docs alignment: v1 TLS posture owned by deployment.md, QueueOpts numeric consumer-obligation notes (task pg-fix-docs-alignment, review 002 Finding 6 remainder)
- forwarder.rs's ListenerConnection doc corrected: NoTls is hardwired on every connection path (pooled, listener, reconnect) — the pooled path never rode the consumer's Config sslmode (a sslmode=require DSN fails at connect); grep-audited no other in-crate doc repeats the claim - PgOpts doc carries the corrected one-line TLS pointer (engine-crate- docs posture, ADR-016 §2) - deployment.md: new 'TLS posture (v1)' subsection (NoTls everywhere, sslmode=require DSN fails at connect, topology-level confidentiality is the v1 substitute, TLS a post-v1 deployment concern) and a new 'Consumer-obligation notes on engine options' section carrying the QueueOpts trusted-as-given note with code-verified per-field symptoms (max_attempts <= 0: never claimed, dead-lettered at the next claim call's pre-claim sweep; negative visibility: instantly-reclaimable claims; negative retention: every dead row at the next sweep_expired) plus the PgOpts::max_size 0-guard counter-case; frontmatter advanced - alkstore/src/opts.rs: QueueOpts struct doc mirrors the consumer-obligation note (ADR-023 §2 scoping: the domain table covers trait-surface arguments, not consumer-constructed constants) - cross-file doc sweep over the fix batch's touched files (forwarder, tx, scheduler, store) found no further doc-behavior mismatch - gates: cargo build / clippy --all-targets -D warnings / fmt --check all green (doc-only, no test touched)
This commit is contained in:
1 parent
40625090f6
commit
49face898d
5 files changed
+148
-14
No files matched your search
@@ -1,7 +1,7 @@
|
||||
---
|
||||
id: pg-fix-docs-alignment
|
||||
name: Doc alignment — TLS posture, QueueOpts consumer obligations (review 002 Finding 6 remainder)
|
||||
status: pending
|
||||
status: completed
|
||||
depends_on: [pg-fix-forwarder-reconnect]
|
||||
scope: single
|
||||
risk: trivial
|
||||
@@ -51,15 +51,15 @@ it and correct against the settled code.
|
||||
|
||||
## Acceptance Criteria
|
||||
|
||||
- [ ] `forwarder.rs`'s sslmode claim matches the code (`NoTls`
|
||||
- [x] `forwarder.rs`'s sslmode claim matches the code (`NoTls`
|
||||
hardwired); no other doc in the crate repeats the claim
|
||||
- [ ] `deployment.md` states the v1 TLS-unavailable posture on all
|
||||
- [x] `deployment.md` states the v1 TLS-unavailable posture on all
|
||||
connection paths
|
||||
- [ ] `deployment.md` (plus the opts' doc home) carries the
|
||||
- [x] `deployment.md` (plus the opts' doc home) carries the
|
||||
QueueOpts numeric consumer-obligation note
|
||||
- [ ] Cross-file doc sweep over the fix batch's touched files: no
|
||||
- [x] Cross-file doc sweep over the fix batch's touched files: no
|
||||
doc-behavior mismatch remains (grep-auditable claims spot-checked)
|
||||
- [ ] `cargo build`, clippy `-D warnings`, fmt clean (doc-only change;
|
||||
- [x] `cargo build`, clippy `-D warnings`, fmt clean (doc-only change;
|
||||
tests unaffected)
|
||||
|
||||
## References
|
||||
@@ -75,8 +75,74 @@ it and correct against the settled code.
|
||||
|
||||
## Notes
|
||||
|
||||
> To be filled by implementation agent
|
||||
Decisions of record the implementation made that the description
|
||||
didn't pin:
|
||||
|
||||
- **The QueueOpts mirror landed in core's `alkstore/src/opts.rs`,
|
||||
not the pg crate** — the description offered "`queue.rs`'s or
|
||||
`opts.rs`'s doc where the opts are documented"; the pg crate's
|
||||
`opts.rs` documents `PgOpts` (no `QueueOpts` mention), and
|
||||
`QueueOpts`' doc home is core's opts module, which both engines'
|
||||
consumers read. The mirror (trusted-as-given numerics, pointer to
|
||||
deployment.md) went on the `QueueOpts` struct doc there. The pg
|
||||
`PgOpts` doc got a one-line TLS pointer instead (v1 hardwires
|
||||
`NoTls` on every path; deployment.md carries the statement) — that
|
||||
is the engine-crate-docs posture ADR-016 §2 pins, and `PgOpts` is
|
||||
where a consumer meets the config split.
|
||||
- **Per-field behaviors verified against code before writing the
|
||||
symptoms** (the review's "self-dead-letters into churn" was
|
||||
imprecise): `max_attempts <= 0` rows are *never claimed* — the
|
||||
claim statement's `attempts < max_attempts` conjunct excludes them
|
||||
and the pre-claim sweep (`attempts >= max_attempts`) dead-letters
|
||||
each at the next claim call on its queue; negative
|
||||
`dead_letter_retention_s` deletes *every* dead row at the next
|
||||
`sweep_expired` (`died_at <= now - retention` with retention < 0 is
|
||||
always true; the sweeper is caller-driven, retained in the doc's
|
||||
wording); negative/zero `visibility_timeout_s` stamps
|
||||
past-deadline claims (instantly reclaimable). The SQLite engine's
|
||||
`resolution.rs` stamps identically, so the "both engines" framing
|
||||
is verified, not asserted.
|
||||
- **deployment.md gained a `Consumer-obligation notes on engine
|
||||
options` section** (after Connection budgets, before Durability
|
||||
knobs) rather than extending an existing list — the
|
||||
visibility-budgeting precedent lives in core-contract.md, and
|
||||
this document did not yet have an obligations home; the section
|
||||
closes the QueueOpts note and records the one counter-case
|
||||
(`PgOpts::max_size`'s 0-guard, `pg-fix-open-path`'s) so the
|
||||
trusted-as-given posture is bounded, not blanket. The TLS
|
||||
statement is a `TLS posture (v1)` subsection under Connection
|
||||
budgets.
|
||||
|
||||
## Summary
|
||||
|
||||
> To be filled on completion
|
||||
Doc-only alignment landed (review 002 Finding 6's remainder):
|
||||
|
||||
- **`alkstore-postgres/src/forwarder.rs`** — the `ListenerConnection`
|
||||
doc no longer claims the pooled path "rides the consumer's
|
||||
`Config` sslmode"; it now states `NoTls` is hardwired on *every*
|
||||
connection path (pooled, listener, reconnect) and deployment.md
|
||||
owns the statement. Grep-audited: no other doc in the crate (crate
|
||||
docs, `PgOpts`, `open`) repeats the false claim — `PgOpts` gained
|
||||
the corrected TLS pointer.
|
||||
- **`docs/architecture/deployment.md`** — new `TLS posture (v1)`
|
||||
subsection (NoTls everywhere; `sslmode=require` DSN fails at
|
||||
connect; topology-level confidentiality is the v1 substitute;
|
||||
post-v1 concern; ADR-016 spirit) and new
|
||||
`Consumer-obligation notes on engine options` section (the
|
||||
QueueOpts numeric trusted-as-given note with the three verified
|
||||
per-field symptoms + the `max_size` guard counter-case);
|
||||
`last_updated` frontmatter advanced.
|
||||
- **`alkstore/src/opts.rs`** — `QueueOpts` struct doc carries the
|
||||
mirror sentence (trusted-as-given, the ADR-023 §2 scoping, pointer
|
||||
to deployment.md for symptoms).
|
||||
- **Cross-file sweep** (forwarder/tx/scheduler/store, the fix batch's
|
||||
touched files): re-read the module docs against the settled
|
||||
post-fix code — reconnect retry core, fanout release guard,
|
||||
stale-generation reconcile (forwarder); commit-atomic wakes and
|
||||
drop=rollback (tx); quarantine + retry + TTL-lapse posture (scheduler);
|
||||
open-path guard and DSN-options append (store). No mismatch
|
||||
beyond the TLS claim found; the review's scheduler/`sweep_expired`
|
||||
doc fixes had already landed with their own fix tasks.
|
||||
- **Gates**: workspace `cargo build`, `cargo clippy --all-targets --
|
||||
-D warnings`, `cargo fmt --check` all green (doc-only change; no
|
||||
test touched).
|
||||
Reference in new issue
Block a user