Row-first gate: consumer-inventory.md gains an engine-tier section — the mem-engine need recorded operator-authority, dated 2026-10-10 (wasm32 sandboxing across the alk protocol family + downstream ffi/napi/python-adapter economics; rusqlite/tokio-postgres structurally out on wasm, so mem is the only triad member the sandbox can carry). ADR-024 (decisions/024-mem-engine.md) pins the decision set: (1) separate `alkstore-mem` crate — discharges and amends ADR-001 §4 (superseded in part: full contract-v1 engine, not an "implementation convenience"; annotation on ADR-001 §4 + Status, class-1 window still open); (2) honest-ephemeral posture — no durability, single-process, ephemeral by design, never fleet-valid (ADR-010 §3's shared-pool predicate fails structurally), riding ADR-016's carriers unchanged (identity + docs + matrix); (3) full contract v1 tier with the asymmetry classification — `PayloadTooLarge` never produced (SQLite arm), no reconnection concept (reconnect-wake/watcher rows absent from mem's per-engine column), receiver close at engine drop, wake coalescing N/A; (4) `MemStore::new()` engine-native constructor — the one documented exception to the open-prose, core-contract.md Store concept amended; shared-instance (two opens → one engine) rejected with the ADR-016 §4-style re-entry gate (consumer-inventory row), register stays closed; (5) wasm32 — compile-clean for wasm32-unknown-unknown plus the suite's mem column green on host under a current-thread runtime flavor are wave-6 acceptance items; on-target suite execution scoped out with a named collapse condition (wasm-bindgen-test adapter crate) — a scope decision, not a pending-client hedge; (6) mem is not a core dev-dependency — core's doc examples stay mock-based, ADR-001 §4's doctest posture declines. engine-mem.md (draft): the in-process mapping — guarded per-mechanism state (no pool, no schema bootstrap, no forwarder, no spawn_blocking seam), the tx overlay (staged *_tx effects merged atomically at commit; read-your-own-writes easy, drop-=-rollback trivial; wake-at-commit structural — the seam pg needed pg-fix-tx-wake for, mem pins from birth via the existing tx-commit-atomicity rows), ADR-012 §2 third owner of the curve/opts/@every arithmetic (three-way equivalence, ADR-022's StoreFactory reused verbatim — born pinned). deployment.md: host-semantics row (single-process, ephemeral, never fleet-valid, wasm32-clean), mem connection-budget subsection (none — nothing to budget), durability-knobs row (the honest row is the absence), toolchain row (wasm32 subset + current-thread-clean, acceptance-cited). README/overview: engine-mem.md row, ADR-024 row, family table entry (alkstore-mem, no driver deps), current-state updated to the implementation phase with engine specs' stable statuses reflected. implementation.md: wave table gains wave 6 (mem engine, depends waves 1 + 5) and renumbers release readiness to wave 7 (fuzzing decision — the one remaining decided-at-implementation deferral — rides wave 7); wave-6 section records the born-pinned posture, acceptance items, the one suite-harness pre-task (past_stamp_sleep blocking sleep → async sleep, review 003's properties.rs:1683 note), and the window riders (review 003 Finding 1: the pg transient-fault seam, MEDIUM, rides wave 6; Findings 2–3 follow their park into wave 7's pre-release); wave-6 review gate defined; Decided points updated (mem discharged, fuzzing renumbered); stale wave-6 references swept across review docs and the landed tasks' notes (release-readiness items renumbered or annotated). Docs-only change; verified by cross-reference audit (all ADR/OQ/anchor references resolve, residual wave-6 mentions are correct under the new numbering or carry dated annotations).
status: draft last_updated: 2026-10-10 (ADR-024: the mem engine adopted as a third engine — engine-mem.md added, ADR table row, index updated for the implementation phase)
alkstore — Architecture
Architecture documentation for the alkstore project: one reactive store interface (notify, streams, queues, locks, scheduler, outbox) over SQLite, Postgres, and the in-process mem engine, with each engine native underneath (see overview.md).
Current State
Phase 1 (Implementation) — waves 1–5 implemented and reviewed.
Phase 0 is complete (docs/research/phase-0.md): both POCs ran and
passed, the scope inventory is confirmed, and the crate split,
drivers, and ownership postures are decided. All open questions are
resolved (through ADR-023), and the engine specs flipped stable at
the wave-5 review gate. Waves 1–5 (core, substrate fork, SQLite
engine, Postgres engine, contract suite) are implemented and reviewed
per docs/plans/implementation.md. The mem engine was adopted as a
third engine by ADR-024 (2026-10-10,
wave 6 — release readiness renumbered to wave 7).
Architecture Documents
| Doc | Status | Purpose | Key OQs |
|---|---|---|---|
| overview.md | draft | Crate family, feature surface, non-goals, evidence base | — |
| core-contract.md | draft | The unified trait surface, delivery guarantees, tx seam | OQ-10 (resolved) |
| engine-sqlite.md | stable | SQLite engine: forked-substrate/rusqlite mapping | OQ-06 (resolved), OQ-12 (resolved), OQ-13 (resolved) |
| engine-postgres.md | stable | Postgres engine: tokio-postgres/LISTEN mapping | OQ-08 (resolved), OQ-12 (resolved), OQ-13 (resolved) |
| engine-mem.md | draft | Mem engine: in-process ephemeral mapping of the contract (ADR-024) | — |
| queues.md | draft | Queue/scheduler/outbox semantics depth (resolved: ADR-009/ADR-010) | OQ-05 (resolved), OQ-09 (resolved), OQ-06 (resolved) |
| deployment.md | draft | Host semantics, connection budgets, knobs, matrix | OQ-08 (resolved) |
| open-questions.md | draft | OQ tracker (promoted from OQ-ST register) | — |
Architecture Decision Records
| ADR | Title | Status |
|---|---|---|
| 001 | Reactive-core crate + per-engine crates | Accepted |
| 002 | Feature scope — inventory-confirmed surface | Accepted |
| 003 | SQLite engine — rusqlite + honker-core lineage, bridged seam (ownership: ADR-011) | Accepted |
| 004 | Postgres engine — tokio-postgres + deadpool, hand-rolled LISTEN | Accepted |
| 005 | Published libraries by default, named fork triggers | Accepted |
| 006 | Wake contract — opaque wake + re-read; notify-vs-streams split | Accepted |
| 007 | Transactional seam — caller-held TxHandle, *_tx methods |
Accepted |
| 008 | Contract v1 surface pinning — surface partition, TxHandle shape, wake type, reserved strings, error taxonomy |
Accepted |
| 009 | Scheduler collapse — queues + schedule()/run_schedules, @every-only v1, boundary guarantee row |
Accepted |
| 010 | Queue semantics depth — visibility/renewal, backoff curve, dead-letter, no-stranded-rows sweep, schema layout | Accepted |
| 011 | SQLite substrate — fork honker-core into owned code | Accepted |
| 012 | Forked substrate design — contract-blind boundary, fidelity posture, port deltas | Accepted |
| 013 | Fold the forked substrate into alkstore-sqlite — no fourth crate |
Accepted |
| 014 | Transactional outbox enqueue — outbox_enqueue_tx on the TxHandle trait |
Accepted |
| 015 | Streams depth — carried-metadata keys, global-FIFO ordering row, StreamEvent shape, publish_with_key_tx, trim_to |
Accepted |
| 016 | Deployment honesty — no runtime capability surface; compile-time engine identity + documented matrix | Accepted |
| 017 | Contract versioning — core crate's semver is the contract version; change classes, pairing carriers, lockstep duties | Accepted |
| 018 | Substrate provenance register and cherry-pick procedure — PROVENANCE.md in-tree, per-delta category-tagged entries, five-step adoption discipline |
Accepted |
| 019 | Mechanism-handle surfaces — handle traits (Queue/StreamHandle/Outbox/Lock/JobHandle), Job/Schedule shapes, worker_id identity, core StopToken |
Accepted |
| 020 | Enqueue-option semantics — delay/run_at precedence, relative expires, scheduler stamp source, serde_json payload encoding |
Accepted |
| 021 | Third review round — tx-read methods on TxHandle, Job.claimed_at, schedule() queue-argument validation, drop = rollback, receiver close/error arms |
Accepted |
| 022 | Contract-suite layout — shared internal suite crate, properties parameterized over a store factory (discharges ADR-017 §4.2's deferral) | Accepted |
| 023 | Fourth review round — encode_payload typed (Codec), numeric-argument domains by kind (extents clamp empty, durations reject, boundaries total), plain-path SQLite open (URI flag dropped), watcher cadence 1 ms default + SqliteOpts knob |
Accepted |
| 024 | The mem engine — a third engine (alkstore-mem), full contract v1, honest-ephemeral posture (collapses + amends ADR-001 §4's deferral) |
Accepted |
Open Questions
Tracked in open-questions.md (OQ-01..NN; the Phase 0 register's OQ-ST-01..08 promote one-to-one — OQ-NN mirrors OQ-ST-NN — with new Phase 1 questions appended after). The open question set is empty — all thirteen OQs are resolved (2026-10-04 through 2026-10-06, ADR-001 through ADR-018).
Resolved (kept with resolutions): OQ-01 (feature scope), OQ-02
(crate split), OQ-03 (drivers), OQ-07 (extension surface cut),
OQ-04 (contract v1 pinning —
ADR-008), OQ-09
(scheduler collapse — ADR-009;
scheduler guarantee row pinned), OQ-05 (queue semantics depth —
ADR-010), OQ-06
(honker-core quality read — fork fired,
ADR-011), OQ-08
(capability-surface shape — none, by default ever;
ADR-016), OQ-13
(transactional outbox enqueue shape —
ADR-014), OQ-12 (streams
depth — ADR-015), OQ-10
(contract versioning —
ADR-017), OQ-11
(fork follow-through — provenance register + cherry-pick procedure,
ADR-018).
No deferred OQs. The question set closed with OQ-11 (2026-10-06); the 2026-10-06 second review round, the 2026-10-07 third review round, and the 2026-10-08 fourth review round (the waves-1–2 general review) resolved their findings directly as ADR-019/ADR-020 and ADR-021 and ADR-023 respectively, rather than as new OQs. Phase 1 moves to architecture review closure and the implementation-phase gates.
Document Lifecycle
| Status | Meaning | Transitions |
|---|---|---|
draft |
Under active development; may change significantly | → reviewed when the doc's OQs are resolved |
reviewed |
Architecture final; implementation may begin | → stable when implementation verified |
stable |
Locked; changes need review, may warrant an ADR | → deprecated when superseded |
deprecated |
Superseded; kept for reference | Removed when unreferenced |
All spec documents carry YAML frontmatter (status, last_updated);
ADRs carry a ## Status section (Accepted/Proposed/Superseded).
Provenance of decisions
Phase 1 inherits its decisions from Phase 0's evidence base — every Accepted ADR above cites its POC findings and register record. The research documents remain the deep background:
docs/research/phase-0.md— vision, prior art, OQ-ST register, convergence.docs/research/consumer-inventory.md— per-feature scope evidence.docs/research/poc-sqlite-posture-findings.md/docs/research/poc-pg-posture-findings.md— measured ground.