FN-9180: Route deleted-task outbox audits through the bounded seam
Keep deleted-task outbox processing resilient to hostile audit sinks while preserving durable ordering. - Route catch-up, reconciliation fallback, lease-fenced, and retention-pruned events through the core bounded audit emitter. - Add production-path sink-health coverage and update emitter routing ratchets. - Document the class-A decision and add a patch changeset. Files changed: .changeset/fn-9180-outbox-run-audit.md | 7 + AGENTS.md | 1 + docs/run-audit.md | 2 +- .../core-run-audit-emitter-isolation.test.ts | 13 +- .../excluded-awaited-run-audit-layer-sites.test.ts | 203 +-------------------- .../task-deleted-outbox-audit-sink-health.test.ts | 117 ++++++++++++ ...k-lifecycle-retention-audit-sink-health.test.ts | 64 +++++++ .../src/task-store/task-deleted-outbox-consumer.ts | 13 +- .../task-store/task-lifecycle-event-retention.ts | 8 +- 9 files changed, 215 insertions(+), 213 deletions(-) Fusion-Task-Id: FN-9180 Fusion-Task-Lineage: 33e126fd-23d6-4f3b-a377-1c4bfd7b2941 Co-authored-by: Fusion (runfusion.ai) <noreply@runfusion.ai>
This commit is contained in:
@@ -86,6 +86,6 @@ Core best-effort emitters use `packages/core/src/run-audit/emit-bounded-run-audi
|
||||
|
||||
### Awaited core exclusion decision
|
||||
|
||||
FN-9178 classified the remaining awaited sites with hostile-sink characterization tests. `task-deleted-outbox:catch-up`, `:reconciliation-fallback`, `:lease-fenced`, `:retention-pruned`, and recall-capture audit events are class A (bound-safe) candidates. `task:workflow-switch-torn` and `task:reconcile-phantom-committed-reservation` are class B and use the bounded outcome seam because their throw/result payload depends on audit outcome. `task:bypass-review`, `task:resume-step`, and both resurrection-blocked records are class C and intentionally unbounded: they claim persistence before return, destructive cleanup, or a forensic throw.
|
||||
FN-9178 classified awaited sites with hostile-sink characterization tests. FN-9180 routed the class-A `task-deleted-outbox:catch-up`, `:reconciliation-fallback`, `:lease-fenced`, and `:retention-pruned` rows through `emitBoundedRunAudit`; each remains awaited at its post-acknowledgement, post-cursor, or post-DELETE position so bounded telemetry preserves ordering. Recall capture remains class A and is owned by FN-9181. `task:workflow-switch-torn` and `task:reconcile-phantom-committed-reservation` are class B and use the bounded outcome seam because their throw/result payload depends on audit outcome. `task:bypass-review`, `task:resume-step`, and both resurrection-blocked records are class C and intentionally unbounded: they claim persistence before return, destructive cleanup, or a forensic throw.
|
||||
|
||||
All `recordRunAuditEventWithinTransaction(tx, ...)` calls and the `recordRunAuditEventBackend(tx, ...)` transactional call are permanently out of scope. Their audit row shares a transaction with the mutation it describes; bounding would split that atomicity. The full matrix and evidence pointers are in the FN-9178 `decision` task document; `excluded-awaited-run-audit-store-sites.test.ts`, `excluded-awaited-run-audit-layer-sites.test.ts`, and the core routing ratchet pin this boundary.
|
||||
|
||||
Reference in New Issue
Block a user