Commit Graph

  • 5c03fb2130 pg suite-infra hardening (task pg-suite-infra-hardening): the wave-4 review's F-1 defense-in-depth candidates — must_recv_event re-shaped from the 20 ms try_recv polling loop to a parked recv().await under the 15 s timeout wrapper (stream_tests.rs, the sole pg copy — SQLite twin untouched; the poll loop's wake-subscription interaction surface the F-1 flake suspected is out of the hot path, and the deadline assert still bounds the property). The parked form's terminal arms are explicit: Some(Err(e)) keeps the errored-instead-of-idling panic, None gets a receiver-closed panic the poll form never saw. The deadline miss self-diagnoses (the small-honest realization of candidate (b)'s discriminator): read_since(offset, 1000) over rows beyond the receiver's position names the residual class — rows durable undelivered (wake/re-drain class) vs no rows (publish-visibility class); with the parked recv a wake-arrived-but-re-drain-missed arm is structurally implausible (only a read error could miss, and it surfaces Err). Candidate (b)'s literal bridge-side counter skipped, reason recorded in the task (surfacing the bridge wake count across the dyn EventReceiver boundary needs downcast/keyed-global machinery beyond the small-honest bar); the small honest piece did land: wait_wake's Lagged(n) arm now logs (eprintln, house posture matching notify.rs's bridge_loop — and forwarder.rs's 'the receiver bridge's Lagged arm logs / recovers' doc claim now true at both bridges), stream name threaded into wait_wake's signature so the log attributes the lag. Verified: pg stream module 21/21 vs harness server (full module run), tx_publishes_compose_with_the_handle 5 solo re-runs green (determinism re-check under the parked shape), two consecutive full pg harness runs green (121 lib + 25 suite + 9 schema, ~72 s each), cargo test -p alkstore-postgres green server-less (skips clean), workspace cargo test green (12 binaries), clippy -D warnings, fmt clean main glm-5.3-flash 2026-10-10 08:00:29 +00:00
  • 0c7744977c SQLite commit-error-arm coverage (task sqlite-commit-error-arm): the wave-3 review gate's deferred test landed — failed_commit_replenishes_the_writer_slot drives a failing COMMIT through the engine's commit path and pins the review's code-read fix end-to-end: the error surfaces as the opaque Database carrying the SQLITE_FULL-shaped source chain, the failed connection is dropped and the writer slot replenished via the handle's reopen closure (the next begin_tx proceeds within a bounded timeout, no parking — the store-wide-livelock posture), no partial-commit residue (the dropped connection's uncommitted writes read back None), the post-failure commit is a real clean commit (the fault disarms on consumption), and auto-commit notify works afterward. Injection is a cfg(test) commit-fault seam in seam.rs — a per-store Arc<AtomicBool> arm (born disarmed, armed via arm_commit_fault, take() disarms on first consumption so exactly one commit faults) whose fabricated rusqlite SqliteFailure feeds the production commit error arm rather than replicating it; the PRAGMA max_page_count route was probed live against both WAL and DELETE journal modes first and rejected: SQLite checks the page-count limit at page-allocation time, so the squeeze always fails the growth statement (SQLITE_FULL/DiskFull on the first INSERT) and leaves no transaction active for COMMIT to fail — the arm is unreachable through PRAGMA-space (also probed: the pragma is per-connection, so pre-begin arming on the writer conn would have ridden into the tx conn; the route failed on error placement, not delivery). Mechanism choice and probes documented in the seam doc comment and the task Notes. Cross-test safety is per-store scoping; parallel stores never see the arm. Replay-proofed live: with the error arm's writer_reopen replenish temporarily removed the test fails (begin_tx parks past the 5 s timeout — the stranding the review identified), reverted it passes. Plumbing follows the pg-fix-forwarder-reconnect cfg(test) precedent: fields on SqliteStore/SqliteTxHandle and a begin param are cfg-gated, production builds compile the plain path. The waves-1-2 review's optional watcher reconnect-success add rides here (taken — recorded in Notes): reconnect_success_resumes_wake_delivery drives run_poll_loop through its existing open_conn_fn seam (same instrument as the W-1 failure test), with the db file present throughout because the vanished-file route cannot reach the success body (file reappearance trips the dead-man's identity switch first): initial open + first two reconnects fail by injection, the third reconnect succeeds, and a subsequent commit wakes on_change — the success arm's data_version re-baseline and restored delivery pinned. Watcher shape untouched. Verified: cargo test -p alkstore-sqlite green server-less (191 lib + 25 suite), workspace cargo test 399/0, clippy -D warnings, fmt clean glm-5.3-flash 2026-10-10 07:46:40 +00:00
  • 36023914b2 Contract-suite rows (task suite-opts-backoff-rows): the backoff-curve equivalence row and the deferred enqueue-opts clock legs. backoff_curve_equivalence — the equal-jitter exponential pinned as the range, not a jitter label (ADR-010 §3): claim → retry(err, None) cycles on a backoff_base_s = 2 queue land the ranges [1,2], [2,4], [4,8] across attempts 1–3, each computed delay read back through get_job's resolved run_at minus a clock read taken before the retry — the lower bound race-free (the retry's internal clock read cannot precede the suite's, so the observed value over-reads the delay, never under-reads) and the upper bound carrying a one-second straddle tolerance for the integer-second stamp crossing a wall second; identical bounds on both engines is the equivalence pin (ADR-012 §2, the row body shared). The explicit-delay override legs ride the same row: retry(err, Some(5)) honored verbatim ([5, 6] under the same straddle tolerance) and retry(err, Some(0)) resolving ready-now per the boundary-total rule (ADR-023 §2), claimed within a bounded wait. enqueue_opts_resolution extended in place with the wave-5 legs its deferral note named — the run_at-alone literal leg (a future run_at is the row's ready time verbatim, a deterministic equality with no clock read involved; a past run_at stores the literal too and is claimable now through the run_at <= now predicate within a bounded wait, the run_at-ASC ordering making the observation unambiguous among the row's other legs) and the neither-field leg (ready at the enqueue instant, abs_diff(now) <= 5 tolerance-bounded proximity, never a tight timing assert); the deferral note replaced by the completion statement, ADR-023 §2 stamp accumulated per the convention (ADR-020 §1 governs the resolutions). Cap-leg disposition recorded in Notes for the review gate: the 1-hour cap is not suite-pinnable (capped attempts need minute-scale waits) and stays pinned engine-side on both engines' unit tests per the wave-3/4 reviews. Ready-now waits are bounded claim_one poll loops (deadline asserts only, sequential single-store drive), with the one draft defect the finding surfaced (a re-claim after the bounded wait consumed nothing; the helper returns the claimed handle) noted. Wired into both engines' suite targets (SQLite tokio test, pg harness_row!), 25 rows per column up from 24. Verified: SQLite column green server-less (25/25 suite, 189 lib), pg column green vs harness (postgres/poc@:15432 — 25/25 suite, 121 lib + 9 schema), 3 solo re-runs of each new/extended row per engine (determinism), server-less pg skips cleanly via the reachability gate, cargo test -p alkstore-sqlite -p alkstore-postgres green, clippy -D warnings, fmt clean glm-5.3-flash 2026-10-10 07:26:55 +00:00
  • 2a2ad7e11f Contract-suite wake row (task suite-wake-rows): wake_receiver_shapes — the wake contract's pinnable core, tolerance-bounded to state outcomes (never delivery counts or latencies): a pre-attached listener receives a wake after a committed notify on its channel through all three recv forms (recv/try_recv/recv_timeout), every wake's channel field matching the listened channel (the one piece of semantic content a wake carries, ADR-008 §3); a three-notify burst floors at one wake — never an exact per-notify count (coalescing the documented engine asymmetry: SQLite's 1-slot feed vs pg per-notify, the row pins the floor not the shape); a listener attached after a commit never sees that commit's notify — recv_timeout idles a 400 ms absence window (a 300 ms pre-settle sleep closes SQLite's watcher baseline race: the last_version baseline is store-open-captured, so an unconsumed commit's version change would fire one late tick at the new subscriber indistinguishable from replay; pg's gap-commit no-replay hole and SQLite's burst coalescing both legal under the pin); and the channel-scoped leg — a foreign-channel notify never surfaces a wake naming it (SQLite's same-commit overtrigger may deliver but carries only the listened channel; the pg LISTEN fanout skips foreign channels; the reserved reconnect straggler tolerated), with a same-channel positive control proving the silence is scoping not a dead listener. The failure-surface close arms (SQLite watcher-death recv()->None, pg synthetic reconnect-wake) stay pinned engine-side and in receiver_close_and_save_arms's disposal leg — cross-referenced in the doc comment, not re-pinned. Stamped ADR-006 + ADR-008 §3. Wired into both engines' suite targets (SQLite tokio test, pg harness_row!), 24 rows per column up from 23. Dispositions in Notes: the backlog row stays in core-contract.md's inventory (flushes at review-wave-5's stable gate, like the other discharged rows), the absence windows are single recv_timeout calls (the documented Ok(None) idle arm as the bounded wait), and the scoping leg's observable is the channel field not absence (SQLite overtrigger makes an absence-only pin vacuous there). Verified: SQLite column green server-less, pg column green vs harness (postgres/poc@:15432), 3 solo re-runs of the row per engine (determinism), cargo test -p alkstore-sqlite -p alkstore-postgres green (SQLite 189+24, pg 121+24+9), workspace cargo test green (12 binaries), clippy -D warnings, fmt clean glm-5.3-flash 2026-10-10 07:12:31 +00:00
  • 98de4a49cd Contract-suite lock rows (task suite-lock-rows): two version-stamped rows discharging the lock backlog rows — lock_ttl_expiry_and_reacquisition (the ADR-008 §7 guarantee row: a held lock excludes a second acquirer (contender None); after a 1 s TTL the exclusion lapses silently — no revocation event, no error — and a second owner acquires; the original holder's post-expiry renew is refused (false, the lost-it arm); the second owner's release frees the name for a third acquirer, which consumes cleanly; tolerance-sleep posture, state outcomes only; ADR-008 §7 + ADR-019 §1, duration-guard legs cross-referenced to duration_refusal_on_non_positive_ttl) and concurrent_try_lock_loser_is_a_value (the contention posture: four sequential contenders — two owners, repeated — against a held lock all land the clean None value, never Database, never a busy-throw; the backlog row's SQLite busy-path open question answered: no divergence from the pg reference; release-then-contend cycle proves the loser path leaves no state blocking a later acquire, granted to a former loser and consumed cleanly; ADR-008 §5 + §7 + ADR-019 §1) — wired into both engines' suite targets (SQLite tokio tests, pg harness_row!s), 23 rows per column up from 21. Dispositions in Notes: no divergence found (no fix/ADR call needed), ADR-023 §2 excluded from stamps (its guard property is the duration-refusal row's, cross-referenced), the backlog parenthetical re-acquire-does-not-refresh-TTL stays engine-pinned, renew-refusal asserted after the second owner's re-acquisition (strongest form), contenders distinct-owner only (same-owner re-acquire grants per the inherited substrate shape), and one unreproducible first-cold-run pg failure recorded (message lost to truncation; 13 subsequent clean runs incl. concurrent SQLite+pg — no timing hazard identified, the lapse assertions are post-sleep state outcomes). Drive-by: alkstore-contract-suite's tokio dep gained the macros feature — a pre-existing compile break in the crate's own tests/suite_harness.rs (since 7f749ac) failed the harness target and the workspace test gate on HEAD; test-side non-event (ADR-017 §2 class 4). Verified: cargo test -p alkstore-sqlite -p alkstore-postgres green (SQLite 121+23+9, pg 189+23 vs harness server on :15432, server-less pg skips clean), workspace cargo test green (12 binaries), clippy -D warnings, fmt clean glm-5.3-flash 2026-10-10 06:58:54 +00:00
  • 1d05df200e Contract-suite stream rows (task suite-stream-rows): two version-stamped rows discharging ADR-015's backlog legs — stream_ordering_equivalence (a keyed/unkeyed interleaved publish sequence of 6 reads back in the same order on every read form: whole + cursor-paginated + mid-stream read_since, read_from_consumer fresh and from a mid checkpoint, and a subscriber's attach drain; offsets strictly increasing per stream — per-stream relative order, absolute values explicitly not cross-pinned (pg bigserial vs SQLite AUTOINCREMENT); key round-trips exactly None/Some on every read form including the explicit-None keyed publish form; stream carries the name; created_at tolerance-bounded informational, never an ordering assertion; ADR-015 §4/§3/§1, byte-exactness and tx-seam legs cross-referenced to the payload-round-trip and keyed-tx-atomicity rows) and trim_to_semantics (the full ADR-015 §5 row: exact-boundary trim — the horizon's own row deletes, horizon+1 survives, repeated trim 0; survivors keep offsets; reads from a trimmed-away region resume at the horizon's first remaining row; a below-horizon saved checkpoint stays a get_offset-visible position marker with read_from_consumer and a fresh subscribe both resuming at the horizon, never a renumbered past; a pre-trim subscriber's above-horizon checkpoint keeps its place; a pre-attached listener idles across the trim in a 400 ms bounded window — no dedicated wake, SQLite's spurious watcher hint contract-legal and delivering nothing; ADR-015 §5/ADR-019 §6, negative-horizon/immutability legs cross-referenced to extent_clamp_semantics). Wired into both engines' suite targets (SQLite tokio tests, pg harness_row!s). Dispositions in Notes: the attach-drain pattern leads with a blocking recv() before the try_recv drain (engines deliver the attach read asynchronously); the pg LISTEN channel is mechanism-named and database-wide so concurrent suite rows' wakes cross schemas — safe by construction (wakes re-drain own-schema storage only, delivering nothing), no "events" rename needed. Verified: sqlite suite 21/21, pg suite 21/21 vs harness (postgres/poc@:15432, 7 consecutive full runs), 5 focused --test-threads=6 runs of the two rows per engine, workspace build/test green, clippy -D warnings, fmt clean glm-5.3-flash 2026-10-10 06:33:27 +00:00
  • 360e71e51e Contract-suite tx commit-atomicity rows (task suite-tx-commit-atomicity-rows): the N-5 panic-probe admission in properties.rs's module doc (spawned with_tx task joined via JoinError::is_panic — catch_unwind around an async closure cannot see the panic point across an await; post-panic assertions read-only until convergence, single-task drive, no race window; ADR-017 §2 class 4) and three version-stamped rows: outbox_enqueue_tx_commit_atomicity (rollback drops the backing-queue job with the business write — get_job_tx-gone + run_once claims nothing; commit makes the job claimable exactly when the business write commits, real delivery through the RecordingDelivery closure with job-id identity, derived __alkstore_outbox:mail queue, exact payload, 60/5/5 stamps, consumed-after-ack; ADR-014 §1, ADR-010 §3a, ADR-021 §4, ADR-007), publish_with_key_tx_commit_atomicity (rollback drops the keyed event with the business write, key round-tripping inside the tx; commit surfaces it to read_since and a post-commit subscriber attach with the key round-tripping; ADR-015 §2/§4, ADR-021 §4, ADR-007), and with_tx_panicking_closure_rolls_back (N-5's probe against real engines: the panicking closure writes all four kinds then panics mid-flight; panic surfaces via the join; no-ghost reads converge with begin_tx granting every iteration; pre-panic listener silence on the notified channel; ghost never claimable; fresh with_tx commits through the same seam — both engines green; ADR-007, ADR-021 §4) — wired into both engines' suite targets (SQLite tokio tests, pg harness_row!s). Dispositions recorded in Notes: the 60/5/5 stamp inspection rides the delivery handle's job() because get_job cannot target the reserved derived backing queue through the contract surface (exemplar row pins the rejection; engine-side raw-row probes stayed put), the panic row's notify leg is a windowed silence (SQLite's wake overtriggers on any commit — the fully cross-engine notify-ghost pin rides the engines' rollback-ghosts twins, the suite's drop-rollback row made the same call), the closure tail routes through a #[cold] mid_flight_panic -> Error helper (a bare Err(panic!()) tail trips unreachable_code under -D warnings), and the post-panic convergence loop is the suite-side bounded wait (state outcomes only, begin_tx doubling as the seam-still-grants probe). Verified: sqlite suite 19/19, pg suite 19/19 vs harness twice (postgres/poc@:15432) + solo re-runs of each new row per engine (determinism), workspace build/test green, clippy -D warnings, fmt clean glm-5.3-flash 2026-10-10 06:17:18 +00:00
  • 7f749ac673 Contract-suite scheduler rows (task suite-scheduler-rows): the determinism-posture extension in properties.rs's module doc (runner-driving rows admitted — spawned run_schedules(stop) tasks on a core StopToken against state outcomes only, elapsed-boundary-band tolerances, never timing-value assertions, never two-task race windows; ADR-017 §2 class 4) and three version-stamped rows: scheduler_boundary_fires (fired jobs are ordinary claimable work with ScheduleOpts over the plain-queue derived defaults 300/9/5/none + payload exact, clean-stop Ok(()), fired count inside the elapsed-boundary band — no double-fire per boundary while one leader runs; ADR-009 §3/§4, ADR-020 §3, ADR-019 §4), scheduler_bounded_catchup (runner-less downtime proves no fire without a runner, ≥3 elapsed boundaries replay boundary-by-boundary bounded below the 64-cap and inside the band; ADR-009 §4), scheduler_leadership_discipline (two spawned runners on one store: exactly one Ok(())/Err(LeadershipLost) pair by value, no duplicated fires inside the band; ADR-009 §1/§6, ADR-019 §4) — wired into both engines' suite targets (SQLite tests, pg harness_row!s), suite tokio dep added for the runner rows. Dispositions recorded in Notes: the beyond-cap skip-forward leg stays pinned engine-side (both engines' scheduler tests already backdate next_fire_at directly — catch_up_replays_up_to_the_cap_then_skips_forward twins), and the pg fire-wake parity gap is not demanded by these rows' shapes (claim-polling observation only; the one-call wake_tx disposition recorded for a later task). Verified: sqlite suite 16/16, pg suite 16/16 vs harness twice + solo re-runs of the three rows per engine (determinism), workspace build/test green, clippy -D warnings, fmt clean glm-5.3-flash 2026-10-10 06:04:30 +00:00
  • 5c9ae6a7fc Contract-suite queue-depth rows (task suite-queue-depth-rows): the job-handle validity predicate row (in-window heartbeat/ack landing, late-heartbeat/post-lapse-ack/retry/fail refusals past a 1 s stamp with the row untouched, ack_batch per-id predicate live-1/lapsed-0/nonexistent-0, fail(None)→"failed" and retry-at-budget→"max attempts exceeded"), the ADR-010 depth row (reclaim consumes an attempt with claimed_at/deadline refreshed and the original holder refusing, reclaim-exhaustion dead-lettering with the pre-claim sweep — get_job-visible "max attempts exceeded"+died_at, cancel unconditional delete with the not-an-interrupt refusal shape plus pending/dead/missing arms), and the no-stranded-rows sweep row (both states move with "expired", unexpired/never-expiring untouched, retention TTL enforcing with the moved+deleted sum, None=forever) — each version-stamped per the suite convention (ADR-010 §1–§5, ADR-019 §3, ADR-008 §5), wired into both engines' suite targets (SQLite tokio tests, pg harness_row!s). M-1's retention-failure pin dispositioned engine-side per the task's honest call: the storage-level DELETE failure is not injectable through the contract surface, so it lands in the SQLite substrate's trigger seam (sweep_rolls_back_the_retention_half_with_the_move — the move half rolls back with the retention half), with the pg twin verified structurally (both halves inside in_tx's frame) and the disposition recorded in the task Notes. Verified: sqlite suite 13/13, pg suite 13/13 vs harness twice (postgres/poc@:15432), substrate sweep-rollback tests 4/4, workspace build/test green, clippy -D warnings, fmt clean glm-5.3-flash 2026-10-10 05:50:26 +00:00
  • 250511d480 decompose wave 5 — contract suite: audit-first split of the verification backlog (engines' columns already discharge most rows; map in review-wave-5's appendix), seven mechanism-grouped suite-row tasks (queue depth, scheduler, tx commit-atomicity, streams, locks, wakes, opts/backoff equivalence), two engine-side hardening tasks (sqlite commit-error arm, pg F-1 defense-in-depth), and the review-wave-5 gate that flips the engine specs to stable glm-5.3-flash 2026-10-10 05:37:53 +00:00
  • 9a00fb8a7e Review gate — wave-4 fix batch passed: all seven pg-fix resolutions verified against review 002's failure mechanisms (code-read + live gates), one minor doc mismatch fixed inline (outbox wake comment's 'scheduler's fire-wake' claim — the tick fires issue no wake and schedule() can never target a reserved backing queue); no pinned posture regressed; pg suite green vs harness twice + compose determinism 20/20 re-verified; wave 5 may decompose (task review-wave-4-fixes) glm-5.3-flash 2026-10-10 05:18:27 +00:00
  • 49face898d docs alignment: v1 TLS posture owned by deployment.md, QueueOpts numeric consumer-obligation notes (task pg-fix-docs-alignment, review 002 Finding 6 remainder) glm-5.3-flash 2026-10-10 05:08:27 +00:00
  • 40625090f6 pg queue/tx/notify dedupe + doc truth-telling: job_from_row has one owner (queue.rs, tx.rs imports it) and get_job_tx reuses live_columns()/dead_columns() instead of inlining the 18-column lists — the contract-pinned Job shape now has exactly one decode owner (ADR-012 §2); sweep_expired's doc states the moved + retention-deleted sum in the in_tx multi-statement frame (the sum the SQLite twin returns — the doc was the only liar); notify.rs's closed-store listen error routes through the shared database_error helper; bridge_capacity() is a const with its rationale doc carried. No behavior change — identical SQL strings, error shapes, and capacity. (task pg-fix-dedupe-cleanup, review 002 minor notes + Finding 6 queue bullet) glm-5.3-flash 2026-10-10 05:04:09 +00:00
  • 12d0497b1c pg: scheduler runner resilience — quarantine bad rows, retry transient ticks glm-5.3-flash 2026-10-10 04:58:43 +00:00
  • ace94f0e13 pg forwarder: generation-tagged commands — a reconnect drops its predecessor's queued commands before replaying, closing the stale-UNLISTEN window (a stale UNLISTEN replayed after the snapshot's re-issued LISTENs silently cancelled a re-registered channel, its wakes lost until the next reconnect); the reconcile decision is the pure helper (stale LISTEN and UNLISTEN dropped, current-generation commands replay in queue order, dropped stale LISTENs ack the transient mid-LISTEN error) pinned by a four-combination server-less unit test (replay-proven against the neutered shape); 'queued commands replay harmlessly' doc corrected and the post-reconnect LISTEN-set invariant (server LISTEN set = registry snapshot, dead-generation commands can't undo it) stated in the module + loop docs (task pg-fix-stale-unlisten, review 002 Finding 4) glm-5.3-flash 2026-10-10 04:49:35 +00:00
  • 86719a39cc pg open path: validate max_size > 0 at entry (typed Database before any round trip — 'max_size: 0' previously hung open forever at the bootstrap checkout, deadpool 0.13/0.14 neither validates nor defaults timeouts) and append the engine's '-c synchronous_commit' SET to the DSN's parse-carried options (was: setter replaced them, a silent override); pins: the zero-guard test (bounded by inner timeout, server-less-capable — fires pre-connect) and the DSN-options coexistence test (consumer SHOW statement_timeout + engine SHOW synchronous_commit, both settings) (task pg-fix-open-path, review 002 Finding 3 + options note) glm-5.3-flash 2026-10-09 23:00:35 +00:00
  • 9a5d1f4705 pg tx producer paths wake commit-atomically: publish_with_key_tx/enqueue_tx/outbox_enqueue_tx issue pg_notify on their mechanism-named channel (stream name / queue name / derived backing queue) inside the caller's tx — empty payload, best-effort log-and-swallow, no double-wake on the auto-commit paths; shared tx::wake_tx owner + module-doc section pinning the semantics; new tx_tests harness test pinning pre-commit silence, commit delivery on all three channels, and rollback silence; F-1 engine arm retired in review-wave-4 + implementation.md records (tx_publishes_compose_with_the_handle deterministic: 20 solo runs green; pg suite 116/116 x2 vs harness) (task pg-fix-tx-wake, review 002 Finding 2) glm-5.3-flash 2026-10-09 22:38:38 +00:00
  • 7ae426a01d pg forwarder: the reconnect arm retries failed connects until success or shutdown — one failed connect no longer kills the loop permanently; every loop exit path releases the fanout sender via the shared-slot drop guard (receivers-terminal-iff-loop-gone); reconnect-config test seam + failed-connect pins: six-cycle exhausted-backoff server-less unit, pre-flip abort, guard drop, and the harness end-to-end unreachable-outage → full-recovery test (bug replay-proven against the old shape) (task pg-fix-forwarder-reconnect, review 002 Finding 1) glm-5.3-flash 2026-10-09 22:31:05 +00:00
  • e067357de9 Wave-4 fix-batch decomposition: seven pg-fix tasks + review-wave-4-fixes gate from the general review (002) — forwarder reconnect retry (Finding 1, with the failed-connect test seam), tx pg_notify wakes retiring F-1's engine arm (Finding 2), max_size/DSN-options open path (Finding 3), stale-UNLISTEN generation drop (Finding 4), scheduler quarantine/retry (Finding 5), decode dedupe + cleanups, doc alignment; wave 5 gates on the two HIGH fixes landing glm-5.3-flash 2026-10-09 22:11:13 +00:00
  • 89828170f4 Wave-4 general review (002): two live-proven bugs — the forwarder's permanent death after one failed reconnect (the failure arm the gate's test never covered) and the tx enqueue/publish paths' missing pg_notify wake (F-1's root cause, engine-side) — plus a max_size:0 open-hang, two narrow robustness gaps, doc mismatches, and the decode-duplication smell; reviews renumbered 001/002 per the alk* numbering pattern (references updated) glm-5.3-flash 2026-10-09 22:01:04 +00:00
  • f9bd5716fa Wave-4 review gate: conformance code-read clean (0 findings) — forwarder/seam integrity, ADR-023/016 follow-through, backoff + boundary math vs ADR text, schema posture, 10-row backlog column green against the harness server; the flagged tx-compose flake reproduced twice, root cause unresolved, recorded as F-1 for wave 5's suite hardening + three no-action notes (task review-wave-4) glm-5.3-flash 2026-10-09 11:43:46 +00:00
  • fb37da617d Postgres engine integration: StoreFactory (fresh schema per open, owned idempotent CASCADE teardown, isolation/idempotence pinned), the engine's backlog column (all ten rows green against the harness server — exemplar verified, the three ADR-023 rows verified not rewritten, the five engine-scoped rows, the new pg-arm PayloadTooLarge row discharging the SQLite task's deferred adoption), test-observation accessors cfg(test)-gated with the unused PgStore::new cut, stale stub-era doc text removed, lib docs stating the finished-engine posture (task pg-engine-integration) glm-5.3-flash 2026-10-09 10:22:25 +00:00
  • 77619c5e93 Postgres engine: scheduler + outbox — schedule (validation triad, the pg-owned @every-only parser, upsert over the schedule table), unschedule, run_schedules (leadership via the engine's lock machinery on __alkstore_scheduler with a per-instance owner token, in-sleep lease renewals, the row-locked FOR UPDATE tick in one pool tx — fire enqueues + boundary advance + soonest read commit together — the 64-boundary catch-up cap with skip-forward, clean stop / Err(LeadershipLost) arms), outbox (validated constructor, enqueue into the derived __alkstore_outbox:{name} with the 60/5/5 stamps + max_attempts override, run_once ack/retry-curve/false over the ordinary claim machinery, no engine-issued heartbeat) (task pg-engine-scheduler-outbox) glm-5.3-flash 2026-10-09 09:53:48 +00:00
  • c3591c2d44 Postgres engine: named locks — try_lock (validated entry, duration guard, opportunistic expiry-delete + insert-or-reacquire + holder read-back over the locks table), PgLockHandle (full-window renew, consuming owner-scoped release with both boolean arms), same-owner re-acquire matched to the SQLite arm, silent-lapse posture pinned, second open re-acquires after expiry (task pg-engine-locks) glm-5.3-flash 2026-10-09 09:17:39 +00:00
  • 3dd83791ff Postgres engine: queues — Queue (validated constructor over the handle's QueueOpts stamps), the FOR UPDATE SKIP LOCKED claim (one statement, the pre-claim exhausted-reclaimable sweep in the atomic claim frame), JobHandle (one-shot ack/retry/fail in tx frames under the uniform validity predicate, absolute-reset heartbeat, engine-side equal-jitter backoff), dead-letter moves transactional (the #133 class excluded), worker-less ack_batch, unconditional cancel, dead-visible get_job, both-states+retention sweep, best-effort queue-channel wake, wake-driven claim loop pinned (task pg-engine-queues) glm-5.3-flash 2026-10-09 08:44:59 +00:00
  • cb067bb4be Postgres engine: streams — StreamHandle (auto-commit publishes + best-effort pg_notify wake, ASC reads with the extent guard, monotone offsets, pool-connection trim) and the durable subscribe receiver (async bridge, wake-driven re-drains, reconnect gap-heal, shutdown-only terminal close, stateless idle wake runtime for the sync save) (task pg-engine-streams) glm-5.3-flash 2026-10-09 08:05:34 +00:00
  • 8f5c2add5e Postgres engine: LISTEN forwarder full behavior + notify/listen — wake contract pg arm glm-5.3-flash 2026-10-09 07:37:56 +00:00
  • cf5ceea70e Postgres engine: transactional seam — begin_tx, PgTxHandle, all eleven *_tx methods with drop=rollback detached teardown, probe-pinned unknowable-state discard arms, engine-side resolution arithmetic (task pg-engine-seam-tx) glm-5.3-flash 2026-10-09 06:50:53 +00:00
  • c6a7eeaa45 Postgres engine: open constructor, PgOpts, pool + listener wiring — forwarder skeleton with the POC-pinned pitfalls structurally excluded, seam error mappings, wave-3 stub surface (task pg-engine-open-opts) glm-5.3-flash 2026-10-09 06:00:31 +00:00
  • 2f1353bd41 Postgres engine: schema bootstrap — engine-owned schema, table family, idempotent DDL, schema-prefixed indexes (task pg-engine-schema) glm-5.3-flash 2026-10-09 05:11:48 +00:00
  • 4caea21098 Wave 4 decomposed: Postgres engine — 11 tasks (schema, open/opts, seam, forwarder, mechanisms, scheduler/outbox, integration, review gate); plan synced glm-5.3-flash 2026-10-08 22:49:00 +00:00
  • ecb8211694 Wave-3 review gate: contract conformance clean; two findings fixed inline — substrate boundary move (open_writer_connection → seam.rs), writer-slot release on with_writer/begin/commit error arms + regression tests (task review-wave-3) glm-5.3-flash 2026-10-08 20:57:10 +00:00
  • a82c543b40 SQLite engine integration: lint removal, contract-suite adoption, backlog column (task sqlite-engine-integration) glm-5.3-flash 2026-10-08 16:15:43 +00:00
  • 8502a51af7 SQLite engine: scheduler + outbox — schedule/unschedule/run_schedules leader loop, outbox enqueue/run_once (task sqlite-engine-scheduler-outbox) glm-5.3-flash 2026-10-08 14:08:43 +00:00
  • 1edcb0e27d SQLite engine: named locks — try_lock, SqliteLockHandle, duration guards (task sqlite-engine-locks) glm-5.3-flash 2026-10-08 13:37:22 +00:00
  • 513df0b311 SQLite engine: queues — Queue/JobHandle over the writer slot, engine-side backoff curve, extent guard (task sqlite-engine-queues) glm-5.3-flash 2026-10-08 12:59:57 +00:00
  • 4913302b47 SQLite engine: streams — StreamHandle, extent-guarded reads, trim, durable subscribe (task sqlite-engine-streams) glm-5.3-flash 2026-10-08 12:30:32 +00:00
  • 8efe0c2e78 SQLite engine: notify/listen — auto-commit notify, watcher-fanout WakeReceiver bridge (task sqlite-engine-notify-listen) glm-5.3-flash 2026-10-08 12:12:34 +00:00
  • c38033db1a SQLite engine: transactional seam — begin_tx, writer-slot lease, all eleven *_tx methods (task sqlite-engine-seam-tx) glm-5.3-flash 2026-10-08 11:50:16 +00:00
  • 7d400906f5 SQLite engine open: SqliteOpts, connection architecture, spawn_blocking seam posture (task sqlite-engine-open-opts) glm-5.3-flash 2026-10-08 11:25:16 +00:00
  • 5474141f2b Core: #[doc(hidden)] engine-side constructors for Job, StreamEvent, Schedule, Wake glm-5.3-flash 2026-10-08 11:07:53 +00:00
  • 1269246faf Wave-3 decomposition: SQLite engine tasks (open/opts, seam+tx, mechanisms, integration, review gate) + core value-constructor pre-work; plan synced for waves-1-2 review + ADR-023 follow-through glm-5.3-flash 2026-10-08 10:57:29 +00:00
  • 44637eea5b Fourth review round (ADR-023): encode_payload typed (Codec), numeric-argument domains pinned by kind, plain-path SQLite open (URI flag dropped, D-29), watcher cadence posture — waves-1-2 general-review findings glm-5.3-flash 2026-10-08 10:17:56 +00:00
  • ee7871d25d General review waves 1-2: sweep_expired savepoint scope fix (M-1), coverage adds (arg_opt_i64, StopToken Debug), review report (docs/reviews/) glm-5.3-flash 2026-10-08 09:36:24 +00:00
  • af5b59ec8e Wave-2 review gate: scheduler fire expires resolution fix (D-27, ADR-020 §2), pressure-test lock quality (D-28), lineage diff re-verified clean (task review-wave-2) glm-5.3-flash 2026-10-08 09:17:47 +00:00
  • 6618e13c3a Fork gate: provenance register completion + test floor green (ADR-018 §2, ADR-011 tests clause, task fork-provenance-and-floor) glm-5.3-flash 2026-10-08 04:19:54 +00:00
  • 915641bfe6 Fork re-derivation: queue ops on contract v1 (stamps, per-row claim visibility, savepoint-guarded dead-letter, both-states sweep, dead-visible get_job, @every scheduler) — ADR-010 §1–§5/§3a/§8, ADR-009 §2–§4, ADR-011/012, task fork-rederive-queue-ops glm-5.3-flash 2026-10-08 04:10:43 +00:00
  • 43a135c453 Fork port: connection architecture + watcher machinery into the substrate (ADR-011/012 §3–§5, task fork-port-connection-watcher) glm-5.3-flash 2026-10-08 03:25:48 +00:00
  • 2d855b9546 Fork scaffold: substrate subtree, provenance register, dual-license notice (ADR-011/012/013/018, task fork-substrate-scaffold) glm-5.3-flash 2026-10-08 03:01:51 +00:00
  • 8b03960e39 Wave-1 review gate: validation coverage fixes (unschedule, handle-level consumer-local entry points), ADR-008 §4 annotations (whitespace-exclusion, class scope), task check-line staleness fix (ADR-008/009/021, core-contract) glm-5.3-flash 2026-10-07 16:15:48 +00:00
  • 621415cc47 Contract-suite scaffold: alkstore-contract-suite crate + ADR-022 (suite layout decision), engine dev-dep edges (ADR-017 §4.2 discharged, ADR-012 §2 mirror) glm-5.3-flash 2026-10-07 16:03:00 +00:00
  • eefee9ec1d Core trait surface: Store, TxHandle, mechanism handles, receivers, with_tx (ADR-007 §with_tx, ADR-008 §1–§3/§8, ADR-009 §1/§6, ADR-014, ADR-015 §2, ADR-019 §1–§6, ADR-021 §1/§4/§5) glm-5.3-flash 2026-10-07 15:50:02 +00:00
  • 92615f7b7d Core value types: opts structs, Job/JobState, Schedule, StreamEvent, Wake, StopToken, payload encode/decode (ADR-008 §1/§3, ADR-010 §3, ADR-015 §3, ADR-017 §3, ADR-019 §3/§4, ADR-020 §1–§4, ADR-021 §2) glm-5.3-flash 2026-10-07 15:08:26 +00:00
  • 74105a16ae Core error taxonomy + name validation (ADR-008 §4/§5, ADR-017 §3); AGENTS.md updated to Phase 1 posture glm-5.3-flash 2026-10-07 15:04:04 +00:00
  • 34e0b9732d Scaffold Cargo workspace: alkstore core + sqlite/postgres engine stubs (ADR-001) glm-5.3-flash 2026-10-07 14:57:34 +00:00
  • 49743c690e Implementation plan: wave-based decomposition; waves 1-2 decomposed (11 tasks) glm-5.3-flash 2026-10-07 14:37:31 +00:00
  • 83767e880b Third review round follow-through: enqueue_tx stamp source, sweep_expired handle form, with_tx signature, and B-block ambiguity pins glm-5.3-flash 2026-10-07 14:01:36 +00:00
  • 08dc1bf011 ADR-021: third review round — tx-read methods, Job.claimed_at, schedule() queue validation, drop=rollback, receiver arms glm-5.3-flash 2026-10-07 06:25:39 +00:00
  • 8323a7853e ADR-019/020: second review round — handle surfaces, enqueue semantics, payload bridge + mechanical fixes glm-5.3-flash 2026-10-06 13:06:23 +00:00
  • c49befd195 ADR-018: substrate provenance register + cherry-pick procedure (OQ-11 resolved — Phase 1 question set closed) glm-5.3-flash 2026-10-06 07:50:43 +00:00
  • eba77909a7 ADR-017: contract versioning — core crate's semver is the contract version (OQ-10 resolved) glm-5.3-flash 2026-10-06 07:29:09 +00:00
  • 8c8fec5cb8 ADR-016: deployment honesty — no runtime capability surface; compile-time identity + matrix (OQ-08 resolved) glm-5.3-flash 2026-10-06 06:29:42 +00:00
  • 8c4ec48f92 ADR-015: streams depth — carried-metadata keys, global-FIFO ordering, StreamEvent, trim_to (OQ-12 resolved) glm-5.3-flash 2026-10-05 14:15:28 +00:00
  • 04a04651dc ADR-014: transactional outbox enqueue — outbox_enqueue_tx on TxHandle (OQ-13 resolved) glm-5.3-flash 2026-10-05 13:28:39 +00:00
  • d401908f13 docs: Phase 1 review round — wake wording honesty, job-handle validity predicate, outbox/streams depth OQs glm-5.3-flash 2026-10-05 12:50:33 +00:00
  • 8e68b44194 ADR-013: fold the forked substrate into alkstore-sqlite — no fourth crate glm-5.3-flash 2026-10-05 11:56:01 +00:00
  • 2949612e2c ADR-012: forked-substrate design — contract-blind boundary, fidelity posture, port deltas glm-5.3-flash 2026-10-05 05:00:55 +00:00
  • befbe2e714 OQ-06 resolved: honker-core quality read fires the fork trigger (ADR-011) glm-5.3-flash 2026-10-05 03:39:46 +00:00
  • 79a135c934 docs: resolve OQ-05 + OQ-09 — queue semantics depth (ADR-010) and scheduler collapse (ADR-009) glm-5.3-flash 2026-10-05 03:10:52 +00:00
  • 7ad8ac56bc docs: resolve OQ-04 — contract v1 pinned (ADR-008): surface partition, TxHandle-on-handle-trait, Wake/WakeReceiver, reserved __alkstore_ namespace, error taxonomy, engine-crate constructors, locks guarantee row glm-5.3-flash 2026-10-05 02:23:15 +00:00
  • 4391f6e879 docs: open Phase 1 — architecture spec set over the Phase 0 evidence glm-5.3-flash 2026-10-04 18:13:10 +00:00
  • db73678090 docs: restructure phase-0 for Phase 1 readiness glm-5.3-flash 2026-10-04 17:53:09 +00:00
  • f9e350bf22 docs: POC #2 findings verified + folded — OQ-ST-03 closed (per-engine drivers) glm-5.3-flash 2026-10-04 17:32:43 +00:00
  • 80e6af0a0a docs: POC #2 ran and passed — OQ-ST-03 closed (per-engine drivers: tokio-postgres+deadpool for pg), OQ-ST-04 ground complete glm-5.3-flash 2026-10-04 17:25:27 +00:00
  • 4c144f8f7f docs: fold verified LISTEN research into POC #2 spec glm-5.3-flash 2026-10-04 16:08:45 +00:00
  • e18281735e docs: specify POC #2 — Postgres engine posture (poc-pg-posture-spec.md) glm-5.3-flash 2026-10-04 15:26:01 +00:00
  • 299603b164 docs: POC #1 findings land — SQLite posture resolved (Arm A: honker-core on our rusqlite) glm-5.3-flash 2026-10-04 15:13:25 +00:00
  • 26ee734ae6 docs: POC #1 ran — SQLite posture verdict Arm A, findings + register note glm-5.3-flash 2026-10-04 11:38:29 +00:00
  • 4165c94ab0 docs: specify POC #1 — SQLite engine posture comparison (poc-sqlite-posture-spec.md) glm-5.3-flash 2026-10-04 09:31:46 +00:00
  • 8331a96817 docs: OQ-ST-03 gains the explicit SQLite option space (three postures) glm-5.3-flash 2026-10-04 09:26:25 +00:00
  • 69fd5f4eda docs: record alktty REQ-TTY-01 as family precedent for OQ-ST-03's async question glm-5.3-flash 2026-10-04 09:21:45 +00:00
  • 7ddd4e472b docs: resolve OQ-ST-02 — reactive-core + engine crates (operator decision) glm-5.3-flash 2026-10-04 09:13:50 +00:00
  • f4e24f321d docs: streams upgraded to in-scope (operator-authority record) glm-5.3-flash 2026-10-04 08:47:19 +00:00
  • d44dfb5a08 docs: consumer inventory answers OQ-ST-01; phase-0 consumes it glm-5.3-flash 2026-10-04 05:27:22 +00:00
  • 1cb007d894 docs: tidy phase-0 corrections, pin reference revisions by path+rev glm-5.3-flash 2026-10-03 17:10:18 +00:00
  • 8e6da2f6c9 phase-0: interface finding — honker-rs surface as the unified-API candidate glm-5.3-flash 2026-10-03 16:50:54 +00:00
  • f6531b5532 phase 0 setup: agent defs cleaned, AGENTS.md, initial phase-0.md draft glm-5.3-flash 2026-10-03 16:36:46 +00:00
  • 5bcd1b7a2f init glm-5.3-flash 2026-10-03 15:23:54 +00:00