mirror of
https://github.com/rustfs/rustfs.git
synced 2026-07-26 08:18:18 +00:00
dbc628f169
fix(audit): propagate dispatch delivery failures instead of swallowing them (backlog#962) AuditPipeline::dispatch and dispatch_batch accumulated per-target save() errors, logged them, and then unconditionally returned Ok(()). When every configured target failed the audit entry was lost outright (for store-backed targets a failed save() means the event was neither delivered nor persisted for replay), yet callers such as dispatch_audit_log saw success and assumed the audit trail was intact. Audit is a compliance-critical path, so a total delivery failure that reports success is a silent data-loss bug. Both methods now distinguish three outcomes: all targets succeeded (Ok), partial failure where at least one target accepted the event (log a warning and return Ok, since the entry is not lost), and total failure where no delivery succeeded while errors were recorded (record the failure metric, log an error, and return Err(AuditError::Target) carrying the first target error). This lets the caller react instead of assuming success. Adds regression tests with a FailingTarget mock asserting that dispatch and dispatch_batch return Err on total failure and Ok on partial failure.