Skip to main content

recall_server/audit/
mod.rs

1//! The audit log: a Merkle tree over every authenticated action, following
2//! [`docs/design/part5-plan.md`](../../../../docs/design/part5-plan.md)'s
3//! "PR 1: audit" and "The audit chain".
4//!
5//! [`merkle`] is the pure hash tree (RFC 9162 ยง2.1), with no knowledge of
6//! Recall's own shapes. [`leaf`] is the canonical, versioned encoding of one
7//! entry โ€” what gets hashed and stored. Persistence โ€” the `audit_log`
8//! table, the in-memory [`merkle::Tree`] it is rebuilt into at start,
9//! and the single transaction a leaf commits in alongside the state change
10//! it records โ€” lives in [`crate::store`], which is where the two meet.
11//!
12//! [`merkle`] itself lives in `recall-wire` and is re-exported here, since
13//! the client checks what this server proves with the same code: a
14//! consistency proof built from this tree is verified by `recall doctor`
15//! with [`merkle::verify_consistency`], and an export's root rebuilt by
16//! `recall audit verify` with [`merkle::Tree`].
17
18pub mod leaf;
19pub use recall_wire::audit::merkle;