)
- [ ] The watcher reconnect-success test either landed or explicitly
recorded as not-taken with the reason
- [ ] `cargo test -p alkstore-sqlite` green server-less; clippy
`-D warnings`; fmt clean
## References
- tasks/review-wave-3.md (Notes: the deferred commit-error-arm coverage)
- tasks/sqlite-engine-seam-tx.md (the `commit` replenish fix the test pins)
- tasks/pg-fix-forwarder-reconnect.md (the `cfg(test)` seam precedent)
- docs/reviews/001-waves-1-2-general-review.md §2 (the watcher
reconnect-success suggestion)
## Notes
> To be filled by implementation agent
## Summary
> To be filled on completion