package store import ( "context" "crypto/sha256" "database/sql" "fmt" ) // appendLateExpiryAudit records the first observed queue-deadline // contradiction without copying command text, script bodies, or output into // the separate audit budget. The command row remains the fast status path; // this row is the durable operator/audit history. func appendLateExpiryAudit(ctx context.Context, tx *sql.Tx, occurredAt int64, clientID string, issue [16]byte, receiptUnixNano int64) error { payload := []byte(fmt.Sprintf("receipt_unix_nano=%d", receiptUnixNano)) digest := sha256.Sum256(payload) _, err := tx.ExecContext(ctx, `INSERT INTO audit_events ( occurred_at, source, client_id, issue_uuid, action, outcome, compression, payload, raw_bytes, stored_bytes, sha256 ) VALUES (?, 'session', ?, ?, 'late_after_expiry', 'observed', 1, ?, ?, ?, ?)`, occurredAt, clientID, issue[:], payload, len(payload), len(payload), digest[:]) return err }