Problem
Detached hosts send stdout and stderr to /dev/null unless HEADLESS_HOST_LOG is set to an absolute path. Startup failures and later host faults are therefore invisible in normal use, and support tooling has no stable diagnostic source.
Split from #54 G2.
Contract
- Add an architecture decision for the default log location, ownership, bounds, rotation, redaction, and environment override behavior.
- Default to a private per-user log below the existing runtime directory.
- Create directories and files with restrictive permissions and reject unsafe file types, symlinks, and paths.
- Preserve
HEADLESS_HOST_LOG as an explicit absolute-path override for tests and operators.
- Bound disk use with deterministic rotation. Rotation must not follow symlinks or overwrite unrelated files.
- Capture detached host stdout and stderr without placing page content, secrets, credential values, cookie values, storage values, or fill values into new logs.
- Surface launch exits and timeouts with the safe log path and a bounded diagnostic tail.
- Keep supervised launches and both macOS and Linux behavior consistent.
Acceptance criteria
- Normal detached startup writes to the private default log instead of
/dev/null.
- Existing explicit log overrides continue to work.
- Permissions, rotation, symlink rejection, malformed path handling, and disk bounds are tested.
- Startup exit and timeout errors include actionable diagnostics without leaking secrets.
- Concurrent launches do not corrupt or bypass log bounds.
- Protocol behavior and the no-TCP/no-arbitrary-JavaScript security boundaries are unchanged.
- CLI help and operator documentation describe the log location and override.
- Protocol, CLI, Linux E2E, and macOS E2E coverage pass.
Problem
Detached hosts send stdout and stderr to
/dev/nullunlessHEADLESS_HOST_LOGis set to an absolute path. Startup failures and later host faults are therefore invisible in normal use, and support tooling has no stable diagnostic source.Split from #54 G2.
Contract
HEADLESS_HOST_LOGas an explicit absolute-path override for tests and operators.Acceptance criteria
/dev/null.