feat(audit): add bounded snapshot manifests - #66
seonghobae wants to merge 42 commits into
Conversation
|
Important Review skippedDraft detected. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Comment |
|
Closing as superseded by #84. Exact #66 head remains |
Commercial and acquisition gap
PR #65 adds bounded stable audit export pages, but a buyer/operator still needs a package-owned deterministic identity for one complete snapshot-stable audit traversal. This bounded slice adds a compact SHA-256 snapshot manifest without claiming signature, non-repudiation, delivery, external retention, provenance, or administrator-proof tamper resistance.
Implemented bounded slice
CheckpointAuditSnapshotManifestschema version 1 and the opt-inbuild_audit_snapshot_manifest_in_transaction()API;REPEATABLE READorSERIALIZABLEandtransaction_read_only = on, failing closed on autocommit,READ COMMITTED, read-write transactions, malformed transaction metadata, or unknown modes before page traversal;page_size1..1,000 andmax_events1..100,000 bounds, keeping only one page plus fixed digest state in package-owned memory;Strict RED → GREEN → refactor evidence
6849ae16f2231c699bcb543421afcc6ba6028c48.30f947a8ce99f28d0028ea54dfd5ce54ff0d7cbd; exact-head CI31197234197failed the new deterministic regression because the predecessor implementation accepted an active read-writeREPEATABLE READtransaction.664e182f8717086bd4ccd59c9f18f1dd51fe11a0;_require_audit_snapshot_isolation()now verifies activeINTRANS, stable isolation, andSHOW transaction_read_only = onbefore any page traversal.SET TRANSACTION ISOLATION LEVEL REPEATABLE READ READ ONLYand remains least-privilege.e945a3bb64fa551c6a791f5bb3426cb0862678d6required the read-only boundary across project contracts.31198877520on predecessor4522a609842871d2393daa5a2b242cb897052c4cproved all unit, live PostgreSQL, container, lint, and docstring jobs green but correctly exposed one uncovered malformed read-only-evidence branch, leaving production coverage at 99.94%; that run is failure evidence only.eec888bdbb4612abbb0f03d73ec90ad3f911028eadds deterministic malformedtransaction_read_onlyevidence coverage without weakening the production gate.Current exact-head evidence
eec888bdbb4612abbb0f03d73ec90ad3f911028e.4589fe07abd8a3c151bc98c5cfabfe9328d5f992(agent/bounded-checkpoint-audit-export-pages-v2). Git compare reports the head ahead of that exact base and zero behind.31199147845: completed / success on the exact source head. Python 3.10, 3.12, and 3.14 unit jobs, exact-head checkout assertions, compilation, Ruff, public-docstring enforcement, locked dependency verification, package build, Compose/container builds, and the live checkpoint-audit PostgreSQL integration all succeeded.31199146966: completed / success on the exact source head.APPROVEDreview exists on this draft.Assurance boundary
The snapshot digest is deterministic content identity and change detection only. It is not a MAC, signature, credential, trusted timestamp, delivery receipt, authenticated provenance statement, or non-repudiation mechanism. External immutable/WORM retention, signing/authentication, key management, legal hold, delivery evidence, destination credentials, and reconciliation remain host/operator controls. PostgreSQL owners, superusers,
BYPASSRLSidentities, disabled triggers, and physical database administrators remain outside the package's tamper-resistance claim.Dependency and merge boundary
Required order remains
.github#790 -> #53 -> #55 -> #56 -> #57 -> #58 -> #59 -> #60 -> #61 -> #62 -> #63 -> #65 -> this PR.This PR remains intentionally draft. It must not be marked ready or merged until every prerequisite integrates into protected
main, the branch is reconciled onto the actual integrated base, and fresh integrated exact-head/exact-base quality, security, dependency, packaging, live PostgreSQL, provenance, supply-chain, release-acceptance, branch-protection, ruleset, required-check, and independent-review gates all succeed. Zero unresolved valid findings and a qualifying independent non-author GitHubAPPROVEDreview are mandatory.