Vouch request: mdabydeen #4004
mdabydeen
started this conversation in
Vouch Request
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
What do you want to work on?
Hi, I'd like to pick up #3886. I already have a fix ready and tested in PR #4001.
The bug that I found is in the OCSF shorthand formatter, where
severity_tag()gives an Unknown (0) and Other (99) the same[INFO]tag as Informational. So inopenshell.log, an event that nobody assigned a severity to looks the same as one someone marked informational. I noticed because two other helpers in the same file already print those two values as blank. severity_tag was the only one that didn't.My proposed fix is 0 and 99 now get their own
[UNK]tag.[INFO]through[FATAL]stay the same. I also added a test for the mapping. It's one function incrates/openshell-ocsf, andcargo test,clippyandrustfmtall pass for that crate.The risk seems low. This only changes what's displayed, and the JSONL still has the correct severity_id. It just keeps the human-readable audit log from showing the wrong severity for an event.
Happy to change the tag text if you'd like something other than [UNK].
Why this change?
The shorthand log is what people actually read during an incident or an audit. So it should show the difference between "someone rated this event informational" and "nobody rated this event at all". Right now it doesn't. Unknown (0), Other (99) and Informational (1) all come out as [INFO].
That matters for two reasons:
[UNK]keeps the tag the same width and shape as the others while making the gap visible. The JSONL output doesn't change and still carries the correct severity_id, so nothing downstream that parses it is affected.Checklist
All reactions