Documentation
¶
Overview ¶
Package audit writes a bounded, local JSONL audit trail without retaining terminal input, raw prompt matches, environment values, or backend errors.
Index ¶
- Constants
- Variables
- func AuditGenerationIndex(base, name string) (int, bool)
- func DefaultPath() (string, error)
- func Redact(value string) string
- func ResolvePath(path string) (string, error)
- func Validate(config Config) error
- func VerifyJournalFile(path string) error
- type Config
- type Decision
- type DecisionBy
- type Entry
- type FileSink
- type Kind
- type LineSink
- type Mode
- type Option
- type Outcome
- type Recorder
Constants ¶
const (
// CurrentSchemaVersion identifies the on-disk Entry representation.
CurrentSchemaVersion = 1
)
Variables ¶
var ErrClosed = errors.New("enregistreur d'audit fermé")
var ErrNotAuditJournal = errors.New("le chemin d'audit contient un fichier étranger")
ErrNotAuditJournal reports an audit path that already holds a file Relayer did not write.
Functions ¶
func AuditGenerationIndex ¶
AuditGenerationIndex applies the exact filename recognition used by audit rotation. It is exported within Relayer's internal boundary so passive diagnostics can inspect precisely the files the runtime would mutate.
func DefaultPath ¶
DefaultPath returns the private per-user audit file location.
func Redact ¶
Redact removes common credential forms from arbitrary text. It is intentionally conservative and idempotent.
func ResolvePath ¶
ResolvePath returns an absolute effective path, using DefaultPath for an empty configured value.
func VerifyJournalFile ¶
VerifyJournalFile reports whether an existing path holds a Relayer audit journal. It only reads, so read-only diagnostics can warn about a foreign file before startup refuses to open it. An absent path is not an error here: callers decide what a missing journal means.
Types ¶
type Config ¶
type Config struct {
Enabled bool `json:"enabled" yaml:"enabled"`
Mode Mode `json:"mode" yaml:"mode"`
Path string `json:"path" yaml:"path"`
MaxFileSizeMB int `json:"max_file_size_mb" yaml:"max_file_size_mb"`
MaxFiles int `json:"max_files" yaml:"max_files"`
}
Config controls local audit persistence. MaxFiles counts the active file as well as its rotated generations.
func DefaultConfig ¶
func DefaultConfig() Config
DefaultConfig enables a conservative metadata-only audit trail.
type Decision ¶
type Decision string
Decision is the audited policy outcome. It intentionally differs from an adapter's wire decision: asking a human is an explicit, content-free audit action rather than a copy of the submitted terminal input.
type DecisionBy ¶
type DecisionBy string
DecisionBy identifies the actor without storing any submitted value.
const ( DecisionBySystem DecisionBy = "system" DecisionByHuman DecisionBy = "human" DecisionByPolicy DecisionBy = "policy" DecisionByUnknown DecisionBy = "unknown" )
type Entry ¶
type Entry struct {
SchemaVersion int `json:"schema_version"`
Sequence uint64 `json:"sequence"`
Timestamp time.Time `json:"timestamp"`
EntryID string `json:"entry_id"`
RunID string `json:"run_id"`
Kind Kind `json:"kind,omitempty"`
SessionID string `json:"session_id,omitempty"`
AgentID string `json:"agent_id,omitempty"`
Backend string `json:"backend,omitempty"`
Adapter string `json:"adapter,omitempty"`
EventID string `json:"event_id,omitempty"`
EventType adapters.EventType `json:"event_type,omitempty"`
Risk adapters.RiskLevel `json:"risk,omitempty"`
Rule string `json:"rule,omitempty"`
Decision Decision `json:"decision,omitempty"`
DecisionBy DecisionBy `json:"decision_by,omitempty"`
Outcome Outcome `json:"outcome,omitempty"`
Reason string `json:"reason,omitempty"`
Summary string `json:"summary,omitempty"`
Sensitive bool `json:"sensitive"`
Metadata map[string]string `json:"metadata,omitempty"`
}
Entry is the versioned JSONL record. It intentionally has no Match, manual-input, environment, or raw-error field.
func SanitizeEntry ¶
SanitizeEntry returns a deep, redacted copy suitable for the selected mode.
type FileSink ¶
type FileSink struct {
// contains filtered or unexported fields
}
FileSink writes complete lines synchronously and rotates them by size.
func NewFileSink ¶
NewFileSink opens a private append-only audit file. maxFiles includes the active file, so maxFiles=1 retains no rotated generation.
type Kind ¶
type Kind string
Kind identifies a closed set of audit lifecycle records.
const ( KindRunStarted Kind = "run_started" KindRunFinished Kind = "run_finished" KindSessionStarted Kind = "session_started" // KindSupervisionFinished means Relayer stopped supervising the session; // it does not claim that a persistent tmux process exited. KindSupervisionFinished Kind = "supervision_finished" KindSessionFinished Kind = "session_finished" KindEventDetected Kind = "event_detected" // KindEventWithdrawn records that an occurrence which was awaiting a human // stopped being pending without a decision being delivered. It is the only // evidence that a supervision gate opened on its own. KindEventWithdrawn Kind = "event_withdrawn" KindPolicyEvaluated Kind = "policy_evaluated" KindDecision Kind = "decision" KindDelivery Kind = "delivery" // KindOperatorInput records only the lifecycle of a direct, human line // submission. Entry intentionally has no field for the submitted text, // its length, or the encoded terminal bytes. KindOperatorInput Kind = "operator_input" KindAttachStarted Kind = "attach_started" KindAttachFinished Kind = "attach_finished" KindBackendError Kind = "backend_error" KindSessionCleanup Kind = "session_cleanup" KindUnknown Kind = "unknown" )
type Mode ¶
type Mode string
Mode controls how much already-sanitized event information reaches disk.
type Option ¶
type Option func(*openOptions) error
Option customizes Open without weakening its filesystem invariants.
func WithIDGenerator ¶
WithIDGenerator supplies run and entry identifiers.
type Outcome ¶
type Outcome string
Outcome is a safe, finite result vocabulary for lifecycle and policy audit.
const ( OutcomeStarted Outcome = "started" OutcomeFinished Outcome = "finished" OutcomeDetected Outcome = "detected" OutcomePending Outcome = "pending" OutcomeInFlight Outcome = "in_flight" OutcomeApplied Outcome = "applied" OutcomeAsk Outcome = "ask" OutcomeDryRun Outcome = "dry_run" OutcomeFallbackUnsupported Outcome = "fallback_unsupported" OutcomeFallbackStale Outcome = "fallback_stale" OutcomeFallbackDeliveryUncertain Outcome = "fallback_delivery_uncertain" OutcomeSucceeded Outcome = "succeeded" OutcomeFailed Outcome = "failed" OutcomeCancelled Outcome = "cancelled" OutcomeSkipped Outcome = "skipped" OutcomeUnknown Outcome = "unknown" )
type Recorder ¶
type Recorder struct {
// contains filtered or unexported fields
}
Recorder assigns identities and a total order before writing sanitized JSONL.
func NewRecorder ¶
func NewRecorder( config Config, sink LineSink, clock func() time.Time, idGenerator func() (string, error), ) (*Recorder, error)
NewRecorder constructs a recorder around an injectable line sink, clock, and ID generator. Nil clock and generator select secure production defaults.
func Open ¶
Open creates a rotating FileSink and wraps it in a Recorder. Disabled and off configurations perform no filesystem or ID-generator work.