diff --git a/docs/reviews/003-wave-5-general-review.md b/docs/reviews/003-wave-5-general-review.md index 3bf8c4e..20b6dfe 100644 --- a/docs/reviews/003-wave-5-general-review.md +++ b/docs/reviews/003-wave-5-general-review.md @@ -40,6 +40,32 @@ SKIP posture, but reviewers should set the env before believing a pg claim: this review's first baseline run reported zero pg tests executed (25 suite tests "passing" in 0.02 s). +## Env-variable boundary (verified — family posture) + +The alk* family rule is "nothing important goes in env vars" (alkvault +README), with the alkhttp spelling as the wire-facing case ("no handler +reads `std::env::var`"). Verified this session by grep across the whole +workspace: **every `env::var` read lives in a test target** — the pg +gate modules (`store/*_tests.rs`, `tests/schema_tests.rs`, +`tests/contract_suite.rs`). Production paths (`alkstore/src`, both +engines' machinery, the contract suite, the constructors) are env-free +— the only `std::env` uses in the other crates are `std::env::temp_dir()` +inside test modules for temp-file paths, not configuration. +Configuration reaches production exclusively through `PgOpts` / +`SqliteOpts` / DSN arguments passed by the caller's own config layer +(`engine-postgres.md`, ADR-008 §6; deployment.md's config table carries +no env entry) — the engines never consult the process environment, so +no credential (or any setting) can arrive implicitly. + +For wave 6 (release readiness / prepublish) this boundary is an +explicit re-check item, not a settled fact: re-run the +no-env-in-production grep, and pin the boundary in the engine specs / +deployment matrix in one sentence ("env reads are harness-only; +production configuration is the opts-constructor surface"). Should a +future consumer-facing surface ever want env conveniences, the family +pattern is caller-side: the app's own config layer reads env (or +vault/config file) and hands the store's opts its values. + ## Verdict **No correctness or security defects found; wave 5's deliverables are @@ -214,4 +240,6 @@ No changes required to keep wave 5's verdict standing. For wave 6's window: Finding 1 is a decomposable small task (transient-fault seam + retry/exhaustion pin); Findings 2–3 can ride the same task or be accepted with the code-read as their pin — either way the disposition -should be recorded. Findings 4–5 need no work. \ No newline at end of file +should be recorded. Findings 4–5 need no work. The env-variable +boundary section above folds into wave 6's release-readiness pass as a +verified-now / re-check-at-prepublish item. \ No newline at end of file