docs: Phase 1 review round — wake wording honesty, job-handle validity predicate, outbox/streams depth OQs

- C2: 'at-least-once wake delivery' collapsed to 'best-effort hints'
  (ADR-006 §1 + core-contract) — coalescing and the pg no-replay hole
  contradict per-commit wake promises; the guarantee table's row was
  already correct.
- W2: uniform job-handle validity predicate pinned (ADR-010 §2,
  core-contract, queues.md; verification-backlog row): processing
  state + unexpired deadline; D-12's missing-check not inherited.
- W1: outbox run_once worker semantics pinned in core-contract
  (pull op, ack/retry-on-curve, no heartbeat in delivery — honker
  parity, dual-execution window documented).
- W3: named-locks tx-seam posture stated (no lock_tx; acquisition is
  auto-commit; TTL discipline governs).
- C1 -> OQ-12: streams depth (key semantics w/ honker ground, event
  shape, ordering row, retention); method names pinned, depth open.
- New find -> OQ-13: the v1 TxHandle surface cannot express the
  transactional outbox enqueue (derived backing-queue name is
  reserved-prefix-rejected; honker's raw-Transaction seam unavailable);
  option set + decision rule sketched.
- README resolution order refreshed (OQ-06 resolved); ScheduleOpts +
  stream consumption-trigger lines added to core-contract.
This commit is contained in:
glm-5.3-flash committed 2026-10-05 12:50:33 +00:00
1 parent 8e68b44194
commit d401908f13
9 files changed
+250 -35

No files matched your search

@@ -94,6 +94,20 @@ no-renewal/expire-sweep model is not inherited):
claimable by ordinary claim (no transition fires on lapse); there
is no separate reaper for expired claims, only the budget rules
below and the no-stranded-rows sweep (§5).
- **Job-handle op validity predicate** (the D-12 disposition, stated
uniformly): every handle op (`ack`/`heartbeat`/`retry`/`fail`)
succeeds only when the row is in `processing` **and** the caller's
claim deadline has not lapsed — ADR-008 §5's false-case list
("expired, acked elsewhere, cancelled") is the same rule one
predicate-wide: deadline lapse refuses *all* ops, not just
heartbeat. The dual-execution window stays honest under this: the
original worker between lapse and reclaim may still *complete its
work* (the side effects happen), but its ack will not land and the
row is reprocessed at reclaim — at-least-once, as documented. The
reclaim wins atomically when it races the ack (one statement, same
predicate). This state check is engine-pinned in both engines'
implementations (upstream's missing-check defect class D-12 is
*not* inherited).
### 3. Retry and backoff: explicit delay or the queue's curve