Context
PermissionEngine.check() (xcore/kernel/permissions/engine.py) already skips event emission on a cache hit (_audit(..., emit_event=False)), but _audit() still unconditionally appends to self._audit_log (a deque) on every cache hit. There's no way to opt out of that append.
Flagged in reports/technical_debt_remediation_2026-08-10.md (item 3), confirmed partially real in reports/technical_debt_remediation_verification_2026-08-11.md — the more expensive part (event emission) is already optimized, this closes the remainder.
Task
Add a parameter (e.g. audit_cache_hit: bool) to control whether cache hits get appended to _audit_log, defaulting to current behavior (append) to stay backward compatible.
Acceptance criteria
- No change in behavior when the new option isn't set
- Unit test covering both the default and the opt-out path
PermissionEngine.check() docstring updated
Files
xcore/kernel/permissions/engine.py
Context
PermissionEngine.check()(xcore/kernel/permissions/engine.py) already skips event emission on a cache hit (_audit(..., emit_event=False)), but_audit()still unconditionally appends toself._audit_log(adeque) on every cache hit. There's no way to opt out of that append.Flagged in
reports/technical_debt_remediation_2026-08-10.md(item 3), confirmed partially real inreports/technical_debt_remediation_verification_2026-08-11.md— the more expensive part (event emission) is already optimized, this closes the remainder.Task
Add a parameter (e.g.
audit_cache_hit: bool) to control whether cache hits get appended to_audit_log, defaulting to current behavior (append) to stay backward compatible.Acceptance criteria
PermissionEngine.check()docstring updatedFiles
xcore/kernel/permissions/engine.py