Skip to main content

Module dispatch

Module dispatch 

Source
Expand description

Post-recordAction PDS-admin dispatch (#87, v1.7).

Bridges cairn-mod’s recordAction pipeline (§F20-F22) to the configured PdsAdminBackend (v1.7 = OzoneBackend only). Called by the writer task in crate::writer after a subject_actions row has been committed and labels have been emitted; this module decides whether to dispatch a backend call, fires it, and audit-logs the result.

§Failure semantics (per §A13)

  • The recordAction transaction has already committed by the time this runs. Backend-call failures do not roll back the cairn-mod-side action.
  • On backend-call failure, log loudly (WARN for transient variants, ERROR for operator-actionable variants like Auth / Validation), record the failure in pds_admin_audit, and return.
  • On audit-insert failure, log at ERROR and return — do NOT propagate to the writer task; the cairn-mod-side action stays committed regardless. The audit divergence is a discoverability issue, not a correctness issue at this layer.
  • cairn-mod does NOT retry. Retry policy lands in v1.8 with operator feedback informing it.

§Method-selection logic

  1. If PdsAdminPolicy::enabled is false → no-op.
  2. Look up the action_type in PdsAdminPolicy::action_map. Missing key → no-op (defensive — #83’s resolver guarantees coverage but a future config-shape change shouldn’t crash here).
  3. ActionMapEntry::Skip → no-op.
  4. ActionMapEntry::Method → dispatch:
    • TakedownAccount (v1.7 implemented) → call the trait method.
    • SuspendAccount (lands in #88) → call the trait method; OzoneBackend’s body currently unimplemented!()s, which would panic. Acceptable in-cycle; #88 fills it in before any tagged release.
    • RestoreAccount → log error and skip. recordAction doesn’t carry a prior backend action id; restore is reachable only from the revokeAction path (separate flow, future cycle).
    • ApplyLabel / NegateLabel → log warn and skip. #83’s action_map validation already warned at config-load; this is defense-in-depth.

Structs§

DispatchContext
Snapshot of the just-committed recordAction’s fields the dispatch needs. Borrowed from the writer’s RecordActionRequest to avoid cloning the whole struct across the post-commit boundary.
PdsAdminBridge
Bundled v1.7 PDS-admin runtime: the resolved PdsAdminPolicy from #83 + the trait-object backend the dispatch fires against.
RevokeDispatchContext
Snapshot of a revoke-action commit the PDS-admin restore dispatch needs.

Functions§

dispatch_after_record_action
Dispatch the post-recordAction PDS-admin call (if any).
dispatch_after_revoke_action
Dispatch the post-revokeAction PDS-admin call (if any).