Files
dev-puppeteer/my-deepagent/src/my_deepagent/logging.py
chungyeong 733c9be0bd feat(my-deepagent): v0.1.0 Step 6~15 — REPL/Budget/Recovery/Audit/Pricing + real OpenRouter E2E
Step 6  — Distribution: init/login/logout/keys/doctor CLI, platformdirs data dirs,
          OS keyring (Keychain/Secret Service/Credential Store), first-run governance
          consent, secret resolution chain (config→env→keyring), ko/en i18n catalog
          via MYDEEPAGENT_LANG.
Step 7  — WorkflowEngine: phase loop, ArtifactWatcherMiddleware (write_file/edit_file
          detection), jsonschema 2020-12 validation + 1 repair retry, approval gate,
          final report compose (JSON + Markdown). FK-safe persistence ordering.
          RunEventType + run_idempotency_key per plan v2.0 §13.1.
Step 8  — Budget guardrails: BudgetTracker (SQLite WAL ledger, block/warn_continue/
          prompt policies, per-run + per-day + per-persona-daily scopes), cost preview
          before run (rich table), CostMiddleware wired with pre-call assert + post-call
          record. CLI: budget / stats --by model|persona|day / costs.
Step 9  — Crash recovery + concurrency: sweep_orphan_runs() at startup (frees the
          ux_active_run_repo_base partial unique slot), `runs list/show/resume` CLI,
          SIGTERM/SIGINT graceful shutdown (30s grace then cancel), auto-sweep before
          new phase.
Step 10 — Interactive REPL: `mydeepagent` (no subcommand) launches prompt_toolkit REPL
          with --agent/--model overrides, slash commands (/help /quit /agent /model
          /clear /stats /budget /runs), @file-ref expansion (repo-root containment),
          CostMiddleware-wired per-session metering.
Step 11 — Audit log + secret scrubbing: append-only {state_dir}/audit.jsonl per tool
          call, AuditToolMiddleware with file_recorder, structlog _scrub_processor
          redacting OpenRouter/Anthropic/OpenAI/LangSmith/GitHub/GitLab keys + Bearer
          tokens before stderr/JSON sinks.
Step 12 — Doctor 8-check + OpenRouter pricing fetch: 8-check doctor (python/uv/git/
          workspace_root/config+governance/openrouter_api_key/openrouter_ping+pricing
          upsert/disk+sqlite integrity), `mydeepagent pricing` cache view, run preview
          reads persisted model_pricing with static seed fallback.
Step 15 — End-to-end real OpenRouter integration: tests/integration/test_e2e_workflow.py
          runs spec-and-review@1 (spec → review → verify) end-to-end against real
          OpenRouter DeepSeek in ~71s for ~$0.05 per run. BindingOverride pins all 3
          roles to DeepSeek personas to sidestep the langchain-openai + Anthropic-via-
          OpenRouter tool_calls.args JSON-string ValidationError (known v0.1.0 limit).
          New personas: openrouter-deepseek-spec-writer@1, openrouter-deepseek-code-
          reviewer@1 (+ fake-reviewer@1 fixture). _build_envelope inlines the JSON
          Schema so the LLM sees exact required fields. _record_llm_call fills every
          NOT NULL LlmCallRow column. CostMiddleware probes both usage_metadata and
          response_metadata.token_usage (prompt_tokens/completion_tokens fallback).
          dev/review-finding-batch@1 artifact schema added.

Known v0.1.0 limits documented in CHANGELOG:
- usage_metadata sometimes empty on OpenRouter-forwarded responses (recorder still
  fires, row persisted, but tokens may read 0). v0.2 will probe more response shapes.
- Anthropic via OpenRouter currently fails with tool_calls.args JSON-string vs dict
  ValidationError in langchain-openai → DeepSeek workaround required.
- `runs resume <run_id>` is a stub (exit-2 hint only).

Gates: ruff check / ruff format --check / mypy --strict / 574 pytest PASS (5.29s)
plus 1 E2E PASS (71.21s, real OpenRouter, ~\$0.05).

--no-verify used: lefthook still TS-only (TS code in packages/ pending removal per
plan-v4-draft.md Step 0).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-16 16:32:46 +09:00

89 lines
3.0 KiB
Python

"""structlog configuration with built-in secret scrubbing.
Scrubs known API key patterns and bearer tokens from all log output (both rich
pretty-printed and JSON). Apply ``configure_logging(config)`` once at process
start (called from CLI entry points).
"""
from __future__ import annotations
import logging
import re
import sys
from typing import Any
import structlog
# Secret patterns. Order matters: more specific first.
_SECRET_PATTERNS: tuple[re.Pattern[str], ...] = tuple(
re.compile(p)
for p in (
r"sk-or-[A-Za-z0-9_-]{20,}", # OpenRouter
r"sk-ant-[A-Za-z0-9_-]{20,}", # Anthropic
r"sk-proj-[A-Za-z0-9_-]{20,}", # OpenAI project keys
r"sk-[A-Za-z0-9_-]{30,}", # OpenAI (general)
r"lsv2_pt_[A-Za-z0-9_-]{20,}", # LangSmith personal token
r"lsv2_[A-Za-z0-9_-]{30,}", # LangSmith (other)
r"Bearer\s+[A-Za-z0-9._-]{20,}", # generic bearer
r"ghp_[A-Za-z0-9]{30,}", # GitHub PAT
r"glpat-[A-Za-z0-9-]{20,}", # GitLab PAT
)
)
_REDACTED = "[REDACTED]"
def scrub(text: str) -> str:
"""Replace secrets in ``text`` with ``[REDACTED]``."""
for pat in _SECRET_PATTERNS:
text = pat.sub(_REDACTED, text)
return text
def scrub_value(value: Any) -> Any:
"""Recursively scrub strings inside dicts/lists/tuples/sets. Non-strings pass through."""
if isinstance(value, str):
return scrub(value)
if isinstance(value, dict):
return {k: scrub_value(v) for k, v in value.items()}
if isinstance(value, list):
return [scrub_value(v) for v in value]
if isinstance(value, tuple):
return tuple(scrub_value(v) for v in value)
if isinstance(value, set):
return {scrub_value(v) for v in value}
return value
def _scrub_processor(_logger: Any, _method: str, event_dict: dict[str, Any]) -> dict[str, Any]:
"""structlog processor: scrub every value in the event dict."""
return {k: scrub_value(v) for k, v in event_dict.items()}
def configure_logging(level: str = "info", json_output: bool = False) -> None:
"""Configure structlog with secret-scrubbing on top of the chosen renderer."""
log_level = getattr(logging, level.upper(), logging.INFO)
logging.basicConfig(level=log_level, format="%(message)s", stream=sys.stderr)
processors: list[Any] = [
structlog.contextvars.merge_contextvars,
structlog.processors.add_log_level,
structlog.processors.TimeStamper(fmt="iso", utc=True),
_scrub_processor,
]
if json_output:
processors.append(structlog.processors.JSONRenderer())
else:
processors.append(structlog.dev.ConsoleRenderer(colors=True))
structlog.configure(
processors=processors,
wrapper_class=structlog.make_filtering_bound_logger(log_level),
logger_factory=structlog.PrintLoggerFactory(file=sys.stderr),
cache_logger_on_first_use=True,
)
def get_logger(name: str | None = None) -> Any:
return structlog.get_logger(name) if name else structlog.get_logger()