fix(observability): name the module on the chain-request lines - #376
Merged
Merged
Conversation
Four tracing sites in the chain host call named no module, so the two that print at the default level said a read was denied or a response was capped without saying whose. nexum_runtime_chain_request_total carries no module label either, which left the denied-read-surface signal docs/production.md sells as an alert undiagnosable from telemetry alone. check_response_cap gains the module rather than reading it from a span: the guest init path calls into the same host seams and runs inside no span at all. Also fix the runbook query, which filtered on .fields.module while the JSON layer sets flatten_event, so event fields sit at the top level and there is no .fields object. It matched nothing on every line. AI Assistance: claude-opus-5 used for the fix, after a four-lens review of the span approach it replaces.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Four tracing sites in the chain host call now name the module: the response-cap refusal, the denied-method refusal, and the two
chain::requestlines below the default level.check_response_captakes the module rather than deriving it, since it is a free function.The runbook query in
docs/production.mdis fixed. It filtered on.fields.module, butcrates/nexum-launch/src/lib.rssetsflatten_event(true), so event fields sit at the top level and there is no.fieldsobject. The published command matched nothing on every line.Why
Two of the four print at the default
log_level = "info"and are the only lines that answer "which module".nexum_runtime_chain_request_totalcarrieschain_id,methodandoutcomebut nomodulelabel, anddocs/production.mdsellsmethod="<denied>"as the signal that a module is reaching outside the read surface. Neither the counter nor the log line named which one, so that alert was undiagnosable from telemetry alone. Same hole onnexum_runtime_chain_response_capped_total.The runbook fix is unrelated and pre-existing. It is here because it is one line and was found in the same review.
Why not a span
#373 proposed a
dispatchspan carrying the module, and is closed unmerged. Four lenses agreed it did not earn the change: every tracing site insupervisor/dispatch.rsalready carriesmodule, as do the guest-mirror sites, the http gate and the store error path, so the span would have duplicated a field already on the line. It carried no span id, so it did not distinguish two concurrent dispatches of one module either. These four sites were its entire verified benefit.Passing the field also covers a case the span could not:
instantiate_moduleruns guestinitinside no span, and a host call made frominitreaches these same seams.Testing
cargo nextest run -p nexum-runtime-wasm --all-features --locked: 28 passed. Clippy over the crate with-D warningsclean,cargo fmt --all --checkclean,content-lint.shok,just buildgreen.AI Assistance
Review by four claude-opus-5 lenses; fix and PR description by claude-opus-5.