Dispose OrwellLoggingDiagnostics as adapt (INFO-DEC-2026-003)

The canon owner disposed coordination-engine's candidate practice pattern as
adapt, which unblocks COORDINATION-WP-0004-T01. Preserve the source, record
the DecisionRecord, and register the assimilation. The TAMQ known use is
implemented and tested, so the pattern enters at candidate. Canon placement
is planned as proposed workplan INFO-WP-0030.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 121421@bnt-lap001
Assistant-Session: 36f8657c-ebfa-4a2e-9ba0-bff06738f233
This commit is contained in:
tegwick 2026-09-22 16:21:37 +02:00
parent 6e39f6d0c9
commit 5a1ea90f64
20 changed files with 406 additions and 101 deletions

View file

@ -0,0 +1,67 @@
# Assimilation — OrwellLoggingDiagnostics
**Status:** Decided. Canon placement is pending under INFO-WP-0030.
**Disposition:** Adapt
**Source:** coordination-engine candidate
`docs/orwell-logging-diagnostics-candidate.md` at `628f984`, preserved
under `source/`
**Authority:** `INFO-DEC-2026-003`, canon owner decision of 2026-09-22
**Consumer follow-up:** coordination-engine `COORDINATION-WP-0004`
## Scope
The candidate proposes a practice for rare local debugging that needs fields
normal logging must omit, such as message bodies, credentials, and terminal
output. The capture is an explicit, per-invocation, non-production diagnostic
mode that writes to an owner-controlled private sink and is never projected
remotely. This assimilation covers the generic practice. TAMQ's `--orwell`
flag, its field list, and its sink location remain owned by tmux-amq.
## Findings
- **Not a duplicate.** The Observability Model owns `Log`, `LogRecord`,
`LogLevel` and `LogStream`, but states no rule separating verbosity from
disclosure. The Data and Security models own sensitive-data classification
and do not describe a controlled, temporary exception to omission. No
existing pattern covers the tension between diagnosability and
non-disclosure.
- **Pattern-shaped.** The candidate resolves a recurring tension with ordered
practice steps and evidence (the six verifications in its §6). That fits
`PracticePatternScheme`.
- **Known use is implemented, not intended.** tmux-amq `04de219` implements the
flag in `src/tamq/diagnostics.py` and `src/tamq/cli.py`, with
`tests/test_diagnostics.py`. That satisfies the scheme's rule that a
known use identifies what was observed. There is one known use, so the
lifecycle entry point is `candidate`.
- **Why adapt, not adopt.** The name and the `--orwell` flag are
consumer-specific. The canon form needs a generic name, the scheme's section
layout, and imports of the owning concepts instead of restated definitions.
The substance of the six practice points carries over.
## DecisionRecord — INFO-DEC-2026-003
### Context
coordination-engine prepared the candidate under COORDINATION-WP-0003-T04 and
transferred canon review to COORDINATION-WP-0004. That workplan cannot close
without an explicit owner disposition. The request had not reached this
repository through intake. It was raised with the owner directly on
2026-09-22.
### Decision
Adapt the candidate into a generic candidate-status practice pattern under
`infospace/patterns/`. It will have a neutral name, import Log/LogRecord,
data classification and environment concepts from their owners, and cite
tmux-amq as its known use. The Orwell name may remain as an alias in the
pattern's Known Uses.
### Consequences
- Canon placement, registration, and the canon version change are INFO-WP-0030
(stage 4 and 5). The assimilation closes when that workplan finishes.
- coordination-engine can record this disposition in COORDINATION-WP-0004-T01.
COORDINATION-WP-0004-T02 waits for the registered artifact ID from
INFO-WP-0030.
- This disposition does not authorize unsafe logging in any runtime. The
pattern describes a practice, and its adoption stays with each consumer.

View file

@ -0,0 +1,26 @@
id: assimilation/orwell-logging-diagnostics
title: Assimilation — OrwellLoggingDiagnostics candidate practice pattern
source: coordination-engine candidate practice pattern (COORDINATION-WP-0003-T04)
source_version: "628f984"
source_type: internal-candidate
source_files:
- source/orwell-logging-diagnostics-candidate.md
requested_by: coordination-engine
status: decided
disposition: adapt
impacts:
- scheme/practice-pattern
- model/observability
- model/data
- model/security
known_uses:
- repo: tmux-amq
revision: "04de219"
implementation: src/tamq/diagnostics.py, src/tamq/cli.py
tests: tests/test_diagnostics.py
decision:
authority: INFO-DEC-2026-003
decided_by: Bernd Worsch
decided_at: "2026-09-22"
consumer_workplan: COORDINATION-WP-0004
workplan: INFO-WP-0030

View file

@ -0,0 +1,52 @@
# OrwellLoggingDiagnostics — candidate practice pattern
Candidate ID: `practice-pattern/orwell-logging-diagnostics`
Canonical owner: info-tech-canon
Requested by: coordination-engine / COORDINATION-WP-0003-T04
Follow-up: COORDINATION-WP-0004
Known use: tmux-amq's local diagnostic mode
Status: candidate prepared; owner review and registration outstanding
## Problem
Normal operational logs must omit message bodies, credentials, and unrestricted
terminal output. Rare local debugging sessions may need otherwise omitted
fields to explain a transport failure. A diagnostic override must never quietly
become the production logging policy.
## Proposed practice
1. Safe logging is the default at every verbosity. Increasing verbosity alone
must not disclose sensitive fields.
2. An explicit per-invocation `--orwell` option selects the unsafe diagnostic
mode. Configuration files, inherited profile defaults and background startup
must not enable it silently.
3. Refuse the option in the production policy. Emit a prominent warning before
collecting any additional fields in an explicitly non-production session.
4. Write only to an owner-controlled local mode-0600 sink. Never send those fields
to State Hub, central telemetry, message exports, or shared CI artifacts.
5. Document precisely which fields can be captured. Prefer synthetic data for
reproduction. The operator selects the shortest useful capture and removes
the unsafe log after diagnosis using the storage owner's procedure.
6. Verify default omission, per-invocation opt-in, production rejection, file
permissions, and separation from remote projection in the consumer tests.
## Consumer boundary
TAMQ owns its diagnostic flag and sensitive transport fields. Coordination-engine
only emits sanitized transition receipts, has no unsafe logging flag, and never
projects checkpoint contents. Introducing an unsafe runtime sink is unnecessary
for WP-0003's worker coordination behavior.
## Canon review handoff
The owner should compare this candidate with existing observability and data
handling practices, decide whether to observe/map/adapt/adopt/reject it, and
register the accepted artifact through its assimilation process. The canonical
`infospace/assimilation/intake-and-assimilation-practice.md` requires an explicit
owner disposition before a canon change; a candidate is not registration.
2026-09-07: the operator approved transferring canon review/registration from
WP-0003-T04 to `workplans/COORDINATION-WP-0004-orwell-canon-review.md`. The
follow-up requires explicit owner disposition and, if accepted, a canonical
artifact/version/index entry. WP-0003 closure does not imply canonical acceptance.