Expand description
The audit log: a Merkle tree over every authenticated action, following
docs/design/part5-plan.md’s
“PR 1: audit” and “The audit chain”.
merkle is the pure hash tree (RFC 9162 §2.1), with no knowledge of
Recall’s own shapes. leaf is the canonical, versioned encoding of one
entry — what gets hashed and stored. Persistence — the audit_log
table, the in-memory merkle::Tree it is rebuilt into at start,
and the single transaction a leaf commits in alongside the state change
it records — lives in crate::store, which is where the two meet.
merkle itself lives in recall-wire and is re-exported here, since
the client checks what this server proves with the same code: a
consistency proof built from this tree is verified by recall doctor
with merkle::verify_consistency, and an export’s root rebuilt by
recall audit verify with merkle::Tree.
Modules§
- leaf
- The audit leaf, version 1: one per authenticated push, pull, delete,
and change to a device or authkey, and one per action the server
takes itself. See
docs/design/part5-plan.md’s “PR 1: audit” for the wire shape this mirrors exactly. - merkle
- The Merkle tree hash, RFC 9162 §2.1 exactly (the same tree RFC 6962 defines, restated for Certificate Transparency 2.0). SHA-256 throughout.