Skip to content

docs: specify the 0.4.0 monorepo engine - #14

Merged
0xgleb merged 1 commit into
masterfrom
spec/0.4-monorepo-engine
Jul 16, 2026
Merged

0xgleb merged 1 commit into
masterfrom
spec/0.4-monorepo-engine

Conversation

@0xgleb

@0xgleb 0xgleb commented Jul 14, 2026 •

Copy link
Copy Markdown
Member

Defines the 0.4.0 extraction contract: the shared engine must be carved out of the existing cqrs-es, Apalis, sqlite-es, SQLx, and SQLite implementation. It preserves the current Rust API and job/dispatch semantics, prohibits parallel Rust or Haskell framework implementations, and makes deterministic CBOR an ABI encoding rather than a storage rewrite.

Updates ADR-0010 and the roadmap so characterization of current behavior precedes facade extraction.

Part of #9.


This is part 1 of 32 in a stack made with GitButler:

Summary by CodeRabbit

  • Documentation
    • Expanded the 0.4.0 roadmap with the “one engine” extraction plan and release readiness checklist.
    • Replaced the system specification with a new 0.4.0 contract covering the shared engine facade, FFI/ABI rules, deterministic encoding, and cross-language conformance.
    • Published an ADR outlining the single-engine, multi-binding architecture and mandatory migration/cutover validation gates.
    • Added a 0.4.0 threat model detailing boundary risks (STRIDE) and required verification controls for the engine and ABI surface.

@coderabbitai

coderabbitai Bot commented Jul 14, 2026 •

Copy link
Copy Markdown

Review Change Stack

Important

Review skipped

Too many files!

This PR contains 315 files, which is 265 over the limit of 50.

To get a review, narrow the scope:
• coderabbit review --type committed # exclude uncommitted changes
• coderabbit review --dir # limit to a subdirectory
• coderabbit review --base # compare against a closer base

Upgrade to a paid plan to raise the limit.

Usage-priced reviews support at most 300 files.

⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: f18a419a-70e4-4f3f-acbf-72246577fef1

📥 Commits

Reviewing files that changed from the base of the PR and between c5368fd and 9d6593d.

⛔ Files ignored due to path filters (16)
  • .auto-resolution/Cargo.lock is excluded by !**/*.lock
  • .auto-resolution/examples/complex/Cargo.lock is excluded by !**/*.lock
  • .auto-resolution/examples/simple/Cargo.lock is excluded by !**/*.lock
  • .auto-resolution/flake.lock is excluded by !**/*.lock
  • .conflict-base-0/Cargo.lock is excluded by !**/*.lock
  • .conflict-base-0/examples/complex/Cargo.lock is excluded by !**/*.lock
  • .conflict-base-0/examples/simple/Cargo.lock is excluded by !**/*.lock
  • .conflict-base-0/flake.lock is excluded by !**/*.lock
  • .conflict-side-0/Cargo.lock is excluded by !**/*.lock
  • .conflict-side-0/examples/complex/Cargo.lock is excluded by !**/*.lock
  • .conflict-side-0/examples/simple/Cargo.lock is excluded by !**/*.lock
  • .conflict-side-0/flake.lock is excluded by !**/*.lock
  • .conflict-side-1/Cargo.lock is excluded by !**/*.lock
  • .conflict-side-1/examples/complex/Cargo.lock is excluded by !**/*.lock
  • .conflict-side-1/examples/simple/Cargo.lock is excluded by !**/*.lock
  • .conflict-side-1/flake.lock is excluded by !**/*.lock
📒 Files selected for processing (315)
  • .auto-resolution/.coderabbit.yaml
  • .auto-resolution/.envrc
  • .auto-resolution/.github/PULL_REQUEST_TEMPLATE.md
  • .auto-resolution/.github/workflows/ci.yaml
  • .auto-resolution/.gitignore
  • .auto-resolution/.yamlfmt
  • .auto-resolution/AGENTS.md
  • .auto-resolution/CLAUDE.md
  • .auto-resolution/Cargo.toml
  • .auto-resolution/LICENSE
  • .auto-resolution/README.md
  • .auto-resolution/ROADMAP.md
  • .auto-resolution/SPEC.md
  • .auto-resolution/adrs/0001-jobs-replace-services.md
  • .auto-resolution/adrs/0003-snapshot-discard-compaction-policy.md
  • .auto-resolution/adrs/0005-backend-agnostic-event-store.md
  • .auto-resolution/adrs/0006-cqrs-native-durable-jobs.md
  • .auto-resolution/adrs/0007-reactor-side-job-enqueue.md
  • .auto-resolution/adrs/0008-entity-scoped-durable-operations.md
  • .auto-resolution/adrs/0009-handlers-return-events-or-one-job-dispatch.md
  • .auto-resolution/adrs/0010-one-engine-multiple-bindings.md
  • .auto-resolution/clippy.toml
  • .auto-resolution/crates/event-sorcery/Cargo.toml
  • .auto-resolution/crates/event-sorcery/benches/dispatch.rs
  • .auto-resolution/crates/event-sorcery/benches/store.rs
  • .auto-resolution/crates/event-sorcery/src/dependency.rs
  • .auto-resolution/crates/event-sorcery/src/dispatch.rs
  • .auto-resolution/crates/event-sorcery/src/job.rs
  • .auto-resolution/crates/event-sorcery/src/job_backend.rs
  • .auto-resolution/crates/event-sorcery/src/job_sqlite.rs
  • .auto-resolution/crates/event-sorcery/src/job_store.rs
  • .auto-resolution/crates/event-sorcery/src/lib.rs
  • .auto-resolution/crates/event-sorcery/src/lifecycle.rs
  • .auto-resolution/crates/event-sorcery/src/projection.rs
  • .auto-resolution/crates/event-sorcery/src/reactor.rs
  • .auto-resolution/crates/event-sorcery/src/schema_registry.rs
  • .auto-resolution/crates/event-sorcery/src/sqlite_event_repository.rs
  • .auto-resolution/crates/event-sorcery/src/testing.rs
  • .auto-resolution/crates/event-sorcery/src/view_backend.rs
  • .auto-resolution/crates/event-sorcery/src/wire.rs
  • .auto-resolution/crates/sqlite-es/Cargo.toml
  • .auto-resolution/crates/sqlite-es/README.md
  • .auto-resolution/crates/sqlite-es/migrations/20251016210348_init.sql
  • .auto-resolution/crates/sqlite-es/migrations/20260627041347_job_queue.sql
  • .auto-resolution/crates/sqlite-es/migrations/20260627171021_job_queue_reclaim_index.sql
  • .auto-resolution/crates/sqlite-es/migrations/20260627223938_job_queue_event_sourced_view.sql
  • .auto-resolution/crates/sqlite-es/src/cqrs.rs
  • .auto-resolution/crates/sqlite-es/src/event_repository.rs
  • .auto-resolution/crates/sqlite-es/src/lib.rs
  • .auto-resolution/crates/sqlite-es/src/sql_query.rs
  • .auto-resolution/crates/sqlite-es/src/testing.rs
  • .auto-resolution/crates/sqlite-es/src/view_repository.rs
  • .auto-resolution/docs/cqrs.md
  • .auto-resolution/docs/domain.md
  • .auto-resolution/docs/event-sourced-job-backend-spec.md
  • .auto-resolution/docs/migrating-to-durable-jobs.md
  • .auto-resolution/docs/sqlx.md
  • .auto-resolution/docs/threat-model-0.4.md
  • .auto-resolution/docs/ttdd.md
  • .auto-resolution/examples/README.md
  • .auto-resolution/examples/complex/Cargo.toml
  • .auto-resolution/examples/complex/README.md
  • .auto-resolution/examples/complex/migrations/20260513104032_init.sql
  • .auto-resolution/examples/complex/migrations/20260513104033_inventory_view.sql
  • .auto-resolution/examples/complex/migrations/20260513104034_job_queue.sql
  • .auto-resolution/examples/complex/src/audit_log.rs
  • .auto-resolution/examples/complex/src/inventory.rs
  • .auto-resolution/examples/complex/src/main.rs
  • .auto-resolution/examples/complex/src/order.rs
  • .auto-resolution/examples/complex/src/stock_alert.rs
  • .auto-resolution/examples/simple/Cargo.toml
  • .auto-resolution/examples/simple/README.md
  • .auto-resolution/examples/simple/migrations/20260513104023_init.sql
  • .auto-resolution/examples/simple/migrations/20260513104024_support_ticket_view.sql
  • .auto-resolution/examples/simple/migrations/20260513104025_job_queue.sql
  • .auto-resolution/examples/simple/src/main.rs
  • .auto-resolution/examples/simple/src/support_ticket.rs
  • .auto-resolution/flake.nix
  • .auto-resolution/scripts/check-examples.nu
  • .conflict-base-0/.coderabbit.yaml
  • .conflict-base-0/.envrc
  • .conflict-base-0/.github/PULL_REQUEST_TEMPLATE.md
  • .conflict-base-0/.github/workflows/ci.yaml
  • .conflict-base-0/.gitignore
  • .conflict-base-0/.yamlfmt
  • .conflict-base-0/AGENTS.md
  • .conflict-base-0/CLAUDE.md
  • .conflict-base-0/Cargo.toml
  • .conflict-base-0/LICENSE
  • .conflict-base-0/README.md
  • .conflict-base-0/SPEC.md
  • .conflict-base-0/adrs/0001-jobs-replace-services.md
  • .conflict-base-0/adrs/0003-snapshot-discard-compaction-policy.md
  • .conflict-base-0/adrs/0005-backend-agnostic-event-store.md
  • .conflict-base-0/adrs/0006-cqrs-native-durable-jobs.md
  • .conflict-base-0/adrs/0007-reactor-side-job-enqueue.md
  • .conflict-base-0/adrs/0008-entity-scoped-durable-operations.md
  • .conflict-base-0/adrs/0009-handlers-return-events-or-one-job-dispatch.md
  • .conflict-base-0/clippy.toml
  • .conflict-base-0/crates/event-sorcery/Cargo.toml
  • .conflict-base-0/crates/event-sorcery/benches/dispatch.rs
  • .conflict-base-0/crates/event-sorcery/benches/store.rs
  • .conflict-base-0/crates/event-sorcery/src/dependency.rs
  • .conflict-base-0/crates/event-sorcery/src/dispatch.rs
  • .conflict-base-0/crates/event-sorcery/src/job.rs
  • .conflict-base-0/crates/event-sorcery/src/job_backend.rs
  • .conflict-base-0/crates/event-sorcery/src/job_sqlite.rs
  • .conflict-base-0/crates/event-sorcery/src/job_store.rs
  • .conflict-base-0/crates/event-sorcery/src/lib.rs
  • .conflict-base-0/crates/event-sorcery/src/lifecycle.rs
  • .conflict-base-0/crates/event-sorcery/src/projection.rs
  • .conflict-base-0/crates/event-sorcery/src/reactor.rs
  • .conflict-base-0/crates/event-sorcery/src/schema_registry.rs
  • .conflict-base-0/crates/event-sorcery/src/sqlite_event_repository.rs
  • .conflict-base-0/crates/event-sorcery/src/testing.rs
  • .conflict-base-0/crates/event-sorcery/src/view_backend.rs
  • .conflict-base-0/crates/event-sorcery/src/wire.rs
  • .conflict-base-0/crates/sqlite-es/Cargo.toml
  • .conflict-base-0/crates/sqlite-es/README.md
  • .conflict-base-0/crates/sqlite-es/migrations/20251016210348_init.sql
  • .conflict-base-0/crates/sqlite-es/migrations/20260627041347_job_queue.sql
  • .conflict-base-0/crates/sqlite-es/migrations/20260627171021_job_queue_reclaim_index.sql
  • .conflict-base-0/crates/sqlite-es/migrations/20260627223938_job_queue_event_sourced_view.sql
  • .conflict-base-0/crates/sqlite-es/src/cqrs.rs
  • .conflict-base-0/crates/sqlite-es/src/event_repository.rs
  • .conflict-base-0/crates/sqlite-es/src/lib.rs
  • .conflict-base-0/crates/sqlite-es/src/sql_query.rs
  • .conflict-base-0/crates/sqlite-es/src/testing.rs
  • .conflict-base-0/crates/sqlite-es/src/view_repository.rs
  • .conflict-base-0/docs/cqrs.md
  • .conflict-base-0/docs/domain.md
  • .conflict-base-0/docs/event-sourced-job-backend-spec.md
  • .conflict-base-0/docs/migrating-to-durable-jobs.md
  • .conflict-base-0/docs/sqlx.md
  • .conflict-base-0/docs/ttdd.md
  • .conflict-base-0/examples/README.md
  • .conflict-base-0/examples/complex/Cargo.toml
  • .conflict-base-0/examples/complex/README.md
  • .conflict-base-0/examples/complex/migrations/20260513104032_init.sql
  • .conflict-base-0/examples/complex/migrations/20260513104033_inventory_view.sql
  • .conflict-base-0/examples/complex/migrations/20260513104034_job_queue.sql
  • .conflict-base-0/examples/complex/src/audit_log.rs
  • .conflict-base-0/examples/complex/src/inventory.rs
  • .conflict-base-0/examples/complex/src/main.rs
  • .conflict-base-0/examples/complex/src/order.rs
  • .conflict-base-0/examples/complex/src/stock_alert.rs
  • .conflict-base-0/examples/simple/Cargo.toml
  • .conflict-base-0/examples/simple/README.md
  • .conflict-base-0/examples/simple/migrations/20260513104023_init.sql
  • .conflict-base-0/examples/simple/migrations/20260513104024_support_ticket_view.sql
  • .conflict-base-0/examples/simple/migrations/20260513104025_job_queue.sql
  • .conflict-base-0/examples/simple/src/main.rs
  • .conflict-base-0/examples/simple/src/support_ticket.rs
  • .conflict-base-0/flake.nix
  • .conflict-base-0/scripts/check-examples.nu
  • .conflict-files
  • .conflict-side-0/.coderabbit.yaml
  • .conflict-side-0/.envrc
  • .conflict-side-0/.github/PULL_REQUEST_TEMPLATE.md
  • .conflict-side-0/.github/workflows/ci.yaml
  • .conflict-side-0/.gitignore
  • .conflict-side-0/.yamlfmt
  • .conflict-side-0/AGENTS.md
  • .conflict-side-0/CLAUDE.md
  • .conflict-side-0/Cargo.toml
  • .conflict-side-0/LICENSE
  • .conflict-side-0/README.md
  • .conflict-side-0/SPEC.md
  • .conflict-side-0/adrs/0001-jobs-replace-services.md
  • .conflict-side-0/adrs/0003-snapshot-discard-compaction-policy.md
  • .conflict-side-0/adrs/0005-backend-agnostic-event-store.md
  • .conflict-side-0/adrs/0006-cqrs-native-durable-jobs.md
  • .conflict-side-0/adrs/0007-reactor-side-job-enqueue.md
  • .conflict-side-0/adrs/0008-entity-scoped-durable-operations.md
  • .conflict-side-0/adrs/0009-handlers-return-events-or-one-job-dispatch.md
  • .conflict-side-0/clippy.toml
  • .conflict-side-0/crates/event-sorcery/Cargo.toml
  • .conflict-side-0/crates/event-sorcery/benches/dispatch.rs
  • .conflict-side-0/crates/event-sorcery/benches/store.rs
  • .conflict-side-0/crates/event-sorcery/src/dependency.rs
  • .conflict-side-0/crates/event-sorcery/src/dispatch.rs
  • .conflict-side-0/crates/event-sorcery/src/job.rs
  • .conflict-side-0/crates/event-sorcery/src/job_backend.rs
  • .conflict-side-0/crates/event-sorcery/src/job_sqlite.rs
  • .conflict-side-0/crates/event-sorcery/src/job_store.rs
  • .conflict-side-0/crates/event-sorcery/src/lib.rs
  • .conflict-side-0/crates/event-sorcery/src/lifecycle.rs
  • .conflict-side-0/crates/event-sorcery/src/projection.rs
  • .conflict-side-0/crates/event-sorcery/src/reactor.rs
  • .conflict-side-0/crates/event-sorcery/src/schema_registry.rs
  • .conflict-side-0/crates/event-sorcery/src/sqlite_event_repository.rs
  • .conflict-side-0/crates/event-sorcery/src/testing.rs
  • .conflict-side-0/crates/event-sorcery/src/view_backend.rs
  • .conflict-side-0/crates/event-sorcery/src/wire.rs
  • .conflict-side-0/crates/sqlite-es/Cargo.toml
  • .conflict-side-0/crates/sqlite-es/README.md
  • .conflict-side-0/crates/sqlite-es/migrations/20251016210348_init.sql
  • .conflict-side-0/crates/sqlite-es/migrations/20260627041347_job_queue.sql
  • .conflict-side-0/crates/sqlite-es/migrations/20260627171021_job_queue_reclaim_index.sql
  • .conflict-side-0/crates/sqlite-es/migrations/20260627223938_job_queue_event_sourced_view.sql
  • .conflict-side-0/crates/sqlite-es/src/cqrs.rs
  • .conflict-side-0/crates/sqlite-es/src/event_repository.rs
  • .conflict-side-0/crates/sqlite-es/src/lib.rs
  • .conflict-side-0/crates/sqlite-es/src/sql_query.rs
  • .conflict-side-0/crates/sqlite-es/src/testing.rs
  • .conflict-side-0/crates/sqlite-es/src/view_repository.rs
  • .conflict-side-0/docs/cqrs.md
  • .conflict-side-0/docs/domain.md
  • .conflict-side-0/docs/event-sourced-job-backend-spec.md
  • .conflict-side-0/docs/migrating-to-durable-jobs.md
  • .conflict-side-0/docs/sqlx.md
  • .conflict-side-0/docs/ttdd.md
  • .conflict-side-0/examples/README.md
  • .conflict-side-0/examples/complex/Cargo.toml
  • .conflict-side-0/examples/complex/README.md
  • .conflict-side-0/examples/complex/migrations/20260513104032_init.sql
  • .conflict-side-0/examples/complex/migrations/20260513104033_inventory_view.sql
  • .conflict-side-0/examples/complex/migrations/20260513104034_job_queue.sql
  • .conflict-side-0/examples/complex/src/audit_log.rs
  • .conflict-side-0/examples/complex/src/inventory.rs
  • .conflict-side-0/examples/complex/src/main.rs
  • .conflict-side-0/examples/complex/src/order.rs
  • .conflict-side-0/examples/complex/src/stock_alert.rs
  • .conflict-side-0/examples/simple/Cargo.toml
  • .conflict-side-0/examples/simple/README.md
  • .conflict-side-0/examples/simple/migrations/20260513104023_init.sql
  • .conflict-side-0/examples/simple/migrations/20260513104024_support_ticket_view.sql
  • .conflict-side-0/examples/simple/migrations/20260513104025_job_queue.sql
  • .conflict-side-0/examples/simple/src/main.rs
  • .conflict-side-0/examples/simple/src/support_ticket.rs
  • .conflict-side-0/flake.nix
  • .conflict-side-0/scripts/check-examples.nu
  • .conflict-side-1/.coderabbit.yaml
  • .conflict-side-1/.envrc
  • .conflict-side-1/.github/PULL_REQUEST_TEMPLATE.md
  • .conflict-side-1/.github/workflows/ci.yaml
  • .conflict-side-1/.gitignore
  • .conflict-side-1/.yamlfmt
  • .conflict-side-1/AGENTS.md
  • .conflict-side-1/CLAUDE.md
  • .conflict-side-1/Cargo.toml
  • .conflict-side-1/LICENSE
  • .conflict-side-1/README.md
  • .conflict-side-1/ROADMAP.md
  • .conflict-side-1/SPEC.md
  • .conflict-side-1/adrs/0001-jobs-replace-services.md
  • .conflict-side-1/adrs/0003-snapshot-discard-compaction-policy.md
  • .conflict-side-1/adrs/0005-backend-agnostic-event-store.md
  • .conflict-side-1/adrs/0006-cqrs-native-durable-jobs.md
  • .conflict-side-1/adrs/0007-reactor-side-job-enqueue.md
  • .conflict-side-1/adrs/0008-entity-scoped-durable-operations.md
  • .conflict-side-1/adrs/0009-handlers-return-events-or-one-job-dispatch.md
  • .conflict-side-1/adrs/0010-one-engine-multiple-bindings.md
  • .conflict-side-1/clippy.toml
  • .conflict-side-1/crates/event-sorcery/Cargo.toml
  • .conflict-side-1/crates/event-sorcery/benches/dispatch.rs
  • .conflict-side-1/crates/event-sorcery/benches/store.rs
  • .conflict-side-1/crates/event-sorcery/src/dependency.rs
  • .conflict-side-1/crates/event-sorcery/src/dispatch.rs
  • .conflict-side-1/crates/event-sorcery/src/job.rs
  • .conflict-side-1/crates/event-sorcery/src/job_backend.rs
  • .conflict-side-1/crates/event-sorcery/src/job_sqlite.rs
  • .conflict-side-1/crates/event-sorcery/src/job_store.rs
  • .conflict-side-1/crates/event-sorcery/src/lib.rs
  • .conflict-side-1/crates/event-sorcery/src/lifecycle.rs
  • .conflict-side-1/crates/event-sorcery/src/projection.rs
  • .conflict-side-1/crates/event-sorcery/src/reactor.rs
  • .conflict-side-1/crates/event-sorcery/src/schema_registry.rs
  • .conflict-side-1/crates/event-sorcery/src/sqlite_event_repository.rs
  • .conflict-side-1/crates/event-sorcery/src/testing.rs
  • .conflict-side-1/crates/event-sorcery/src/view_backend.rs
  • .conflict-side-1/crates/event-sorcery/src/wire.rs
  • .conflict-side-1/crates/sqlite-es/Cargo.toml
  • .conflict-side-1/crates/sqlite-es/README.md
  • .conflict-side-1/crates/sqlite-es/migrations/20251016210348_init.sql
  • .conflict-side-1/crates/sqlite-es/migrations/20260627041347_job_queue.sql
  • .conflict-side-1/crates/sqlite-es/migrations/20260627171021_job_queue_reclaim_index.sql
  • .conflict-side-1/crates/sqlite-es/migrations/20260627223938_job_queue_event_sourced_view.sql
  • .conflict-side-1/crates/sqlite-es/src/cqrs.rs
  • .conflict-side-1/crates/sqlite-es/src/event_repository.rs
  • .conflict-side-1/crates/sqlite-es/src/lib.rs
  • .conflict-side-1/crates/sqlite-es/src/sql_query.rs
  • .conflict-side-1/crates/sqlite-es/src/testing.rs
  • .conflict-side-1/crates/sqlite-es/src/view_repository.rs
  • .conflict-side-1/docs/cqrs.md
  • .conflict-side-1/docs/domain.md
  • .conflict-side-1/docs/event-sourced-job-backend-spec.md
  • .conflict-side-1/docs/migrating-to-durable-jobs.md
  • .conflict-side-1/docs/sqlx.md
  • .conflict-side-1/docs/threat-model-0.4.md
  • .conflict-side-1/docs/ttdd.md
  • .conflict-side-1/examples/README.md
  • .conflict-side-1/examples/complex/Cargo.toml
  • .conflict-side-1/examples/complex/README.md
  • .conflict-side-1/examples/complex/migrations/20260513104032_init.sql
  • .conflict-side-1/examples/complex/migrations/20260513104033_inventory_view.sql
  • .conflict-side-1/examples/complex/migrations/20260513104034_job_queue.sql
  • .conflict-side-1/examples/complex/src/audit_log.rs
  • .conflict-side-1/examples/complex/src/inventory.rs
  • .conflict-side-1/examples/complex/src/main.rs
  • .conflict-side-1/examples/complex/src/order.rs
  • .conflict-side-1/examples/complex/src/stock_alert.rs
  • .conflict-side-1/examples/simple/Cargo.toml
  • .conflict-side-1/examples/simple/README.md
  • .conflict-side-1/examples/simple/migrations/20260513104023_init.sql
  • .conflict-side-1/examples/simple/migrations/20260513104024_support_ticket_view.sql
  • .conflict-side-1/examples/simple/migrations/20260513104025_job_queue.sql
  • .conflict-side-1/examples/simple/src/main.rs
  • .conflict-side-1/examples/simple/src/support_ticket.rs
  • .conflict-side-1/flake.nix
  • .conflict-side-1/scripts/check-examples.nu
  • ROADMAP.md
  • SPEC.md
  • adrs/0010-one-engine-multiple-bindings.md
  • docs/threat-model-0.4.md

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Walkthrough

The documentation defines a 0.4.0 Rust engine extraction, a shared erased facade, versioned C ABI, Haskell binding strategy, migration criteria, verification requirements, and threat model.

Changes

One-engine extraction

Layer / File(s) Summary
Architecture and migration scope
ROADMAP.md, SPEC.md, adrs/0010-one-engine-multiple-bindings.md
Defines the one-engine Rust extraction, monorepo binding strategy, migration order, and 0.4.0 release criteria.
Engine facade and domain boundaries
SPEC.md
Specifies preserved engine authorities, binding responsibilities, domain protocols, and the erased facade’s shared writer path.
C ABI and language bindings
SPEC.md
Defines opaque-handle behavior, deterministic CBOR, ABI errors and versioning, required capabilities, and native Rust/Haskell adapter rules.
Verification, build, and threat contracts
SPEC.md, docs/threat-model-0.4.md
Adds Nix guidance, characterization and conformance requirements, benchmarks, migration validation, trust boundaries, STRIDE controls, and abuse-test requirements.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately captures the main change: documenting the 0.4.0 monorepo engine and related extraction plan.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch spec/0.4-monorepo-engine

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 4

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@adrs/0010-one-engine-multiple-bindings.md`:
- Around line 32-37: Revise the migration rollback policy to archive the
event-sorcery-hs repository as read-only instead of deleting it. Retain a
verified export and restore procedure, including repository metadata and
configuration, until the defined retention period expires and rollback approval
is granted; remove the claim that a local clone can recreate the remote
repository.

In `@SPEC.md`:
- Around line 253-258: Expand the “Error identity” section in SPEC.md to define
stable versioned numeric error codes for each required error class, a canonical
bounded schema for deterministic details, and explicit redaction rules ensuring
opaque payload bytes are excluded from errors and logs. Require all bindings to
preserve these codes, details, and redaction guarantees across the ABI.
- Around line 236-243: Define one shared set of concrete normative ABI limits in
SPEC.md at the framework encoding section, covering input/output byte sizes,
nesting depth, page and event counts, and payload sizes, with deterministic
rejection behavior. Update docs/threat-model-0.4.md in the denial-of-service
controls and abuse tests to reference those exact specification limits directly
rather than duplicating or leaving them undefined.
- Around line 216-223: Update the store lifecycle semantics in SPEC.md around
the close/finalizer requirements to define a linearization rule: once explicit
close or the ForeignPtr finalizer begins, reject all newly started calls, allow
already in-flight calls to complete, and wait for them to drain before
destroying the store handle. Preserve idempotence when close and finalization
race, ensuring destruction occurs exactly once.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: 34914b1a-6859-40a7-9db7-dd6a4fb66e31

📥 Commits

Reviewing files that changed from the base of the PR and between 1935def and 383b09a.

📒 Files selected for processing (4)
  • ROADMAP.md
  • SPEC.md
  • adrs/0010-one-engine-multiple-bindings.md
  • docs/threat-model-0.4.md
📜 Review details
🧰 Additional context used
📓 Path-based instructions (4)
**/*.{rs,toml,sql,md}

📄 CodeRabbit inference engine (AGENTS.md)

Read SPEC.md and docs/domain.md before doing work; update README.md and relevant docs when implementation or architecture changes.

Files:

  • ROADMAP.md
  • adrs/0010-one-engine-multiple-bindings.md
  • SPEC.md
  • docs/threat-model-0.4.md
**/*

📄 CodeRabbit inference engine (AGENTS.md)

**/*: Generated files must be placed under .tmp/; do not add ad-hoc top-level generated entries to .gitignore.
Do not read secret-bearing files such as .env*, credentials.json, *.key, *.pem, *.p12, or *.pfx without explicit permission.
Never bypass, disable, or suppress quality-control mechanisms without explicit permission; fix lint and test failures at their root.
Before handover, review the diff, revert unjustified changes, and check for scope creep.

Files:

  • ROADMAP.md
  • adrs/0010-one-engine-multiple-bindings.md
  • SPEC.md
  • docs/threat-model-0.4.md
*

⚙️ CodeRabbit configuration file

Focus on providing constructive criticism. Whenever you see a suboptimal approach, suggest more idiomatic or robust alternative(s). Flag potential footguns. Suggest FP alternatives to mutable/imperative code. Point out architectural flaws like leaky abstractions, tight coupling, wrong level of abstraction, poor type modeling, over-abstraction, unclear domain boundaries. Code should generally be organized based on business concerns rather than technical aspects - suggest improvements if you find violations. Point out gaps in test coverage but suggest tests that are not too coupled to the implementation and actually test domain invariants and business logic

Files:

  • ROADMAP.md
  • SPEC.md
**/*.md

⚙️ CodeRabbit configuration file

Focus on the contents of the docs and not on cosmetic things like markdown formatting. We use markdown files for various docs including but not limited to guidelines for AI contributors (AGENTS.md), project overview and instructions for human contributors (README.md), and topic-focused references under docs/ (cqrs.md, sqlx.md, ttdd.md). Think about the target audience of a document when deciding what comment to leave. For instructions, suggest better rules and guidelines and point out missing instructions. For topic references, suggest improvements that would make non-obvious framework behavior or pitfalls easier to discover. In all cases, flag needless bloat, prefer clear concise writing, and consider the structure of the document and order of the sections

Files:

  • ROADMAP.md
  • adrs/0010-one-engine-multiple-bindings.md
  • SPEC.md
  • docs/threat-model-0.4.md
🪛 LanguageTool
SPEC.md

[style] ~212-~212: Consider replacing this word to strengthen your wording.
Context: ... header. The header is a build artifact and MUST NOT be hand-maintained. ### Handl...

(AND_THAT)


[style] ~222-~222: This phrase is redundant. Use simply “import”.
Context: ...askell imports for those calls MUST use foreign import capi safe. Only constant-time function...

(FOREIGN_IMPORT)


[uncategorized] ~337-~337: The official name of this software platform is spelled with a capital “H”.
Context: ... The flake consumes the shared external github:dataclique/but.nix library rather than...

(GITHUB)


[grammar] ~346-~346: Ensure spelling is correct
Context: ...e CI checks and MUST NOT be git hooks. Fourmolu uses the repository configuration and a...

(QB_NEW_EN_ORTHOGRAPHY_ERROR_IDS_1)


[grammar] ~396-~396: Use a hyphen to join words.
Context: ...d generated header. 6. Bring the Haskell typed surface into the monorepo and repl...

(QB_NEW_EN_HYPHEN)

🔇 Additional comments (2)
ROADMAP.md (1)

1-42: LGTM!

SPEC.md (1)

161-178: 🗄️ Data Integrity & Integration

No conflict in the domain effect shape. The “events or one declared job dispatch” wording matches the binding-side API; the atomic event+durable-job requirement is already carried by the engine’s commit request and persistence contract. This comment should be dropped.

			> Likely an incorrect or invalid review comment.

Comment thread adrs/0010-one-engine-multiple-bindings.md Outdated
Comment thread SPEC.md
Comment thread SPEC.md
Comment thread SPEC.md Outdated

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 3

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@docs/threat-model-0.4.md`:
- Around line 35-37: Clarify the abuse-test requirement by defining the
contract-stub harness and its expected pre-implementation failure, or replace
“contract stubs” with a deterministic test-first rule requiring tests to fail
before implementation and pass afterward. Update the surrounding requirement
without changing the separate dependency advisory-review and build-script
inspection criteria.

In `@SPEC.md`:
- Around line 235-239: Update the Versioning ABI contract to define
minor-version compatibility: require bindings to declare and validate a minimum
supported minor version, or specify an equivalent capability-negotiation
mechanism. Ensure libraries lacking required additive exports are rejected
before any calls begin, while preserving the existing major-version mismatch
rule.
- Around line 376-382: The documented Nix dependency contract is inconsistent
with the flake’s pinned input. Align the `Build and repository contract` section
of `SPEC.md` with the actual `flake.nix` dependency graph, or update the flake
pin to match the documented `github:dataclique/but.nix`; ensure both describe
the same external library source.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: c3f72832-8483-48c4-9bdd-6feba19adcac

📥 Commits

Reviewing files that changed from the base of the PR and between 383b09a and 4150c20.

📒 Files selected for processing (4)
  • ROADMAP.md
  • SPEC.md
  • adrs/0010-one-engine-multiple-bindings.md
  • docs/threat-model-0.4.md
📜 Review details
⏰ Context from checks skipped due to timeout. (6)
  • GitHub Check: test
  • GitHub Check: check
  • GitHub Check: fmt
  • GitHub Check: examples
  • GitHub Check: clippy
  • GitHub Check: hooks
🧰 Additional context used
📓 Path-based instructions (4)
**/*.{rs,toml,sql,md}

📄 CodeRabbit inference engine (AGENTS.md)

Read SPEC.md and docs/domain.md before doing work; update README.md and relevant docs when implementation or architecture changes.

Files:

  • docs/threat-model-0.4.md
  • ROADMAP.md
  • adrs/0010-one-engine-multiple-bindings.md
  • SPEC.md
**/*

📄 CodeRabbit inference engine (AGENTS.md)

**/*: Generated files must be placed under .tmp/; do not add ad-hoc top-level generated entries to .gitignore.
Do not read secret-bearing files such as .env*, credentials.json, *.key, *.pem, *.p12, or *.pfx without explicit permission.
Never bypass, disable, or suppress quality-control mechanisms without explicit permission; fix lint and test failures at their root.
Before handover, review the diff, revert unjustified changes, and check for scope creep.

Files:

  • docs/threat-model-0.4.md
  • ROADMAP.md
  • adrs/0010-one-engine-multiple-bindings.md
  • SPEC.md
**/*.md

⚙️ CodeRabbit configuration file

Focus on the contents of the docs and not on cosmetic things like markdown formatting. We use markdown files for various docs including but not limited to guidelines for AI contributors (AGENTS.md), project overview and instructions for human contributors (README.md), and topic-focused references under docs/ (cqrs.md, sqlx.md, ttdd.md). Think about the target audience of a document when deciding what comment to leave. For instructions, suggest better rules and guidelines and point out missing instructions. For topic references, suggest improvements that would make non-obvious framework behavior or pitfalls easier to discover. In all cases, flag needless bloat, prefer clear concise writing, and consider the structure of the document and order of the sections

Files:

  • docs/threat-model-0.4.md
  • ROADMAP.md
  • adrs/0010-one-engine-multiple-bindings.md
  • SPEC.md
*

⚙️ CodeRabbit configuration file

Focus on providing constructive criticism. Whenever you see a suboptimal approach, suggest more idiomatic or robust alternative(s). Flag potential footguns. Suggest FP alternatives to mutable/imperative code. Point out architectural flaws like leaky abstractions, tight coupling, wrong level of abstraction, poor type modeling, over-abstraction, unclear domain boundaries. Code should generally be organized based on business concerns rather than technical aspects - suggest improvements if you find violations. Point out gaps in test coverage but suggest tests that are not too coupled to the implementation and actually test domain invariants and business logic

Files:

  • ROADMAP.md
  • SPEC.md
🪛 LanguageTool
SPEC.md

[style] ~212-~212: Consider replacing this word to strengthen your wording.
Context: ... header. The header is a build artifact and MUST NOT be hand-maintained. ### Handl...

(AND_THAT)


[style] ~229-~229: This phrase is redundant. Use simply “import”.
Context: ...askell imports for those calls MUST use foreign import capi safe. Only constant-time function...

(FOREIGN_IMPORT)


[uncategorized] ~378-~378: The official name of this software platform is spelled with a capital “H”.
Context: ... The flake consumes the shared external github:dataclique/but.nix library rather than...

(GITHUB)


[grammar] ~387-~387: Ensure spelling is correct
Context: ...e CI checks and MUST NOT be git hooks. Fourmolu uses the repository configuration and a...

(QB_NEW_EN_ORTHOGRAPHY_ERROR_IDS_1)


[grammar] ~437-~437: Use a hyphen to join words.
Context: ...d generated header. 6. Bring the Haskell typed surface into the monorepo and repl...

(QB_NEW_EN_HYPHEN)

🔇 Additional comments (4)
SPEC.md (2)

428-444: Do not make remote repository deletion the rollback boundary.

Step 8 deletes event-sorcery-hs while retaining only an export and local clone. The migration needs a read-only archive plus a verified export/restore procedure retained for a defined period before deletion is approved.


372-374: 🩺 Stability & Availability

Make the GHC capability-release guarantee implementable.

foreign import capi safe is specified, but the document separately requires every potentially blocking call to release a GHC capability. Define the adapter/runtime mechanism and add a test proving blocking store calls do not monopolize capabilities, including close/finalizer races.

adrs/0010-one-engine-multiple-bindings.md (1)

32-41: Retain a read-only archive instead of deleting the remote repository.

The export and disposable-repository restore test are useful, but deletion remains the rollback plan and no retention period is defined. Archive event-sorcery-hs read-only and retain the verified export/restore procedure until rollback approval and the documented retention period expire.

ROADMAP.md (1)

1-42: LGTM!

Comment thread docs/threat-model-0.4.md Outdated
Comment thread SPEC.md Outdated
Comment thread SPEC.md
@0xgleb
0xgleb force-pushed the spec/0.4-monorepo-engine branch from 287bf0d to a048fdf Compare July 15, 2026 16:31

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@adrs/0010-one-engine-multiple-bindings.md`:
- Around line 32-41: Replace the final deletion of event-sorcery-hs in
adrs/0010-one-engine-multiple-bindings.md lines 32-41 with read-only archival,
retaining the verified export/restore procedure until rollback approval and the
defined retention period expire. Update SPEC.md lines 451-452 to make repository
archival, rather than deletion, the migration step; preserve the existing
migration order and backup/restore requirements.

In `@SPEC.md`:
- Around line 293-302: The ABI_MISMATCH canonical detail in the specification
must include minor-version information. Update the ABI_MISMATCH entry to report
expected major, minimum minor, actual major, and actual minor, preserving the
existing representation and ordering conventions used by the version-negotiation
contract.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: 7083781a-818d-4430-bb99-469806f1a078

📥 Commits

Reviewing files that changed from the base of the PR and between 4150c20 and a048fdf.

📒 Files selected for processing (4)
  • ROADMAP.md
  • SPEC.md
  • adrs/0010-one-engine-multiple-bindings.md
  • docs/threat-model-0.4.md
📜 Review details
⏰ Context from checks skipped due to timeout. (6)
  • GitHub Check: examples
  • GitHub Check: clippy
  • GitHub Check: test
  • GitHub Check: fmt
  • GitHub Check: check
  • GitHub Check: hooks
🧰 Additional context used
📓 Path-based instructions (4)
**/*.{rs,toml,sql,md}

📄 CodeRabbit inference engine (AGENTS.md)

Read SPEC.md and docs/domain.md before doing work; update README.md and relevant docs when implementation or architecture changes.

Files:

  • ROADMAP.md
  • adrs/0010-one-engine-multiple-bindings.md
  • docs/threat-model-0.4.md
  • SPEC.md
**/*

📄 CodeRabbit inference engine (AGENTS.md)

**/*: Generated files must be placed under .tmp/; do not add ad-hoc top-level generated entries to .gitignore.
Do not read secret-bearing files such as .env*, credentials.json, *.key, *.pem, *.p12, or *.pfx without explicit permission.
Never bypass, disable, or suppress quality-control mechanisms without explicit permission; fix lint and test failures at their root.
Before handover, review the diff, revert unjustified changes, and check for scope creep.

Files:

  • ROADMAP.md
  • adrs/0010-one-engine-multiple-bindings.md
  • docs/threat-model-0.4.md
  • SPEC.md
*

⚙️ CodeRabbit configuration file

Focus on providing constructive criticism. Whenever you see a suboptimal approach, suggest more idiomatic or robust alternative(s). Flag potential footguns. Suggest FP alternatives to mutable/imperative code. Point out architectural flaws like leaky abstractions, tight coupling, wrong level of abstraction, poor type modeling, over-abstraction, unclear domain boundaries. Code should generally be organized based on business concerns rather than technical aspects - suggest improvements if you find violations. Point out gaps in test coverage but suggest tests that are not too coupled to the implementation and actually test domain invariants and business logic

Files:

  • ROADMAP.md
  • SPEC.md
**/*.md

⚙️ CodeRabbit configuration file

Focus on the contents of the docs and not on cosmetic things like markdown formatting. We use markdown files for various docs including but not limited to guidelines for AI contributors (AGENTS.md), project overview and instructions for human contributors (README.md), and topic-focused references under docs/ (cqrs.md, sqlx.md, ttdd.md). Think about the target audience of a document when deciding what comment to leave. For instructions, suggest better rules and guidelines and point out missing instructions. For topic references, suggest improvements that would make non-obvious framework behavior or pitfalls easier to discover. In all cases, flag needless bloat, prefer clear concise writing, and consider the structure of the document and order of the sections

Files:

  • ROADMAP.md
  • adrs/0010-one-engine-multiple-bindings.md
  • docs/threat-model-0.4.md
  • SPEC.md
🪛 LanguageTool
SPEC.md

[style] ~219-~219: Consider replacing this word to strengthen your wording.
Context: ... header. The header is a build artifact and MUST NOT be hand-maintained. ### Handl...

(AND_THAT)


[style] ~236-~236: This phrase is redundant. Use simply “import”.
Context: ...askell imports for those calls MUST use foreign import capi safe. Only constant-time function...

(FOREIGN_IMPORT)


[uncategorized] ~389-~389: The official name of this software platform is spelled with a capital “H”.
Context: ... The flake consumes the shared external github:dataclique/but.nix library rather than...

(GITHUB)


[grammar] ~398-~398: Ensure spelling is correct
Context: ...e CI checks and MUST NOT be git hooks. Fourmolu uses the repository configuration and a...

(QB_NEW_EN_ORTHOGRAPHY_ERROR_IDS_1)


[grammar] ~448-~448: Use a hyphen to join words.
Context: ...d generated header. 6. Bring the Haskell typed surface into the monorepo and repl...

(QB_NEW_EN_HYPHEN)

🔇 Additional comments (6)
ROADMAP.md (1)

1-42: LGTM!

SPEC.md (3)

1-119: LGTM!

Also applies to: 124-222, 227-292, 303-450, 453-470


120-123: 🗄️ Data Integrity & Integration | 🏗️ Heavy lift

Define and test claim-handle validation consistently.

The ABI contract must make opaque handles non-authoritative caller input: the engine must validate ownership and job/stream/claim scope before any lifecycle mutation.

  • SPEC.md#L120-L123: specify authenticity, store ownership, job/stream binding, and stable rejection behavior.
  • docs/threat-model-0.4.md#L27-L27: add malformed, forged, wrong-job, wrong-stream, and cross-store handle abuse tests.

223-226: 🩺 Stability & Availability | 🏗️ Heavy lift

Define invalid and repeated buffer-release behavior.

“Freed exactly once” is incomplete without a deterministic rule for NULL, foreign, and already-released pointers.

  • SPEC.md#L223-L226: define the memory-safe result of invalid or repeated release.
  • docs/threat-model-0.4.md#L30-L30: assert that behavior in the double-free abuse test.
adrs/0010-one-engine-multiple-bindings.md (1)

1-31: LGTM!

Also applies to: 43-58

docs/threat-model-0.4.md (1)

1-26: LGTM!

Also applies to: 28-29, 31-37

Comment thread adrs/0010-one-engine-multiple-bindings.md
Comment thread SPEC.md

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@docs/threat-model-0.4.md`:
- Line 27: Update the Tampering threat entry to describe a forged or stale claim
handle rather than a forged lease token. Require validation and rejection
against the existing ClaimId and persisted claim sequence fence, preserving the
SPEC.md claim-fencing model and boundary-value stale-handle tests.

In `@SPEC.md`:
- Around line 239-240: Update the export panic-handling and poisoned-handle
behavior described in SPEC.md so poisoning blocks only data operations, while
close/finalization remains callable, idempotent, and able to drain and destroy
the handle exactly once. Preserve the requirement that panics never unwind
across the C boundary.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: c112cad9-e017-4899-a40a-f76d6a28448d

📥 Commits

Reviewing files that changed from the base of the PR and between a048fdf and c5368fd.

📒 Files selected for processing (4)
  • ROADMAP.md
  • SPEC.md
  • adrs/0010-one-engine-multiple-bindings.md
  • docs/threat-model-0.4.md
📜 Review details
⏰ Context from checks skipped due to timeout. (6)
  • GitHub Check: examples
  • GitHub Check: fmt
  • GitHub Check: hooks
  • GitHub Check: test
  • GitHub Check: check
  • GitHub Check: clippy
🧰 Additional context used
📓 Path-based instructions (4)
**/*.{rs,toml,sql,md}

📄 CodeRabbit inference engine (AGENTS.md)

Read SPEC.md and docs/domain.md before doing work; update README.md and relevant docs when implementation or architecture changes.

Files:

  • ROADMAP.md
  • docs/threat-model-0.4.md
  • adrs/0010-one-engine-multiple-bindings.md
  • SPEC.md
**/*

📄 CodeRabbit inference engine (AGENTS.md)

**/*: Generated files must be placed under .tmp/; do not add ad-hoc top-level generated entries to .gitignore.
Do not read secret-bearing files such as .env*, credentials.json, *.key, *.pem, *.p12, or *.pfx without explicit permission.
Never bypass, disable, or suppress quality-control mechanisms without explicit permission; fix lint and test failures at their root.
Before handover, review the diff, revert unjustified changes, and check for scope creep.

Files:

  • ROADMAP.md
  • docs/threat-model-0.4.md
  • adrs/0010-one-engine-multiple-bindings.md
  • SPEC.md
*

⚙️ CodeRabbit configuration file

Focus on providing constructive criticism. Whenever you see a suboptimal approach, suggest more idiomatic or robust alternative(s). Flag potential footguns. Suggest FP alternatives to mutable/imperative code. Point out architectural flaws like leaky abstractions, tight coupling, wrong level of abstraction, poor type modeling, over-abstraction, unclear domain boundaries. Code should generally be organized based on business concerns rather than technical aspects - suggest improvements if you find violations. Point out gaps in test coverage but suggest tests that are not too coupled to the implementation and actually test domain invariants and business logic

Files:

  • ROADMAP.md
  • SPEC.md
**/*.md

⚙️ CodeRabbit configuration file

Focus on the contents of the docs and not on cosmetic things like markdown formatting. We use markdown files for various docs including but not limited to guidelines for AI contributors (AGENTS.md), project overview and instructions for human contributors (README.md), and topic-focused references under docs/ (cqrs.md, sqlx.md, ttdd.md). Think about the target audience of a document when deciding what comment to leave. For instructions, suggest better rules and guidelines and point out missing instructions. For topic references, suggest improvements that would make non-obvious framework behavior or pitfalls easier to discover. In all cases, flag needless bloat, prefer clear concise writing, and consider the structure of the document and order of the sections

Files:

  • ROADMAP.md
  • docs/threat-model-0.4.md
  • adrs/0010-one-engine-multiple-bindings.md
  • SPEC.md
🪛 LanguageTool
SPEC.md

[style] ~219-~219: Consider replacing this word to strengthen your wording.
Context: ... header. The header is a build artifact and MUST NOT be hand-maintained. ### Handl...

(AND_THAT)


[style] ~236-~236: This phrase is redundant. Use simply “import”.
Context: ...askell imports for those calls MUST use foreign import capi safe. Only constant-time function...

(FOREIGN_IMPORT)


[uncategorized] ~394-~394: The official name of this software platform is spelled with a capital “H”.
Context: ... The flake consumes the shared external github:dataclique/but.nix library rather than...

(GITHUB)


[grammar] ~403-~403: Ensure spelling is correct
Context: ...e CI checks and MUST NOT be git hooks. Fourmolu uses the repository configuration and a...

(QB_NEW_EN_ORTHOGRAPHY_ERROR_IDS_1)


[grammar] ~453-~453: Use a hyphen to join words.
Context: ...d generated header. 6. Bring the Haskell typed surface into the monorepo and repl...

(QB_NEW_EN_HYPHEN)

🔇 Additional comments (5)
SPEC.md (3)

456-457: 🗄️ Data Integrity & Integration

Archive the superseded repository instead of deleting it.

The migration still makes remote deletion the final step. Replace it with read-only archival plus a verified export/restore procedure, explicit retention, and rollback approval.


223-233: 🩺 Stability & Availability

Handle invalidation is already specified. The ABI leaves a closed owner value that absorbs later closes without touching freed memory, so extra pointer-null/tombstone semantics are not required here.

			> Likely an incorrect or invalid review comment.

429-435: 🗄️ Data Integrity & Integration

No shared payload fixture is needed here. Domain payload bytes are intentionally opaque, so cross-binding conformance should focus on framework values and error identity.

			> Likely an incorrect or invalid review comment.
adrs/0010-one-engine-multiple-bindings.md (1)

32-41: 🗄️ Data Integrity & Integration

Archive the superseded repository instead of deleting it.

Deleting the remote repository is not a reversible rollback plan; a local clone cannot restore issues, pull requests, settings, protections, or other remote metadata. Use read-only archival with a verified export/restore procedure, explicit retention, and rollback approval.

ROADMAP.md (1)

1-42: LGTM!

Comment thread docs/threat-model-0.4.md Outdated
Comment thread SPEC.md Outdated
GitButler-Conflict: This is a GitButler-managed conflicted commit. Files are auto-resolved
   using the "ours" side. The commit tree contains additional directories:
     .conflict-side-0  — our tree
     .conflict-side-1  — their tree
     .conflict-base-0  — the merge base tree
     .auto-resolution  — the auto-resolved tree
     .conflict-files   — metadata about conflicted files
   To manually resolve, check out this commit, remove the directories
   listed above, resolve the conflicts, and amend the commit.
@0xgleb
0xgleb force-pushed the spec/0.4-monorepo-engine branch from 34d4e94 to 9d6593d Compare July 16, 2026 08:32
@0xgleb
0xgleb added this pull request to the merge queue Jul 16, 2026
Merged via the queue into master with commit 3ecbc04 Jul 16, 2026
7 of 13 checks passed
@0xgleb
0xgleb deleted the spec/0.4-monorepo-engine branch July 16, 2026 08:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant