feat(audit): receive confirmed audit notifications atomically - #463
Merged
jscott3201 merged 1 commit intoAug 30, 2026
Merged
Conversation
Owner
Author
Immutable delivery evidence
Local validation at this head:
Hosted CI run The implementation was grounded in ASHRAE 135-2020 §§5.3.5.3, 12.64, 13.20, and 19.6 plus the Clause 21 productions. Claims remain qualified: confirmed receipt only; one explicit sink; fail-closed application authorization; synchronous durable persistence; process-local duplicate detection; no Unconfirmed receiver, producer/forwarder, durable idempotency, Python receiver builder, or Audit BIBB claim. |
jscott3201
deleted the
codex/pr-0109-confirmed-audit-notification-receiver
branch
August 30, 2026 18:55
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
ConfirmedAuditNotificationthrough one explicitly configured Audit Log sink and a fail-closed, provenance-aware authorizerCurrent_ValueprecedenceStandard grounding
2 × APDU_Timeoutmatching windowValidation
cargo test -p bacnet-objects audit --locked— 28 passedcargo test -p bacnet-server audit_notification --locked— 9 passedcargo test -p bacnet-server audit_notification --all-features --locked— 10 passed, including BACnet/SC builder coveragecargo test -p bacnet-server --locked— 663 unit + 3 integration passedcargo test --workspace --exclude rusty-bacnet --locked— passedcargo clippy --workspace --exclude rusty-bacnet --all-targets --locked— passed with pre-existing warnings onlycargo check -p rusty-bacnet --tests --locked— passedCompatibility and limits
BACnetObjectcapability is defaulted; builder methods are additiveServerConfigfields affect callers using exhaustive struct literalsAPDU_Timeoutis requiredRefs #345