mirror of
https://github.com/block/buzz.git
synced 2026-08-18 06:50:31 +02:00
+1








14fba21e57
Signed-off-by: tlongwell-block <109685178+tlongwell-block@users.noreply.github.com> Signed-off-by: npub1jh9wn95s0472h86ahapupaf7m6kx4v9sx2n0atj2hltcfer8k06s5n3pyf <95cae996907d7cab9f5dbf43c0f53edeac6ab0b032a6feae4abfd784e467b3f5@sprout-oss.stage.blox.sqprod.co> Signed-off-by: Tyler Longwell <tlongwell@block.xyz> Signed-off-by: npub1t2tgm7d8f995uqvmnm8h88sg3wnpp9a5xysjf6dg3tjmgt3ltulqdp8ehr <5a968df9a7494b4e019b9ecf739e088ba61097b4312124e9a88ae5b42e3f5f3e@sprout-oss.stage.blox.sqprod.co> Signed-off-by: npub17jjz49l9jjmhhk7cac63j8yt9z555n9cw8vk7v5jz4vzw4ppld5qgj57cc <f4a42a97e594b77bdbd8ee35191c8b28a94a4cb871d96f32921558275421fb68@sprout-oss.stage.blox.sqprod.co> Co-authored-by: Eva <011987e296fd5006292d2f930b574be47c7801048d1983c46c425d3c95f0cffd@sprout-oss.stage.blox.sqprod.co> Co-authored-by: Mari <95cae996907d7cab9f5dbf43c0f53edeac6ab0b032a6feae4abfd784e467b3f5@sprout-oss.stage.blox.sqprod.co> Co-authored-by: Sami <f4a42a97e594b77bdbd8ee35191c8b28a94a4cb871d96f32921558275421fb68@sprout-oss.stage.blox.sqprod.co> Co-authored-by: Max <d8473ee32b973aa31a21a65adddcc4b69cc2a8a4dee8121ecd51926e0cddbc02@sprout-oss.stage.blox.sqprod.co> Co-authored-by: Quinn <96f056ad5f2305c8ddf637dc65d048aa4c12d7daeb8867690e34fca46b0ef64c@sprout-oss.stage.blox.sqprod.co> Co-authored-by: Dawn <c6237ef84fa537c78dcee78efd2d4e59f728859c7f194da42ac51ededfa0be05@sprout-oss.stage.blox.sqprod.co> Co-authored-by: Tyler Longwell <tlongwell@block.xyz> Co-authored-by: Sami <sami@sprout-oss.stage.blox.sqprod.co> Co-authored-by: npub1t2tgm7d8f995uqvmnm8h88sg3wnpp9a5xysjf6dg3tjmgt3ltulqdp8ehr <5a968df9a7494b4e019b9ecf739e088ba61097b4312124e9a88ae5b42e3f5f3e@sprout-oss.stage.blox.sqprod.co>
36 lines
1.5 KiB
Rust
36 lines
1.5 KiB
Rust
#![deny(unsafe_code)]
|
|
#![warn(missing_docs)]
|
|
//! Tamper-evident, **per-community** hash-chain audit log.
|
|
//!
|
|
//! Each community owns an independent chain: rows are keyed `(community_id, seq)`,
|
|
//! `seq` is monotonic *within a community*, and each entry chains to the previous
|
|
//! entry *of the same community* via SHA-256. The `community_id` is folded into the
|
|
//! hash, so a row lifted out of one community's chain can never verify inside
|
|
//! another's — chain identity carries the tenant. This is the audit half of the
|
|
//! non-interference floor (`auditHeads[c]` in `MultiTenantRelay.tla`): an audit
|
|
//! observation reveals only its own community's head.
|
|
//!
|
|
//! Writes for a given community are serialized by a **per-community** Postgres
|
|
//! advisory lock, so the chain stays consistent across relay processes without one
|
|
//! global lock serializing (and timing-coupling) every tenant.
|
|
//!
|
|
//! The `audit_log` table is owned by the consolidated `0001` migration — this crate
|
|
//! is pure chain logic and ships no DDL.
|
|
|
|
/// Audit action types recorded in the log.
|
|
pub mod action;
|
|
/// Audit log entry types (stored and input).
|
|
pub mod entry;
|
|
/// Error types for audit operations.
|
|
pub mod error;
|
|
/// SHA-256 hash computation for audit entries.
|
|
pub mod hash;
|
|
/// Audit log service — append and verify entries.
|
|
pub mod service;
|
|
|
|
pub use action::AuditAction;
|
|
pub use entry::{AuditEntry, NewAuditEntry};
|
|
pub use error::AuditError;
|
|
pub use hash::{compute_hash, GENESIS_HASH};
|
|
pub use service::AuditService;
|