Repository navigation
runtime errorの送信をLattice自身が持つ(ADR 0193、0.74.0) - #10
Merged
Merged
Conversation
…・ADRは未) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
オーナーの裁定で、エラーを上げるのは各プロダクトの責務になった。これまで工場(dotagents)のreportが 運んでいたLatticeのruntime error記録を、Lattice自身がBugHubの製品報告の受け口へ送る。 - 既定では通信しない。`runtime-errors reporting enable` を打ち、BugHubの持ち主が合鍵のfileを置いた 端末だけが送る。どちらかが欠ければnetworkへ触れない。dotagentsの設定は送信の判断に使わない。 - 合鍵のfileは本人所有・0600・symlinkでない形だけを使う。秘密は通信に載せず、送るバイト列と時刻への HMAC-SHA256署名を付ける。 - 受領済み(storeのack)にするのは、200・accepted・report_id一致・応答の署名一致がそろった時だけ。 そろわなければ未受領のまま残し、後から新しいreport_idでその時点の累計を送り直す。 - 送る時機: 故障を記録した直後と、以後のCLI実行(hooksを除く)の終わりに、切り離した子processで送る。 1分に1回まで、同じ中身の送り直しは1時間に1回まで。 - 送信を有効にした端末では、工場の設定が無くても収集が有効になる。 - 製品試験の環境は `LATTICE_RUNTIME_ERROR_REPORTING=0` を持つ(runnerは利用者の本物のHOMEで走る)。 署名と応答の署名は、BugHubの契約の試験値と一致する。 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
何を変えるか
オーナーの裁定で、エラーを上げるのは各プロダクトの責務になった。これまで工場(dotagents)のreportが運んでいたLatticeのruntime error記録を、Lattice自身がBugHubの製品報告の受け口へ送る。受け口の契約はBugHubの持ち主(フラジャイル)が決めたもの。
既定では通信しない
送るのは、次の2つがそろった端末だけ。どちらかが欠ければnetworkへ触れない。
lattice runtime-errors reporting enable --jsonを打った(設定は~/.config/lattice/runtime-error-reporting.json)。~/.config/bughub/product-credentials/lattice.json)を置いた。設定を変えていない端末の動きは今までと同じ。
中身
src/runtime-error-reporting.mjs: 合鍵の読み取り(本人所有・0600・symlinkでない形だけ)、署名、本文、送信、受領の確認、時機の制限。accepted: true・report_id一致・応答の署名一致がそろった時だけ。そろわなければ未受領のまま残し、後から送り直す。hooksを除く)の終わりに、切り離した子processで送る。CLIの応答は待たせない。1分に1回まで、同じ中身の送り直しは1時間に1回まで。unsupportedと答える。LATTICE_RUNTIME_ERROR_REPORTING=0を持つ。CIのrunnerは利用者の本物のHOMEで走るので、試験がその端末の設定を拾って送らないようにする。試験
test/runtime-error-reporting.test.mjs(手元のHTTP serverを受け口の代わりにする)report_id・accepted: false・5xx・時間切れでは、ackが進まない。手元のroot側の試験: 1950件中1914成功、0失敗(36はOS限定のskip)。
公開
公開と端末への適用は、オーナーへ伺ってから行う。BugHub側の受け口と合鍵の配置が入るまで、どの端末からも送らない。
🤖 Generated with Claude Code