feat(triggers): shared dead-letter trigger fan-out (B2)
A group declares a declaratively-authored [[triggers.dead_letter]] shared=true handler; when a message in the group's SHARED queue is exhausted, the dispatcher's q_terminal group branch (after persisting to group_dead_letters) fans out to it via list_matching_shared_dead_letter(owning_group, "queue", …), each outbox row stamped the WRITER app_id (the consuming app — the M2 shared -write model), so the handler runs under the consumer. The per-app list_matching_dead_letter gained AND t.shared = FALSE (the shared flag is the namespace boundary); the owning-group filter is the isolation boundary. Adds BundleTrigger::DeadLetter + a DeadLetterTriggerSpec manifest kind (group +shared only — validate_bundle_for rejects app-owned or non-shared, and exempts it from the shared-requires-a-collection rule); insert_trigger_tx now accepts dead_letter and writes dead_letter_trigger_details; current_trigger_identity matches a group-shared dead_letter so re-apply is a NoOp (app-owned ones stay diff-invisible). Pinned by tests/shared_dead_letter.rs (owning group matches, per-app query does not, foreign group does not). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in: