Skip to content

fix(logging): consolidate tool and command audit events - #623

Open
owtaylor wants to merge 3 commits into
feat/log-default-levelfrom
feat/audit-events
Open

owtaylor wants to merge 3 commits into
feat/log-default-levelfrom
feat/audit-events

Conversation

@owtaylor

Copy link
Copy Markdown
Collaborator

Stacked on #622; base branch: feat/log-default-level.

Log tool calls around authorization and execution, with a per-call UUID,
sanitized parameters, the resolved target host, and HTTP client address
and verified claims where available. Propagate this context to command,
gatekeeper, and diagnostic records, keeping concurrent calls separate.

Give local and SSH command execution the same completion event, with
elapsed time and either an exit status or an error. Let local execution
errors propagate so tools can handle them. Log the intended script and
interpreter instead of the execution wrapper at INFO.

Record parsed gatekeeper decisions and failures, including revalidation
and malformed model responses. Log new SSH connections at INFO, keeping
connection reuse and authorization diagnostics at DEBUG.

Separate event names and attributes from messages. JSON records use a
top-level event and nested attributes; text records quote field values,
escape newlines, and use UTC timestamps. Update logging documentation
and tests for the event format, failure paths, and context isolation.

Fixes #620

Validation:

  • make verify: lint, formatting, and type checking pass; 826 tests pass. The six existing service-test failures are due to unavailable systemctl/journalctl in the sandbox.
  • 100% added-line coverage, including interrupts and exception groups, context isolation, nested redaction, command outcomes, and pooled SSH connection logging.
  • Regenerated tool documentation; no generated changes.

Log tool calls around authorization and execution, with a per-call UUID,
sanitized parameters, the resolved target host, and HTTP client address
and verified claims where available. Propagate this context to command,
gatekeeper, and diagnostic records, keeping concurrent calls separate.

Give local and SSH command execution the same completion event, with
elapsed time and either an exit status or an error. Let local execution
errors propagate so tools can handle them. Log the intended script and
interpreter instead of the execution wrapper at INFO.

Record parsed gatekeeper decisions and failures, including revalidation
and malformed model responses. Log new SSH connections at INFO, keeping
connection reuse and authorization diagnostics at DEBUG.

Separate event names and attributes from messages. JSON records use a
top-level event and nested attributes; text records quote field values,
escape newlines, and use UTC timestamps. Update logging documentation
and tests for the event format, failure paths, and context isolation.

Fixes #620
@owtaylor
owtaylor requested a review from a team as a code owner September 24, 2026 18:06
@owtaylor
owtaylor added this pull request to stack #624 September 24, 2026 18:07
Raise asyncio.TimeoutError in the audit timeout test, matching asyncio.wait_for. Before Python 3.11 it is distinct from the built-in TimeoutError, so the mock bypassed the timeout handler.
Python 3.10 resolves dotted mock targets through package attributes, so exported run_script and check_run_script functions shadow their modules. Import the modules explicitly and use patch.object for the audit tests.
@codecov

codecov Bot commented Sep 24, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

Flag Coverage Δ
unittests 98.34% <100.00%> (+0.19%) ⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

Files with missing lines Coverage Δ
src/linux_mcp_server/__main__.py 100.00% <100.00%> (ø)
src/linux_mcp_server/audit.py 100.00% <100.00%> (+3.67%) ⬆️
src/linux_mcp_server/auth_policy.py 82.35% <100.00%> (ø)
src/linux_mcp_server/connection/ssh.py 95.58% <100.00%> (+1.64%) ⬆️
...rc/linux_mcp_server/gatekeeper/check_run_script.py 100.00% <100.00%> (ø)
src/linux_mcp_server/gatekeeper/llm.py 100.00% <100.00%> (ø)
src/linux_mcp_server/logging_config.py 97.80% <100.00%> (+0.83%) ⬆️
src/linux_mcp_server/server.py 98.38% <100.00%> (+0.33%) ⬆️
src/linux_mcp_server/tools/logs.py 100.00% <100.00%> (ø)
src/linux_mcp_server/tools/network.py 100.00% <ø> (ø)
... and 14 more
🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@panyamkeerthana

Copy link
Copy Markdown
Contributor

Looks good! I see that sensitive fields are redacted but the full script is logged under command at INFO is that intentional?

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Fine-tune log output

2 participants