ADR-016: deployment honesty — no runtime capability surface; compile-time identity + matrix (OQ-08 resolved)

This commit is contained in:
glm-5.3-flash committed 2026-10-06 06:29:42 +00:00
1 parent 8c4ec48f92
commit 8c8fec5cb8
12 files changed
+494 -72

No files matched your search

@@ -94,7 +94,10 @@ implement identically):
`schedule()`) — OQ-09 decides; the scheduler surface (if any) is not
part of contract v1.
- **Capability flags** — OQ-08 decides whether `Store` exposes them at
all; v1 has no capability surface.
all; v1 has no capability surface. *(Resolved 2026-10-06 by
[ADR-016](016-deployment-honesty.md): no capability surface — by
default ever; the boundary is compile-time engine identity +
deployment.md's matrix.)*
- **`claim_waker`** — dropped from the contract surface; wake-driven
claim is the engine's consumption posture
([engine-postgres.md](../engine-postgres.md)'s LISTEN-driven claim),
@@ -311,6 +314,10 @@ elsewhere, cancelled); `try_lock` returning `Option<Lock>`; lock
constructor's own obligation — a `Store` handed out by an engine
crate honors the full v1 surface.
- No capability surface in v1 (OQ-08 owns whether one ever exists).
*(Resolved 2026-10-06 by [ADR-016](016-deployment-honesty.md): by
default never — the engine choice stays a dependency-graph fact;
`PayloadTooLarge` is the one runtime carriage of an engine
asymmetry.)*
- Consumer code stays engine-agnostic by depending on core and being
constructed by exactly one engine crate (ADR-001's single-driver
binaries) — the engine choice is a dependency-graph fact, not a
@@ -410,9 +417,12 @@ prefix, §4).
reused after commit (callers re-`begin_tx`) — matches the
caller-owned lifetime the POCs verified, but is stricter than
honker's re-usable `&Transaction` style.
- OQ-05/OQ-09/OQ-08 remain open: this ADR deliberately does not pin
queue depth, the scheduler shape, or capability flags; the v1
additions to those surfaces will be later contract extensions.
- OQ-05/OQ-09/OQ-08 remained open here: this ADR deliberately did not
pin queue depth, the scheduler shape, or capability flags; the v1
additions to those surfaces were later contract decisions.
*(OQ-05/OQ-09 resolved by [ADR-010](010-queue-semantics-depth.md)/
[ADR-009](009-scheduler-collapse.md); OQ-08 resolved 2026-10-06 by
[ADR-016](016-deployment-honesty.md) — none, by default ever.)*
## References
@@ -432,5 +442,7 @@ prefix, §4).
[ADR-006](006-wake-and-delivery-contract.md) (wake contract,
namespace existence, guarantee table),
[ADR-007](007-transactional-seam.md) (tx seam mechanics).
- OQ-09 (scheduler row transfer), OQ-08 (capability surface), OQ-10
- OQ-09 (scheduler row transfer), OQ-08 (capability surface —
resolved by [ADR-016](016-deployment-honesty.md), no runtime
surface), OQ-10
(versioning discipline for future contract extensions).