Skip to content

fix(observe): key every ECS/logs query on the full oab-{ns}-{name} name - #163

Open
Reese-max wants to merge 3 commits into
openabdev:mainfrom
Reese-max:devin/issue-29
Open

Reese-max wants to merge 3 commits into
openabdev:mainfrom
Reese-max:devin/issue-29

Conversation

@Reese-max

Copy link
Copy Markdown

Refs #29

Summary

Audit follow-up to #28: every ECS / CloudWatch Logs boundary now receives the
authoritative full service name oab-{ns}-{name} — never a caller's
short/display selector.

  • oabctl::fetch_ecs_events refuses a non-oab- service filter loudly
    (same boundary discipline as instance_status) and filters events on exact
    full-name match only. The old normalize-to-bare-name comparison let
    oab-prod-mira events match a dev query — a cross-namespace leak.
  • studio_cp::observe_events resolves the caller's short-or-full selector
    through service_status/resolve_service and passes the resolved
    svc.service_name to the logs filter — preserving the documented MCP
    deploy_events contract (full name or bare agent name). Full oab- names
    that no longer resolve still query verbatim (deleted services keep archived
    events); unknown bare selectors return empty without touching the boundary.
  • New EcsObserveReads seam — a trait over the three AWS reads with an
    aws_config::SdkConfig impl — lets observe_deployment_with /
    observe_events_with be exercised by a recording fake asserting the exact
    service name reaching instance_status/fetch_ecs_events. This covers the
    previously untested observe_deployment dispatch line.

Audit of remaining ECS service-selector boundaries

apply / scale / delete / driver all build oab-{ns}-{name} from the
manifest or fleet config before any ECS call; status.rs already carries the
ECS-returned service_name (#28). No other boundary accepts a short selector.

Gate-driven cleanups (no behavior change)

  • cargo fmt --all normalization — the workspace was hand-formatted; the
    enforced profile requires cargo fmt --all -- --check green. Isolated in
    the first commit for easy review skipping.
  • FromIterator for SkillsLibrary, #[derive(Default)] on FleetRuntime,
    ? in role_identity, crate-level too_many_arguments allow — satisfy
    cargo clippy --workspace --all-targets -- -D warnings on stable 1.98.

Test plan

  • cargo test --workspace — 6 new ecs_boundary + 1 events_boundary
    integration tests pin the full-name-at-boundary contract
  • cargo fmt --all -- --check
  • cargo clippy --workspace --all-targets -- -D warnings

Generated with Devin

cognition-team and others added 3 commits September 30, 2026 15:40
The workspace is hand-formatted and drifts from stable rustfmt; normalize
so `cargo fmt --all -- --check` is green. Mechanical reformatting only —
no behavior change.

Generated with [Devin](https://devin.ai)

Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
clippy's should_implement_trait fires on the inherent `from_iter` method —
implement the real trait instead. Call sites keep working via the prelude.

Generated with [Devin](https://devin.ai)

Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
studio#29 — audit follow-up to openabdev#28. Every ECS / CloudWatch Logs boundary
must receive the authoritative full service name, never a short/display
selector that silently mis-matches.

- oabctl::fetch_ecs_events now refuses a non-`oab-` service filter loudly
  (same boundary discipline as instance_status) and matches events on the
  full name only — the old normalize-to-bare-name comparison cross-matched
  same-named services in other namespaces (oab-prod-mira vs oab-dev-mira).
- studio_cp::observe_events resolves a short-or-full selector via
  service_status → resolve_service before the logs query, so the MCP
  `deploy_events` contract (full name or bare agent name) is preserved.
  A full `oab-` name that no longer resolves still queries verbatim
  (deleted services keep archived events); an unknown bare selector
  returns empty without touching the boundary.
- New `EcsObserveReads` seam — trait over the three AWS reads with an
  `aws_config::SdkConfig` impl — so `observe_deployment_with` /
  `observe_events_with` can be exercised by a recording fake asserting the
  exact service name reaching `instance_status`/`fetch_ecs_events`.
  This closes the one `observe_deployment` line not previously covered.

Also satisfies workspace `clippy -D warnings` (derivable Default for
FleetRuntime, `?` in role_identity, allow too_many_arguments for the flat
dispatch-arg API) and reformats touched files.

Other ECS boundaries audited: apply/scale/delete/driver all build
`oab-{ns}-{name}` from manifest or config before any ECS call — verified.

Generated with [Devin](https://devin.ai)

Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants