Skip to main content

Module export

Module export 

Source
Expand description

Getting the record out, in a form nothing here has to be present to read.

§Why this is a deliverable and not a serde derive

audit exists because the party under examination must not also be the only party able to examine. That argument has a second half this crate did not have: an auditor who can check the history but cannot obtain it is still dependent on the operator, and a regulator asking a financial entity to demonstrate an exit is asking about obtaining, not checking. A store nobody can get data out of is a concentration risk with a hash chain on top.

So the export is a first-class operation with three properties, and each one is a refusal of an easier design:

  • Streaming, one JSON object per line. A whole-journal Vec is a memory ceiling disguised as an API, and the export that matters most is the one taken from the largest store. JSON Lines also means an interrupted export is a prefix rather than a corrupt document — which is the failure an operator actually hits.
  • Self-describing. The first line is a header naming the log, its checkpoint, and the canonicalization rule the digests were computed under. Without that, an export is bytes an auditor has to be told how to read, and being told is the dependency this module exists to remove.
  • It says what it did not export. The trailer carries the counts and any run that could not be read. A truncated export shaped exactly like a complete one is the failure this project refuses everywhere else, and it is worst here: the missing run is the interesting one.

§What it deliberately does not do

It does not decrypt. With a key ring configured the journal commits to ciphertext, and an export of plaintext would quietly undo erasure — destroying the key would no longer reach the copy somebody exported last month. The export carries what the chain committed to, which is also what verifies.

It does not re-verify. audit answers is this sound, this answers here it is, and folding them would produce an export that refuses to emit the very history an auditor wants to examine because it is suspect.

It is scoped to one tenant, because a JournalStore handle is. There is no argument here that could widen it, which is the same reason the rest of the tenancy story is in keys rather than in filters.

Structs§

CaseBlock
One case, as an export line — the case layer’s whole account of one matter.
ExportedRecord
One journal record, as an export line.
Header
The first line of an export: what this is and how to read it.
InFlight
What runs_in_flight found, and what it could not read.
Package
What a disclosure package carried, for the act that records it.
PackageHeader
A disclosure package’s first line: the export header plus its selection.
ReplaySource
An export, restored into a store that lives only as long as the process.
RestoreReport
What a restore did, and what it could not carry across.
RunBlock
A run’s header line, emitted before its records.
RunsToRead
The runs an offline reader of one tenant reads, and what it could not reach.
Selection
What a disclosure package was asked for: whole cases, single runs, or both.
Trailer
The last line of an export: what it contains, and what it does not.
Unreadable
A run the export could not read.
VerifyReport
What a verification pass concluded, and what it could not look at.

Enums§

DisplayBody
A record line’s display copy, which says what the hashed bytes say.

Constants§

DISCLOSURE_KIND
The first line of a disclosure package: an export of chosen runs, which says so.
FORMAT_VERSION
The export format’s own version — see Header::version.

Functions§

foreign_canon
Why this build cannot hold an export to its digests, when its header line names a canon this build does not implement.
from_jsonl
Rebuild a store from an export, then prove it by its own checkpoint.
from_jsonl_with
from_jsonl, reading each record through upcaster rather than the one this build ships.
open_for_replay
Restore an export into memory for replay.
package_to_jsonl
Write a disclosure package: the runs selection names, each sealed one with its inclusion path against the header’s checkpoint, and only the cases those runs belong to.
runs_in_flight
Every run the outcome indexes cannot name: the ones still in flight.
runs_to_read
The runs under outcomes, at most limit per outcome, plus the runs still in flight when include_in_flight.
to_jsonl
Write every record of runs as JSON Lines, framed by a header and trailer.
verify
Recompute an export from its own bytes, and check it against its checkpoint.
verify_with
verify, reading each record through upcaster rather than the one this build ships.