Commit Graph
29 Commits
Author SHA1 Message Date
glm-5.3-flash c49befd195 ADR-018: substrate provenance register + cherry-pick procedure (OQ-11 resolved — Phase 1 question set closed) 2026-10-06 07:50:43 +00:00
glm-5.3-flash eba77909a7 ADR-017: contract versioning — core crate's semver is the contract version (OQ-10 resolved) 2026-10-06 07:29:09 +00:00
glm-5.3-flash 8c8fec5cb8 ADR-016: deployment honesty — no runtime capability surface; compile-time identity + matrix (OQ-08 resolved) 2026-10-06 06:29:42 +00:00
glm-5.3-flash 8c4ec48f92 ADR-015: streams depth — carried-metadata keys, global-FIFO ordering, StreamEvent, trim_to (OQ-12 resolved) 2026-10-05 14:15:28 +00:00
glm-5.3-flash 04a04651dc ADR-014: transactional outbox enqueue — outbox_enqueue_tx on TxHandle (OQ-13 resolved) 2026-10-05 13:28:39 +00:00
glm-5.3-flash d401908f13 docs: Phase 1 review round — wake wording honesty, job-handle validity predicate, outbox/streams depth OQs
- C2: 'at-least-once wake delivery' collapsed to 'best-effort hints'
  (ADR-006 §1 + core-contract) — coalescing and the pg no-replay hole
  contradict per-commit wake promises; the guarantee table's row was
  already correct.
- W2: uniform job-handle validity predicate pinned (ADR-010 §2,
  core-contract, queues.md; verification-backlog row): processing
  state + unexpired deadline; D-12's missing-check not inherited.
- W1: outbox run_once worker semantics pinned in core-contract
  (pull op, ack/retry-on-curve, no heartbeat in delivery — honker
  parity, dual-execution window documented).
- W3: named-locks tx-seam posture stated (no lock_tx; acquisition is
  auto-commit; TTL discipline governs).
- C1 -> OQ-12: streams depth (key semantics w/ honker ground, event
  shape, ordering row, retention); method names pinned, depth open.
- New find -> OQ-13: the v1 TxHandle surface cannot express the
  transactional outbox enqueue (derived backing-queue name is
  reserved-prefix-rejected; honker's raw-Transaction seam unavailable);
  option set + decision rule sketched.
- README resolution order refreshed (OQ-06 resolved); ScheduleOpts +
  stream consumption-trigger lines added to core-contract.
2026-10-05 12:50:33 +00:00
glm-5.3-flash 8e68b44194 ADR-013: fold the forked substrate into alkstore-sqlite — no fourth crate
Operator review of ADR-012's fork design re-litigated §1's crate
identity. alkstore-substrate misdescribed what the code is (unpublished,
path-dep-only, one consumer, SQLite-only — not a family-wide substrate);
the mechanical-diff hope was gone at fork time regardless (port deltas,
renames, re-derived half); and the alksocks F-1 lesson applies — a
vendored region under a second, weaker instruction set is a defect seam.
The fork folds into alkstore-sqlite as a bounded module subtree
(src/substrate/); ADR-012 §3–§6 retained verbatim, §2 retained with its
enforcement re-sited from the crate graph to diff fence + review +
contract-suite equivalence pins. OQ-11 item (1) dissolved.
2026-10-05 11:56:01 +00:00
glm-5.3-flash 2949612e2c ADR-012: forked-substrate design — contract-blind boundary, fidelity posture, port deltas
Follow-through on OQ-06/ADR-011: pin the fork's structural decisions
(alkstore-substrate as a vendored path-dep crate, contract-blind API
boundary with contract formulas computed engine-side and pinned
equivalent by the contract suite, keep-the-kept-half API fidelity for
cheap cherry-picks, the W-1/W-2/dead-man's-switch/W-4 port deltas
decided per item, bootstrap re-keying off error-string matching, no
rename migration, deliberate upstream tracking).

Consistency sweep across the doc set for the fork: annotate ADR-003/
005/009/010 and core-contract for superseded ownership facts, fix
schedule-storage table naming (ADR-009 §5, queues.md), re-key ADR-010
§6's notifications hygiene to the at-attach cap the fork scope
realizes, add OQ-11 (scaffold-time residue), and complete both ADR
indexes. Independent review: 0 critical, warnings addressed.
2026-10-05 05:00:55 +00:00
glm-5.3-flash befbe2e714 OQ-06 resolved: honker-core quality read fires the fork trigger (ADR-011)
Quality read of honker-core's watcher/transactional core cross-checked
against the published crates.io artifact: the core itself is clean
(Writer/Readers, polling-watcher failure handling, WatcherDeathGuard
all verified), but published 0.5.0 predates upstream's unreleased fix
train carrying the issue-#133 savepoint hardening (silent job loss in
the dead-letter paths) and five .ok() error swallows — and ADR-010's
queue depth requires engine-owned queue SQL in any posture. Resolution:
fork honker-core at the reference revision, inherit the clean machinery
and test suites, re-derive queue ops on contract v1, rename tables to
__alkstore_*.

- docs/research/quality-read-honker-core.md — full evidence
- docs/architecture/decisions/011-sqlite-substrate-fork.md — decision
- OQ-06 resolved in open-questions.md; ADR-003/005/008, engine-sqlite,
  queues, README annotated for consistency
2026-10-05 03:39:46 +00:00
glm-5.3-flash 79a135c934 docs: resolve OQ-05 + OQ-09 — queue semantics depth (ADR-010) and scheduler collapse (ADR-009)
ADR-009: scheduler collapses into queues — schedule()/unschedule()/
run_schedules (opt-in, no ambient timers), @every-only v1 grammar
(dissolves honker's local-TZ cron brittleness), boundary guarantee
row (at-least-once per boundary, fixed 64-cap catch-up with
skip-forward, row-locked fire tx as engine-generic no-double-fire
floor), __alkstore_scheduler leadership lock, InvalidSpec +
LeadershipLost taxonomy additions.

ADR-010: queue depth pinned engine-uniformly — three-state machine
(pending/processing/dead) with delete-on-ack, get_job sees dead rows,
heartbeat = renewal with late-heartbeat refusal, reclaim-consumes-
an-attempt stated as contract text, equal-jitter exponential backoff
(range definitionally pinned, 1 h cap), QueueOpts stamped onto job
rows at enqueue (no per-queue registry), move-to-dead dead-letter
with retention-sweep support and no redrive API, sweep_expired
carries the no-stranded-rows property (fixes honker's expired-
processing zombie hole — SQLite-side realization rides OQ-06 as a
concrete fork candidate), one engine-owned pg schema, queues are
rows not tables, result-storage cut-flag stands.

Also: full honker-machinery and pgboss-rs reference reads persisted
(docs/research/reference-*.md — the honker defect list pre-stages the
OQ-06 quality read), queues.md rewritten from design-space frame to
resolved-depth spec, core-contract/engines/README/overview/deployment/
ADR-002 propagated.
2026-10-05 03:10:52 +00:00
glm-5.3-flash 7ad8ac56bc docs: resolve OQ-04 — contract v1 pinned (ADR-008): surface partition, TxHandle-on-handle-trait, Wake/WakeReceiver, reserved __alkstore_ namespace, error taxonomy, engine-crate constructors, locks guarantee row 2026-10-05 02:23:15 +00:00
glm-5.3-flash 4391f6e879 docs: open Phase 1 — architecture spec set over the Phase 0 evidence
docs/architecture/ now exists: README index, overview, five component
specs (core-contract, engine-sqlite, engine-postgres, queues,
deployment), ADR-001..007 carrying the Phase 0 resolved decisions
(crate split, feature scope, per-engine drivers, dependency
ownership, wake contract, tx seam), and the centralized
open-questions tracker promotion: OQ-ST-01..08 mirror to OQ-01..08
one-to-one with statuses/resolutions carried; new Phase 1 questions
append (OQ-09 scheduler collapse, OQ-10 contract versioning).
Open Phase 1 work: OQ-04 contract pinning (high), OQ-05 queue
semantics depth (high), OQ-06 honker-core quality read (high;
fork-trigger gate), OQ-08 capability surface, OQ-09, OQ-10.

Erratum fixed in phase-0 OQ-ST-04 (thread-affinity friction is
SQLite-side, previously garbled as pg-side) and a stale scheduler-
boundary pointer corrected in consumer-inventory.md. Two review
passes run (findings: OQ-promotion numbering faithfulness, ADR
back-reference sync) — all critical/warning findings resolved.
2026-10-04 18:13:10 +00:00
glm-5.3-flash db73678090 docs: restructure phase-0 for Phase 1 readiness
- Convergence section added: the assembled recommendation (shape,
  engines, contract starting shape, ownership, scope) in one place
- OQ register given consistent status lines (resolved / open —
  <work-type> / open); OQ-ST-03 deduplicated (two duplicate
  resolution paragraphs collapsed), OQ-ST-07's stale extraction
  residue removed, OQ-ST-08 absorbs POC #2's pg multi-host input
- Front-matter changelog compressed; interface finding promoted to
  a real heading (anchors were informal § prose references)
- Driver-conflict section updated to resolved state, corrections
  folded; Phase 0 plan renumbered and marked final state
- Scope: no content decisions changed — restructure only
2026-10-04 17:53:09 +00:00
glm-5.3-flash f9e350bf22 docs: POC #2 findings verified + folded — OQ-ST-03 closed (per-engine drivers)
Review pass in this repo: contract suite re-verified (11/11 pass under
--test-threads=1 against the harness server; default parallel runs
interfere across tests via the shared db/channels engine_for_test
harness — each test spawns its own listener on poc:q/s/n and truncates
shared tables, so parallel tests receive each other's notifications and
race truncates). Recorded as a harness caveat in the findings with the
Phase 1 note (per-test namespaces), NOT as a contract failure — every
test passes in isolation. Findings invocation note + artifacts section
updated; phase-0 frontmatter carries the verification qualifier.
OQ-ST-03 closure text already folded by the POC session stands.
2026-10-04 17:32:43 +00:00
glm-5.3-flash 80e6af0a0a docs: POC #2 ran and passed — OQ-ST-03 closed (per-engine drivers: tokio-postgres+deadpool for pg), OQ-ST-04 ground complete
Findings: unified surface holds on tokio-postgres with the transactional
property intact (in-tx NOTIFY is commit-atomic; rollback drops all);
LISTEN wake beats poll 5-16x at p50 with 300/300 isolated delivery;
pooled-LISTEN discard (deadpool#360) verified and pinned as our own test;
postgres-notify 0.3.8 evaluated and passed over (lazy reconnect, no
initial-connect script, unquoted identifier LISTENs) in favor of the
~90-line hand-rolled forwarder with test-pinned pitfalls. sqlx PgListener
fallback retired unfired.
2026-10-04 17:25:27 +00:00
glm-5.3-flash 4c144f8f7f docs: fold verified LISTEN research into POC #2 spec
Two claims verified independently before folding: (1) deadpool-postgres
discards async notifications — upstream deadpool-rs/deadpool#360 (open,
Oct 2024) confirms the pool's connect task awaits the connection to
completion, dropping what only poll_message exposes; pooled LISTEN is
lost at recycle. The dedicated non-pooled LISTEN connection is now
upstream-verified required, not spec-preferred. (2) postgres-notify
0.3.8 exists as described (MIT, tokio-postgres, auto-reconnect with
backoff+jitter, multi-channel subscribe_notify, connect_script hook)
— admitted as sub-module L's second arm (hand-rolled forwarder vs
turnkey listener substrate), with in-probe verification required:
docs don't explicitly promise subscription restoration across
reconnect; connect_script is the mechanism; single-maintainer posture
recorded. New property test pinned: pooled-LISTEN-discard assertion
(our own evidence for the #360 behavior, flips if upstream fixes).
Probe 5 updated to budget accounting (listener conn outside the pool).
2026-10-04 16:08:45 +00:00
glm-5.3-flash e18281735e docs: specify POC #2 — Postgres engine posture (poc-pg-posture-spec.md)
Completes OQ-ST-03: one driver posture (tokio-postgres + deadpool, the
POC #5/#7-validated stack) with three sub-modules — L (LISTEN plumbing:
dedicated connection, multi-channel, payload boundary), T (tx-seam over
the pool: caller-owned tx handle vs closure-scoped, both implemented
and compared — direct OQ-ST-04 input), W (wake-vs-poll parity, LISTEN
reconnect + the replay hole honesty). Property tests are the POC #1
suite's pg twin; seam probe mirrors the POC #1 workload for the
cross-engine relative claim. Gate: commit-atomicity via in-tx NOTIFY
(load-bearing), exactly-once claim, seam costs, LISTEN robustness -
failure names the sqlx PgListener fallback posture. Out of scope:
queue semantics depth (OQ-ST-05), pgboss-rs code adoption, multi-host
stress (OQ-ST-08). Register row added, plan updated (POC #2 running
closes OQ-ST-03).
2026-10-04 15:26:01 +00:00
glm-5.3-flash 299603b164 docs: POC #1 findings land — SQLite posture resolved (Arm A: honker-core on our rusqlite)
Findings (poc-sqlite-posture-findings.md, run in a parallel session;
tests re-verified in this session — 4 passing): all three of Arm A's
gate conditions fired in its favor — bridged rusqlite ~2x sqlx
native-async at p50 (B's premise measured false), honker-core's
inherited watcher tighter than a re-derived one (p50 1.40 vs 2.15 ms,
max 29 vs 172 ms, battle-tested failure handling), and the .so runtime
dependency is packaging cost with no compensating advantage.
Transactional property holds identically on both (SQLite's property,
not the posture's). Constraints recorded: honker-core 0.5.0 pins
rusqlite ^0.40.1 (rustc >=1.99); mixed rusqlite+sqlx binaries need a
vendored libsqlite3-sys patch (OQ-ST-02's per-engine-crate split keeps
the engine binary single-driver). Fixed the findings' test-count
discrepancy (4 tests, verified running). Phase-0: OQ-ST-03 SQLite half
resolved (pg half remains), OQ-ST-04/05/06 carry POC input, register
row gains findings link + status, plan step 2 split into done/next,
frontmatter updated, POC crate added to references.
2026-10-04 15:13:25 +00:00
glm-5.3-flash 26ee734ae6 docs: POC #1 ran — SQLite posture verdict Arm A, findings + register note 2026-10-04 11:38:29 +00:00
glm-5.3-flash 4165c94ab0 docs: specify POC #1 — SQLite engine posture comparison (poc-sqlite-posture-spec.md)
Arm A: honker-core linked on our rusqlite (bridge per REQ-TTY-01, honker's watcher). Arm B: honker extension .so over sqlx-sqlite (natively async call path, own watcher, per-pool-connection extension + bootstrap — stress-testing what the CI proof script doesn't cover: pool wiring, lost connections, full surface). Option 2 (honker-rs-as-substrate) dropped from scope with reasoning: its mutex-pinned sync transaction model is subsumed by both other postures' trade space. Five probes (async seam, watcher, transactional contract, packaging, cross-process interop), a decision gate including a legitimate hybrid verdict, and out-of-scope boundaries (postgres side, full surface, extension-as-consumer-feature regardless of outcome). Phase-0: POC register added, plan/frontmatter updated; AGENTS.md: POC-register convention codified.
2026-10-04 09:31:46 +00:00
glm-5.3-flash 8331a96817 docs: OQ-ST-03 gains the explicit SQLite option space (three postures)
Operator-named options, verified against the honker checkout @ f4e53c6:
(1) honker-core on our own rusqlite connection (attach_honker_functions,
the alknet-filesystem POC's usage); (2) honker-rs as the SQLite
substrate (max reuse, least control — own connections, mutex-pinned
transactions, sync-under-async-core); (3) raw SQL over sqlx-sqlite with
the honker loadable extension — CI-proven in the checkout's own ORM
proof suite (scripts/proof/orm/rust: transactional enqueue natively
async, rollback-drops-job asserted), which dissolves most of the async
tension on the SQLite side at the cost of a runtime .so dependency and
watcher ownership moving in-crate. Options 1/3 are compatible with
tokio-postgres on the postgres side under the OQ-ST-02 split. First-POC
candidate named: options-1-vs-3 comparison on the same surface.
2026-10-04 09:26:25 +00:00
glm-5.3-flash 69fd5f4eda docs: record alktty REQ-TTY-01 as family precedent for OQ-ST-03's async question
The async-facing-trait + sync-bridge posture (blocking impl on dedicated
threads/spawn_blocking feeding tokio channels, documented as a supported
strategy not a workaround) is already family-standard twice over: alktty
REQ-TTY-01 and alkblobs' spawn_blocking-in-engine-impls execution
posture. Recorded verbatim-sourced in OQ-ST-03; reframes the honker-rs
sync→async port as bridge-at-the-trait-seam vs native-async-rewrite and
weakens sqlx's main differentiator on the sqlite side. alktty added to
references.
2026-10-04 09:21:45 +00:00
glm-5.3-flash 7ddd4e472b docs: resolve OQ-ST-02 — reactive-core + engine crates (operator decision)
Supersedes the inventory's single-crate lean (which was inductive from
'feature sets do not diverge'). Reason recorded: the split isolates the
engines' real asymmetry of work — sqlite rides honker's machinery as
the baseline; postgres is the build-heavy side (LISTEN/NOTIFY +
pg-boss-family schema work) — and makes future engines additive rather
than feature-graph edits. The inventory's uniform-feature-family fact
stands, re-read as 'the core contract stays small'; correction noted in
both documents. Phase-0 plan updated (step 2 resolved, step 3 references
the core-crate trait surface).
2026-10-04 09:13:50 +00:00
glm-5.3-flash f4e24f321d docs: streams upgraded to in-scope (operator-authority record)
The inventory graded streams absent because no paused consumer document
names it; the operator correction: type-filtered event watching from
several places (e.g. repo-change subscriptions in a git app at
gitea/gitlab scale) is a basic reactivity requirement — and notify
(fire-and-forget, no replay) cannot serve subscriptions honestly.
The wanters are applications above the paused crates, which is why the
docs don't carry the row.

Inventory: streams row recorded on operator authority (the REQ-2
recording convention from alkblobs requirements.md), confidence system
gains the operator-authority grade; rate-limits becomes the sole
first-cut candidate. phase-0: OQ-ST-01 summary and OQ-ST-04's
contract-candidates updated to match.
2026-10-04 08:47:19 +00:00
glm-5.3-flash d44dfb5a08 docs: consumer inventory answers OQ-ST-01; phase-0 consumes it
consumer-inventory.md: per-feature scope synthesis over the paused
consumers' written artifacts (alkfs phase-0, alkgit architecture,
alkblobs ADRs, alknet-filesystem POC) — dissolves the circular
'deferring to consumers who can't run until we exist' framing.
notify/locks pinned-or-documented (alkfs invalidation + writer coord,
alkblobs fleet sweeper); queues/outbox documented (alkfs sync outbox,
alkblobs embedder-owned cadence); scheduler documented-thin; streams/
rate-limits/result-storage have no named consumer — kept per working
posture with cut flags, to revisit before implementation.

phase-0.md: OQ-ST-01 answered by the inventory; OQ-ST-02 narrowed
(uniform feature family across engines favors single-crate shape);
OQ-ST-07 sharpened (no consumer needs the loadable-extension surface —
cut-only decision); OQ-ST-04 contract-pinning scoped to inventory rows;
plan step 1 marked done; references extended.

AGENTS.md: architecture context gains the inventory with its
add-a-row-before-assuming rule.
2026-10-04 05:27:22 +00:00
glm-5.3-flash 1cb007d894 docs: tidy phase-0 corrections, pin reference revisions by path+rev
- complete the dangling honker prior-art sentence; fold the pg_notify
  posture into the interface-finding paragraph instead of the
  'restated conclusion' trailing paragraph
- reference checkouts are read freely but not for direct dependency
  use; published versions unless vendored/forked (alksocks precedent)
- pin honker @ f4e53c6 (russellromney/honker) and pgboss-rs @ 98f7d9e
  by path+revision per AGENTS.md §3
- reflow one hard-broken hyphen in the honker-rs limitations list
2026-10-03 17:10:18 +00:00
glm-5.3-flash 8e6da2f6c9 phase-0: interface finding — honker-rs surface as the unified-API candidate
Read the four honker.dev guides (queues/streams/pubsub/scheduler) +
packages/honker-rs/src/lib.rs (v0.5.0, 1706 lines):

- honker's Rust binding exposes the exact surface shape alkstore wants
  (queue claim/ack/visibility, streams with tx-aware offsets, notify/
  listen, leader-elected scheduler, outbox, locks/rate-limits/results)
  — the unified-API question shifts from shape-invention to contract-
  pinning on that surface (new 'Interface finding' section)
- honker's own processing-guarantees table (per-binding auto-checkpoint
  vs manual offset save) is the named seam a single-crate contract
  cleans up
- honker-rs is sync-only (std threads, no tokio) — SQLite side is a
  port-and-adapt under any posture, folded into driver-conflict
  corrections + OQ-ST-03/04/06 refinements
- pgboss-rs LISTEN/NOTIFY absence (verified earlier) now stated as the
  substantive fork-or-derive comparison point (OQ-ST-05)
2026-10-03 16:50:54 +00:00
glm-5.3-flash f6531b5532 phase 0 setup: agent defs cleaned, AGENTS.md, initial phase-0.md draft
- sdd_process.md + coordinator.md: stale @alkdev/alkblobs name from the
  copy fixed to @alkdev/alkstore
- implementation-specialist.md: copied alkcall-family conventions
  (OperationEnv, vendored core types, BAST/wire formats) replaced with
  crate-neutral rules + an ADR-escalation rule
- code-reviewer.md: stale tls/iroh/acme feature list removed; anyhow
  posture corrected; db-specific review checks added
- AGENTS.md: phase-0 posture (no crate yet, no README, POC/discipline
  conventions, OQ-ST-NN register, reference checkouts)
- docs/research/phase-0.md: initial draft — vision, prior art (honker,
  pgboss-rs read incl. verified pgboss-rs LISTEN/NOTIFY absence), open
  questions OQ-ST-01..08, phase 0 plan
2026-10-03 16:36:46 +00:00
glm-5.3-flash 5bcd1b7a2f init 2026-10-03 15:23:54 +00:00