docs alignment: v1 TLS posture owned by deployment.md, QueueOpts numeric consumer-obligation notes (task pg-fix-docs-alignment, review 002 Finding 6 remainder)

- forwarder.rs's ListenerConnection doc corrected: NoTls is hardwired on
  every connection path (pooled, listener, reconnect) — the pooled path
  never rode the consumer's Config sslmode (a sslmode=require DSN fails
  at connect); grep-audited no other in-crate doc repeats the claim
- PgOpts doc carries the corrected one-line TLS pointer (engine-crate-
  docs posture, ADR-016 §2)
- deployment.md: new 'TLS posture (v1)' subsection (NoTls everywhere,
  sslmode=require DSN fails at connect, topology-level confidentiality
  is the v1 substitute, TLS a post-v1 deployment concern) and a new
  'Consumer-obligation notes on engine options' section carrying the
  QueueOpts trusted-as-given note with code-verified per-field symptoms
  (max_attempts <= 0: never claimed, dead-lettered at the next claim
  call's pre-claim sweep; negative visibility: instantly-reclaimable
  claims; negative retention: every dead row at the next sweep_expired)
  plus the PgOpts::max_size 0-guard counter-case; frontmatter advanced
- alkstore/src/opts.rs: QueueOpts struct doc mirrors the
  consumer-obligation note (ADR-023 §2 scoping: the domain table covers
  trait-surface arguments, not consumer-constructed constants)
- cross-file doc sweep over the fix batch's touched files (forwarder,
  tx, scheduler, store) found no further doc-behavior mismatch
- gates: cargo build / clippy --all-targets -D warnings / fmt --check
  all green (doc-only, no test touched)
This commit is contained in:
glm-5.3-flash committed 2026-10-10 05:08:27 +00:00
1 parent 40625090f6
commit 49face898d
5 files changed
+148 -14

No files matched your search

+6 -4
View File
@@ -81,10 +81,12 @@ pub(crate) type ReconnectConfigSlot = Arc<std::sync::Mutex<tokio_postgres::Confi
pub(crate) type GenerationPair = (tokio_postgres::Client, ListenerConnection);
/// The listener connection's concrete type for the `NoTls` posture
/// (the engine's TLS story rides the consumer's `Config` sslmode for
/// the pooled path; the dedicated listener connects with `NoTls` —
/// TLS hardening is the deployment's ingress posture, the notify-
/// listen task revisits if a task or ADR demands listener TLS).
/// (v1 TLS is unavailable on *every* connection path — pooled,
/// listener, and reconnect alike hardwire `NoTls`; the engine does
/// not ride the consumer's `Config` sslmode — TLS is a post-v1
/// deployment concern and deployment.md owns the statement; the
/// notify-listen task revisits if a task or ADR demands listener
/// TLS).
pub(crate) type ListenerConnection = tokio_postgres::Connection<
tokio_postgres::Socket,
<tokio_postgres::NoTls as tokio_postgres::tls::MakeTlsConnect<tokio_postgres::Socket>>::Stream,
+4 -1
View File
@@ -36,7 +36,10 @@ pub(crate) const LISTENER_APPLICATION_NAME: &str = "alkstore-pg-listener";
/// [`Config`](::tokio_postgres::Config)-parseable form, ADR-008 §6's
/// `open(url, PgOpts)` pin); the engine never invents defaults for
/// them. `open` fails with [`Error::Database`] if the config is
/// unparseable or the server unreachable.
/// unparseable or the server unreachable. TLS: the engine hardwires
/// `NoTls` on every connection path regardless of the config's
/// sslmode — v1 TLS is a post-v1 deployment concern
/// (deployment.md's TLS posture carries the statement).
#[derive(Debug, Clone)]
pub struct PgOpts {
/// The engine-owned PostgreSQL schema (ADR-010 §8). Default