rdmsm4x-changelog-20260902-1518-ecs0lib-typed-privacy-logging
ecs0lib typed fail-closed privacy logging
Implemented and verified a typed logging API that removes private labelled values before any retained, encoded, sink, or OSLog output. This unblocks a future Tyrell logging migration without changing Tyrell or production runtime.
Scope
- Host:
rdmsm4xonly. - Repository:
/Users/richh/dev/lib/ecs0lib. - Isolated worktree:
/Users/richh/dev/_worktrees/ecs0lib-typed-privacy-logging-20260902. - Branch:
codex/ecs0-typed-privacy-logging-20260902. - Base:
90c3c6ddd6377be6012617d1934a5fbce5c028aa. - Source commit:
2fca9b6a3fcd53813f868c70f6c852c7c963ac3a. - Checkpoint commit:
812eadc0a7e5c4c387322a6d49d14d580bbb0fce. - Ticket:
SEC-20260902-02resolved; pre-existing platform defect recorded asISSUE-20260902-13.
Files changed
Sources/ECS0System/ECSPrivacyLogging.swiftSources/ECS0System/ECSUnifiedLogging.swiftTests/ECS0LibTests/ECSPrivacyLoggingTests.swiftSESSION-STATE.md/Users/richh/dev/_handoff/ecs0lib-typed-privacy-logging.md/Users/richh/.agent-coordination/checkins/codex-rdmsm4x-ecs0-typed-privacy-logging-20260902.json
The ticket tool also wrote its normal metadata and generated HTML
under /Users/richh/dev/issues/,
/Users/richh/Desktop/issues/tickets/, and
/Users/richh/dev/sites/dev.ecs0.net/wiki/issues/.
Behavior
- Added typed severity, subsystem, category, and privacy-labelled message segments.
- Added a sanitized injectable sink and Apple unified-log sink.
- Added exact and ordered minimum-severity queries.
- Preserved the legacy free-form API and equality query, marking them deprecated for privacy-sensitive consumers.
- Added tests for redaction across memory/JSON/sink, every level, exact and minimum queries, concurrency, ring eviction, and legacy behavior.
Commands and verification
swift test --filter ECSPrivacyLoggingTests: 7/7 XCTest passed.swift test --sanitize=thread: 191 XCTest plus 11 Swift Testing = 202 total, zero failures and no ThreadSanitizer data-race report.swift build -c release --product ECS0System: exit 0.- Generic macOS builds for
ecs0libandECS0System: exit 0. git diff --check: exit 0.- Redacted Gitleaks scan of the source commit: one commit, 15.43 KB, zero findings.
- Detached untouched-base reproduction confirmed that non-macOS scheme failures predate this work: ProcessRunner uses unavailable APIs, and the aggregate library also has CECSNetTopBridge/LocalAuthentication platform failures.
Preservation, rollback, and outstanding actions
- The canonical checkout's pre-existing untracked Hardware/Provenance work was not modified, staged, moved, or removed.
- No Tyrell file, production logger, log store, secret, deployment, signing state, remote branch, or public service changed.
- No backup was necessary because all source changes are isolated commits and no production state changed.
- Rollback: revert
2fca9b6a3fcd53813f868c70f6c852c7c963ac3aon a future integration branch. - Owner action: review and integrate the ecs0lib commit, address or
gate
ISSUE-20260902-13, then let the Tyrell owner perform a separatePowerGovernanceActormigration and validation.