diff --git a/.gitea/workflows/ci.yml b/.gitea/workflows/ci.yml index 04c104b..6cd955a 100644 --- a/.gitea/workflows/ci.yml +++ b/.gitea/workflows/ci.yml @@ -39,6 +39,10 @@ jobs: # that runs does so against the fake UDS herdr and fake ccs/claude stubs. run: mvn -B clean install + - name: javadoc reference lint + working-directory: fleetd + run: mvn -B -DskipTests javadoc:javadoc -Ddoclint=reference + # Deliberately NOT actions/upload-artifact: this Gitea instance presents as GHES, and # @actions/artifact v2+ (i.e. upload-artifact@v4) refuses to run there — # "GHESNotSupportedError ... not currently supported on GHES", which red-Xes an otherwise diff --git a/fleetd/src/main/java/dev/ltms/fleet/config/ConfigRef.java b/fleetd/src/main/java/dev/ltms/fleet/config/ConfigRef.java index 96e1ab1..5f478a1 100644 --- a/fleetd/src/main/java/dev/ltms/fleet/config/ConfigRef.java +++ b/fleetd/src/main/java/dev/ltms/fleet/config/ConfigRef.java @@ -208,7 +208,7 @@ import java.util.function.Supplier; * that is correctly hot and for a key nobody triaged. Three times now — {@code worktreeGroup} (#323), * {@code primary}/{@code configReload} (#326), and {@code fleet.leaders} sitting in the escape hatch * (#333) — the second kind hid among the first. A top-level coverage checker in the - * {@link ConfigRefProfileCoverageTest} shape (one level up, over {@code FleetConfig} itself rather + * {@code ConfigRefProfileCoverageTest} shape (one level up, over {@code FleetConfig} itself rather * than {@code FleetConfig.Profile}) proves this file's four classes exhaust the record's components * — see {@code ConfigRefTopLevelCoverageTest}. That test proves the record's shape is fully * triaged; it does NOT prove a {@code SPLIT_KEYS}/{@code COLD_KEYS}/{@code DEFERRED_KEYS} member has diff --git a/fleetd/src/main/java/dev/ltms/fleet/config/FleetConfig.java b/fleetd/src/main/java/dev/ltms/fleet/config/FleetConfig.java index b53707d..32d6e2a 100644 --- a/fleetd/src/main/java/dev/ltms/fleet/config/FleetConfig.java +++ b/fleetd/src/main/java/dev/ltms/fleet/config/FleetConfig.java @@ -1670,7 +1670,7 @@ public record FleetConfig( *

A herdr pane runs a login shell that re-sources the operator's own secret store, so a * member inherits every credential the operator's shell holds — measured at 31 names on this * host, of which only one ({@code GITEA_ACCESS_TOKEN}) used to be blocked, and that block was a - * single name hardcoded in {@link HerdrPeerLauncher} rather than driven by config (gitea issue + * single name hardcoded in {@link dev.ltms.fleet.member.HerdrPeerLauncher} rather than driven by config (gitea issue * #82). This record replaces that hardcoded shadow with a config-driven one. * *

deny-by-default, not a deny-list. A deny-list (block these specific names, let diff --git a/fleetd/src/main/java/dev/ltms/fleet/msg/AmqpReplyInbox.java b/fleetd/src/main/java/dev/ltms/fleet/msg/AmqpReplyInbox.java index 3c631f8..88d52db 100644 --- a/fleetd/src/main/java/dev/ltms/fleet/msg/AmqpReplyInbox.java +++ b/fleetd/src/main/java/dev/ltms/fleet/msg/AmqpReplyInbox.java @@ -246,7 +246,7 @@ public final class AmqpReplyInbox implements ReplyInbox, AutoCloseable { * neither. So before this method existed with a requeue step, it dropped {@link #held}'s entries * for {@code target} while the broker still considered them outstanding: never acked, never * nacked, never requeued, and no longer reachable by {@link #peek} — permanently invisible. This - * is unlike {@link #handleRecovery} and {@link #close()}, whose bare {@code held.clear()} is + * is unlike {@link RecoveryListener#handleRecovery(Recoverable)} and {@link #close()}, whose bare {@code held.clear()} is * correct because each has already made the broker requeue (a real connection drop, or * {@code channel.close()} respectively) before clearing local state. * diff --git a/fleetd/src/main/java/dev/ltms/fleet/msg/MessageService.java b/fleetd/src/main/java/dev/ltms/fleet/msg/MessageService.java index cf5a76f..b76c5cf 100644 --- a/fleetd/src/main/java/dev/ltms/fleet/msg/MessageService.java +++ b/fleetd/src/main/java/dev/ltms/fleet/msg/MessageService.java @@ -713,7 +713,7 @@ public final class MessageService { * failure. * *

Without {@code sweepAsking} on the release path, a target torn down while - * genuinely {@code ASKING} was unrecoverable. {@link #resolveQuestion} had already + * genuinely {@code ASKING} was unrecoverable. {@link Rendezvous#resolveQuestion(String, String, String)} had already * closed the forward waiter the instant the question surfaced (so the {@code waiter} branch * below finds nothing to fail), the {@code question == null} guard excluded the task from * {@code matching} (so the loop below skipped it too), and the worker's own {@code fleet_ask} diff --git a/fleetd/src/main/java/dev/ltms/fleet/msg/ReplyPushLoop.java b/fleetd/src/main/java/dev/ltms/fleet/msg/ReplyPushLoop.java index d30dc39..b79c51e 100644 --- a/fleetd/src/main/java/dev/ltms/fleet/msg/ReplyPushLoop.java +++ b/fleetd/src/main/java/dev/ltms/fleet/msg/ReplyPushLoop.java @@ -44,7 +44,7 @@ import java.util.stream.Collectors; * still holds an unacked message ({@link #pendingReplies}), tickets not yet collected * ({@link #pendingTickets}), and open questions not yet answered or lapsed * ({@link #pendingQuestions}) — and sends at most one combined nudge per tick - * ({@link #injectNudge(String, int, int, int)}). Work that arrives while the lead is busy is + * ({@link #injectNudge(String, int, int, int, int, int)}). Work that arrives while the lead is busy is * never lost: it is re-read fresh on every tick until the lead is injectable or its own reminder * cap ({@link #maxReminders}) is reached — each source spends from its own budget, so one source * exhausting its cap does not stop nudges about the others (post-CB-590 regression fix; see