Skip to content

store: on the host's connector (door only), pinned busbar 1c9e599003; RED arms split; lock from busbar's at the pin - #20

Open
MattJackson wants to merge 6 commits into
devfrom
p4-fleet-doors
Open

MattJackson wants to merge 6 commits into
devfrom
p4-fleet-doors

Conversation

@MattJackson

Copy link
Copy Markdown
Contributor

Replaces #19 (same branch history: the Postgres store on the host's connector, no own socket, door only, cold twin gone; busbar pin 1c9e599003ad2b2789b271482824b52f390c3200) and #15 (RED-arm split), plus the fixes for #19's red linux job (run 37270299144):

  • both-ways conformance: the two RED arms move out of the_linked_and_the_dropped_in_postgres_store_are_one_store into foreign_bytes_dropped_in_are_not_the_postgres_store and the_postgres_store_library_loaded_as_another_kind_is_refused; every assertion kept; neither needs a database.
  • cargo deny: Cargo.lock re-derived from busbar's lock at the pin; rustls 0.23.43 -> 0.23.45 (RUSTSEC-2026-0285). cargo deny check is clean locally.
  • Cargo.lock parity: down from 64 findings to 6. The 6 left cannot be cleared from this repo without a busbar change or a rewrite: postgres-protocol >= 0.6.11 needs sha2 0.11 (sha2 0.11.0, digest 0.11.3, block-buffer 0.12.1, crypto-common 0.2.2, const-oid 0.10.2), and busbar's lock at 1c9e599003 holds only the sha2 0.10 line; tokio-postgres 0.7.18 (dev-only, via the postgres test client) needs whoami 2 -> wasi 0.14.7 (busbar holds 0.11.1). The parity-clean versions (postgres-protocol 0.6.10, tokio-postgres 0.7.15) carry RUSTSEC-2026-0178/0179/0180, so deny goes red instead. Open question is in the lane report.

Behaviour unchanged.

ARCHITECT rulings 2026-10-03 on Q-L14-1 and Q-L16-2 (busbar THE DESIGN: every call Ready or
Pending(wake); no plugin opens its own socket). Depends on busbar lane-dg-storebridge@c7cc4f6696.

- The logic crate drops the `postgres` driver. src/pgwire.rs is an async Postgres frontend on the
  sans-IO postgres-protocol (messages, SCRAM-SHA-256, md5) and postgres-types (the same binary
  ToSql/FromSql the 1.5.5 driver used), every byte over the op's one connection (store SDK
  wire::drive / Op::checkout). Parse/Describe/Sync then Bind/Execute/Sync, binary values; an
  uncommitted Transaction is rolled back before the connection's next statement.
- store_door!(.., needs: NEEDS): one outbound `tcp` need, operator-infrastructure, target = the
  DSN's host:port. `open` parses the settings (same refusal texts); StoreSlots::connect connects,
  authenticates and migrates, so an unreachable or refusing server still fails the load at boot in
  the driver's words ("error connecting to server: ...", password scrubbed).
- Every op is one connection: startup + auth, the 1.5.5 SQL body (now on a Session, with .await),
  Terminate. RepeatableRead snapshots, advisory locks, SQLSTATE checks, render_pg_error/scrub and
  the durable op_id dedupe are unchanged. sslmode=require|verify-* -> SSLRequest + upgrade_secure
  through the host; the other modes stay plaintext as 1.5.5's NoTls.
- The plugin crate exports only the door; the cold-lane registration is deleted.
- busbar pinned at c7cc4f6696d53654ba1ac4f8e8c4fad0b9cd9df8 (manifests, .busbar-ref, workflows).

Tests open the store through the real loader with busbar's test connection table (tcp_conns),
raw verification on an independent `postgres` connection (dev-dependency). The metering test moves
to bucket 20_270_611: it raced the purge test on 20_270_601.
…root connector wakes a plugin's pending connection and drives dispatcher-worker sockets on its own I/O thread; the real-binary e2e tests need it)
…ion); TLS test through the host; busbar pin 180d92c205 -> 8faed15ca4

ARCHITECT rulings 2026-10-03 12:10Z (STORE-KEEP, TLS).

- STORE-KEEP: the instance holds the store SDK's kept set (wire::Pool) bounded at KEPT_CONNECTIONS = 1,
  1.5.5's one mutex-guarded connection (the 1.5.5 store has no pool setting). The connect step and
  every op run under wire::drive_kept: a kept connection skips TLS + startup/auth; the connection is
  kept only if the session is idle (last ReadyForQuery status I, nothing unread, no rollback
  pending; pgwire::Client::release), and a client dropped any other way (early return, protocol
  failure, open or failed transaction) discards it, so the next op connects afresh. No retry 1.5.5
  did not have.
- TLS: unchanged mapping (disable/allow/prefer plaintext as 1.5.5 NoTls; require/verify-* SSLRequest,
  'S', upgrade_secure on the DSN host; 'N' fails the load). Docs say the host always verifies.
- Tests: src/tests/tls.rs (live): verify_full_secures_the_connection_through_the_host (in-test TLS
  proxy with a per-run rcgen CA in front of the live server; TcpConns::with_roots),
  an_untrusted_server_certificate_fails_the_load_in_the_drivers_words,
  the_store_keeps_one_connection_across_its_ops (one backend pid across the connect step and ten
  ops). The harness closes each test store's instance on drop. rustls/rustls-pki-types/rcgen are
  dev-dependencies only.
- Pin: busbar 8faed15ca46ec48d5818dc0bd0c22a9c15218de1 (manifests, .busbar-ref, workflows, Cargo.lock).
…dStore closes its instance on drop)

The harness's own close-on-drop workaround is struck: busbar's LoadedStore now closes its instance
when dropped, and its kept connection with it. the_store_keeps_one_connection_across_its_ops again
asserts that dropping the store closes its backend connection. The full live suite runs at the
server's default max_connections (100).
The fleet's bothways gate needs a RED arm in the conformance target as a test of its own. The
foreign-bytes arm and the as-another-kind arm move out of
the_linked_and_the_dropped_in_postgres_store_are_one_store into
foreign_bytes_dropped_in_are_not_the_postgres_store and
the_postgres_store_library_loaded_as_another_kind_is_refused, every assertion kept; neither needs a
database. The loader at the pin dlopens the path it is given (no memfd), and the foreign image sits
under its own directory, so the arm no longer depends on running first.
Seeded from busbar's Cargo.lock at the pin and re-resolved: every crate both locks hold is at
busbar's version (rustls 0.23.43 -> 0.23.45 clears RUSTSEC-2026-0285), except the sha2 0.11 line
postgres-protocol 0.6.12 needs (sha2 0.11.0, digest 0.11.3, block-buffer 0.12.1, crypto-common
0.2.2, const-oid 0.10.2) and wasi 0.14.7 (dev-only: postgres -> tokio-postgres 0.7.18 -> whoami 2).
Older postgres-protocol (<= 0.6.10, sha2 0.10) carries RUSTSEC-2026-0179/0180 and tokio-postgres
< 0.7.18 RUSTSEC-2026-0178.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant