Conversation
The workspace is hand-formatted and drifts from stable rustfmt; normalize so `cargo fmt --all -- --check` is green. Mechanical reformatting only — no behavior change. Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
clippy's should_implement_trait fires on the inherent `from_iter` method — implement the real trait instead. Call sites keep working via the prelude. Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
studio#29 — audit follow-up to openabdev#28. Every ECS / CloudWatch Logs boundary must receive the authoritative full service name, never a short/display selector that silently mis-matches. - oabctl::fetch_ecs_events now refuses a non-`oab-` service filter loudly (same boundary discipline as instance_status) and matches events on the full name only — the old normalize-to-bare-name comparison cross-matched same-named services in other namespaces (oab-prod-mira vs oab-dev-mira). - studio_cp::observe_events resolves a short-or-full selector via service_status → resolve_service before the logs query, so the MCP `deploy_events` contract (full name or bare agent name) is preserved. A full `oab-` name that no longer resolves still queries verbatim (deleted services keep archived events); an unknown bare selector returns empty without touching the boundary. - New `EcsObserveReads` seam — trait over the three AWS reads with an `aws_config::SdkConfig` impl — so `observe_deployment_with` / `observe_events_with` can be exercised by a recording fake asserting the exact service name reaching `instance_status`/`fetch_ecs_events`. This closes the one `observe_deployment` line not previously covered. Also satisfies workspace `clippy -D warnings` (derivable Default for FleetRuntime, `?` in role_identity, allow too_many_arguments for the flat dispatch-arg API) and reformats touched files. Other ECS boundaries audited: apply/scale/delete/driver all build `oab-{ns}-{name}` from manifest or config before any ECS call — verified. Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Refs #29
Summary
Audit follow-up to #28: every ECS / CloudWatch Logs boundary now receives the
authoritative full service name
oab-{ns}-{name}— never a caller'sshort/display selector.
oabctl::fetch_ecs_eventsrefuses a non-oab-service filter loudly(same boundary discipline as
instance_status) and filters events on exactfull-name match only. The old normalize-to-bare-name comparison let
oab-prod-miraevents match adevquery — a cross-namespace leak.studio_cp::observe_eventsresolves the caller's short-or-full selectorthrough
service_status/resolve_serviceand passes the resolvedsvc.service_nameto the logs filter — preserving the documented MCPdeploy_eventscontract (full name or bare agent name). Fulloab-namesthat no longer resolve still query verbatim (deleted services keep archived
events); unknown bare selectors return empty without touching the boundary.
EcsObserveReadsseam — a trait over the three AWS reads with anaws_config::SdkConfigimpl — letsobserve_deployment_with/observe_events_withbe exercised by a recording fake asserting the exactservice name reaching
instance_status/fetch_ecs_events. This covers thepreviously untested
observe_deploymentdispatch line.Audit of remaining ECS service-selector boundaries
apply/scale/delete/driverall buildoab-{ns}-{name}from themanifest or fleet config before any ECS call;
status.rsalready carries theECS-returned
service_name(#28). No other boundary accepts a short selector.Gate-driven cleanups (no behavior change)
cargo fmt --allnormalization — the workspace was hand-formatted; theenforced profile requires
cargo fmt --all -- --checkgreen. Isolated inthe first commit for easy review skipping.
FromIteratorforSkillsLibrary,#[derive(Default)]onFleetRuntime,?inrole_identity, crate-leveltoo_many_argumentsallow — satisfycargo clippy --workspace --all-targets -- -D warningson stable 1.98.Test plan
cargo test --workspace— 6 newecs_boundary+ 1events_boundaryintegration tests pin the full-name-at-boundary contract
cargo fmt --all -- --checkcargo clippy --workspace --all-targets -- -D warningsGenerated with Devin