Skip to content

fix(supervisor): isolate shorthand and OCSF log retention - #4257

Closed
matthewgrossman wants to merge 1 commit into
mainfrom
fix/4256-independent-log-retention/matthewgrossman
Closed

matthewgrossman wants to merge 1 commit into
mainfrom
fix/4256-independent-log-retention/matthewgrossman

Conversation

@matthewgrossman

Copy link
Copy Markdown
Member

Summary

Keep supervisor shorthand and OCSF JSONL retention independent by changing the shorthand filename prefix to openshell-text. JSONL filenames, /var/log, daily rotation, and the three-file limits stay unchanged.

Related Issue

Closes #4256

Changes

  • Use disjoint appender prefixes and share the existing builder settings through a small private binary module so regression tests exercise production configuration.
  • Read both new and legacy shorthand files in /v1/denials, while continuing to exclude JSONL files.
  • Test initialization in either order, real rollover of both writers, and preservation of legacy files in a shared directory.
  • Update collection examples and policy-advisor guidance. Existing shorthand files remain readable but are no longer automatically pruned; operators should collect and remove them as needed. JSONL collectors need no changes.

Testing

  • Checks appropriate to the affected code and behavior pass
  • Unit tests added/updated
  • Deployment E2E tests run (not run; validation targets file retention and the denial reader)

Passed locally on macOS:

  • mise exec -- cargo test -p openshell-supervisor --bin openshell-supervisor --locked -- --nocapture (9 tests)
  • mise exec -- cargo test -p openshell-supervisor-network --lib policy_local::tests --locked (39 tests; also passed with --no-default-features)
  • mise exec -- cargo clippy -p openshell-supervisor -p openshell-supervisor-network --all-targets --locked -- -D warnings
  • Targeted cargo fmt --check, Markdown lint, mise run docs, and git diff --check. Fern reported zero errors and three existing warnings.

The test filesystem exposes creation timestamps. An isolated copy of the regression test using the original openshell prefix failed as expected: initializing shorthand reduced three JSONL files to one. A prefix-disjointness assertion also guards the timestamp-unavailable fallback, since filtering precedes either timestamp path. Rollover coverage uses MINUTELY to cross a real boundary within 65 seconds; it exercises the same pruning path as production's DAILY rotation without a dependency patch or mock clock.

Checklist

  • Follows Conventional Commits
  • Commits are signed off (DCO)
  • Architecture docs updated (not applicable; no architecture change)

Signed-off-by: Matthew Grossman <mgrossman@nvidia.com>
@copy-pr-bot

copy-pr-bot Bot commented Oct 6, 2026

Copy link
Copy Markdown

Auto-sync is disabled for draft pull requests in this repository. Workflows must be run manually.

Contributors can view more details about this message here.

@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown

@matthewgrossman
matthewgrossman deleted the fix/4256-independent-log-retention/matthewgrossman branch October 6, 2026 22:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

bug(logging): shorthand retention can prune supervisor OCSF JSONL history

1 participant