Fourth review round (ADR-023): encode_payload typed (Codec), numeric-argument domains pinned by kind, plain-path SQLite open (URI flag dropped, D-29), watcher cadence posture — waves-1-2 general-review findings

This commit is contained in:
glm-5.3-flash committed 2026-10-08 10:17:56 +00:00
1 parent ee7871d25d
commit 44637eea5b
11 files changed
+502 -22

No files matched your search

@@ -117,6 +117,7 @@ fixes. Cherry-picks: empty at scaffold, append-only forever.
| D-26 | hygiene | `volume_serial_number as u64` → `u64::from(volume_serial_number)` in `VolumeIdentity` (clippy lint conformance, zero behavior change) | watcher.rs (`stat_identity` region) | family clippy `-D warnings` gate | ours |
| D-27 | re-derivation | wave-2 review fix — `scheduler_tick`'s fire enqueue resolved the schedule row's relative `expires_s` into the absolute row `expires_at` (`now + s` at the fire transaction, one clock read) instead of passing the relative value through; regression test pins a fired job's `expires_at = fire-instant + s` and its claimability. The pre-fix pass-through would have produced rows expired in 1970 under any `expires_s` schedule | `queue_ops.rs` (`scheduler_tick`, fire-expiry resolution + test) | ADR-020 §2 (relative `expires` → resolved absolute row value, resolved at enqueue against the single clock) — D-12's landed state carried the lineage's `expires_s` field shape without carrying the lineage's enqueue-side resolution; wave-2 review (task review-wave-2) re-derivation spot-check found it | ours |
| D-28 | hygiene | wave-2 review fix — the cross-mechanism pressure test's lock-churn branch exercised a per-producer lock name (literal `"p{producer}"` had no interpolation, so all producers contended on one name) with its result swallowed via `.unwrap_or(0)`; now interpolates, releases periodically, propagates errors | `ops.rs` (pressure test, lock branch) | test-quality only (no lineage counterpart, no library code touched); `fork-provenance-and-floor`'s ported-surface pressure intent | ours |
| D-29 | port delta | `SQLITE_OPEN_URI` dropped from `open_conn`'s flags (the watcher's own opens never carried it — the inherited posture was internally inconsistent); the path argument is a plain filesystem path, `?name=value` suffixes are literal filenames, no connection-semantics mutation outside the engine constructor's opts; pinned by test (`open_conn_treats_uri_shaped_path_as_plain_filename`) | `schema.rs` (`open_conn`) | ADR-023 §3 (plain-path open — the URI parameter surface is SQLite's, not this engine's; no consumer-inventory row names URI features) | ours |
### Cherry-picks
+26 -3
View File
@@ -309,11 +309,13 @@ pub(crate) fn bootstrap_schema(conn: &Connection) -> Result<(), Error> {
}
pub(crate) fn open_conn(path: &str, install_notify: bool) -> Result<Connection, Error> {
// No SQLITE_OPEN_URI (ADR-023 §3 delta): the path argument is a
// plain filesystem path — URI-interpreted `?name=value` suffixes
// would mutate connection semantics outside the engine
// constructor's opts.
let conn = Connection::open_with_flags(
path,
OpenFlags::SQLITE_OPEN_READ_WRITE
| OpenFlags::SQLITE_OPEN_CREATE
| OpenFlags::SQLITE_OPEN_URI,
OpenFlags::SQLITE_OPEN_READ_WRITE | OpenFlags::SQLITE_OPEN_CREATE,
)?;
apply_default_pragmas(&conn)?;
if install_notify {
@@ -554,6 +556,27 @@ mod writer_reader_tests {
let _ = std::fs::remove_file(format!("{}-shm", tmp.display()));
}
#[test]
fn open_conn_treats_uri_shaped_path_as_plain_filename() {
// ADR-023 §3: no SQLITE_OPEN_URI — a `?name=value` suffix must
// be a literal filename (the file exists with that name), not
// URI interpretation (which for a bare-relative "file"-less
// string with query params would error or mutate semantics).
let dir = std::env::temp_dir().join(format!(
"alkstore-uri-literal-{}-{:?}",
std::process::id(),
std::thread::current().id()
));
std::fs::create_dir_all(&dir).unwrap();
let path = dir.join("plain.db?mode=memory");
let conn = open_conn(path.to_str().unwrap(), false).unwrap();
conn.execute("CREATE TABLE t (x)", []).unwrap();
drop(conn);
let plain = dir.join("plain.db?mode=memory");
assert!(plain.exists(), "literal-named file must exist on disk");
let _ = std::fs::remove_dir_all(&dir);
}
#[test]
fn concurrent_opens_never_return_database_is_locked() {
const ROUNDS: usize = 8;