Skip to content

feat(cli): add private rotating host logs - #197

Merged
SarthakWade merged 1 commit into
mainfrom
feat/193-private-host-logs
Sep 19, 2026
Merged

SarthakWade merged 1 commit into
mainfrom
feat/193-private-host-logs

Conversation

@SarthakWade

Copy link
Copy Markdown
Collaborator

Summary

  • write detached host stdout and stderr to a private, bounded JSON-lines log by default
  • rotate one 1 MiB archive and reject unsafe paths, symlinks, hard links, ownership, and permissions
  • redact common secret forms and include only a bounded redacted tail in startup failures
  • preserve the absolute HEADLESS_HOST_LOG operator override on macOS and Linux
  • document the contract in ADR 29 and update the G2 backlog item

Security

  • logs and lock files use owner-only modes, final-component O_NOFOLLOW, ownership checks, and single-link checks
  • concurrent writers serialize rotation with a private lock
  • the writer receives native host output only and exposes no protocol command, TCP listener, page content, or credential API
  • logging failures continue draining the host pipe so diagnostics cannot terminate or block the browser host

Validation

  • pnpm test
  • pnpm test:runtime
  • pnpm --filter @headless/app build
  • Linux release build and 68 protocol tests in Docker
  • full Linux Chromium E2E using the current binaries and test payload
  • manual macOS normal startup, startup-failure diagnostics, shutdown cleanup, and PATH-based launch
  • shell syntax checks and git diff --check

The standard Linux E2E image rebuild was blocked by Docker networking to deb.debian.org:80; the full suite passed by layering the current build onto the existing provisioned test image. Local macOS E2E passed the new log checks, then hit the existing accessibility HUD flake at start-page-address-hud; the macos-e2e PR check is requested.

Closes #193

@SarthakWade SarthakWade added the macos-e2e Run the macOS WKWebView E2E suite label Sep 19, 2026
@SarthakWade
SarthakWade added this pull request to stack #202 September 19, 2026 09:58

@yashranaway yashranaway left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Private bounded host logs look right for G2.

The writer is a same-binary helper behind __host-log-writer plus env authorization, not a protocol command. Default destination is the 0700 runtime dir; files are 0600, one link, O_NOFOLLOW, flocked rotation, 1 MiB + one archive. Secret-looking assignments and URL userinfo are redacted before disk. Startup failures only attach an 8 KiB tail that already went through that writer.

HEADLESS_HOST_LOG still has to be absolute and still gets the same file checks. Logging cannot fail open to /dev/null after a bad override: HOST_LOG_UNAVAILABLE fails closed.

CI is green, including Linux E2E.

@SarthakWade
SarthakWade merged commit 49f1b91 into main Sep 19, 2026
32 checks passed
@SarthakWade
SarthakWade deleted the feat/193-private-host-logs branch September 19, 2026 11:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

macos-e2e Run the macOS WKWebView E2E suite

Projects

None yet

Development

Successfully merging this pull request may close these issues.

G2: Add private rotating host logs and startup diagnostics

2 participants