Expand description
ADR-133 Slice 1: the audit-batch seam.
Incidental audit writes (gate denials, dispatch outcomes, config-lock
rows, git.digest receipts, and pure-observability rows like
RecallExecuted) no longer take one writer-task acquisition per row on
the request hot path. Concurrent submissions arriving while a generation
is committing share the next generation instead of each taking their
own writer acquisition, so N concurrent producers collapse to one
khive_storage::EventStore::append_events_idempotent call per
generation rather than N.
AuditBatch owns this seam. A lazily-spawned supervisor task drains
pending rows into generations and drives each through the store; the
supervisor’s own JoinHandle is retained (never discarded) so an
abnormal exit — panic, cancellation, a lost child join, or a driver that
returns Ok while state is not terminally consistent — is observed and
converted into a Failed transition with all accepted waiters resolved,
per owner ruling R1/R4 (.khive/OWNER_RULING_adr133_gate.md).
Structs§
- Audit
Batch - The batch owner. Constructed once per configured
EventStore; every dispatch-audit call site routes its row throughAuditBatch::submitinstead of taking its own writer-task acquisition. - Audit
Batch Config - Tunables for the batch seam. Defaults are conservative; every field is exercised by at least one mechanism test.
- Audit
Batch Health Metrics - Production-visible snapshot of
AuditBatch::health_metrics. See there for field semantics.khive_db::diagnostics::RuntimeAuditBatchMetricscarries these three fields plusadmission_refused_obligationsandadmission_unresolved_obligations, which are sourced from process-wide counters outsideAuditBatchrather than from this struct — seeVerbRegistry::audit_batch_metrics. - Audit
Generation Snapshot - A committed/failed generation’s accounting, retained for the lifetime of the process (bounded in practice by process lifetime and generation volume; this slice makes no attempt to prune history).
- Prepared
Audit Row - One row accepted for batching: the immutable event identity plus the producer that minted it, used for classification and, on failure, degradation accounting.
Enums§
- Audit
Commit Outcome - What
AuditBatchControl::submitresolves to on a non-error outcome. - Audit
Producer - Every call site that can submit a row through
AuditBatchControl. Adding a variant here without extending the crate-privateclassifyfunction’s match is a compile error — there is no wildcard arm. - Audit
Terminal Reason - Exhaustive terminal reasons an
AuditBatchControl::submit,AuditBatchControl::quiesce, orAuditBatchControl::close_and_draincall can resolve to. Never mapped through a wildcard arm anywhere in this module (R4).