Skip to content

Fix: redirect Serilog output to stderr (clean stdout for diagnostic commands)

Placeholder ppxd requested to merge fix/show-thumbprint-suppress-serilog into main

Summary

  • Production fix: Serilog log lines were leaking onto stdout for diagnostic commands (show-thumbprint, show-config, list-instances, new-certificate), polluting $(...) shell captures.
  • Fix: redirect Serilog's Console sink to stderr (Unix convention: diagnostic on stderr, output on stdout).
  • One-line change: standardErrorFromLevel: LogEventLevel.Verbose parameter added to WriteTo.Console.

Why this matters

Caught by Linux D1h + Windows W-D1h E2E tests. Without this fix:

THUMBPRINT=$(squid-tentacle show-thumbprint)
# THUMBPRINT contains "[12:34:56 INF] Loading existing ...\n1A2B3C..." (broken)

Operators using shell pipelines for trust-list debugging, fleet automation, or scripting hit silent bugs.

Test plan

  • dotnet build green
  • CI: existing 172 E2E tests still pass (the defensive regex extraction in tests continues to work correctly)
  • Future: tighten D1h + W-D1h tests to assert stdout (alone) is exactly the thumbprint (separate PR after this lands)

Affected commands

Command Effect
version, show-thumbprint, show-config, list-instances, new-certificate Stdout becomes clean (only the actual value/output)
register, service install, service start/stop/uninstall Summary output (MachineId, etc.) still on stdout; log diagnostics moved to stderr
run (systemd ExecStart) systemd's journald captures both — no behavior change for operators

🤖 Generated with Claude Code

Merge request reports

Loading