Expand description
Getting the record out, in a form nothing here has to be present to read.
§Why this is a deliverable and not a serde derive
audit exists because the party under examination must not
also be the only party able to examine. That argument has a second half this
crate did not have: an auditor who can check the history but cannot
obtain it is still dependent on the operator, and a regulator asking a
financial entity to demonstrate an exit is asking about obtaining, not
checking. A store nobody can get data out of is a concentration risk with a
hash chain on top.
So the export is a first-class operation with three properties, and each one is a refusal of an easier design:
- Streaming, one JSON object per line. A whole-journal
Vecis a memory ceiling disguised as an API, and the export that matters most is the one taken from the largest store. JSON Lines also means an interrupted export is a prefix rather than a corrupt document — which is the failure an operator actually hits. - Self-describing. The first line is a header naming the log, its checkpoint, and the canonicalization rule the digests were computed under. Without that, an export is bytes an auditor has to be told how to read, and being told is the dependency this module exists to remove.
- It says what it did not export. The trailer carries the counts and any run that could not be read. A truncated export shaped exactly like a complete one is the failure this project refuses everywhere else, and it is worst here: the missing run is the interesting one.
§What it deliberately does not do
It does not decrypt. With a key ring configured the journal commits to ciphertext, and an export of plaintext would quietly undo erasure — destroying the key would no longer reach the copy somebody exported last month. The export carries what the chain committed to, which is also what verifies.
It does not re-verify. audit answers is this sound, this
answers here it is, and folding them would produce an export that refuses
to emit the very history an auditor wants to examine because it is
suspect.
It is scoped to one tenant, because a JournalStore handle is. There is
no argument here that could widen it, which is the same reason the rest of
the tenancy story is in keys rather than in filters.
Structs§
- Case
Block - One case, as an export line — the case layer’s whole account of one matter.
- Exported
Record - One journal record, as an export line.
- Header
- The first line of an export: what this is and how to read it.
- InFlight
- What
runs_in_flightfound, and what it could not read. - Package
- What a disclosure package carried, for the act that records it.
- Package
Header - A disclosure package’s first line: the export header plus its selection.
- Replay
Source - An export, restored into a store that lives only as long as the process.
- Restore
Report - What a restore did, and what it could not carry across.
- RunBlock
- A run’s header line, emitted before its records.
- Runs
ToRead - The runs an offline reader of one tenant reads, and what it could not reach.
- Selection
- What a disclosure package was asked for: whole cases, single runs, or both.
- Trailer
- The last line of an export: what it contains, and what it does not.
- Unreadable
- A run the export could not read.
- Verify
Report - What a verification pass concluded, and what it could not look at.
Enums§
- Display
Body - A record line’s display copy, which says what the hashed bytes say.
Constants§
- DISCLOSURE_
KIND - The first line of a disclosure package: an export of chosen runs, which says so.
- FORMAT_
VERSION - The export format’s own version — see
Header::version.
Functions§
- foreign_
canon - Why this build cannot hold an export to its digests, when its header line names a canon this build does not implement.
- from_
jsonl - Rebuild a store from an export, then prove it by its own checkpoint.
- from_
jsonl_ with from_jsonl, reading each record throughupcasterrather than the one this build ships.- open_
for_ replay - Restore an export into memory for replay.
- package_
to_ jsonl - Write a disclosure package: the runs
selectionnames, each sealed one with its inclusion path against the header’s checkpoint, and only the cases those runs belong to. - runs_
in_ flight - Every run the outcome indexes cannot name: the ones still in flight.
- runs_
to_ read - The runs under
outcomes, at mostlimitper outcome, plus the runs still in flight wheninclude_in_flight. - to_
jsonl - Write every record of
runsas JSON Lines, framed by a header and trailer. - verify
- Recompute an export from its own bytes, and check it against its checkpoint.
- verify_
with verify, reading each record throughupcasterrather than the one this build ships.