For agents, on top of README.md, which they read first.

  • #![forbid(unsafe_code)] holds through pgrx's macros; keep it. Anything that needs unsafe goes in postjevsql-pg behind a safe API.
  • jev.endpoint stays superuser-only: whoever sets it receives the API key. The same goes for jev.api_key_file (whose account pays), jev.dns_servers (where names point) and jev.price_per_mtok (what spend is reckoned from).
  • The control file's version is @CARGO_VERSION@, filled from build/defs.bzl. Never write a version here.
  • A SQL function's body only refuses (Failure::Unbatched). The scan answers every call it claims; never give a body real work, or a call the scan missed would send one request per row.
  • A new function is three edits that must agree: its #[pg_extern], its entry in JevScan::FUNCTIONS, and a REVOKE line in revoke_from_public (tests/privileges.rs fails on a function left executable by PUBLIC). TREE_FUNCTIONS and SHORTLIST_FUNCTIONS are indexes into FUNCTIONS, so inserting an entry before them shifts them.