Skip to main content

Module audit_batch

Module audit_batch 

Source
Expand description

ADR-133 Slice 1: the audit-batch seam.

Incidental audit writes (gate denials, dispatch outcomes, config-lock rows, git.digest receipts, and pure-observability rows like RecallExecuted) no longer take one writer-task acquisition per row on the request hot path. Concurrent submissions arriving while a generation is committing share the next generation instead of each taking their own writer acquisition, so N concurrent producers collapse to one khive_storage::EventStore::append_events_idempotent call per generation rather than N.

AuditBatch owns this seam. A lazily-spawned supervisor task drains pending rows into generations and drives each through the store; the supervisor’s own JoinHandle is retained (never discarded) so an abnormal exit — panic, cancellation, a lost child join, or a driver that returns Ok while state is not terminally consistent — is observed and converted into a Failed transition with all accepted waiters resolved, per owner ruling R1/R4 (.khive/OWNER_RULING_adr133_gate.md).

Structs§

AuditBatch
The batch owner. Constructed once per configured EventStore; every dispatch-audit call site routes its row through AuditBatch::submit instead of taking its own writer-task acquisition.
AuditBatchConfig
Tunables for the batch seam. Defaults are conservative; every field is exercised by at least one mechanism test.
AuditBatchHealthMetrics
Production-visible snapshot of AuditBatch::health_metrics. See there for field semantics. khive_db::diagnostics::RuntimeAuditBatchMetrics carries these three fields plus admission_refused_obligations and admission_unresolved_obligations, which are sourced from process-wide counters outside AuditBatch rather than from this struct — see VerbRegistry::audit_batch_metrics.
AuditGenerationSnapshot
A committed/failed generation’s accounting, retained for the lifetime of the process (bounded in practice by process lifetime and generation volume; this slice makes no attempt to prune history).
PreparedAuditRow
One row accepted for batching: the immutable event identity plus the producer that minted it, used for classification and, on failure, degradation accounting.

Enums§

AuditCommitOutcome
What AuditBatchControl::submit resolves to on a non-error outcome.
AuditProducer
Every call site that can submit a row through AuditBatchControl. Adding a variant here without extending the crate-private classify function’s match is a compile error — there is no wildcard arm.
AuditTerminalReason
Exhaustive terminal reasons an AuditBatchControl::submit, AuditBatchControl::quiesce, or AuditBatchControl::close_and_drain call can resolve to. Never mapped through a wildcard arm anywhere in this module (R4).

Traits§

AuditBatchControl