docs: Phase 1 review round — wake wording honesty, job-handle validity predicate, outbox/streams depth OQs

- C2: 'at-least-once wake delivery' collapsed to 'best-effort hints'
  (ADR-006 §1 + core-contract) — coalescing and the pg no-replay hole
  contradict per-commit wake promises; the guarantee table's row was
  already correct.
- W2: uniform job-handle validity predicate pinned (ADR-010 §2,
  core-contract, queues.md; verification-backlog row): processing
  state + unexpired deadline; D-12's missing-check not inherited.
- W1: outbox run_once worker semantics pinned in core-contract
  (pull op, ack/retry-on-curve, no heartbeat in delivery — honker
  parity, dual-execution window documented).
- W3: named-locks tx-seam posture stated (no lock_tx; acquisition is
  auto-commit; TTL discipline governs).
- C1 -> OQ-12: streams depth (key semantics w/ honker ground, event
  shape, ordering row, retention); method names pinned, depth open.
- New find -> OQ-13: the v1 TxHandle surface cannot express the
  transactional outbox enqueue (derived backing-queue name is
  reserved-prefix-rejected; honker's raw-Transaction seam unavailable);
  option set + decision rule sketched.
- README resolution order refreshed (OQ-06 resolved); ScheduleOpts +
  stream consumption-trigger lines added to core-contract.
This commit is contained in:
glm-5.3-flash committed 2026-10-05 12:50:33 +00:00
1 parent 8e68b44194
commit d401908f13
9 files changed
+250 -35

No files matched your search

@@ -42,9 +42,13 @@ a cache invalidates on wake and re-reads, instead of re-polling).
- Postgres: LISTEN delivers per-notification (no coalescing), and the
forwarder's synthetic reconnect-wake covers connection gaps.
- Both: consumer code must be correct if wakes repeat, coalesce, or
arrive in any order, with at-least-once wake delivery. Exactly-once
*processing* semantics belong to queues/streams (below), never to
the wake layer.
arrive in any order. **Wakes are best-effort hints, not a per-commit
delivery guarantee** — SQLite coalescing and Postgres's no-replay hole
(a commit during a connection gap is never re-delivered) both mean
individual changes can get *no* wake; recovery is consumers' re-read,
the reconnect-wake, and idempotence — never a promised per-commit
deliver. Exactly-once *processing* semantics belong to queues/streams
(below), never to the wake layer.
Measured ground: wake latency p50 ≈ 1.1–2.2 ms on both engines at
default cadence; per-payload burst delivery verified (30/30 on pg,