Skip to content

Add opt-in write-size and outcome audit metadata - #152

Draft
arkmish wants to merge 4 commits into
branch-3.6from
armishra/zk-write-audit
Draft

arkmish wants to merge 4 commits into
branch-3.6from
armishra/zk-write-audit

Conversation

@arkmish

@arkmish arkmish commented Sep 28, 2026 •

Copy link
Copy Markdown

Description

Make audit records useful for diagnosing large writes and failed or rolled-back mutations without changing the client's operation result.

Enhanced logging adds schema_version=2, attempted data_length, known error_code, transaction identifiers, and an explicit outcome of committed, failed, rolled_back, or unknown.

  • Decode the correct request type for create variants, including TTL creates, and setData; retain the original request buffer's position, limit, and mark.
  • Correlate multi members by their position in the full request, including checks and repeated paths. Use the final returned path for successful sequential creates.
  • Determine whole-multi failure before classifying members, so a rolled-back member with error code zero is never logged as committed.
  • Escape v2 fields reversibly, sanitize untrusted user/ACL identities, and never emit payload values. One captured mode governs sanitization and formatting throughout an operation.
  • Keep audit sink and error-reporting failures from changing valid writes or interrupting system ephemeral deletions. Expose observed failures through a bounded audit_errors counter.

Enablement requires both zookeeper.audit.enable=true and zookeeper.audit.enhanced.enable=true. Both default to false.

Tests

Validated AuditHelperTest, AuditEventTest, StandaloneServerAuditTest, Slf4JAuditLoggerTest, CreateTTLTest, ServerMetricsTest, DataTreeTest, and AuthUtilTest on JDK 11 with Java 8 API targeting:

Tests run: 85, Failures: 0, Errors: 0, Skipped: 0
BUILD SUCCESS

Coverage includes real write results, atomic multi rollback, payload-size boundaries, typed TTL handling, buffer preservation, custom-provider redaction, logger/counter failures, and deterministic mode changes during emission.

  • Local code review completed

Changes that Break Backward Compatibility (Optional)

Default audit output and existing public logging overloads are preserved. Enhanced mode is opt-in and adds versioned fields and conservative identity redaction; consumers must be prepared before it is enabled.

No authentication/ACL decision, client response, persistence-format, or ordinary-read auditing change. committed describes transaction application, not client delivery. The error counter cannot detect silent asynchronous-appender or downstream log loss.

Documentation (Optional)

Updated zookeeper-docs/src/main/resources/markdown/zookeeperAuditLogs.md with fields, escaping, operation/outcome semantics, privacy requirements, rollout guidance, and coverage limits.

🤖 Generated with GitHub Copilot CLI

arkmish and others added 4 commits September 28, 2026 12:19
Decode typed requests without changing their buffers, cover TTL writes, correlate multi members by position and distinguish atomic rollback from commit. Add safe enhanced ACL metadata, deletion identity and observable audit failures while retaining legacy logging defaults.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Use validated concrete built-in authentication providers for enhanced user extraction, redact custom and unknown identity representations, and preserve legacy behavior. Cover the registered default-getUserName leak with real client authentication.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Report audit failures through independently best-effort counter and diagnostic operations without recursive retries. Verify an applied write still receives success and multiple system deletions complete when both the audit sink and error counter fail.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Carry the captured enhanced mode into event construction without rereading the property. Preserve public delegating overloads and keep every multi parent/member on the same mode. Cover deterministic ACL off-to-on and multi mode transitions with subsequent genuine v2 emission.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

audit log enhancement Audit log metadata, privacy, outcomes, and session or authentication correlation enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant