Repository navigation
feat(ocsf): emit full JSON records to supervisor stderr - #4323
Conversation
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com>
|
🌿 Preview your docs: https://nvidia-preview-pr-4323.docs.buildwithfern.com/openshell |
BlockedThe independent review identified a security-sensitive concern requiring private maintainer triage under SECURITY.md. Detailed evidence is retained in the sandbox and is not being posted publicly. Action required: @johntmyers and the maintainers should coordinate private security review through the channels in SECURITY.md before Gator advances to test dispatch. Gator metadata
|
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com>
|
Label |
johntmyers
left a comment
There was a problem hiding this comment.
gator-agent
PR Review Status
@johntmyers, I checked your latest commit and its regression coverage against the earlier review concern. That finding is resolved, and the independent review found no remaining blocking code findings.
Action required: a maintainer should select Re-run all jobs for Branch E2E Checks run 37707051030. The E2E Label Help bot requires this rerun after applying test:e2e; the sandbox policy denied Gator's authorized rerun request, so E2E has not started.
Blocking findings: None.
Carried findings: None; GATOR-b78beea3-01 is resolved by the current head.
Gator metadata
- Validation: Maintainer-authored implementation of the collector workflow scoped in #4322.
- Docs: Relevant Fern and operator documentation updated; the earlier non-blocking schema wording suggestion remains optional.
- Checks: DCO and Trivy passed; Helm gate is green; Branch Checks is pending. Required checks are not all green.
- E2E:
test:e2eapplied. The mirror matches the current head, so/ok to testis unnecessary. Current E2E attempt 1 skipped its suites; the bot requires a rerun. REST rerun was rejected by sandbox policy, and no new attempt was queued. - Review validation: Code-only independent review; local tests were not executed this cycle.
- Head SHA:
a20525aabf8e3d0ad901ee6b0c2c415b2aed303b - Base SHA:
249c6e727ffd6cf3c6171758acf49e18bb022eb4 - Merge base SHA:
a4954d3a99f3c578a3cd22c9281c5286a2dfbbdd - Patch ID:
f64e9360c347756cabc8ea1c0c2eac12fb21890a - Gator payload:
11 - Review mode:
initial(authoritative ledger; earlier private evidence retained and reconciled) - Previous reviewed SHA: none in ledger; prior blocked head
b78beea3f20f507a5544f722abe6229252026f1cchecked for carried obligations. - Review budget exhausted: no
- Maintainer decision required: no review convergence decision; test dispatch action remains.
- Next state:
gator:blocked - Blocked reason:
test_dispatch_required
Monitoring CompleteMonitoring is complete because this PR has merged. Final status: Gator's current-head review recorded no remaining blocking code findings, and the PR reached I removed the active |
Summary
Enabling
ocsf_json_enablednow emits full OCSF records to supervisor stderr with anOCSF-JSONmarker, so container log collectors can retrieve structured events without accessing the supervisor's private log filesystem. The output works even when file logging is unavailable and respects the existing schema-version setting.Related Issue
Closes #4322
Changes
Testing
mise run e2e:dockerpasses all six CLI conformance scenarios and the new collector E2E test againstopenshell/supervisor:ocsf-json-4322. The test confirms JSON is emitted on stderr after a live settings toggle, shorthand remains available, and gateway log responses contain no JSON records.Console delivery is best-effort. The stderr queue can drop records under backpressure, and retention remains controlled by the runtime and external collector.
Checklist