85 Commits
Author SHA1 Message Date
glm-5.3-flash 2a2ad7e11f Contract-suite wake row (task suite-wake-rows): wake_receiver_shapes — the wake contract's pinnable core, tolerance-bounded to state outcomes (never delivery counts or latencies): a pre-attached listener receives a wake after a committed notify on its channel through all three recv forms (recv/try_recv/recv_timeout), every wake's channel field matching the listened channel (the one piece of semantic content a wake carries, ADR-008 §3); a three-notify burst floors at one wake — never an exact per-notify count (coalescing the documented engine asymmetry: SQLite's 1-slot feed vs pg per-notify, the row pins the floor not the shape); a listener attached after a commit never sees that commit's notify — recv_timeout idles a 400 ms absence window (a 300 ms pre-settle sleep closes SQLite's watcher baseline race: the last_version baseline is store-open-captured, so an unconsumed commit's version change would fire one late tick at the new subscriber indistinguishable from replay; pg's gap-commit no-replay hole and SQLite's burst coalescing both legal under the pin); and the channel-scoped leg — a foreign-channel notify never surfaces a wake naming it (SQLite's same-commit overtrigger may deliver but carries only the listened channel; the pg LISTEN fanout skips foreign channels; the reserved reconnect straggler tolerated), with a same-channel positive control proving the silence is scoping not a dead listener. The failure-surface close arms (SQLite watcher-death recv()->None, pg synthetic reconnect-wake) stay pinned engine-side and in receiver_close_and_save_arms's disposal leg — cross-referenced in the doc comment, not re-pinned. Stamped ADR-006 + ADR-008 §3. Wired into both engines' suite targets (SQLite tokio test, pg harness_row!), 24 rows per column up from 23. Dispositions in Notes: the backlog row stays in core-contract.md's inventory (flushes at review-wave-5's stable gate, like the other discharged rows), the absence windows are single recv_timeout calls (the documented Ok(None) idle arm as the bounded wait), and the scoping leg's observable is the channel field not absence (SQLite overtrigger makes an absence-only pin vacuous there). Verified: SQLite column green server-less, pg column green vs harness (postgres/poc@:15432), 3 solo re-runs of the row per engine (determinism), cargo test -p alkstore-sqlite -p alkstore-postgres green (SQLite 189+24, pg 121+24+9), workspace cargo test green (12 binaries), clippy -D warnings, fmt clean 2026-10-10 07:12:31 +00:00
glm-5.3-flash 98de4a49cd Contract-suite lock rows (task suite-lock-rows): two version-stamped rows discharging the lock backlog rows — lock_ttl_expiry_and_reacquisition (the ADR-008 §7 guarantee row: a held lock excludes a second acquirer (contender None); after a 1 s TTL the exclusion lapses silently — no revocation event, no error — and a second owner acquires; the original holder's post-expiry renew is refused (false, the lost-it arm); the second owner's release frees the name for a third acquirer, which consumes cleanly; tolerance-sleep posture, state outcomes only; ADR-008 §7 + ADR-019 §1, duration-guard legs cross-referenced to duration_refusal_on_non_positive_ttl) and concurrent_try_lock_loser_is_a_value (the contention posture: four sequential contenders — two owners, repeated — against a held lock all land the clean None value, never Database, never a busy-throw; the backlog row's SQLite busy-path open question answered: no divergence from the pg reference; release-then-contend cycle proves the loser path leaves no state blocking a later acquire, granted to a former loser and consumed cleanly; ADR-008 §5 + §7 + ADR-019 §1) — wired into both engines' suite targets (SQLite tokio tests, pg harness_row!s), 23 rows per column up from 21. Dispositions in Notes: no divergence found (no fix/ADR call needed), ADR-023 §2 excluded from stamps (its guard property is the duration-refusal row's, cross-referenced), the backlog parenthetical re-acquire-does-not-refresh-TTL stays engine-pinned, renew-refusal asserted after the second owner's re-acquisition (strongest form), contenders distinct-owner only (same-owner re-acquire grants per the inherited substrate shape), and one unreproducible first-cold-run pg failure recorded (message lost to truncation; 13 subsequent clean runs incl. concurrent SQLite+pg — no timing hazard identified, the lapse assertions are post-sleep state outcomes). Drive-by: alkstore-contract-suite's tokio dep gained the macros feature — a pre-existing compile break in the crate's own tests/suite_harness.rs (since 7f749ac) failed the harness target and the workspace test gate on HEAD; test-side non-event (ADR-017 §2 class 4). Verified: cargo test -p alkstore-sqlite -p alkstore-postgres green (SQLite 121+23+9, pg 189+23 vs harness server on :15432, server-less pg skips clean), workspace cargo test green (12 binaries), clippy -D warnings, fmt clean 2026-10-10 06:58:54 +00:00
glm-5.3-flash 1d05df200e Contract-suite stream rows (task suite-stream-rows): two version-stamped rows discharging ADR-015's backlog legs — stream_ordering_equivalence (a keyed/unkeyed interleaved publish sequence of 6 reads back in the same order on every read form: whole + cursor-paginated + mid-stream read_since, read_from_consumer fresh and from a mid checkpoint, and a subscriber's attach drain; offsets strictly increasing per stream — per-stream relative order, absolute values explicitly not cross-pinned (pg bigserial vs SQLite AUTOINCREMENT); key round-trips exactly None/Some on every read form including the explicit-None keyed publish form; stream carries the name; created_at tolerance-bounded informational, never an ordering assertion; ADR-015 §4/§3/§1, byte-exactness and tx-seam legs cross-referenced to the payload-round-trip and keyed-tx-atomicity rows) and trim_to_semantics (the full ADR-015 §5 row: exact-boundary trim — the horizon's own row deletes, horizon+1 survives, repeated trim 0; survivors keep offsets; reads from a trimmed-away region resume at the horizon's first remaining row; a below-horizon saved checkpoint stays a get_offset-visible position marker with read_from_consumer and a fresh subscribe both resuming at the horizon, never a renumbered past; a pre-trim subscriber's above-horizon checkpoint keeps its place; a pre-attached listener idles across the trim in a 400 ms bounded window — no dedicated wake, SQLite's spurious watcher hint contract-legal and delivering nothing; ADR-015 §5/ADR-019 §6, negative-horizon/immutability legs cross-referenced to extent_clamp_semantics). Wired into both engines' suite targets (SQLite tokio tests, pg harness_row!s). Dispositions in Notes: the attach-drain pattern leads with a blocking recv() before the try_recv drain (engines deliver the attach read asynchronously); the pg LISTEN channel is mechanism-named and database-wide so concurrent suite rows' wakes cross schemas — safe by construction (wakes re-drain own-schema storage only, delivering nothing), no "events" rename needed. Verified: sqlite suite 21/21, pg suite 21/21 vs harness (postgres/poc@:15432, 7 consecutive full runs), 5 focused --test-threads=6 runs of the two rows per engine, workspace build/test green, clippy -D warnings, fmt clean 2026-10-10 06:33:27 +00:00
glm-5.3-flash 360e71e51e Contract-suite tx commit-atomicity rows (task suite-tx-commit-atomicity-rows): the N-5 panic-probe admission in properties.rs's module doc (spawned with_tx task joined via JoinError::is_panic — catch_unwind around an async closure cannot see the panic point across an await; post-panic assertions read-only until convergence, single-task drive, no race window; ADR-017 §2 class 4) and three version-stamped rows: outbox_enqueue_tx_commit_atomicity (rollback drops the backing-queue job with the business write — get_job_tx-gone + run_once claims nothing; commit makes the job claimable exactly when the business write commits, real delivery through the RecordingDelivery closure with job-id identity, derived __alkstore_outbox:mail queue, exact payload, 60/5/5 stamps, consumed-after-ack; ADR-014 §1, ADR-010 §3a, ADR-021 §4, ADR-007), publish_with_key_tx_commit_atomicity (rollback drops the keyed event with the business write, key round-tripping inside the tx; commit surfaces it to read_since and a post-commit subscriber attach with the key round-tripping; ADR-015 §2/§4, ADR-021 §4, ADR-007), and with_tx_panicking_closure_rolls_back (N-5's probe against real engines: the panicking closure writes all four kinds then panics mid-flight; panic surfaces via the join; no-ghost reads converge with begin_tx granting every iteration; pre-panic listener silence on the notified channel; ghost never claimable; fresh with_tx commits through the same seam — both engines green; ADR-007, ADR-021 §4) — wired into both engines' suite targets (SQLite tokio tests, pg harness_row!s). Dispositions recorded in Notes: the 60/5/5 stamp inspection rides the delivery handle's job() because get_job cannot target the reserved derived backing queue through the contract surface (exemplar row pins the rejection; engine-side raw-row probes stayed put), the panic row's notify leg is a windowed silence (SQLite's wake overtriggers on any commit — the fully cross-engine notify-ghost pin rides the engines' rollback-ghosts twins, the suite's drop-rollback row made the same call), the closure tail routes through a #[cold] mid_flight_panic -> Error helper (a bare Err(panic!()) tail trips unreachable_code under -D warnings), and the post-panic convergence loop is the suite-side bounded wait (state outcomes only, begin_tx doubling as the seam-still-grants probe). Verified: sqlite suite 19/19, pg suite 19/19 vs harness twice (postgres/poc@:15432) + solo re-runs of each new row per engine (determinism), workspace build/test green, clippy -D warnings, fmt clean 2026-10-10 06:17:18 +00:00
glm-5.3-flash 7f749ac673 Contract-suite scheduler rows (task suite-scheduler-rows): the determinism-posture extension in properties.rs's module doc (runner-driving rows admitted — spawned run_schedules(stop) tasks on a core StopToken against state outcomes only, elapsed-boundary-band tolerances, never timing-value assertions, never two-task race windows; ADR-017 §2 class 4) and three version-stamped rows: scheduler_boundary_fires (fired jobs are ordinary claimable work with ScheduleOpts over the plain-queue derived defaults 300/9/5/none + payload exact, clean-stop Ok(()), fired count inside the elapsed-boundary band — no double-fire per boundary while one leader runs; ADR-009 §3/§4, ADR-020 §3, ADR-019 §4), scheduler_bounded_catchup (runner-less downtime proves no fire without a runner, ≥3 elapsed boundaries replay boundary-by-boundary bounded below the 64-cap and inside the band; ADR-009 §4), scheduler_leadership_discipline (two spawned runners on one store: exactly one Ok(())/Err(LeadershipLost) pair by value, no duplicated fires inside the band; ADR-009 §1/§6, ADR-019 §4) — wired into both engines' suite targets (SQLite tests, pg harness_row!s), suite tokio dep added for the runner rows. Dispositions recorded in Notes: the beyond-cap skip-forward leg stays pinned engine-side (both engines' scheduler tests already backdate next_fire_at directly — catch_up_replays_up_to_the_cap_then_skips_forward twins), and the pg fire-wake parity gap is not demanded by these rows' shapes (claim-polling observation only; the one-call wake_tx disposition recorded for a later task). Verified: sqlite suite 16/16, pg suite 16/16 vs harness twice + solo re-runs of the three rows per engine (determinism), workspace build/test green, clippy -D warnings, fmt clean 2026-10-10 06:04:30 +00:00
glm-5.3-flash 5c9ae6a7fc Contract-suite queue-depth rows (task suite-queue-depth-rows): the job-handle validity predicate row (in-window heartbeat/ack landing, late-heartbeat/post-lapse-ack/retry/fail refusals past a 1 s stamp with the row untouched, ack_batch per-id predicate live-1/lapsed-0/nonexistent-0, fail(None)→"failed" and retry-at-budget→"max attempts exceeded"), the ADR-010 depth row (reclaim consumes an attempt with claimed_at/deadline refreshed and the original holder refusing, reclaim-exhaustion dead-lettering with the pre-claim sweep — get_job-visible "max attempts exceeded"+died_at, cancel unconditional delete with the not-an-interrupt refusal shape plus pending/dead/missing arms), and the no-stranded-rows sweep row (both states move with "expired", unexpired/never-expiring untouched, retention TTL enforcing with the moved+deleted sum, None=forever) — each version-stamped per the suite convention (ADR-010 §1–§5, ADR-019 §3, ADR-008 §5), wired into both engines' suite targets (SQLite tokio tests, pg harness_row!s). M-1's retention-failure pin dispositioned engine-side per the task's honest call: the storage-level DELETE failure is not injectable through the contract surface, so it lands in the SQLite substrate's trigger seam (sweep_rolls_back_the_retention_half_with_the_move — the move half rolls back with the retention half), with the pg twin verified structurally (both halves inside in_tx's frame) and the disposition recorded in the task Notes. Verified: sqlite suite 13/13, pg suite 13/13 vs harness twice (postgres/poc@:15432), substrate sweep-rollback tests 4/4, workspace build/test green, clippy -D warnings, fmt clean 2026-10-10 05:50:26 +00:00
glm-5.3-flash 250511d480 decompose wave 5 — contract suite: audit-first split of the verification backlog (engines' columns already discharge most rows; map in review-wave-5's appendix), seven mechanism-grouped suite-row tasks (queue depth, scheduler, tx commit-atomicity, streams, locks, wakes, opts/backoff equivalence), two engine-side hardening tasks (sqlite commit-error arm, pg F-1 defense-in-depth), and the review-wave-5 gate that flips the engine specs to stable 2026-10-10 05:37:53 +00:00
glm-5.3-flash 9a00fb8a7e Review gate — wave-4 fix batch passed: all seven pg-fix resolutions verified against review 002's failure mechanisms (code-read + live gates), one minor doc mismatch fixed inline (outbox wake comment's 'scheduler's fire-wake' claim — the tick fires issue no wake and schedule() can never target a reserved backing queue); no pinned posture regressed; pg suite green vs harness twice + compose determinism 20/20 re-verified; wave 5 may decompose (task review-wave-4-fixes) 2026-10-10 05:18:27 +00:00
glm-5.3-flash 49face898d docs alignment: v1 TLS posture owned by deployment.md, QueueOpts numeric consumer-obligation notes (task pg-fix-docs-alignment, review 002 Finding 6 remainder)
- forwarder.rs's ListenerConnection doc corrected: NoTls is hardwired on
  every connection path (pooled, listener, reconnect) — the pooled path
  never rode the consumer's Config sslmode (a sslmode=require DSN fails
  at connect); grep-audited no other in-crate doc repeats the claim
- PgOpts doc carries the corrected one-line TLS pointer (engine-crate-
  docs posture, ADR-016 §2)
- deployment.md: new 'TLS posture (v1)' subsection (NoTls everywhere,
  sslmode=require DSN fails at connect, topology-level confidentiality
  is the v1 substitute, TLS a post-v1 deployment concern) and a new
  'Consumer-obligation notes on engine options' section carrying the
  QueueOpts trusted-as-given note with code-verified per-field symptoms
  (max_attempts <= 0: never claimed, dead-lettered at the next claim
  call's pre-claim sweep; negative visibility: instantly-reclaimable
  claims; negative retention: every dead row at the next sweep_expired)
  plus the PgOpts::max_size 0-guard counter-case; frontmatter advanced
- alkstore/src/opts.rs: QueueOpts struct doc mirrors the
  consumer-obligation note (ADR-023 §2 scoping: the domain table covers
  trait-surface arguments, not consumer-constructed constants)
- cross-file doc sweep over the fix batch's touched files (forwarder,
  tx, scheduler, store) found no further doc-behavior mismatch
- gates: cargo build / clippy --all-targets -D warnings / fmt --check
  all green (doc-only, no test touched)
2026-10-10 05:08:27 +00:00
glm-5.3-flash 40625090f6 pg queue/tx/notify dedupe + doc truth-telling: job_from_row has one owner (queue.rs, tx.rs imports it) and get_job_tx reuses live_columns()/dead_columns() instead of inlining the 18-column lists — the contract-pinned Job shape now has exactly one decode owner (ADR-012 §2); sweep_expired's doc states the moved + retention-deleted sum in the in_tx multi-statement frame (the sum the SQLite twin returns — the doc was the only liar); notify.rs's closed-store listen error routes through the shared database_error helper; bridge_capacity() is a const with its rationale doc carried. No behavior change — identical SQL strings, error shapes, and capacity. (task pg-fix-dedupe-cleanup, review 002 minor notes + Finding 6 queue bullet) 2026-10-10 05:04:09 +00:00
glm-5.3-flash 12d0497b1c pg: scheduler runner resilience — quarantine bad rows, retry transient ticks
Review 002 Finding 5 (+ Finding 6's scheduler doc bullet):

- tick: a due row whose stored spec fails @every re-parse is
  quarantined, not fatal — logged with the schedule name, boundary
  advanced strictly past now (skip-forward at min interval), tick tx
  still commits, remaining due rows proceed
- run_schedules: a pool/database tick failure retries 3x with a short
  doubling backoff (250ms -> 1s cap) before the loop exits Err; the
  top-of-iteration renew keeps owning the lease-loss decision
- exiting errors carry schedule-name/tick-phase context in the source
  chain (ErrorContext wrapper; Database's Display is opaque)
- module docs: the Err-exit TTL-lapse posture stated; the false
  per-slice soonest re-read claim corrected to the honest slice/idle
  posture (60s idle floor)

Tests: behavioral quarantine pin (tampered via direct SQL UPDATE;
runner survives to clean Ok(()), other schedule fires, bad row never
fires, boundary advanced) and a server-less retry-policy pin.
Verified: cargo test -p alkstore-postgres green against the harness
server (121+10+9), build/clippy -D warnings/fmt green server-less.
2026-10-10 04:58:43 +00:00
glm-5.3-flash ace94f0e13 pg forwarder: generation-tagged commands — a reconnect drops its predecessor's queued commands before replaying, closing the stale-UNLISTEN window (a stale UNLISTEN replayed after the snapshot's re-issued LISTENs silently cancelled a re-registered channel, its wakes lost until the next reconnect); the reconcile decision is the pure helper (stale LISTEN and UNLISTEN dropped, current-generation commands replay in queue order, dropped stale LISTENs ack the transient mid-LISTEN error) pinned by a four-combination server-less unit test (replay-proven against the neutered shape); 'queued commands replay harmlessly' doc corrected and the post-reconnect LISTEN-set invariant (server LISTEN set = registry snapshot, dead-generation commands can't undo it) stated in the module + loop docs (task pg-fix-stale-unlisten, review 002 Finding 4) 2026-10-10 04:49:35 +00:00
glm-5.3-flash 86719a39cc pg open path: validate max_size > 0 at entry (typed Database before any round trip — 'max_size: 0' previously hung open forever at the bootstrap checkout, deadpool 0.13/0.14 neither validates nor defaults timeouts) and append the engine's '-c synchronous_commit' SET to the DSN's parse-carried options (was: setter replaced them, a silent override); pins: the zero-guard test (bounded by inner timeout, server-less-capable — fires pre-connect) and the DSN-options coexistence test (consumer SHOW statement_timeout + engine SHOW synchronous_commit, both settings) (task pg-fix-open-path, review 002 Finding 3 + options note) 2026-10-09 23:00:35 +00:00
glm-5.3-flash 9a5d1f4705 pg tx producer paths wake commit-atomically: publish_with_key_tx/enqueue_tx/outbox_enqueue_tx issue pg_notify on their mechanism-named channel (stream name / queue name / derived backing queue) inside the caller's tx — empty payload, best-effort log-and-swallow, no double-wake on the auto-commit paths; shared tx::wake_tx owner + module-doc section pinning the semantics; new tx_tests harness test pinning pre-commit silence, commit delivery on all three channels, and rollback silence; F-1 engine arm retired in review-wave-4 + implementation.md records (tx_publishes_compose_with_the_handle deterministic: 20 solo runs green; pg suite 116/116 x2 vs harness) (task pg-fix-tx-wake, review 002 Finding 2) 2026-10-09 22:38:38 +00:00
glm-5.3-flash 7ae426a01d pg forwarder: the reconnect arm retries failed connects until success or shutdown — one failed connect no longer kills the loop permanently; every loop exit path releases the fanout sender via the shared-slot drop guard (receivers-terminal-iff-loop-gone); reconnect-config test seam + failed-connect pins: six-cycle exhausted-backoff server-less unit, pre-flip abort, guard drop, and the harness end-to-end unreachable-outage → full-recovery test (bug replay-proven against the old shape) (task pg-fix-forwarder-reconnect, review 002 Finding 1) 2026-10-09 22:31:05 +00:00
glm-5.3-flash e067357de9 Wave-4 fix-batch decomposition: seven pg-fix tasks + review-wave-4-fixes gate from the general review (002) — forwarder reconnect retry (Finding 1, with the failed-connect test seam), tx pg_notify wakes retiring F-1's engine arm (Finding 2), max_size/DSN-options open path (Finding 3), stale-UNLISTEN generation drop (Finding 4), scheduler quarantine/retry (Finding 5), decode dedupe + cleanups, doc alignment; wave 5 gates on the two HIGH fixes landing 2026-10-09 22:11:13 +00:00
glm-5.3-flash 89828170f4 Wave-4 general review (002): two live-proven bugs — the forwarder's permanent death after one failed reconnect (the failure arm the gate's test never covered) and the tx enqueue/publish paths' missing pg_notify wake (F-1's root cause, engine-side) — plus a max_size:0 open-hang, two narrow robustness gaps, doc mismatches, and the decode-duplication smell; reviews renumbered 001/002 per the alk* numbering pattern (references updated) 2026-10-09 22:01:04 +00:00
glm-5.3-flash f9bd5716fa Wave-4 review gate: conformance code-read clean (0 findings) — forwarder/seam integrity, ADR-023/016 follow-through, backoff + boundary math vs ADR text, schema posture, 10-row backlog column green against the harness server; the flagged tx-compose flake reproduced twice, root cause unresolved, recorded as F-1 for wave 5's suite hardening + three no-action notes (task review-wave-4) 2026-10-09 11:43:46 +00:00
glm-5.3-flash fb37da617d Postgres engine integration: StoreFactory (fresh schema per open, owned idempotent CASCADE teardown, isolation/idempotence pinned), the engine's backlog column (all ten rows green against the harness server — exemplar verified, the three ADR-023 rows verified not rewritten, the five engine-scoped rows, the new pg-arm PayloadTooLarge row discharging the SQLite task's deferred adoption), test-observation accessors cfg(test)-gated with the unused PgStore::new cut, stale stub-era doc text removed, lib docs stating the finished-engine posture (task pg-engine-integration) 2026-10-09 10:22:25 +00:00
glm-5.3-flash 77619c5e93 Postgres engine: scheduler + outbox — schedule (validation triad, the pg-owned @every-only parser, upsert over the schedule table), unschedule, run_schedules (leadership via the engine's lock machinery on __alkstore_scheduler with a per-instance owner token, in-sleep lease renewals, the row-locked FOR UPDATE tick in one pool tx — fire enqueues + boundary advance + soonest read commit together — the 64-boundary catch-up cap with skip-forward, clean stop / Err(LeadershipLost) arms), outbox (validated constructor, enqueue into the derived __alkstore_outbox:{name} with the 60/5/5 stamps + max_attempts override, run_once ack/retry-curve/false over the ordinary claim machinery, no engine-issued heartbeat) (task pg-engine-scheduler-outbox) 2026-10-09 09:53:48 +00:00
glm-5.3-flash c3591c2d44 Postgres engine: named locks — try_lock (validated entry, duration guard, opportunistic expiry-delete + insert-or-reacquire + holder read-back over the locks table), PgLockHandle (full-window renew, consuming owner-scoped release with both boolean arms), same-owner re-acquire matched to the SQLite arm, silent-lapse posture pinned, second open re-acquires after expiry (task pg-engine-locks) 2026-10-09 09:17:39 +00:00
glm-5.3-flash 3dd83791ff Postgres engine: queues — Queue (validated constructor over the handle's QueueOpts stamps), the FOR UPDATE SKIP LOCKED claim (one statement, the pre-claim exhausted-reclaimable sweep in the atomic claim frame), JobHandle (one-shot ack/retry/fail in tx frames under the uniform validity predicate, absolute-reset heartbeat, engine-side equal-jitter backoff), dead-letter moves transactional (the #133 class excluded), worker-less ack_batch, unconditional cancel, dead-visible get_job, both-states+retention sweep, best-effort queue-channel wake, wake-driven claim loop pinned (task pg-engine-queues) 2026-10-09 08:44:59 +00:00
glm-5.3-flash cb067bb4be Postgres engine: streams — StreamHandle (auto-commit publishes + best-effort pg_notify wake, ASC reads with the extent guard, monotone offsets, pool-connection trim) and the durable subscribe receiver (async bridge, wake-driven re-drains, reconnect gap-heal, shutdown-only terminal close, stateless idle wake runtime for the sync save) (task pg-engine-streams) 2026-10-09 08:05:34 +00:00
glm-5.3-flash 8f5c2add5e Postgres engine: LISTEN forwarder full behavior + notify/listen — wake contract pg arm
- notify: auto-commit pg_notify path, 8000-byte typed client-side check
  through the tx seam's NOTIFY_PAYLOAD_LIMIT (one limit owner), closed-store
  fail-closed before payload work
- listen: acked synchronous channel registration (listen starts-from-now —
  a notify racing the LISTEN cannot be lost), refcounted ChannelSet
  (UNLISTEN at last-subscriber drop), PgWakeReceiver bridging Wake { channel }
  only, channel-scoped fanout + reserved reconnect-wake to every subscriber,
  Lagged(n) surfaced-not-silent
- receiver close semantics (ADR-021 §5 pg arm): stays open across forwarder
  reconnects, terminal None only at engine shutdown — Forwarder::shutdown
  takes the fanout sender so receiver-held Arc lifetimes can't pin the
  broadcast open
- tests: wake-arrives, 7999/8000/8002 boundary both entry points, no-replay
  during connection gaps, backend-kill reconnect through the receiver stack,
  drop-unregisters (behavioral probe — pg_listening_channels is per-session),
  validation both paths, the two POC deadlock pitfalls re-pinned, 11 new
  tests green against the harness server, gates green server-less

(task pg-engine-notify-listen)
2026-10-09 07:37:56 +00:00
glm-5.3-flash cf5ceea70e Postgres engine: transactional seam — begin_tx, PgTxHandle, all eleven *_tx methods with drop=rollback detached teardown, probe-pinned unknowable-state discard arms, engine-side resolution arithmetic (task pg-engine-seam-tx) 2026-10-09 06:50:53 +00:00
glm-5.3-flash c6a7eeaa45 Postgres engine: open constructor, PgOpts, pool + listener wiring — forwarder skeleton with the POC-pinned pitfalls structurally excluded, seam error mappings, wave-3 stub surface (task pg-engine-open-opts) 2026-10-09 06:00:31 +00:00
glm-5.3-flash 2f1353bd41 Postgres engine: schema bootstrap — engine-owned schema, table family, idempotent DDL, schema-prefixed indexes (task pg-engine-schema) 2026-10-09 05:11:48 +00:00
glm-5.3-flash 4caea21098 Wave 4 decomposed: Postgres engine — 11 tasks (schema, open/opts, seam, forwarder, mechanisms, scheduler/outbox, integration, review gate); plan synced 2026-10-08 22:49:00 +00:00
glm-5.3-flash ecb8211694 Wave-3 review gate: contract conformance clean; two findings fixed inline — substrate boundary move (open_writer_connection → seam.rs), writer-slot release on with_writer/begin/commit error arms + regression tests (task review-wave-3) 2026-10-08 20:57:10 +00:00
glm-5.3-flash a82c543b40 SQLite engine integration: lint removal, contract-suite adoption, backlog column (task sqlite-engine-integration)
- Remove the wave-2 lint suppressions from substrate/mod.rs; the
  six genuinely dead surfaces the removal exposed are cut, not
  suppressed, and registered D-32..D-36 in PROVENANCE.md
  (arg_opt_i64, ops::now_unix, queue_next_claim_at,
  Writer::try_acquire, UpdateWatcher::spawn,
  SharedUpdateWatcher::new); test-observation items
  (subscriber_count, the poll-interval default re-export) are
  honestly #[cfg(test)]-gated
- Contract suite: eight new version-stamped backlog rows
  (extent-clamp + boundary totality, duration-refusal,
  encode_payload round-trip, PayloadTooLarge-never-produced SQLite
  arm, drop=rollback no-ghosts, in-tx read-your-own-writes,
  enqueue-opts resolution, receiver close/save arms)
- Fix the exemplar row's real-engine sequencing defect: the held tx
  handle across the with_tx leg deadlocked any single-writer factory
  (mock-invisible; ADR-007's parking is the pinned behavior)
- SQLite factory: SqliteFactory in the new tests/contract_suite.rs
  target; all nine rows green against it; the factory contract
  (isolation + idempotent teardown) pinned
- Engine lib docs: the single-host and writer-parking posture
  statements surfaced under # Posture
- Gates: build/test/clippy -D warnings/fmt green; coverage 93.6%
  lines, misses confined to error arms
2026-10-08 16:15:43 +00:00
glm-5.3-flash 8502a51af7 SQLite engine: scheduler + outbox — schedule/unschedule/run_schedules leader loop, outbox enqueue/run_once (task sqlite-engine-scheduler-outbox) 2026-10-08 14:08:43 +00:00
glm-5.3-flash 1edcb0e27d SQLite engine: named locks — try_lock, SqliteLockHandle, duration guards (task sqlite-engine-locks) 2026-10-08 13:37:22 +00:00
glm-5.3-flash 513df0b311 SQLite engine: queues — Queue/JobHandle over the writer slot, engine-side backoff curve, extent guard (task sqlite-engine-queues)
queue.rs: SqliteQueueHandle (QueueOpts-carrying, stamp-resolving
enqueue over the seam's shared resolution arithmetic), claim_one/
claim_batch through the writer slot with ADR-023 §2's extent guard
(n <= 0 -> empty Vec at the trait-impl entry), the full JobHandle impl
(one-shot ack/retry/fail as 'static boxed futures, repeatable absolute
reset heartbeat, substrate's uniform validity predicate), and the
engine-owned equal-jitter exponential backoff (std-only RandomState
hash jitter, integerized inclusive [ceil(half), cap], 1-hour cap;
no rand dep - documented).

ack_batch loses its substrate worker filter (register D-31 - ADR-019
§1's worker-less batch form); job_from_json decode + stamps_with_
override moved to their one owners (queue.rs / resolution.rs);
reader-pool helpers lifted from stream.rs into seam.rs. Store::queue
wired; 10 acceptance tests (lifecycle/stamps, extent guard,
exactly-once under concurrency, backoff range + cap + override,
validity predicate + reclaim, dead-letter defaults + get_job
visibility, cancel, ack_batch, sweep both-states + retention,
validation + closed-store). Workspace 25+3+171 green, clippy
-D warnings, fmt clean; sqlite suite 4x green.
2026-10-08 12:59:57 +00:00
glm-5.3-flash 4913302b47 SQLite engine: streams — StreamHandle, extent-guarded reads, trim, durable subscribe (task sqlite-engine-streams) 2026-10-08 12:30:32 +00:00
glm-5.3-flash 8efe0c2e78 SQLite engine: notify/listen — auto-commit notify, watcher-fanout WakeReceiver bridge (task sqlite-engine-notify-listen) 2026-10-08 12:12:34 +00:00
glm-5.3-flash c38033db1a SQLite engine: transactional seam — begin_tx, writer-slot lease, all eleven *_tx methods (task sqlite-engine-seam-tx) 2026-10-08 11:50:16 +00:00
glm-5.3-flash 7d400906f5 SQLite engine open: SqliteOpts, connection architecture, spawn_blocking seam posture (task sqlite-engine-open-opts)
- SqliteOpts (poll_interval: Option<Duration>, None = 1 ms shipping
  default ADR-023 §4; max_readers, DEFAULT_MAX_READERS = 8; opts
  exemption from non_exhaustive per ADR-017 §3)
- open(path, opts) -> Box<dyn Store>: writer slot, reader pool,
  SharedUpdateWatcher with fallible spawn mapped W-2-style into
  Error::Database; plain-path posture (ADR-023 §3) pinned by test
- Substrate delta D-30: open_conn_bootstrapped — every connection
  (writer and pooled readers) carries the full bootstrap surface
  (pragmas, notify, alkstore functions, schema) per engine-sqlite.md;
  lineage opened readers pragmas-only. Registered in PROVENANCE.md
- spawn_blocking seam helper + error mappings (string/rusqlite ->
  Database, source chains preserved); helper cfg(test)-gated until
  sqlite-engine-seam-tx wires the trait impls
- Store trait stubbed with Database errors (no panics); close()/Drop
  join the watcher, clear subscribers (death-guard), close pool+writer
- 15 new tests (open boot, watcher fanout/death-close, cadence
  accounting, plain-path literal filename, :memory:, pool bounding,
  drop teardown, seam smoke incl. panic mapping); gates green
2026-10-08 11:25:16 +00:00
glm-5.3-flash 5474141f2b Core: #[doc(hidden)] engine-side constructors for Job, StreamEvent, Schedule, Wake
Task core-engine-value-constructors (wave-3 pre-work). All four value
types are #[non_exhaustive] (ADR-017 §3), so downstream engine crates
cannot struct-literal-construct them (E0639). Give engines a sanctioned
construction path without weakening the consumer posture: pub
#[doc(hidden)] full-field constructors (Job::from_row, StreamEvent::
from_row, Schedule::new, Wake::new), each doc-commented as engine-
construction-only — not contract surface, not covered by ADR-017's
semver-minor field-addition promise; a field addition changes the
signature and is a lockstep-duty event (ADR-017 §5). Core tests now
construct through the new constructors; no behavior change.
2026-10-08 11:07:53 +00:00
glm-5.3-flash 1269246faf Wave-3 decomposition: SQLite engine tasks (open/opts, seam+tx, mechanisms, integration, review gate) + core value-constructor pre-work; plan synced for waves-1-2 review + ADR-023 follow-through 2026-10-08 10:57:29 +00:00
glm-5.3-flash 44637eea5b Fourth review round (ADR-023): encode_payload typed (Codec), numeric-argument domains pinned by kind, plain-path SQLite open (URI flag dropped, D-29), watcher cadence posture — waves-1-2 general-review findings 2026-10-08 10:17:56 +00:00
glm-5.3-flash ee7871d25d General review waves 1-2: sweep_expired savepoint scope fix (M-1), coverage adds (arg_opt_i64, StopToken Debug), review report (docs/reviews/) 2026-10-08 09:36:24 +00:00
glm-5.3-flash af5b59ec8e Wave-2 review gate: scheduler fire expires resolution fix (D-27, ADR-020 §2), pressure-test lock quality (D-28), lineage diff re-verified clean (task review-wave-2) 2026-10-08 09:17:47 +00:00
glm-5.3-flash 6618e13c3a Fork gate: provenance register completion + test floor green (ADR-018 §2, ADR-011 tests clause, task fork-provenance-and-floor) 2026-10-08 04:19:54 +00:00
glm-5.3-flash 915641bfe6 Fork re-derivation: queue ops on contract v1 (stamps, per-row claim visibility, savepoint-guarded dead-letter, both-states sweep, dead-visible get_job, @every scheduler) — ADR-010 §1–§5/§3a/§8, ADR-009 §2–§4, ADR-011/012, task fork-rederive-queue-ops 2026-10-08 04:10:43 +00:00
glm-5.3-flash 43a135c453 Fork port: connection architecture + watcher machinery into the substrate (ADR-011/012 §3–§5, task fork-port-connection-watcher)
Kept half of the honker-core fork lands in
alkstore-sqlite/src/substrate/ as schema.rs / watcher.rs / ops.rs
(register D-17): PRAGMA/WAL open posture + set_journal_mode_wal retry,
Writer, Readers, the polling watcher family (SharedUpdateWatcher,
WatcherDeathGuard, stat_identity dead-man's switch), in_savepoint/
UnwindUndo mutation discipline, REAL-coercion arg helpers, notify
scalar + notifications table with the ADR-010 §6 at-attach pruning
cap, stream functions, lock functions.

Port deltas (ADR-012 §4): W-1 bounded reconnect backoff
(MAX_RECONNECT_TICKS=100), W-2 fallible watcher spawn (Result; engine
maps to Database at open in wave 3), dead-man's-switch panic replaced
by log-and-exit through the ordinary death path — death still closes
every subscriber (pinned by test, join now Ok). Table family
_honker_* -> __alkstore_* (D-10); duplicate-column race swallow
re-keyed to pragma_table_info (D-11); scheduler cron_expr -> spec;
fresh-only bootstrap, append-column migrations kept, column-order
equality pinned. Drops confirmed absent: cron, kernel/shm backends,
rate-limit/result tables, superseded queue functions (D-01..D-04).
file-id retained for the kept dead-man's switch (D-18).

43 engine-crate tests green (adapted inherited suites + delta tests +
cross-mechanism pressure); cargo build/clippy -D warnings/fmt clean.
PROVENANCE.md register updated to the landed state (D-01..D-20).
2026-10-08 03:25:48 +00:00
glm-5.3-flash 2d855b9546 Fork scaffold: substrate subtree, provenance register, dual-license notice (ADR-011/012/013/018, task fork-substrate-scaffold) 2026-10-08 03:01:51 +00:00
glm-5.3-flash 8b03960e39 Wave-1 review gate: validation coverage fixes (unschedule, handle-level consumer-local entry points), ADR-008 §4 annotations (whitespace-exclusion, class scope), task check-line staleness fix (ADR-008/009/021, core-contract) 2026-10-07 16:15:48 +00:00
glm-5.3-flash 621415cc47 Contract-suite scaffold: alkstore-contract-suite crate + ADR-022 (suite layout decision), engine dev-dep edges (ADR-017 §4.2 discharged, ADR-012 §2 mirror) 2026-10-07 16:03:00 +00:00
glm-5.3-flash eefee9ec1d Core trait surface: Store, TxHandle, mechanism handles, receivers, with_tx (ADR-007 §with_tx, ADR-008 §1–§3/§8, ADR-009 §1/§6, ADR-014, ADR-015 §2, ADR-019 §1–§6, ADR-021 §1/§4/§5) 2026-10-07 15:50:02 +00:00
glm-5.3-flash 92615f7b7d Core value types: opts structs, Job/JobState, Schedule, StreamEvent, Wake, StopToken, payload encode/decode (ADR-008 §1/§3, ADR-010 §3, ADR-015 §3, ADR-017 §3, ADR-019 §3/§4, ADR-020 §1–§4, ADR-021 §2) 2026-10-07 15:08:26 +00:00
glm-5.3-flash 74105a16ae Core error taxonomy + name validation (ADR-008 §4/§5, ADR-017 §3); AGENTS.md updated to Phase 1 posture 2026-10-07 15:04:04 +00:00
glm-5.3-flash 34e0b9732d Scaffold Cargo workspace: alkstore core + sqlite/postgres engine stubs (ADR-001) 2026-10-07 14:57:34 +00:00
glm-5.3-flash 49743c690e Implementation plan: wave-based decomposition; waves 1-2 decomposed (11 tasks)
docs/plans/implementation.md records the wave structure (core ->
substrate fork || pg engine -> sqlite engine -> contract suite ->
release), the decided points (contract-suite layout = option (a),
engine-tests vs equivalence-suite split, no CI, mem-engine/fuzzing
deferrals surfaced), and the review-gate rhythm.

Wave 1 (foundations): workspace scaffold, core errors/validation,
value types, trait surface, contract-suite scaffold (+ADR-022),
review gate.
Wave 2 (substrate fork): fork scaffold/provenance, connection+watcher
port, queue-op re-derivation on contract v1, provenance/floor close,
review gate.
2026-10-07 14:37:31 +00:00
glm-5.3-flash 83767e880b Third review round follow-through: enqueue_tx stamp source, sweep_expired handle form, with_tx signature, and B-block ambiguity pins 2026-10-07 14:01:36 +00:00
glm-5.3-flash 08dc1bf011 ADR-021: third review round — tx-read methods, Job.claimed_at, schedule() queue validation, drop=rollback, receiver arms 2026-10-07 06:25:39 +00:00
glm-5.3-flash 8323a7853e ADR-019/020: second review round — handle surfaces, enqueue semantics, payload bridge + mechanical fixes
ADR-019: mechanism-handle traits pinned (Queue/StreamHandle/Outbox/
Lock/JobHandle), Job/Schedule struct shapes, worker_id claimant
identity, core StopToken — closes the 'pin at implementation' residue
before ADR-017's amend-in-place window terminates at first release.

ADR-020: delay-wins-over-run_at precedence (honker parity), relative
expires, scheduler-fired stamps from derived queue defaults, serde_json
byte-level payload encoding.

Mechanical: overview/engine-postgres ADR tables completed through 020,
core-contract Errors section re-framed to class-1, ADR-014 sketch
annotated with publish_with_key_tx, ADR-015 status dated, reserved-
namespace kinds list normalized to six kinds, redrive gate wording
aligned, broken link fixed, StopToken deferral superseded in ADR-009.
2026-10-06 13:06:23 +00:00
glm-5.3-flash c49befd195 ADR-018: substrate provenance register + cherry-pick procedure (OQ-11 resolved — Phase 1 question set closed) 2026-10-06 07:50:43 +00:00
glm-5.3-flash eba77909a7 ADR-017: contract versioning — core crate's semver is the contract version (OQ-10 resolved) 2026-10-06 07:29:09 +00:00
glm-5.3-flash 8c8fec5cb8 ADR-016: deployment honesty — no runtime capability surface; compile-time identity + matrix (OQ-08 resolved) 2026-10-06 06:29:42 +00:00
glm-5.3-flash 8c4ec48f92 ADR-015: streams depth — carried-metadata keys, global-FIFO ordering, StreamEvent, trim_to (OQ-12 resolved) 2026-10-05 14:15:28 +00:00
glm-5.3-flash 04a04651dc ADR-014: transactional outbox enqueue — outbox_enqueue_tx on TxHandle (OQ-13 resolved) 2026-10-05 13:28:39 +00:00
glm-5.3-flash d401908f13 docs: Phase 1 review round — wake wording honesty, job-handle validity predicate, outbox/streams depth OQs
- C2: 'at-least-once wake delivery' collapsed to 'best-effort hints'
  (ADR-006 §1 + core-contract) — coalescing and the pg no-replay hole
  contradict per-commit wake promises; the guarantee table's row was
  already correct.
- W2: uniform job-handle validity predicate pinned (ADR-010 §2,
  core-contract, queues.md; verification-backlog row): processing
  state + unexpired deadline; D-12's missing-check not inherited.
- W1: outbox run_once worker semantics pinned in core-contract
  (pull op, ack/retry-on-curve, no heartbeat in delivery — honker
  parity, dual-execution window documented).
- W3: named-locks tx-seam posture stated (no lock_tx; acquisition is
  auto-commit; TTL discipline governs).
- C1 -> OQ-12: streams depth (key semantics w/ honker ground, event
  shape, ordering row, retention); method names pinned, depth open.
- New find -> OQ-13: the v1 TxHandle surface cannot express the
  transactional outbox enqueue (derived backing-queue name is
  reserved-prefix-rejected; honker's raw-Transaction seam unavailable);
  option set + decision rule sketched.
- README resolution order refreshed (OQ-06 resolved); ScheduleOpts +
  stream consumption-trigger lines added to core-contract.
2026-10-05 12:50:33 +00:00
glm-5.3-flash 8e68b44194 ADR-013: fold the forked substrate into alkstore-sqlite — no fourth crate
Operator review of ADR-012's fork design re-litigated §1's crate
identity. alkstore-substrate misdescribed what the code is (unpublished,
path-dep-only, one consumer, SQLite-only — not a family-wide substrate);
the mechanical-diff hope was gone at fork time regardless (port deltas,
renames, re-derived half); and the alksocks F-1 lesson applies — a
vendored region under a second, weaker instruction set is a defect seam.
The fork folds into alkstore-sqlite as a bounded module subtree
(src/substrate/); ADR-012 §3–§6 retained verbatim, §2 retained with its
enforcement re-sited from the crate graph to diff fence + review +
contract-suite equivalence pins. OQ-11 item (1) dissolved.
2026-10-05 11:56:01 +00:00
glm-5.3-flash 2949612e2c ADR-012: forked-substrate design — contract-blind boundary, fidelity posture, port deltas
Follow-through on OQ-06/ADR-011: pin the fork's structural decisions
(alkstore-substrate as a vendored path-dep crate, contract-blind API
boundary with contract formulas computed engine-side and pinned
equivalent by the contract suite, keep-the-kept-half API fidelity for
cheap cherry-picks, the W-1/W-2/dead-man's-switch/W-4 port deltas
decided per item, bootstrap re-keying off error-string matching, no
rename migration, deliberate upstream tracking).

Consistency sweep across the doc set for the fork: annotate ADR-003/
005/009/010 and core-contract for superseded ownership facts, fix
schedule-storage table naming (ADR-009 §5, queues.md), re-key ADR-010
§6's notifications hygiene to the at-attach cap the fork scope
realizes, add OQ-11 (scaffold-time residue), and complete both ADR
indexes. Independent review: 0 critical, warnings addressed.
2026-10-05 05:00:55 +00:00
glm-5.3-flash befbe2e714 OQ-06 resolved: honker-core quality read fires the fork trigger (ADR-011)
Quality read of honker-core's watcher/transactional core cross-checked
against the published crates.io artifact: the core itself is clean
(Writer/Readers, polling-watcher failure handling, WatcherDeathGuard
all verified), but published 0.5.0 predates upstream's unreleased fix
train carrying the issue-#133 savepoint hardening (silent job loss in
the dead-letter paths) and five .ok() error swallows — and ADR-010's
queue depth requires engine-owned queue SQL in any posture. Resolution:
fork honker-core at the reference revision, inherit the clean machinery
and test suites, re-derive queue ops on contract v1, rename tables to
__alkstore_*.

- docs/research/quality-read-honker-core.md — full evidence
- docs/architecture/decisions/011-sqlite-substrate-fork.md — decision
- OQ-06 resolved in open-questions.md; ADR-003/005/008, engine-sqlite,
  queues, README annotated for consistency
2026-10-05 03:39:46 +00:00
glm-5.3-flash 79a135c934 docs: resolve OQ-05 + OQ-09 — queue semantics depth (ADR-010) and scheduler collapse (ADR-009)
ADR-009: scheduler collapses into queues — schedule()/unschedule()/
run_schedules (opt-in, no ambient timers), @every-only v1 grammar
(dissolves honker's local-TZ cron brittleness), boundary guarantee
row (at-least-once per boundary, fixed 64-cap catch-up with
skip-forward, row-locked fire tx as engine-generic no-double-fire
floor), __alkstore_scheduler leadership lock, InvalidSpec +
LeadershipLost taxonomy additions.

ADR-010: queue depth pinned engine-uniformly — three-state machine
(pending/processing/dead) with delete-on-ack, get_job sees dead rows,
heartbeat = renewal with late-heartbeat refusal, reclaim-consumes-
an-attempt stated as contract text, equal-jitter exponential backoff
(range definitionally pinned, 1 h cap), QueueOpts stamped onto job
rows at enqueue (no per-queue registry), move-to-dead dead-letter
with retention-sweep support and no redrive API, sweep_expired
carries the no-stranded-rows property (fixes honker's expired-
processing zombie hole — SQLite-side realization rides OQ-06 as a
concrete fork candidate), one engine-owned pg schema, queues are
rows not tables, result-storage cut-flag stands.

Also: full honker-machinery and pgboss-rs reference reads persisted
(docs/research/reference-*.md — the honker defect list pre-stages the
OQ-06 quality read), queues.md rewritten from design-space frame to
resolved-depth spec, core-contract/engines/README/overview/deployment/
ADR-002 propagated.
2026-10-05 03:10:52 +00:00
glm-5.3-flash 7ad8ac56bc docs: resolve OQ-04 — contract v1 pinned (ADR-008): surface partition, TxHandle-on-handle-trait, Wake/WakeReceiver, reserved __alkstore_ namespace, error taxonomy, engine-crate constructors, locks guarantee row 2026-10-05 02:23:15 +00:00
glm-5.3-flash 4391f6e879 docs: open Phase 1 — architecture spec set over the Phase 0 evidence
docs/architecture/ now exists: README index, overview, five component
specs (core-contract, engine-sqlite, engine-postgres, queues,
deployment), ADR-001..007 carrying the Phase 0 resolved decisions
(crate split, feature scope, per-engine drivers, dependency
ownership, wake contract, tx seam), and the centralized
open-questions tracker promotion: OQ-ST-01..08 mirror to OQ-01..08
one-to-one with statuses/resolutions carried; new Phase 1 questions
append (OQ-09 scheduler collapse, OQ-10 contract versioning).
Open Phase 1 work: OQ-04 contract pinning (high), OQ-05 queue
semantics depth (high), OQ-06 honker-core quality read (high;
fork-trigger gate), OQ-08 capability surface, OQ-09, OQ-10.

Erratum fixed in phase-0 OQ-ST-04 (thread-affinity friction is
SQLite-side, previously garbled as pg-side) and a stale scheduler-
boundary pointer corrected in consumer-inventory.md. Two review
passes run (findings: OQ-promotion numbering faithfulness, ADR
back-reference sync) — all critical/warning findings resolved.
2026-10-04 18:13:10 +00:00
glm-5.3-flash db73678090 docs: restructure phase-0 for Phase 1 readiness
- Convergence section added: the assembled recommendation (shape,
  engines, contract starting shape, ownership, scope) in one place
- OQ register given consistent status lines (resolved / open —
  <work-type> / open); OQ-ST-03 deduplicated (two duplicate
  resolution paragraphs collapsed), OQ-ST-07's stale extraction
  residue removed, OQ-ST-08 absorbs POC #2's pg multi-host input
- Front-matter changelog compressed; interface finding promoted to
  a real heading (anchors were informal § prose references)
- Driver-conflict section updated to resolved state, corrections
  folded; Phase 0 plan renumbered and marked final state
- Scope: no content decisions changed — restructure only
2026-10-04 17:53:09 +00:00
glm-5.3-flash f9e350bf22 docs: POC #2 findings verified + folded — OQ-ST-03 closed (per-engine drivers)
Review pass in this repo: contract suite re-verified (11/11 pass under
--test-threads=1 against the harness server; default parallel runs
interfere across tests via the shared db/channels engine_for_test
harness — each test spawns its own listener on poc:q/s/n and truncates
shared tables, so parallel tests receive each other's notifications and
race truncates). Recorded as a harness caveat in the findings with the
Phase 1 note (per-test namespaces), NOT as a contract failure — every
test passes in isolation. Findings invocation note + artifacts section
updated; phase-0 frontmatter carries the verification qualifier.
OQ-ST-03 closure text already folded by the POC session stands.
2026-10-04 17:32:43 +00:00
glm-5.3-flash 80e6af0a0a docs: POC #2 ran and passed — OQ-ST-03 closed (per-engine drivers: tokio-postgres+deadpool for pg), OQ-ST-04 ground complete
Findings: unified surface holds on tokio-postgres with the transactional
property intact (in-tx NOTIFY is commit-atomic; rollback drops all);
LISTEN wake beats poll 5-16x at p50 with 300/300 isolated delivery;
pooled-LISTEN discard (deadpool#360) verified and pinned as our own test;
postgres-notify 0.3.8 evaluated and passed over (lazy reconnect, no
initial-connect script, unquoted identifier LISTENs) in favor of the
~90-line hand-rolled forwarder with test-pinned pitfalls. sqlx PgListener
fallback retired unfired.
2026-10-04 17:25:27 +00:00
glm-5.3-flash 4c144f8f7f docs: fold verified LISTEN research into POC #2 spec
Two claims verified independently before folding: (1) deadpool-postgres
discards async notifications — upstream deadpool-rs/deadpool#360 (open,
Oct 2024) confirms the pool's connect task awaits the connection to
completion, dropping what only poll_message exposes; pooled LISTEN is
lost at recycle. The dedicated non-pooled LISTEN connection is now
upstream-verified required, not spec-preferred. (2) postgres-notify
0.3.8 exists as described (MIT, tokio-postgres, auto-reconnect with
backoff+jitter, multi-channel subscribe_notify, connect_script hook)
— admitted as sub-module L's second arm (hand-rolled forwarder vs
turnkey listener substrate), with in-probe verification required:
docs don't explicitly promise subscription restoration across
reconnect; connect_script is the mechanism; single-maintainer posture
recorded. New property test pinned: pooled-LISTEN-discard assertion
(our own evidence for the #360 behavior, flips if upstream fixes).
Probe 5 updated to budget accounting (listener conn outside the pool).
2026-10-04 16:08:45 +00:00
glm-5.3-flash e18281735e docs: specify POC #2 — Postgres engine posture (poc-pg-posture-spec.md)
Completes OQ-ST-03: one driver posture (tokio-postgres + deadpool, the
POC #5/#7-validated stack) with three sub-modules — L (LISTEN plumbing:
dedicated connection, multi-channel, payload boundary), T (tx-seam over
the pool: caller-owned tx handle vs closure-scoped, both implemented
and compared — direct OQ-ST-04 input), W (wake-vs-poll parity, LISTEN
reconnect + the replay hole honesty). Property tests are the POC #1
suite's pg twin; seam probe mirrors the POC #1 workload for the
cross-engine relative claim. Gate: commit-atomicity via in-tx NOTIFY
(load-bearing), exactly-once claim, seam costs, LISTEN robustness -
failure names the sqlx PgListener fallback posture. Out of scope:
queue semantics depth (OQ-ST-05), pgboss-rs code adoption, multi-host
stress (OQ-ST-08). Register row added, plan updated (POC #2 running
closes OQ-ST-03).
2026-10-04 15:26:01 +00:00
glm-5.3-flash 299603b164 docs: POC #1 findings land — SQLite posture resolved (Arm A: honker-core on our rusqlite)
Findings (poc-sqlite-posture-findings.md, run in a parallel session;
tests re-verified in this session — 4 passing): all three of Arm A's
gate conditions fired in its favor — bridged rusqlite ~2x sqlx
native-async at p50 (B's premise measured false), honker-core's
inherited watcher tighter than a re-derived one (p50 1.40 vs 2.15 ms,
max 29 vs 172 ms, battle-tested failure handling), and the .so runtime
dependency is packaging cost with no compensating advantage.
Transactional property holds identically on both (SQLite's property,
not the posture's). Constraints recorded: honker-core 0.5.0 pins
rusqlite ^0.40.1 (rustc >=1.99); mixed rusqlite+sqlx binaries need a
vendored libsqlite3-sys patch (OQ-ST-02's per-engine-crate split keeps
the engine binary single-driver). Fixed the findings' test-count
discrepancy (4 tests, verified running). Phase-0: OQ-ST-03 SQLite half
resolved (pg half remains), OQ-ST-04/05/06 carry POC input, register
row gains findings link + status, plan step 2 split into done/next,
frontmatter updated, POC crate added to references.
2026-10-04 15:13:25 +00:00
glm-5.3-flash 26ee734ae6 docs: POC #1 ran — SQLite posture verdict Arm A, findings + register note 2026-10-04 11:38:29 +00:00
glm-5.3-flash 4165c94ab0 docs: specify POC #1 — SQLite engine posture comparison (poc-sqlite-posture-spec.md)
Arm A: honker-core linked on our rusqlite (bridge per REQ-TTY-01, honker's watcher). Arm B: honker extension .so over sqlx-sqlite (natively async call path, own watcher, per-pool-connection extension + bootstrap — stress-testing what the CI proof script doesn't cover: pool wiring, lost connections, full surface). Option 2 (honker-rs-as-substrate) dropped from scope with reasoning: its mutex-pinned sync transaction model is subsumed by both other postures' trade space. Five probes (async seam, watcher, transactional contract, packaging, cross-process interop), a decision gate including a legitimate hybrid verdict, and out-of-scope boundaries (postgres side, full surface, extension-as-consumer-feature regardless of outcome). Phase-0: POC register added, plan/frontmatter updated; AGENTS.md: POC-register convention codified.
2026-10-04 09:31:46 +00:00
glm-5.3-flash 8331a96817 docs: OQ-ST-03 gains the explicit SQLite option space (three postures)
Operator-named options, verified against the honker checkout @ f4e53c6:
(1) honker-core on our own rusqlite connection (attach_honker_functions,
the alknet-filesystem POC's usage); (2) honker-rs as the SQLite
substrate (max reuse, least control — own connections, mutex-pinned
transactions, sync-under-async-core); (3) raw SQL over sqlx-sqlite with
the honker loadable extension — CI-proven in the checkout's own ORM
proof suite (scripts/proof/orm/rust: transactional enqueue natively
async, rollback-drops-job asserted), which dissolves most of the async
tension on the SQLite side at the cost of a runtime .so dependency and
watcher ownership moving in-crate. Options 1/3 are compatible with
tokio-postgres on the postgres side under the OQ-ST-02 split. First-POC
candidate named: options-1-vs-3 comparison on the same surface.
2026-10-04 09:26:25 +00:00
glm-5.3-flash 69fd5f4eda docs: record alktty REQ-TTY-01 as family precedent for OQ-ST-03's async question
The async-facing-trait + sync-bridge posture (blocking impl on dedicated
threads/spawn_blocking feeding tokio channels, documented as a supported
strategy not a workaround) is already family-standard twice over: alktty
REQ-TTY-01 and alkblobs' spawn_blocking-in-engine-impls execution
posture. Recorded verbatim-sourced in OQ-ST-03; reframes the honker-rs
sync→async port as bridge-at-the-trait-seam vs native-async-rewrite and
weakens sqlx's main differentiator on the sqlite side. alktty added to
references.
2026-10-04 09:21:45 +00:00
glm-5.3-flash 7ddd4e472b docs: resolve OQ-ST-02 — reactive-core + engine crates (operator decision)
Supersedes the inventory's single-crate lean (which was inductive from
'feature sets do not diverge'). Reason recorded: the split isolates the
engines' real asymmetry of work — sqlite rides honker's machinery as
the baseline; postgres is the build-heavy side (LISTEN/NOTIFY +
pg-boss-family schema work) — and makes future engines additive rather
than feature-graph edits. The inventory's uniform-feature-family fact
stands, re-read as 'the core contract stays small'; correction noted in
both documents. Phase-0 plan updated (step 2 resolved, step 3 references
the core-crate trait surface).
2026-10-04 09:13:50 +00:00
glm-5.3-flash f4e24f321d docs: streams upgraded to in-scope (operator-authority record)
The inventory graded streams absent because no paused consumer document
names it; the operator correction: type-filtered event watching from
several places (e.g. repo-change subscriptions in a git app at
gitea/gitlab scale) is a basic reactivity requirement — and notify
(fire-and-forget, no replay) cannot serve subscriptions honestly.
The wanters are applications above the paused crates, which is why the
docs don't carry the row.

Inventory: streams row recorded on operator authority (the REQ-2
recording convention from alkblobs requirements.md), confidence system
gains the operator-authority grade; rate-limits becomes the sole
first-cut candidate. phase-0: OQ-ST-01 summary and OQ-ST-04's
contract-candidates updated to match.
2026-10-04 08:47:19 +00:00
glm-5.3-flash d44dfb5a08 docs: consumer inventory answers OQ-ST-01; phase-0 consumes it
consumer-inventory.md: per-feature scope synthesis over the paused
consumers' written artifacts (alkfs phase-0, alkgit architecture,
alkblobs ADRs, alknet-filesystem POC) — dissolves the circular
'deferring to consumers who can't run until we exist' framing.
notify/locks pinned-or-documented (alkfs invalidation + writer coord,
alkblobs fleet sweeper); queues/outbox documented (alkfs sync outbox,
alkblobs embedder-owned cadence); scheduler documented-thin; streams/
rate-limits/result-storage have no named consumer — kept per working
posture with cut flags, to revisit before implementation.

phase-0.md: OQ-ST-01 answered by the inventory; OQ-ST-02 narrowed
(uniform feature family across engines favors single-crate shape);
OQ-ST-07 sharpened (no consumer needs the loadable-extension surface —
cut-only decision); OQ-ST-04 contract-pinning scoped to inventory rows;
plan step 1 marked done; references extended.

AGENTS.md: architecture context gains the inventory with its
add-a-row-before-assuming rule.
2026-10-04 05:27:22 +00:00
glm-5.3-flash 1cb007d894 docs: tidy phase-0 corrections, pin reference revisions by path+rev
- complete the dangling honker prior-art sentence; fold the pg_notify
  posture into the interface-finding paragraph instead of the
  'restated conclusion' trailing paragraph
- reference checkouts are read freely but not for direct dependency
  use; published versions unless vendored/forked (alksocks precedent)
- pin honker @ f4e53c6 (russellromney/honker) and pgboss-rs @ 98f7d9e
  by path+revision per AGENTS.md §3
- reflow one hard-broken hyphen in the honker-rs limitations list
2026-10-03 17:10:18 +00:00
glm-5.3-flash 8e6da2f6c9 phase-0: interface finding — honker-rs surface as the unified-API candidate
Read the four honker.dev guides (queues/streams/pubsub/scheduler) +
packages/honker-rs/src/lib.rs (v0.5.0, 1706 lines):

- honker's Rust binding exposes the exact surface shape alkstore wants
  (queue claim/ack/visibility, streams with tx-aware offsets, notify/
  listen, leader-elected scheduler, outbox, locks/rate-limits/results)
  — the unified-API question shifts from shape-invention to contract-
  pinning on that surface (new 'Interface finding' section)
- honker's own processing-guarantees table (per-binding auto-checkpoint
  vs manual offset save) is the named seam a single-crate contract
  cleans up
- honker-rs is sync-only (std threads, no tokio) — SQLite side is a
  port-and-adapt under any posture, folded into driver-conflict
  corrections + OQ-ST-03/04/06 refinements
- pgboss-rs LISTEN/NOTIFY absence (verified earlier) now stated as the
  substantive fork-or-derive comparison point (OQ-ST-05)
2026-10-03 16:50:54 +00:00
glm-5.3-flash f6531b5532 phase 0 setup: agent defs cleaned, AGENTS.md, initial phase-0.md draft
- sdd_process.md + coordinator.md: stale @alkdev/alkblobs name from the
  copy fixed to @alkdev/alkstore
- implementation-specialist.md: copied alkcall-family conventions
  (OperationEnv, vendored core types, BAST/wire formats) replaced with
  crate-neutral rules + an ADR-escalation rule
- code-reviewer.md: stale tls/iroh/acme feature list removed; anyhow
  posture corrected; db-specific review checks added
- AGENTS.md: phase-0 posture (no crate yet, no README, POC/discipline
  conventions, OQ-ST-NN register, reference checkouts)
- docs/research/phase-0.md: initial draft — vision, prior art (honker,
  pgboss-rs read incl. verified pgboss-rs LISTEN/NOTIFY absence), open
  questions OQ-ST-01..08, phase 0 plan
2026-10-03 16:36:46 +00:00
glm-5.3-flash 5bcd1b7a2f init 2026-10-03 15:23:54 +00:00