postjevsql.git / crates / postjevsql-pg

For agents, on top of README.md, which they read first.

  • Every unsafe block carries a // SAFETY: naming the Postgres invariant it relies on.
  • Sockets must executor::deregister before closing: a closed fd reaching AddWaitEventToSet is an ERROR.
  • Task slots are Vacant/Running/Waiting. A spawn during a poll must never take the running task's slot; that bug once silently dropped hyper's h2 driver.
  • Never hold a RefCell borrow across an .await; an ERROR can unwind from any wait.
  • In the scan, evaluate expressions only through ScanTuple::eval. They are compiled for the node's virtual scan slot, which is never deformed; pointing ecxt_scantuple at another slot segfaulted in to_json over a Sort.
  • Tasks that belong to a scan are spawned in its executor::Scope. The (sub)transaction abort callback drops them before the flush, because the scan state itself is freed only later, with the query's memory.
  • No tokio, no threads, no signal handlers in anything this crate pulls in (root CLAUDE.md §2, "Traps"). A dependency that brings a runtime or spawn_blocking (reqwest, hyper-util's default resolver, hickory's tokio feature) is a regression even if every test passes.