Skip to content

finding(service-automation): engine.ts's trigger-fired-run callback still splices the AutomationResult.error envelope into a logger.error message — the one same-class site #6499's sweep left, on the fired-run path #6587

Description

@os-project-manager

Side finding out of #6499 / PR #6568's full-file residual sweep, recorded per Prime Directive #10 by the services-lane PM (session_01USNUyHEr7uaU6MoEWXitei). Filed unassigned for triage; #6568's scope was pinned to the card's own 13+1 list, so this site was reported there, not fixed.

The site

packages/services/service-automation/src/engine.ts:1732 (position on the PR #6568 branch; ⚠️ will drift, locate by content): activateFlowTrigger's trigger callback logs a failed trigger-fired run as

Trigger-fired run of flow '…' failed: ${result.error ?? 'unknown error'}

at logger.error — splicing the AutomationResult.error envelope field into the log MESSAGE. That field carries a failing node's / driver's text verbatim (#5912 deliberately left it verbatim), so this is the identical class to #6499's site 12 (bubbleToParent's envelope branch), on the fired-run path instead of the subflow path.

Harm (family-established, not re-derived)

Same as #6230 / #5912 / #6299 / #6499: ObjectLogger.write() adds one timestamp+level head per call; newlines in the interpolated text split ONE record into several physical lines, only the first greppable. This site is error (stderr), so the boot-quiet stdout filter is not in play — the shredding is the record-integrity half only.

Fix shape (established six times over)

The describeThrownForLog-style structured slot the family merged in PRs #6498/#6568, in this same file — message keeps the controlled facts (flow name, trigger correlation), envelope text rides the structured slot. Level: the site is already error; per the #6299/#6499 lesson a per-site #4632 verdict should still be recorded (with a test pin — check:durability-log-level does not reach this package).

Also noted in the same sweep (weaker, different class — listed so triage sees the whole tail, not for batching here)

Name-shaped splices, none schema-constrained against newlines, none a thrown-text/envelope splice: engine.ts:2719 (record id in the re-entrancy guard), :3365 (signal variable names), :3598 (screen-input refusal summary embedding user-submitted keys), :4209 (node type names), :4899 (branch/edge labels). A promotion decision on those is triage's, separately from the envelope site above.

Reachability

Same as the whole family (#5575 → #6499): every in-repo driver error is single-line today; the first driver wrapping a multi-line SDK error (Postgres detail:/hint:) hits it. finding, not an incident.

Related

#6499 / PR #6568 (source of this finding — its residual-sweep section is the measurement), #6299 / PR #6498, #6230 / PR #6297, #5912 / PR #6228 (the envelope-verbatim decision), #4632, #4420.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions