feat(capture): two-phase classification-aware AuditSink port (#54)
Splits the audit port into Reserve (before any write) + Record (after), so "confidential + sink-down → refuse before any write" is literally true even though the audit record — which lists what landed — can only be written afterwards. - AuditSink.Reserve(ctx, level) → AuditOutcome | error. The error path refuses the capture before writing: confidential + central sink down, or the all-tiers floor (nothing can record). - AuditSink.Record(ctx, entry, outcome) persists per the reserved outcome. - Service: I5 gate runs after the I1 gate and after the dry-run short-circuit (dry-run never probes the sink). AuditBuffered surfaces on the receipt. New ErrAuditUnavailable sentinel (→ HTTP 503). The tier→behaviour decision lives in the sink impl (#54's DegradingSink), not the service — the service just honours Reserve's verdict. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -96,9 +96,31 @@ type AuditEntry struct {
|
||||
SecurityEvents []string
|
||||
}
|
||||
|
||||
// AuditSink records the audit entry. The classification-aware
|
||||
// degradation/refusal policy (confidential fails closed, internal
|
||||
// degrades) is the caller's concern in #54; this port just records.
|
||||
// AuditOutcome is how a capture's audit record was (or will be) persisted.
|
||||
type AuditOutcome int
|
||||
|
||||
const (
|
||||
// AuditCentral means the record goes to the central sink (loki).
|
||||
AuditCentral AuditOutcome = iota
|
||||
// AuditBuffered means the central sink was unreachable and the record
|
||||
// is written to a durable local buffer for later reconciliation
|
||||
// (internal/public tier only).
|
||||
AuditBuffered
|
||||
)
|
||||
|
||||
// AuditSink is the two-phase, classification-aware audit port (I5, §4.4).
|
||||
//
|
||||
// Reserve runs BEFORE any write and decides whether the capture can be
|
||||
// audited at its effective classification: it returns the outcome to use,
|
||||
// or an error to refuse the capture before anything is written
|
||||
// (confidential + central sink down → refuse; the all-tiers floor when
|
||||
// nothing can record → refuse). Record runs AFTER the writes and persists
|
||||
// the final entry per the reserved outcome.
|
||||
//
|
||||
// Splitting reserve from record is what lets "confidential + sink-down →
|
||||
// refuse before any write" be literally true while the record itself
|
||||
// (which lists what landed) is necessarily written afterwards.
|
||||
type AuditSink interface {
|
||||
Record(ctx context.Context, e AuditEntry) error
|
||||
Reserve(ctx context.Context, level classification.Level) (AuditOutcome, error)
|
||||
Record(ctx context.Context, e AuditEntry, outcome AuditOutcome) error
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user