Skip to content

feat(hub): add the Hub SQLite store - #480

Open
oxwen11 wants to merge 3 commits into
mainfrom
feat/hub-store
Open

oxwen11 wants to merge 3 commits into
mainfrom
feat/hub-store

Conversation

@oxwen11

@oxwen11 oxwen11 commented Oct 7, 2026

Copy link
Copy Markdown
Owner

Requirement

Hub Phase 1, slice 2 (RFC #466, sections 6, 8, 9): the synchronous SQLite store the Hub host will use. Independent of #479.

Expected behavior

New package @getpie/hub (./store), node:sqlite only, no ORM. Three STRICT tables as in the RFC, ordered migrations keyed by PRAGMA user_version, integrity check on open, refuses a newer database. HubStore covers: enrollment token mint (10 min, at most 10 unused), enroll (pins UUID, consumes token, conflict on an active UUID, re-enroll after revoke), authenticate, revoke, hold on/off, event insert/dedupe/hold/caps (1000 events, 100 MiB), pending oldest first, attempts, ack (clears payload), sweep (24 h hold TTL, 48 h dedupe window).

Changes and risks

New package, one line in architecture.md, lockfile entry. Nothing imports it yet, so no runtime effect. The package location (packages/hub) is my choice, the RFC does not name one. No host write yet (library only); host-persistence.md is updated in the slice that introduces $HUB_HOME. Security: tokens and credentials are only ever 32-byte hashes in this layer; callers hash before calling.

Verification

Tested revision 9270a43b on origin/main.

  • pnpm exec vitest run in packages/hub: 12 passed, no type errors (token expiry/cap, enroll conflict and re-enroll, revoke ends held events, unknown/revoked target records nothing, dedupe after settle, hold off, inbox_full, TTL and dedupe sweep, reopen persistence, newer-database refusal).
  • Typecheck, oxfmt, and oxlint packages/hub clean (build @getpie/oxlint first).
  • pnpm check fails only in tools/oxlint itself (121 errors), reproducible without any change of mine, so not from this PR.
  • node:sqlite loads under Bun 1.4.2 (SQLite 3.51.0); the tests were not run under Bun. No CI result yet.

@pkg-pr-new

pkg-pr-new Bot commented Oct 7, 2026 •

Copy link
Copy Markdown
npx https://pkg.pr.new/oxwen11/pie/@getpie/cli@480

commit: 7dcc425

@oxwen11

oxwen11 commented Oct 7, 2026

Copy link
Copy Markdown
Owner Author

Review record for head 9270a43b922f (base main a617dcea, rules 2c10c91b): not merged. The design this PR implements has not landed on main yet.

CI (gate 1): passed on this head. Required checks: Check, react-doctor, and both Publish @getpie/cli preview runs. State was MERGEABLE / CLEAN.

Blocker (context, not a code defect). This is the same blocker as #479's record.

  • The PR implements sections 6, 8 and 9 of RFC docs: redesign Hub as a single-deployment event broker #466 (single-deployment broker, three STRICT SQLite tables, event inbox and caps). docs: redesign Hub as a single-deployment event broker #466 is still open and CONFLICTING.
  • On main, docs/rfc/pie-hub.md §8 is titled "Persistence approval worksheet — not shipped inventory". It says the host-write gate (.agents/rules/topics/persistence.md) needs Developer confirmation before formats are chosen or writes are implemented. The candidate it lists is JSON records (relationship.json, deliveries/<deliveryId>.json), not a SQLite store.
  • Main's §8 also says "enrollment tokens are memory-only and expire". This PR persists enrollment token hashes in an enrollment_tokens table.
  • Main's §9 says "Implementation starts only after section 10 and the persistence worksheet are confirmed". Section 10 is still open there.
  • The rules use design decisions from the trusted base, and PR content cannot grant that exemption. So this slice's storage format and lifecycle can't be accepted against an agreed design on main.

Not done for this head: code review against the diff (gate 2) and independent verification (gate 3). They stop at the design gate above, so nothing here is a code-quality or test verdict.

What would warrant another review: #466 (or its persistence/§10 decisions) lands on main with the SQLite store approved. Alternatively, this PR is restacked on #466 so the RFC merges first. Review then restarts at CI on the new head or base.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants