Expand description
Post-recordAction PDS-admin dispatch (#87, v1.7).
Bridges cairn-mod’s recordAction pipeline (§F20-F22) to the
configured PdsAdminBackend (v1.7 = OzoneBackend only).
Called by the writer task in crate::writer after a
subject_actions row has been committed and labels have been
emitted; this module decides whether to dispatch a backend
call, fires it, and audit-logs the result.
§Failure semantics (per §A13)
- The recordAction transaction has already committed by the time this runs. Backend-call failures do not roll back the cairn-mod-side action.
- On backend-call failure, log loudly (
WARNfor transient variants,ERRORfor operator-actionable variants likeAuth/Validation), record the failure inpds_admin_audit, and return. - On audit-insert failure, log at
ERRORand return — do NOT propagate to the writer task; the cairn-mod-side action stays committed regardless. The audit divergence is a discoverability issue, not a correctness issue at this layer. - cairn-mod does NOT retry. Retry policy lands in v1.8 with operator feedback informing it.
§Method-selection logic
- If
PdsAdminPolicy::enabledis false → no-op. - Look up the action_type in
PdsAdminPolicy::action_map. Missing key → no-op (defensive — #83’s resolver guarantees coverage but a future config-shape change shouldn’t crash here). ActionMapEntry::Skip→ no-op.ActionMapEntry::Method→ dispatch:TakedownAccount(v1.7 implemented) → call the trait method.SuspendAccount(lands in #88) → call the trait method;OzoneBackend’s body currentlyunimplemented!()s, which would panic. Acceptable in-cycle; #88 fills it in before any tagged release.RestoreAccount→ log error and skip. recordAction doesn’t carry a prior backend action id; restore is reachable only from the revokeAction path (separate flow, future cycle).ApplyLabel/NegateLabel→ log warn and skip. #83’s action_map validation already warned at config-load; this is defense-in-depth.
Structs§
- Dispatch
Context - Snapshot of the just-committed recordAction’s fields the
dispatch needs. Borrowed from the writer’s
RecordActionRequestto avoid cloning the whole struct across the post-commit boundary. - PdsAdmin
Bridge - Bundled v1.7 PDS-admin runtime: the resolved
PdsAdminPolicyfrom #83 + the trait-object backend the dispatch fires against. - Revoke
Dispatch Context - Snapshot of a revoke-action commit the PDS-admin restore dispatch needs.
Functions§
- dispatch_
after_ record_ action - Dispatch the post-recordAction PDS-admin call (if any).
- dispatch_
after_ revoke_ action - Dispatch the post-revokeAction PDS-admin call (if any).