rdmsm4x-changelog-20260902-2040-ecs0lib-tyrell-typed-audit
rdmsm4x-changelog-20260902-2040-ecs0lib-tyrell-typed-audit
Created an isolated, owner-reviewable ecs0lib typed audit logging candidate so a future safety-actor migration can preserve privacy, bounded local evidence, and deterministic ordering without changing canonical source or any consumer.
Scope
- Host:
rdmsm4x. - Project: Production-mode
ecs0lib. - Ticket/claim:
FEAT-20260902-30,codex@rdmsm4x/ecs0-typed-logging. - Exact base:
9f27867942024c5640f10c35d17d97ff2e6664f2. - Isolated branch/worktree:
codex/ecs0lib-tyrell-typed-audit-20260902at/Users/richh/dev/_worktrees/ecs0lib-tyrell-typed-audit-20260902. - Excluded and unchanged: canonical
/Users/richh/dev/lib/ecs0lib, all Tyrell roots/worktrees, services, signing, installation, canary, fleet rollout, publication, merge, and remote push.
Files changed
- Added
/Users/richh/dev/_worktrees/ecs0lib-tyrell-typed-audit-20260902/Sources/ECS0System/ECSTypedAuditLogging.swift. - Added
/Users/richh/dev/_worktrees/ecs0lib-tyrell-typed-audit-20260902/Tests/ECS0LibTests/ECSTypedAuditLoggingTests.swift. - Added
/Users/richh/dev/_worktrees/ecs0lib-tyrell-typed-audit-20260902/docs/TYPED_AUDIT_LOGGING.md. - Appended
/Users/richh/dev/_worktrees/ecs0lib-tyrell-typed-audit-20260902/SESSION-STATE.md. - Added handoff
/Users/richh/dev/_handoff/ecs0lib-tyrell-typed-audit-20260902.md. - Added/updated coordination check-in
/Users/richh/.agent-coordination/checkins/codex-rdmsm4x-ecs0lib-tyrell-typed-audit-20260902.json. - Ticket system created and updated
FEAT-20260902-30and its generated local HTML views.
What changed and why it matters
- Added typed subsystem/category/event/field identifiers, eliminating a free-form message-body API from the new contract.
- Added closed debug/info/notice/warning/error/critical/fault severity with exact and minimum query semantics.
- Added explicit public/private/hash/omit privacy. Transformation happens before retention, encoding, sink delivery, or OSLog.
- Added bounded local oldest-first retention with monotonic sequences and deterministic actor ordering.
- Added a synchronous optional sink boundary; the caller's await completes only after local retention and sink acceptance/rejection.
- Added opt-in OSLog output that receives only already-transformed structured entries.
- Added sanitized sink errors. A rejected supplemental sink cannot erase the locally accepted entry or expose its own diagnostic text.
- Documented deterministic hashing as correlation rather than encryption; low-entropy sensitive fields should use private or omit.
Commits
- Source and tests:
279dceb30eb31f64a62066b78c5f8620ceec20f3. - Documentation/checkpoint:
d63e1e3a7674a243ed04277ad8e0d88e333bd52b. - Both commits carry
Agent: codex@rdmsm4x (01a04277).
Commands and verification evidence
swift test --filter ECSTypedAuditLoggingTests: 9 XCTest, 0 failures, exit 0.swift test: 214 XCTest + 11 Swift Testing, 225 total, 0 failures, exit 0.swift test --sanitize=thread --scratch-path .build-tsan: same 225 total, 0 failures, no reported data race, exit 0.swift build -c release --product ECS0System: build complete, exit 0.xcrun --sdk <macosx|iphoneos|appletvos|xros> swiftc ... ECSTypedAuditLogging.swift: all four standalone module compiles exit 0.xcodebuild -scheme ecs0lib -destination 'generic/platform=macOS' build: exit 0.- Umbrella iOS/tvOS/visionOS builds reproduce unchanged pre-existing
failures tracked by
ISSUE-20260902-18:CECSNetTopBridge/libproc.h, plus tvOSLocalAuthentication. No portability repair was absorbed into this task. git diff --checkandgit show --check: exit 0.- Staged gitleaks scan: 27.94 KB, 0 findings.
- Final candidate status: clean at
d63e1e3a7674a243ed04277ad8e0d88e333bd52b. - Canonical status re-read: exact base retained its six pre-existing untracked Hardware/Provenance/test paths unchanged.
Coordination and owner action
- Published/synced check-in before source edits.
- Owner review request dispatched to
claude@rdmsm4xas20260902-204011-94D412E5, naming both commits and requiring an explicit ACCEPT or REJECT. - No owner acceptance or clean canonical publication receipt exists yet. Consumers must retain their guards and fallbacks.
- The shared
agentkit_preflightstalled without output in two bounded 30-second attempts; ticketing, check-in sync, and fleet bus operations were independently successful. That unrelated coordination-tool stall was not repaired here.
Backup and rollback
- Git commits are the recoverable source checkpoint; the isolated branch/worktree remains intact for owner review.
- Before publication, rollback is abandonment/removal of only this isolated branch/worktree after review; canonical source and consumers are unchanged.
- After any future publication, revert the exact publication commit and rerun the focused 9-test suite, full 225-test suite, ThreadSanitizer, and platform gates. Any consumer integration has its own separate revert and fallback restoration.