docs alignment: v1 TLS posture owned by deployment.md, QueueOpts numeric consumer-obligation notes (task pg-fix-docs-alignment, review 002 Finding 6 remainder)

- forwarder.rs's ListenerConnection doc corrected: NoTls is hardwired on
  every connection path (pooled, listener, reconnect) — the pooled path
  never rode the consumer's Config sslmode (a sslmode=require DSN fails
  at connect); grep-audited no other in-crate doc repeats the claim
- PgOpts doc carries the corrected one-line TLS pointer (engine-crate-
  docs posture, ADR-016 §2)
- deployment.md: new 'TLS posture (v1)' subsection (NoTls everywhere,
  sslmode=require DSN fails at connect, topology-level confidentiality
  is the v1 substitute, TLS a post-v1 deployment concern) and a new
  'Consumer-obligation notes on engine options' section carrying the
  QueueOpts trusted-as-given note with code-verified per-field symptoms
  (max_attempts <= 0: never claimed, dead-lettered at the next claim
  call's pre-claim sweep; negative visibility: instantly-reclaimable
  claims; negative retention: every dead row at the next sweep_expired)
  plus the PgOpts::max_size 0-guard counter-case; frontmatter advanced
- alkstore/src/opts.rs: QueueOpts struct doc mirrors the
  consumer-obligation note (ADR-023 §2 scoping: the domain table covers
  trait-surface arguments, not consumer-constructed constants)
- cross-file doc sweep over the fix batch's touched files (forwarder,
  tx, scheduler, store) found no further doc-behavior mismatch
- gates: cargo build / clippy --all-targets -D warnings / fmt --check
  all green (doc-only, no test touched)
This commit is contained in:
glm-5.3-flash committed 2026-10-10 05:08:27 +00:00
1 parent 40625090f6
commit 49face898d
5 files changed
+148 -14

No files matched your search

+74 -8
View File
@@ -1,7 +1,7 @@
---
id: pg-fix-docs-alignment
name: Doc alignment — TLS posture, QueueOpts consumer obligations (review 002 Finding 6 remainder)
status: pending
status: completed
depends_on: [pg-fix-forwarder-reconnect]
scope: single
risk: trivial
@@ -51,15 +51,15 @@ it and correct against the settled code.
## Acceptance Criteria
- [ ] `forwarder.rs`'s sslmode claim matches the code (`NoTls`
- [x] `forwarder.rs`'s sslmode claim matches the code (`NoTls`
hardwired); no other doc in the crate repeats the claim
- [ ] `deployment.md` states the v1 TLS-unavailable posture on all
- [x] `deployment.md` states the v1 TLS-unavailable posture on all
connection paths
- [ ] `deployment.md` (plus the opts' doc home) carries the
- [x] `deployment.md` (plus the opts' doc home) carries the
QueueOpts numeric consumer-obligation note
- [ ] Cross-file doc sweep over the fix batch's touched files: no
- [x] Cross-file doc sweep over the fix batch's touched files: no
doc-behavior mismatch remains (grep-auditable claims spot-checked)
- [ ] `cargo build`, clippy `-D warnings`, fmt clean (doc-only change;
- [x] `cargo build`, clippy `-D warnings`, fmt clean (doc-only change;
tests unaffected)
## References
@@ -75,8 +75,74 @@ it and correct against the settled code.
## Notes
> To be filled by implementation agent
Decisions of record the implementation made that the description
didn't pin:
- **The QueueOpts mirror landed in core's `alkstore/src/opts.rs`,
not the pg crate** — the description offered "`queue.rs`'s or
`opts.rs`'s doc where the opts are documented"; the pg crate's
`opts.rs` documents `PgOpts` (no `QueueOpts` mention), and
`QueueOpts`' doc home is core's opts module, which both engines'
consumers read. The mirror (trusted-as-given numerics, pointer to
deployment.md) went on the `QueueOpts` struct doc there. The pg
`PgOpts` doc got a one-line TLS pointer instead (v1 hardwires
`NoTls` on every path; deployment.md carries the statement) — that
is the engine-crate-docs posture ADR-016 §2 pins, and `PgOpts` is
where a consumer meets the config split.
- **Per-field behaviors verified against code before writing the
symptoms** (the review's "self-dead-letters into churn" was
imprecise): `max_attempts <= 0` rows are *never claimed* — the
claim statement's `attempts < max_attempts` conjunct excludes them
and the pre-claim sweep (`attempts >= max_attempts`) dead-letters
each at the next claim call on its queue; negative
`dead_letter_retention_s` deletes *every* dead row at the next
`sweep_expired` (`died_at <= now - retention` with retention < 0 is
always true; the sweeper is caller-driven, retained in the doc's
wording); negative/zero `visibility_timeout_s` stamps
past-deadline claims (instantly reclaimable). The SQLite engine's
`resolution.rs` stamps identically, so the "both engines" framing
is verified, not asserted.
- **deployment.md gained a `Consumer-obligation notes on engine
options` section** (after Connection budgets, before Durability
knobs) rather than extending an existing list — the
visibility-budgeting precedent lives in core-contract.md, and
this document did not yet have an obligations home; the section
closes the QueueOpts note and records the one counter-case
(`PgOpts::max_size`'s 0-guard, `pg-fix-open-path`'s) so the
trusted-as-given posture is bounded, not blanket. The TLS
statement is a `TLS posture (v1)` subsection under Connection
budgets.
## Summary
> To be filled on completion
Doc-only alignment landed (review 002 Finding 6's remainder):
- **`alkstore-postgres/src/forwarder.rs`** — the `ListenerConnection`
doc no longer claims the pooled path "rides the consumer's
`Config` sslmode"; it now states `NoTls` is hardwired on *every*
connection path (pooled, listener, reconnect) and deployment.md
owns the statement. Grep-audited: no other doc in the crate (crate
docs, `PgOpts`, `open`) repeats the false claim — `PgOpts` gained
the corrected TLS pointer.
- **`docs/architecture/deployment.md`** — new `TLS posture (v1)`
subsection (NoTls everywhere; `sslmode=require` DSN fails at
connect; topology-level confidentiality is the v1 substitute;
post-v1 concern; ADR-016 spirit) and new
`Consumer-obligation notes on engine options` section (the
QueueOpts numeric trusted-as-given note with the three verified
per-field symptoms + the `max_size` guard counter-case);
`last_updated` frontmatter advanced.
- **`alkstore/src/opts.rs`** — `QueueOpts` struct doc carries the
mirror sentence (trusted-as-given, the ADR-023 §2 scoping, pointer
to deployment.md for symptoms).
- **Cross-file sweep** (forwarder/tx/scheduler/store, the fix batch's
touched files): re-read the module docs against the settled
post-fix code — reconnect retry core, fanout release guard,
stale-generation reconcile (forwarder); commit-atomic wakes and
drop=rollback (tx); quarantine + retry + TTL-lapse posture (scheduler);
open-path guard and DSN-options append (store). No mismatch
beyond the TLS claim found; the review's scheduler/`sweep_expired`
doc fixes had already landed with their own fix tasks.
- **Gates**: workspace `cargo build`, `cargo clippy --all-targets --
-D warnings`, `cargo fmt --check` all green (doc-only change; no
test touched).