store: on the host's connector (door only), pinned busbar d85c166728; RED arms split; published suite adopted - #20
Merged
Merged
Conversation
This was referenced Oct 5, 2026
ARCHITECT rulings 2026-10-03 on Q-L14-1 and Q-L16-2 (busbar THE DESIGN: every call Ready or
Pending(wake); no plugin opens its own socket). Depends on busbar lane-dg-storebridge@c7cc4f6696.
- The logic crate drops the `postgres` driver. src/pgwire.rs is an async Postgres frontend on the
sans-IO postgres-protocol (messages, SCRAM-SHA-256, md5) and postgres-types (the same binary
ToSql/FromSql the 1.5.5 driver used), every byte over the op's one connection (store SDK
wire::drive / Op::checkout). Parse/Describe/Sync then Bind/Execute/Sync, binary values; an
uncommitted Transaction is rolled back before the connection's next statement.
- store_door!(.., needs: NEEDS): one outbound `tcp` need, operator-infrastructure, target = the
DSN's host:port. `open` parses the settings (same refusal texts); StoreSlots::connect connects,
authenticates and migrates, so an unreachable or refusing server still fails the load at boot in
the driver's words ("error connecting to server: ...", password scrubbed).
- Every op is one connection: startup + auth, the 1.5.5 SQL body (now on a Session, with .await),
Terminate. RepeatableRead snapshots, advisory locks, SQLSTATE checks, render_pg_error/scrub and
the durable op_id dedupe are unchanged. sslmode=require|verify-* -> SSLRequest + upgrade_secure
through the host; the other modes stay plaintext as 1.5.5's NoTls.
- The plugin crate exports only the door; the cold-lane registration is deleted.
- busbar pinned at c7cc4f6696d53654ba1ac4f8e8c4fad0b9cd9df8 (manifests, .busbar-ref, workflows).
Tests open the store through the real loader with busbar's test connection table (tcp_conns),
raw verification on an independent `postgres` connection (dev-dependency). The metering test moves
to bucket 20_270_611: it raced the purge test on 20_270_601.
…root connector wakes a plugin's pending connection and drives dispatcher-worker sockets on its own I/O thread; the real-binary e2e tests need it)
…ion); TLS test through the host; busbar pin 180d92c205 -> 8faed15ca4 ARCHITECT rulings 2026-10-03 12:10Z (STORE-KEEP, TLS). - STORE-KEEP: the instance holds the store SDK's kept set (wire::Pool) bounded at KEPT_CONNECTIONS = 1, 1.5.5's one mutex-guarded connection (the 1.5.5 store has no pool setting). The connect step and every op run under wire::drive_kept: a kept connection skips TLS + startup/auth; the connection is kept only if the session is idle (last ReadyForQuery status I, nothing unread, no rollback pending; pgwire::Client::release), and a client dropped any other way (early return, protocol failure, open or failed transaction) discards it, so the next op connects afresh. No retry 1.5.5 did not have. - TLS: unchanged mapping (disable/allow/prefer plaintext as 1.5.5 NoTls; require/verify-* SSLRequest, 'S', upgrade_secure on the DSN host; 'N' fails the load). Docs say the host always verifies. - Tests: src/tests/tls.rs (live): verify_full_secures_the_connection_through_the_host (in-test TLS proxy with a per-run rcgen CA in front of the live server; TcpConns::with_roots), an_untrusted_server_certificate_fails_the_load_in_the_drivers_words, the_store_keeps_one_connection_across_its_ops (one backend pid across the connect step and ten ops). The harness closes each test store's instance on drop. rustls/rustls-pki-types/rcgen are dev-dependencies only. - Pin: busbar 8faed15ca46ec48d5818dc0bd0c22a9c15218de1 (manifests, .busbar-ref, workflows, Cargo.lock).
…dStore closes its instance on drop) The harness's own close-on-drop workaround is struck: busbar's LoadedStore now closes its instance when dropped, and its kept connection with it. the_store_keeps_one_connection_across_its_ops again asserts that dropping the store closes its backend connection. The full live suite runs at the server's default max_connections (100).
The fleet's bothways gate needs a RED arm in the conformance target as a test of its own. The foreign-bytes arm and the as-another-kind arm move out of the_linked_and_the_dropped_in_postgres_store_are_one_store into foreign_bytes_dropped_in_are_not_the_postgres_store and the_postgres_store_library_loaded_as_another_kind_is_refused, every assertion kept; neither needs a database. The loader at the pin dlopens the path it is given (no memfd), and the foreign image sits under its own directory, so the arm no longer depends on running first.
Seeded from busbar's Cargo.lock at the pin and re-resolved: every crate both locks hold is at busbar's version (rustls 0.23.43 -> 0.23.45 clears RUSTSEC-2026-0285), except the sha2 0.11 line postgres-protocol 0.6.12 needs (sha2 0.11.0, digest 0.11.3, block-buffer 0.12.1, crypto-common 0.2.2, const-oid 0.10.2) and wasi 0.14.7 (dev-only: postgres -> tokio-postgres 0.7.18 -> whoami 2). Older postgres-protocol (<= 0.6.10, sha2 0.10) carries RUSTSEC-2026-0179/0180 and tokio-postgres < 0.7.18 RUSTSEC-2026-0178.
…d lines); Cargo.lock re-derived from busbar's lock at the pin Seeded from busbar's Cargo.lock at d85c166728 and re-resolved: every crate both locks hold is at busbar's version except the lines busbar's .github/fleet/deps.toml [parity-lines] declares for this repo (sha2 0.11, digest 0.11, block-buffer 0.12, crypto-common 0.2, const-oid 0.10 shipped through postgres-protocol 0.6.12; wasi 0.14 tests-only through the postgres test client). xtask plugin-gates parity at the pin: 0 findings.
MattJackson
force-pushed
the
p4-fleet-doors
branch
from
October 5, 2026 11:53
9371fee to
07d7369
Compare
…-release #161: the [parity-lines] rows open their lines) The workspace table and deny.toml are the render of busbar-release PR #161 (p4-parity-lines, f20a4dc) at pin d85c166728: busbar's dependency policy at the pin, and the declared sha2 0.11, digest 0.11, block-buffer 0.12, crypto-common 0.2, const-oid 0.10 and wasi 0.14 lines allowed. rcgen now comes from the workspace table (its row carries the features the TLS test asked for).
…store script over the live Postgres)
store-postgres-plugin/tests/conformance.rs runs busbar_plugin_loader::conformance_suite! over the
logic crate's door and the built cdylib, with conformance.json naming the CI service
(postgres://busbar:busbar@localhost:5432/busbar_test) and the store section's inputs. The repo's
own both-ways test and its two RED tests stay beside it. busbar-plugin-loader gains the
`conformance` feature as a dev-dependency.
The suite's both-ways arm and two of its RED arms do not pass against this store at d85c166728:
the store script pins one crossing per op, but every op of a store that talks to its server over the
connector pends on its reads and is resumed (measured 2 to 26 crossings per op); red_ready expects
`open` to answer READY in one call while this store connects in `open`; the script's credentials
are kind "generic", which the store's schema refuses (kind IN ('sigv4')); and both legs (and the
parallel RED fold) share one database under the same ids and op ids.
… (busbar d85c166728 TcpConns::with_tls) At the pin the loader's test table names no TLS library: TcpConns::with_roots is gone and a test hands it the TLS it secures with. The TLS test's is rustls trusting the run's CA alone (certificate and name verified), the handshake the old with_roots ran, moved into the test.
…uires a store: block)
At the pin busbar refuses a config without `store:` (BUSBAR-9007), so the first boot's config now
names `store: {module: memory}`, the RAM store the absent block used to mean.
…-fold namespace and resumes); Cargo.lock re-derived from busbar's lock at the pin; Cargo.toml and deny.toml the busbar-release #161 render at the pin xtask plugin-gates parity at the pin: 0 findings; cargo deny: clean.
At the pin a Bind's table is a ConnTable: the live tests' binds are ConnTable::Host over the loader's test table; the as-another-kind RED test binds a Probe (no table, nothing opened), so its refusal is still the kind's.
…-fold namespace hooks); Cargo.lock re-derived from busbar's lock at the pin; Cargo.toml and deny.toml the busbar-release #161 render at the pin xtask plugin-gates parity at the pin: 0 findings; cargo deny: clean.
…e hooks, search_path={fold}), credential kind sigv4
conformance.json's url sets search_path to the fold's namespace; the suite's namespace hooks
create that schema before each fold and drop it (CASCADE) after, on an independent connection of
the postgres driver, so the two legs and CI's debug, release and RED runs never share rows. The
store's credential kind input is sigv4, the one its schema holds. Locally (Postgres 17): the suite's
six tests and the repo's three pass in release and debug, the moved count fails on the comparator,
and no fold schema is left behind.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Replaces #19 (the Postgres store on the host's connector: no socket of its own, door only, cold twin gone) and #15 (RED-arm split). Rebased on dev after the fleet render sync (#13); pinned to busbar d85c166728f0bc17b68477248c8d86cf648187ad (lane-p4-fleet-doors, not yet in a busbar PR: do not merge until the pin moves to a merged busbar commit).
foreign_bytes_dropped_in_are_not_the_postgres_store,the_postgres_store_library_loaded_as_another_kind_is_refused), and busbar's published suite (conformance_suite!, conformance.json dialling the CI Postgres) sits beside them.TcpConns::with_tls), so the test hands it rustls trusting the run's CA.Known red: the published suite's store script can't drive a store that talks to its server over the connector at this pin. Crossing counts per op depend on how often a read pends; red_ready expects
opento answer READY in one call; the script's credential kind is "generic", which the schema refuses; and the two legs share one database. These gaps are reported to the busbar lane.Behaviour unchanged.