Expand description
Metrics facade and logging hygiene (PRD §8 M0: tracing, metrics, redaction).
Metrics is a plain trait rather than a dependency on the metrics
crate, so the core stays backend-free on wasm32; the native binary
bridges it to the metrics facade (planner default Q20).
Two header lists govern credentials (SPEC-TRANSPORT-CONNECT §5.1):
NEVER_ECHO names request credentials a response never carries, and
NEVER_LOG adds the receipts and signatures that a response may pass
through to the client but that must stay out of logs, traces and error
messages. Redactor extends NEVER_LOG with deployment-configured
names, such as the headers an admission helper attaches.
Modules§
- pressure
- Physical storage pressure and alert bookkeeping shared by adapters. Alert on physical bytes against the put soft limit. No storage I/O or wall clock is hidden here: callers supply measurements and time.
Structs§
- Noop
Metrics - A
Metricssink that discards everything. - Redactor
- Log redaction policy:
NEVER_LOGplus names the deployment adds, for example its configuredadmission_headers. The default redactsNEVER_LOGonly.
Constants§
- METRIC_
INDEX_ LOOKUP_ CAPPED - Counter: an object index lookup hit a bounded-work cap. Label:
reason. - METRIC_
INDEX_ REJECTED_ WRITE_ FAILED - Counter: a content rejection could not be persisted in verification state.
- METRIC_
INDEX_ SLICE_ SUBREQUESTS - Gauge: subrequests the last scheduled-verification slice spent (WP-4.8).
- METRIC_
INSPECTION_ CALLS - Counter: synchronous inspector calls. Label:
result. - METRIC_
LATENCY - Histogram: request latency in milliseconds. Labels:
procedure. - METRIC_
NAMESPACE_ QUOTA_ REBASE - Counter: a restored shard’s cumulative contribution was re-baselined.
- METRIC_
NAMESPACE_ QUOTA_ ROLLUP_ ERROR - Counter: a quota rollup failed. Label:
reason. - METRIC_
NAMESPACE_ QUOTA_ VIEW_ FALLBACK - Namespace quota writes admitted with no recent coordinator view.
- METRIC_
REF_ POLICY_ ANCESTRY_ UNCHECKED - Counter: a fast-forward check ended unproven (a walk or lookup cap, the
decode budget or a corrupt member) and its write was denied. Label:
reason. - METRIC_
RELAY_ BACKLOG_ ROWS - Gauge: source outbox rows inspected in the current relay window.
- METRIC_
RELAY_ LAG_ EXCEEDED - Counter: an outbox row exceeded the relay lag bound. Label:
source_kind. - METRIC_
RELAY_ LEASE_ LAG - Counter: an expired shard lease remains kept beyond the relay lag bound.
- METRIC_
REQUESTS - Counter: requests handled. Labels:
procedure,code. - METRIC_
UPLOAD_ BYTES - Counter: accepted upload bytes.
- NEVER_
ECHO - Request credentials that are never set on a response, compared ignoring
ASCII case. Every entry is also in
NEVER_LOG. - NEVER_
LOG - Header names whose values never reach a log, trace or error message,
compared ignoring ASCII case:
NEVER_ECHOplus payment receipts, the auth v2 signature andSet-Cookie. A response may still carry the receipts (SPEC-TRANSPORT-CONNECT §5.1). - REDACTED_
VALUE - The placeholder logged in place of a redacted header value.
Traits§
- Metrics
- Metrics sink. Label values are borrowed so a hot path allocates nothing.
Functions§
- is_
never_ echo - Whether
nameis inNEVER_ECHO, ignoring ASCII case. - is_
never_ log - Whether
nameis inNEVER_LOG, ignoring ASCII case.