- forwarder.rs's ListenerConnection doc corrected: NoTls is hardwired on every connection path (pooled, listener, reconnect) — the pooled path never rode the consumer's Config sslmode (a sslmode=require DSN fails at connect); grep-audited no other in-crate doc repeats the claim - PgOpts doc carries the corrected one-line TLS pointer (engine-crate- docs posture, ADR-016 §2) - deployment.md: new 'TLS posture (v1)' subsection (NoTls everywhere, sslmode=require DSN fails at connect, topology-level confidentiality is the v1 substitute, TLS a post-v1 deployment concern) and a new 'Consumer-obligation notes on engine options' section carrying the QueueOpts trusted-as-given note with code-verified per-field symptoms (max_attempts <= 0: never claimed, dead-lettered at the next claim call's pre-claim sweep; negative visibility: instantly-reclaimable claims; negative retention: every dead row at the next sweep_expired) plus the PgOpts::max_size 0-guard counter-case; frontmatter advanced - alkstore/src/opts.rs: QueueOpts struct doc mirrors the consumer-obligation note (ADR-023 §2 scoping: the domain table covers trait-surface arguments, not consumer-constructed constants) - cross-file doc sweep over the fix batch's touched files (forwarder, tx, scheduler, store) found no further doc-behavior mismatch - gates: cargo build / clippy --all-targets -D warnings / fmt --check all green (doc-only, no test touched)
79 lines
3.7 KiB
Rust
79 lines
3.7 KiB
Rust
//! The pg engine's option struct (ADR-008 §6 — constructors and their
|
|
//! option structs live in the engine crates; engine-configuration
|
|
//! concerns never touch the contract surface).
|
|
//!
|
|
//! `#[non_exhaustive]` deliberately does not apply (ADR-017 §3): opts
|
|
//! structs are consumer-*constructed*, and the attribute on them would
|
|
//! push every construction through a builder. New fields may be added
|
|
//! with `Default` fallbacks, per the core opts modules' posture.
|
|
|
|
use crate::DEFAULT_SCHEMA;
|
|
|
|
/// The default deadpool pool size (the deployment matrix's budget
|
|
/// line: the listener connection adds +1 outside the pool per
|
|
/// LISTEN-ing process — deployment.md's connection budgets).
|
|
pub const DEFAULT_MAX_SIZE: usize = 8;
|
|
|
|
/// The listener connection's `application_name` prefix — the base of
|
|
/// the per-instance name `{prefix}-{pid}-{seq}` the store assigns
|
|
/// (kill-targetable and diagnosable server-side; deployment.md's ops
|
|
/// note, the POC's listener-setting carried; the unique suffix makes
|
|
/// parallel instances distinguishable in `pg_stat_activity` without
|
|
/// losing the ops prefix).
|
|
pub(crate) const LISTENER_APPLICATION_NAME: &str = "alkstore-pg-listener";
|
|
|
|
/// Construction options for the pg engine's
|
|
/// [`open`](crate::open) constructor.
|
|
///
|
|
/// Durability knobs, pool sizing, and the engine-owned schema name are
|
|
/// engine-configuration concerns — they never appear on the contract
|
|
/// surface (ADR-008 §6); deployment.md carries the documented tuning
|
|
/// facts (the `synchronous_commit` trade, the `max_size + 1` listener
|
|
/// budget line).
|
|
///
|
|
/// The connection settings themselves do not ride this struct — they
|
|
/// are `open`'s first argument (the tokio-postgres
|
|
/// [`Config`](::tokio_postgres::Config)-parseable form, ADR-008 §6's
|
|
/// `open(url, PgOpts)` pin); the engine never invents defaults for
|
|
/// them. `open` fails with [`Error::Database`] if the config is
|
|
/// unparseable or the server unreachable. TLS: the engine hardwires
|
|
/// `NoTls` on every connection path regardless of the config's
|
|
/// sslmode — v1 TLS is a post-v1 deployment concern
|
|
/// (deployment.md's TLS posture carries the statement).
|
|
#[derive(Debug, Clone)]
|
|
pub struct PgOpts {
|
|
/// The engine-owned PostgreSQL schema (ADR-010 §8). Default
|
|
/// [`DEFAULT_SCHEMA`] (`"alkstore"`). All engine tables live in
|
|
/// this one schema; consumer tables co-tenant the instance
|
|
/// untouched. The name is a quoted identifier boundary
|
|
/// (`quote_identifier`) — reserved-word and hostile names are
|
|
/// safe.
|
|
pub schema: String,
|
|
/// Upper bound on pooled connections (deadpool's `max_size`) —
|
|
/// queries, claims, and all non-transactional work ride these.
|
|
/// Default [`DEFAULT_MAX_SIZE`] = 8 (the deployment matrix's
|
|
/// budget line; the listener adds +1 per LISTEN-ing process
|
|
/// *outside* the pool — sizing rule `max_size + 1`). A value of
|
|
/// `0` fails [`open`](crate::open) with [`Error::Database`]
|
|
/// immediately (validated at entry — no round trip; deadpool
|
|
/// cannot grant checkouts from an empty pool).
|
|
pub max_size: usize,
|
|
/// The per-session `synchronous_commit` durability knob, wired as
|
|
/// a connect-options `-c synchronous_commit=…` on every pooled
|
|
/// connection (POC-verified per-session SET mechanics). Default
|
|
/// `true` — ship config (p50 2.40 ms seam); `false` trades
|
|
/// max-tail (40.9 ms) for slightly better p50 — the measured,
|
|
/// honest trade (ADR-004, deployment.md).
|
|
pub synchronous_commit: bool,
|
|
}
|
|
|
|
impl Default for PgOpts {
|
|
fn default() -> Self {
|
|
Self {
|
|
schema: DEFAULT_SCHEMA.to_string(),
|
|
max_size: DEFAULT_MAX_SIZE,
|
|
synchronous_commit: true,
|
|
}
|
|
}
|
|
}
|