feat(audit): add bounded stable export pages - #65
Conversation
|
Important Review skippedDraft detected. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Comment |
|
@coderabbitai review @opencode-agent @cwl-noema-review review only; do not write the branch, create a repair workflow, mark ready, or merge. Review exact source head |
|
|
|
@coderabbitai review @opencode-agent @cwl-noema-review review only; do not write the branch, create a repair workflow, mark ready, or merge. Review exact source head |
|
I will review source head I will not modify the branch, create a repair workflow, change draft status, mark the PR ready, or merge. I will treat the specified gate and approval conditions as blockers.
|
|
@coderabbitai review Please review exact source head |
|
I will only review the changes. I will not modify the branch, create workflows, change draft status, mark the PR ready, or merge it.
|
|
Current exact-head/base audit after dependency-order ancestry reconciliation:
Older |
|
Closing as superseded by #83. Exact #65 head remains |
Linearized replacement for #64
This draft is intentionally stacked after PR #63 exact base
c213fc549dbf024da43b459df29c0616cd741c96onagent/checkpoint-migration-operator. It supersedes and replaces now-closed sibling-stack PR #64, preventing competing writers, overlapping integration paths, and duplicate ADR 0010 numbering.Strict RED → GREEN → REFACTOR evidence
RED was established on this branch before production changes at exact head
b623b8fc9b1ee21af9f1a5ba72f1e045dcf5711b. Exact-source-head CI run31154004207failed in Python 3.10/3.12/3.14 and coverage during test collection because the new tests imported intentionally absentMAX_CHECKPOINT_AUDIT_EVENT_ID,CheckpointAuditPage, and cursor/page APIs. Container and live checkpoint-audit PostgreSQL jobs remained green, and Release Acceptance31154004206completed successfully; the failing CI is retained only as RED evidence and is not success evidence.Production now enforces signed PostgreSQL
BIGINTaudit identity compatibility, immutable strictly descendingCheckpointAuditPagevalues, strict non-coercive keyset cursor validation, tenant/consumer/endpoint/batch row-key revalidation, one-row bounded lookahead,checkpoint_audit_event_id < before_audit_event_idcontinuation, fail-closed malformed/overrun driver output, and package-owned reads without an explicit commit. Existinglist_audit_events()remains unchanged.The live least-privilege PostgreSQL regression reads page one, commits a newer accepted-save event in a separate transaction, then proves page two continues strictly toward older identities without duplicating page-one rows or admitting the newer row. Package-owned multi-page traversal deliberately does not claim one historic snapshot; hosts requiring that guarantee must start a caller-owned PostgreSQL
REPEATABLE READor stricter transaction before the first query and reuselist_audit_event_page_in_transaction().Authoritative contracts are synchronized in
AGENTS.md,CLAUDE.md,ARCHITECTURE.md,CHANGELOG.md,docs/checkpoint-audit.md, ADR 0011, anddocs/doctoring/checkpoint-audit-export-pagination.md. Doctoring records APA 7 references to NIST SP 800-53 Rev. 5 Release 5.2.0 / AU-9 and PostgreSQL 18 transaction-isolation/concurrency documentation. The cursor is explicitly navigation state, not completeness, chronology, authenticity, delivery, non-repudiation, or release evidence. External immutable/WORM retention, receipts, manifests, reconciliation, legal hold, and disposal remain host/operator controls.No schema migration, release version, provider credential, LLM key, network exporter, scheduled writer, temporary repair workflow, generated coverage database, cache, or build artifact is introduced. Standalone operation remains intact and the page primitive can be embedded into CWL MSA workflows without requiring
contextual-orchestratorornaruon.Exact-head gate boundary
Current exact head is
6a1ee16b551aa960a6f3eaee2162d90af95dfe7fagainst exact stacked basec213fc549dbf024da43b459df29c0616cd741c96.31157889802: completed / success on this exact source head. Python 3.10, 3.12, and 3.14 unit jobs all succeeded; container/Compose builds succeeded; and live checkpoint-audit plus migration-operator PostgreSQL integration succeeded with3 passed.92801332616: completed / success on the exact source head. Ruff passed; public-docstring coverage is 100%; production coverage is 2576 statements, 656 branches, 0 missed, 0 partial, 100.00% with668 passed, 8 deselected;uv lock --checkpassed; and source/wheel builds completed successfully.31157889756: completed / success on this exact source head, including exact-source checkout, two clean exact-head builds, and reproducible wheel/sdist identity evidence.Any newer commit invalidates this exact-head evidence and requires fresh verification.
Required merge order remains
.github#790 -> #53 -> #55 -> #56 -> #57 -> #58 -> #59 -> #60 -> #61 -> #62 -> #63 -> this PR. This PR remains draft and must not merge until all prerequisites integrate, it is reconciled onto protectedmain, branch protection/repository policy/security gates and every required exact-head check succeed, unresolved valid findings are zero, and a qualifying independent non-author GitHubAPPROVEDreview exists. Queued, pending, cancelled, skipped-required, absent, stale-head, stale-base, predecessor, rate-limited-review, status-only, unproven-gate, or synthetic-merge-only evidence is never success.