Dispose OrwellLoggingDiagnostics as adapt (INFO-DEC-2026-003)
The canon owner disposed coordination-engine's candidate practice pattern as adapt, which unblocks COORDINATION-WP-0004-T01. Preserve the source, record the DecisionRecord, and register the assimilation. The TAMQ known use is implemented and tested, so the pattern enters at candidate. Canon placement is planned as proposed workplan INFO-WP-0030. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Assistant: claude-code Assistant-Model: opus Assistant-Process: 121421@bnt-lap001 Assistant-Session: 36f8657c-ebfa-4a2e-9ba0-bff06738f233
This commit is contained in:
parent
6e39f6d0c9
commit
5a1ea90f64
20 changed files with 406 additions and 101 deletions
|
|
@ -0,0 +1,52 @@
|
|||
# OrwellLoggingDiagnostics — candidate practice pattern
|
||||
|
||||
Candidate ID: `practice-pattern/orwell-logging-diagnostics`
|
||||
Canonical owner: info-tech-canon
|
||||
Requested by: coordination-engine / COORDINATION-WP-0003-T04
|
||||
Follow-up: COORDINATION-WP-0004
|
||||
Known use: tmux-amq's local diagnostic mode
|
||||
Status: candidate prepared; owner review and registration outstanding
|
||||
|
||||
## Problem
|
||||
|
||||
Normal operational logs must omit message bodies, credentials, and unrestricted
|
||||
terminal output. Rare local debugging sessions may need otherwise omitted
|
||||
fields to explain a transport failure. A diagnostic override must never quietly
|
||||
become the production logging policy.
|
||||
|
||||
## Proposed practice
|
||||
|
||||
1. Safe logging is the default at every verbosity. Increasing verbosity alone
|
||||
must not disclose sensitive fields.
|
||||
2. An explicit per-invocation `--orwell` option selects the unsafe diagnostic
|
||||
mode. Configuration files, inherited profile defaults and background startup
|
||||
must not enable it silently.
|
||||
3. Refuse the option in the production policy. Emit a prominent warning before
|
||||
collecting any additional fields in an explicitly non-production session.
|
||||
4. Write only to an owner-controlled local mode-0600 sink. Never send those fields
|
||||
to State Hub, central telemetry, message exports, or shared CI artifacts.
|
||||
5. Document precisely which fields can be captured. Prefer synthetic data for
|
||||
reproduction. The operator selects the shortest useful capture and removes
|
||||
the unsafe log after diagnosis using the storage owner's procedure.
|
||||
6. Verify default omission, per-invocation opt-in, production rejection, file
|
||||
permissions, and separation from remote projection in the consumer tests.
|
||||
|
||||
## Consumer boundary
|
||||
|
||||
TAMQ owns its diagnostic flag and sensitive transport fields. Coordination-engine
|
||||
only emits sanitized transition receipts, has no unsafe logging flag, and never
|
||||
projects checkpoint contents. Introducing an unsafe runtime sink is unnecessary
|
||||
for WP-0003's worker coordination behavior.
|
||||
|
||||
## Canon review handoff
|
||||
|
||||
The owner should compare this candidate with existing observability and data
|
||||
handling practices, decide whether to observe/map/adapt/adopt/reject it, and
|
||||
register the accepted artifact through its assimilation process. The canonical
|
||||
`infospace/assimilation/intake-and-assimilation-practice.md` requires an explicit
|
||||
owner disposition before a canon change; a candidate is not registration.
|
||||
|
||||
2026-09-07: the operator approved transferring canon review/registration from
|
||||
WP-0003-T04 to `workplans/COORDINATION-WP-0004-orwell-canon-review.md`. The
|
||||
follow-up requires explicit owner disposition and, if accepted, a canonical
|
||||
artifact/version/index entry. WP-0003 closure does not imply canonical acceptance.
|
||||
Loading…
Add table
Add a link
Reference in a new issue