- forwarder.rs's ListenerConnection doc corrected: NoTls is hardwired on
every connection path (pooled, listener, reconnect) — the pooled path
never rode the consumer's Config sslmode (a sslmode=require DSN fails
at connect); grep-audited no other in-crate doc repeats the claim
- PgOpts doc carries the corrected one-line TLS pointer (engine-crate-
docs posture, ADR-016 §2)
- deployment.md: new 'TLS posture (v1)' subsection (NoTls everywhere,
sslmode=require DSN fails at connect, topology-level confidentiality
is the v1 substitute, TLS a post-v1 deployment concern) and a new
'Consumer-obligation notes on engine options' section carrying the
QueueOpts trusted-as-given note with code-verified per-field symptoms
(max_attempts <= 0: never claimed, dead-lettered at the next claim
call's pre-claim sweep; negative visibility: instantly-reclaimable
claims; negative retention: every dead row at the next sweep_expired)
plus the PgOpts::max_size 0-guard counter-case; frontmatter advanced
- alkstore/src/opts.rs: QueueOpts struct doc mirrors the
consumer-obligation note (ADR-023 §2 scoping: the domain table covers
trait-surface arguments, not consumer-constructed constants)
- cross-file doc sweep over the fix batch's touched files (forwarder,
tx, scheduler, store) found no further doc-behavior mismatch
- gates: cargo build / clippy --all-targets -D warnings / fmt --check
all green (doc-only, no test touched)