Skip to content

feat(ocsf): emit full JSON records to supervisor stderr - #4323

Merged
drew merged 2 commits into
mainfrom
feat/4322-ocsf-json-stderr/johntmyers
Oct 8, 2026
Merged

drew merged 2 commits into
mainfrom
feat/4322-ocsf-json-stderr/johntmyers

Conversation

@johntmyers

Copy link
Copy Markdown
Collaborator

Summary

Enabling ocsf_json_enabled now emits full OCSF records to supervisor stderr with an OCSF-JSON marker, so container log collectors can retrieve structured events without accessing the supervisor's private log filesystem. The output works even when file logging is unavailable and respects the existing schema-version setting.

Related Issue

Closes #4322

Changes

  • Preserve shorthand output and optional plain JSONL files; add timestamped, compact JSON console records with the original event UID.
  • Share a bounded, nonblocking stderr queue across diagnostics, shorthand, and JSON. Submit complete lines to prevent interleaved records; drop new lines when its 1,024-line capacity is full.
  • Keep JSON console filtering independent of diagnostic filters and file-sink initialization.
  • Document collector framing, delivery limits, and the Docker tmpfs access trap; update relevant operator skills.
  • Keep supervisor-to-gateway gRPC log content and CLI/API representations unchanged.

Testing

  • OCSF crate tests and supervisor library/binary tests pass, including toggles, downgrade, event identity, concurrent writes, unavailable file storage, disabled diagnostics, and blocked stderr.
  • Rust formatting and Clippy checks pass for the affected crates and new E2E test. The repository pre-commit suite also passes, including full-workspace Clippy, the sandbox perf harness, E2E and example lint, license and lockfile checks, Helm, Python, TypeScript, and protobuf validation.
  • Supervisor Docker image builds successfully.
  • Fern validation and Markdown lint pass (Fern reports three warnings).
  • mise run e2e:docker passes all six CLI conformance scenarios and the new collector E2E test against openshell/supervisor:ocsf-json-4322. The test confirms JSON is emitted on stderr after a live settings toggle, shorthand remains available, and gateway log responses contain no JSON records.

Console delivery is best-effort. The stderr queue can drop records under backpressure, and retention remains controlled by the runtime and external collector.

Checklist

  • Follows Conventional Commits
  • Commits are signed off (DCO)
  • Relevant implementation and operator documentation updated

Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com>
@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown

@johntmyers

Copy link
Copy Markdown
Collaborator Author

gator-agent

Blocked

The independent review identified a security-sensitive concern requiring private maintainer triage under SECURITY.md. Detailed evidence is retained in the sandbox and is not being posted publicly.

Action required: @johntmyers and the maintainers should coordinate private security review through the channels in SECURITY.md before Gator advances to test dispatch.

Gator metadata
  • Validation: Maintainer-authored implementation of the collector workflow scoped in feat(ocsf): emit opt-in OCSF-JSON records to supervisor stderr for log collectors #4322.
  • Docs: Relevant Fern and operator documentation updated; one non-blocking wording inconsistency noted.
  • Checks: DCO and vouch passed; branch checks are running. No test dispatch performed this cycle.
  • Head SHA: b78beea3f20f507a5544f722abe6229252026f1c
  • Base SHA: 249c6e727ffd6cf3c6171758acf49e18bb022eb4
  • Merge base SHA: a4954d3a99f3c578a3cd22c9281c5286a2dfbbdd
  • Patch ID: 6ea32083dc3ba18997d260a089ea84a8799681ba
  • Gator payload: 11
  • Review mode: initial
  • Previous reviewed SHA: none
  • Review budget exhausted: no
  • Maintainer decision required: yes — private security triage
  • Next state: gator:blocked
  • Blocked reason: private_security_review_required

@johntmyers johntmyers added the gator:blocked Gator is blocked by process or repository gates label Oct 8, 2026
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com>
@johntmyers johntmyers added the test:e2e Requires end-to-end coverage label Oct 8, 2026
@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown

Label test:e2e applied for a20525a. Open the existing run and click Re-run all jobs to execute with the label set. The run will execute the standard E2E suite after building the required gateway, sandbox, and supervisor images once. The matching required CI gate status on this PR will flip green automatically once the run finishes.

@johntmyers johntmyers left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

gator-agent

PR Review Status

@johntmyers, I checked your latest commit and its regression coverage against the earlier review concern. That finding is resolved, and the independent review found no remaining blocking code findings.

Action required: a maintainer should select Re-run all jobs for Branch E2E Checks run 37707051030. The E2E Label Help bot requires this rerun after applying test:e2e; the sandbox policy denied Gator's authorized rerun request, so E2E has not started.

Blocking findings: None.

Carried findings: None; GATOR-b78beea3-01 is resolved by the current head.

Gator metadata
  • Validation: Maintainer-authored implementation of the collector workflow scoped in #4322.
  • Docs: Relevant Fern and operator documentation updated; the earlier non-blocking schema wording suggestion remains optional.
  • Checks: DCO and Trivy passed; Helm gate is green; Branch Checks is pending. Required checks are not all green.
  • E2E: test:e2e applied. The mirror matches the current head, so /ok to test is unnecessary. Current E2E attempt 1 skipped its suites; the bot requires a rerun. REST rerun was rejected by sandbox policy, and no new attempt was queued.
  • Review validation: Code-only independent review; local tests were not executed this cycle.
  • Head SHA: a20525aabf8e3d0ad901ee6b0c2c415b2aed303b
  • Base SHA: 249c6e727ffd6cf3c6171758acf49e18bb022eb4
  • Merge base SHA: a4954d3a99f3c578a3cd22c9281c5286a2dfbbdd
  • Patch ID: f64e9360c347756cabc8ea1c0c2eac12fb21890a
  • Gator payload: 11
  • Review mode: initial (authoritative ledger; earlier private evidence retained and reconciled)
  • Previous reviewed SHA: none in ledger; prior blocked head b78beea3f20f507a5544f722abe6229252026f1c checked for carried obligations.
  • Review budget exhausted: no
  • Maintainer decision required: no review convergence decision; test dispatch action remains.
  • Next state: gator:blocked
  • Blocked reason: test_dispatch_required

@johntmyers johntmyers added gator:watch-pipeline Gator is monitoring PR CI/CD status gator:approval-needed Gator completed review; maintainer approval needed and removed gator:blocked Gator is blocked by process or repository gates gator:watch-pipeline Gator is monitoring PR CI/CD status labels Oct 8, 2026
@drew
drew added this pull request to the merge queue Oct 8, 2026
@johntmyers johntmyers added gator:merge-ready and removed gator:approval-needed Gator completed review; maintainer approval needed labels Oct 8, 2026
Merged via the queue into main with commit 67adcf1 Oct 8, 2026
151 of 154 checks passed
@drew
drew deleted the feat/4322-ocsf-json-stderr/johntmyers branch October 8, 2026 05:47
@johntmyers

Copy link
Copy Markdown
Collaborator Author

gator-agent

Monitoring Complete

Monitoring is complete because this PR has merged.

Final status: Gator's current-head review recorded no remaining blocking code findings, and the PR reached gator:merge-ready before merging.

I removed the active gator:* label because there is nothing left for gator to monitor on this PR.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

test:e2e Requires end-to-end coverage

Projects

None yet

Development

Successfully merging this pull request may close these issues.

feat(ocsf): emit opt-in OCSF-JSON records to supervisor stderr for log collectors

2 participants