All files / core/semantic-log/src render.ts

92.51% Statements 445/481
100% Branches 119/119
73.33% Functions 22/30
92.51% Lines 445/481

Press n or j to go to the next uncovered block, b, p or k for the previous block.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 277 278 279 280 281 282 283 284 285 286 287 288 289 290 291 292 293 294 295 296 297 298 299 300 301 302 303 304 305 306 307 308 309 310 311 312 313 314 315 316 317 318 319 320 321 322 323 324 325 326 327 328 329 330 331 332 333 334 335 336 337 338 339 340 341 342 343 344 345 346 347 348 349 350 351 352 353 354 355 356 357 358 359 360 361 362 363 364 365 366 367 368 369 370 371 372 373 374 375 376 377 378 379 380 381 382 383 384 385 386 387 388 389 390 391 392 393 394 395 396 397 398 399 400 401 402 403 404 405 406 407 408 409 410 411 412 413 414 415 416 417 418 419 420 421 422 423 424 425 426 427 428 429 430 431 432 433 434 435 436 437 438 439 440 441 442 443 444 445 446 447 448 449 450 451 452 453 454 455 456 457 458 459 460 461 462 463 464 465 466 467 468 469 470 471 472 473 474 475 476 477 478 479 480 481 4821x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 86436x 86436x 86436x 1x 15024x 15024x 15024x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 15028x 15028x 15028x 1x 1x 15024x 15024x 15024x 15019x 15019x 15024x 4156x 4156x 15024x 13884x 13884x 13884x     13884x 13884x 13884x 13884x 15024x 15024x 1x 1x 15028x 15028x 15028x 2x 15026x 15028x         15028x                               4137x 4137x 4137x 4137x 4000x 4000x 4000x 4137x 15028x 15025x 15025x 15025x 15025x 15025x 15025x 15025x 15025x 15028x 15024x 15024x 15024x 1x 1x 788x 788x 788x 1x 537x 537x 3x 3x 3x 3x 1x 1x 24241x 24241x 24241x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 28404x 26835x 28390x 28404x 3x 3x 28404x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 133x 133x 133x 133x 133x 1x 1x 1x 1x 1x 1x 1x 1x 1x 45x 45x 45x 45x 4x 4x 45x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 9x 9x 9x 9x 9x 9x     9x 9x 9x 9x 9x 9x 9x 9x 9x 9x 9x 9x 9x 9x 9x 9x 9x 9x 1x 1x 4x 4x 4x 4x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 5x 5x 5x 5x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 15028x 2x           15028x 15028x 15028x 15028x 15028x 257x 257x 257x 257x 15028x 280x 280x 280x 280x 280x 15028x                 113x 113x 113x 113x 113x 113x 113x 115x 15028x 136x 136x 136x 133x 3x 136x 136x 15026x 14997x 14997x 14997x 14997x 14997x 14997x 14997x 24241x 24238x 24241x 24241x 24241x 24241x 24241x 24241x 24241x 24241x 24241x 24241x 24241x 24241x 24241x 24241x 24241x 24241x 24241x 73x 24165x 24241x 24241x 14996x 15023x 15028x 5x 5x 15028x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 37x 37x 37x 854x 1x 1x 854x 722x 722x 854x 39x 39x 854x 1x 1x 130x 130x 130x 37x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 1x 37x 37x 37x 4x 4x 37x  
/**
 * Standard rendered format (PRD R20) and the reference rendering (PRD R19).
 *
 * The header is always exactly one line. It is compact by default: the service
 * name, the version and the base fields are all on the record, but the line does
 * not repeat them, because the deployment that reads it is a Kubernetes pod
 * whose identity the reader already knows from where the line came.
 * `RenderOptions.details` puts them back. Optional detail is indented beneath
 * the header; it is rendered as labelled structured lines — never a raw object
 * dump — because the spec's acceptance criteria say so in as many words.
 *
 * Rendering is a pure read: the record is never mutated, so a caller may cache
 * a record and render it more than once.
 */
 
import {LEVELS, levelName, levelValue, type LevelName} from './level.ts';
import type {Decision, LogRecord} from './record.ts';
import {PAYLOAD_THRESHOLD, encodeSegment, refUri} from './refs.ts';
 
export interface RenderOptions {
    /** ANSI colour. Defaults to false so tests and pipes get plain text. */
    color?: boolean;
    /** Injectable clock for deterministic tests. */
    formatTime?: (time: number) => string;
    /**
     * Print the identity details the human line leaves out by default: the
     * service name and the `version=` token. The base fields (`pid`, `hostname`)
     * follow the record's own `fields`, so they are printed when, and only when,
     * the record carries them — which is what `LoggerOptions.details` decides.
     *
     * Off by default: the pod that reads these lines is already named by where
     * the line came from, so repeating it costs width and buys nothing. The
     * record always carries all of them (JSON mode, the retained store, the
     * cluster service), so this changes the human line alone. The inspector opts
     * in, because printing one record on demand is the case where knowing which
     * service emitted it is the point (R20).
     *
     * One line ignores the flag: the salvage a failed render falls back to always
     * names the service, because a line that exists only because rendering broke
     * is worth nothing if the reader cannot tell which process produced it.
     */
    details?: boolean;
}
 
const ANSI = {
    reset: '\u001B[0m',
    dim: '\u001B[2m',
    red: '\u001B[31m',
    green: '\u001B[32m',
    greenBright: '\u001B[92m',
    yellow: '\u001B[33m',
    blue: '\u001B[34m',
    magenta: '\u001B[35m',
    cyan: '\u001B[36m',
    gray: '\u001B[90m',
} as const;
 
const LEVEL_COLOR: Record<number, string> = {
    10: ANSI.dim,
    20: ANSI.blue,
    30: ANSI.green,
    40: ANSI.yellow,
    50: ANSI.red,
    60: ANSI.red,
};
 
/** Shown when the timestamp cannot be rendered as an instant. */
const TIME_WITHHELD = '[time withheld]';
 
/** Shown when the message cannot even be turned into a string. */
const UNREADABLE = '[unreadable]';
 
/** C0 controls and DEL: every character that could carry line or terminal structure. */
const CONTROL_CHARS = /[\u0000-\u001F\u007F]/g;
 
/**
 * Replace the characters that carry line or terminal structure with spaces.
 *
 * The header must be exactly one line (PRD R20), and an indented detail line
 * must not be able to forge another line. Both are built from caller-supplied
 * text — the message, a field key or value, a request target, an error message,
 * a trace-derived label — and a `\n` in any of them would start a new,
 * unindented line that a reader or a fixed-pattern extractor cannot tell from a
 * real one. C0 also covers `\u001B`, so a value cannot inject terminal colour
 * or an OSC 8 sequence into the rendered form either.
 *
 * Every part of the rendered form passes through here, the error block's stack
 * frames included, so the guarantee is about the whole rendered record rather
 * than the header alone.
 *
 * The value is not assumed to be a string: a redaction pattern can replace a
 * structured slot with the `[redacted]` placeholder, so a later read may find a
 * scalar where the type says `FlowState`. Coercing first keeps those records
 * rendering (as they did through the interpolation this replaced) instead of
 * dropping the whole record to the last-resort line.
 */
function sanitise(value: unknown): string {
    return String(value).replace(CONTROL_CHARS, ' ');
}
 
function defaultFormatTime(time: number): string {
    return new Date(time).toISOString();
}
 
/**
 * Format a record's timestamp without assuming the slot still holds an instant.
 *
 * A configured `redact` pattern can replace `time` with the `[redacted]`
 * placeholder (or collapse the whole record with `**`), and
 * `new Date('[redacted]').toISOString()` throws a `RangeError` out of the log
 * call. A non-finite value is shown as an explicit marker rather than a
 * silently wrong date; a real instant is handed to the configured formatter
 * unchanged, so a record that was not redacted renders exactly as before.
 */
function renderTime(time: unknown, format: (time: number) => string): string {
    return typeof time === 'number' && Number.isFinite(time) ? format(time) : TIME_WITHHELD;
}
 
/** Render the references as a fixed-shape, greppable trailing group. */
function renderRefs(record: LogRecord): string {
    const parts = [`r=${refUri('record', record.refs.record)}`];
    if (record.refs.template) {
        parts.push(`t=${refUri('template', record.refs.template)}`);
    }
    if (record.refs.trace) {
        parts.push(`x=${refUri('trace', record.refs.trace)}`);
    }
    if (record.refs.parent) {
        // Deliberately the bare id rather than a `semantic-log://record/...`
        // URI — the reference group is grep-shaped and the parent is a link
        // *within* the r= family — but the id is still untrusted text when the
        // record is re-rendered from a store, so it goes through the same
        // encoder the URIs use. Without it a `refs.parent` of
        // `x] [r=semantic-log://record/ATTACKER` would close the group and forge
        // a reference (see `refs.ts`).
        parts.push(`p=${encodeSegment(record.refs.parent)}`);
    }
    return `[${parts.join(' ')}]`;
}
 
/** The single-line header: time, level, service, correlators, message, refs. */
function header(record: LogRecord, options: RenderOptions): string {
    const formatTime = options.formatTime ?? defaultFormatTime;
    const paint = options.color
        ? (code: string, text: string): string => `${code}${text}${ANSI.reset}`
        : (_code: string, text: string): string => text;
    const parts = [
        renderTime(record.time, formatTime),
        paint(LEVEL_COLOR[record.level] ?? '', levelName(record.level).padEnd(5)),
    ];
    // The service name is the first of R20's identity details, printed only when
    // they were asked for. Everything a line needs to be greppable without them
    // is below: level, context, message id, operation and the message.
    if (options.details) parts.push(paint(ANSI.cyan, sanitise(record.service)));
    if (record.context) parts.push(sanitise(record.context));
    if (record.fields?.context)
        parts.push(paint(ANSI.greenBright, sanitise(record.fields?.context)));
    if (record.messageId) parts.push(paint(ANSI.magenta, sanitise(record.messageId)));
    if (record.operation) parts.push(paint(ANSI.yellow, sanitise(record.operation)));
    if (record.flow) {
        const index = record.flow.index ?? -1;
        parts.push(
            `flow=${sanitise(record.flow.id)}/${sanitise(record.flow.step ?? '-')}#${index}`,
        );
        // The leg (PRD R22) follows the position it belongs to, as a token of its
        // own: `flow=<id>/<step>#<index>` stays exactly what it was, so a reader or a
        // test parsing the position is unaffected by a record that also names the
        // call it is part of. Its position in the execution rides the same token
        // (`leg=<id>#<seq>`), the way the flow's position rides the flow token, so
        // two lines of one execution can be ordered by reading them.
        if (record.flow.leg) {
            const seq = record.flow.legSeq === undefined ? '' : `#${sanitise(record.flow.legSeq)}`;
            parts.push(`leg=${sanitise(record.flow.leg)}${seq}`);
        }
    }
    if (record.intent) parts.push(`intent=${sanitise(record.intent.name)}`);
    parts.push(paint(ANSI.cyan, sanitise(record.msg)));
    // The version of the base fields rides the header too, under the same flag as
    // the service it belongs with (§5.1 "Base fields (pid, hostname, service,
    // version)"). It is placed *after* R20's normative details — timestamp,
    // level, context, message id, operation, message — so that order stays intact
    // whenever the details are asked for, and before the reference group, which
    // stays last. `version=` rather than a bare token keeps it distinct from the
    // message it follows.
    if (options.details && record.version) parts.push(`version=${sanitise(record.version)}`);
    parts.push(paint(ANSI.gray, renderRefs(record)));
    return parts.filter(Boolean).join(' ');
}
 
/** An indented detail line: two-space block indent, label, two-space gap. */
function blockLine(label: string, text: string): string {
    return `  ${label}  ${text}`;
}
 
function keyValues(prefix: string, values: Record<string, string> | undefined): string[] {
    if (!values) return [];
    return Object.entries(values).map(
        ([key, value]) => `${prefix}${sanitise(key)}: ${sanitise(value)}`,
    );
}
 
/** Values that have no meaningful text form in a log line. */
function isSkippedField(value: unknown): boolean {
    return value === undefined || typeof value === 'function' || typeof value === 'symbol';
}
 
/**
 * Serialise one field value without ever throwing: `JSON.stringify` rejects
 * circular structures and `BigInt`, and returns `undefined` for a value with
 * no text form, which would print the literal text `undefined`. Callers skip
 * such values first; anything that still fails survives as an explicit marker
 * so a single field can never lose the rest of the record.
 *
 * Exported because the logger must judge a field's size by exactly the text this
 * renderer will produce (PRD R19/R20): the decision to retain a payload and the
 * decision to render its reference are the two halves of one threshold, and
 * measuring them with two different serialisations is how they would drift.
 */
export function renderField(value: unknown): string {
    if (typeof value === 'string') return value;
    try {
        return JSON.stringify(value) ?? '[unserializable]';
    } catch {
        return '[unserializable]';
    }
}
 
/**
 * Render a rationale that redaction may have collapsed.
 *
 * A configured pattern can replace the whole `decision` slot with the
 * `[redacted]` placeholder (`decision`, `**`) or only its candidate list
 * (`decision.candidates`, `decision.*`) with that string, so the value here is
 * not necessarily a `Decision` even though the type says so. This guard mirrors
 * `serializeForIdentity`'s: the discriminator and chosen branch still render,
 * and a candidate list that is no longer an array is omitted rather than
 * calling `.join` on a string. A wholly collapsed slot keeps its placeholder
 * text (handled by the caller), so the withheld rationale stays visible.
 */
function decisionDetail(decision: Decision): string {
    const {discriminator, chosen, candidates} = decision;
    const head = `${discriminator} -> ${chosen}`;
    return Array.isArray(candidates) ? `${head} (of ${candidates.join(', ')})` : head;
}
 
/**
 * Read one slot without letting a throw escape.
 *
 * This exists for the last-resort reconstruction below, which runs only because
 * rendering already threw once: a value that broke `JSON.stringify` may be a
 * getter that throws on access, so every read on this path is guarded. It is a
 * property of the fallback itself, not a guard repeated at each call site.
 */
function guardedRead<T>(source: () => T, fallback: T): T {
    try {
        return source();
    } catch {
        return fallback;
    }
}
 
/**
 * Rebuild the smallest readable form of a record.
 *
 * A record that defeated the ordinary render is still a record: a process
 * failure must be reported rather than lost because one value in it was
 * hostile. Every slot is read behind `guardedRead` and coerced to a string, so
 * the result is built from primitives alone and cannot fail again — not while
 * it is assembled and not when it is serialised.
 */
/**
 * Resolve the numeric level of a salvage payload.
 *
 * A normal record stores the number in `level` and its name in `levelName`, and
 * the payload has to match that shape: a consumer parsing `level` as a number
 * must not be handed the name. A `redact` pattern can replace the slot with the
 * `[redacted]` placeholder, so the value is not assumed to be a level at all —
 * anything that does not resolve to a finite number is reported as `info`.
 */
function salvageLevel(value: unknown): number {
    const resolved: unknown = guardedRead(
        () => levelValue(value as LevelName | number),
        LEVELS.info,
    );
    return typeof resolved === 'number' && Number.isFinite(resolved) ? resolved : LEVELS.info;
}

function salvage(record: LogRecord): {
    id: string;
    time: string;
    level: number;
    levelName: string;
    service: string;
    msg: string;
} {
    const level = salvageLevel(record.level);
    return {
        id: guardedRead(() => String(record.id), ''),
        time: guardedRead(() => new Date(record.time).toISOString(), TIME_WITHHELD),
        level,
        levelName: levelName(level),
        service: guardedRead(() => String(record.service), ''),
        msg: guardedRead(() => String(record.msg), UNREADABLE),
    };
}
 
/** A one-line JSON object rebuilt from primitives, so serialising it cannot fail. */
function salvageJson(record: LogRecord): string {
    const {id, time, level, levelName, service, msg} = salvage(record);
    return JSON.stringify({id, time, level, levelName, service, msg, refs: {record: id}});
}
 
/**
 * One greppable line rebuilt from primitives, so assembling it cannot fail.
 *
 * Unlike the header it stands in for, this line always names the service. The
 * compact default exists because a routine line's reader already knows which pod
 * it came from; a line produced *because rendering failed* is the one case where
 * that is exactly what the reader does not know, and a salvage nobody can
 * attribute is a salvage that did not work.
 *
 * `service` and `msg` are caller text and pass through `sanitise` here too: a
 * newline in either would split the salvaged line, which is the one thing the
 * salvage exists to avoid — the whole record would then be read as a record
 * that is not one.
 */
function salvageHuman(record: LogRecord): string {
    const {id, time, levelName, service, msg} = salvage(record);
    return `${time} ${levelName.padEnd(5)} ${sanitise(service)} ${sanitise(msg)} [r=${refUri('record', id)}]`;
}
 
/**
 * Render a record for a human reading a terminal.
 *
 * Total by construction: the header, the labelled blocks and the field lines
 * are each built from values the caller may have supplied, and any one of them
 * can throw (`new Date(1e30).toISOString()`, a `toJSON` that throws, a getter on
 * the fields bag). A logging call that throws defeats the log — in JSON mode
 * `fatal` is what the process-failure hooks call, so a throw there escapes the
 * `uncaughtException` listener and aborts Node instead of reporting it. The one
 * boundary here therefore catches whatever the render attempts and falls back
 * to a minimal reconstructed line, rather than a guard beside every read.
 */
export function renderHuman(record: LogRecord, options: RenderOptions = {}): string {
    const paint = options.color
        ? (code: string, text: string): string => `${code}${text}${ANSI.reset}`
        : (_code: string, text: string): string => text;
    try {
        const resolved: RenderOptions = {
            color: options.color ?? false,
            formatTime: options.formatTime,
            details: options.details ?? false,
        };
        const lines = [header(record, resolved)];
 
        if (record.req) {
            const request = [record.req.operation, record.req.target].filter(Boolean).join(' ');
            lines.push(blockLine('request', sanitise(request)));
            lines.push(...keyValues('    ', record.req.headers));
        }
        if (record.res) {
            const elapsed =
                record.res.elapsedMs === undefined ? '' : ` (${record.res.elapsedMs}ms)`;
            lines.push(blockLine('response', `${record.res.status}${elapsed}`));
            lines.push(...keyValues('    ', record.res.headers));
        }
        if (record.err) {
            lines.push(
                blockLine(
                    'error',
                    sanitise([record.err.type, record.err.message].filter(Boolean).join(': ')),
                ),
            );
            if (record.err.stack) {
                // A stack routinely embeds the message, so an escape sequence in
                // a failure reaches this block through the frames as well as
                // through the message line above. Sanitising each frame is what
                // makes the C0 guarantee true of the whole rendered form.
                lines.push(
                    ...record.err.stack.split('\n').map(frame => `    ${sanitise(frame.trim())}`),
                );
            }
        }
        if (record.decision) {
            const decision: unknown = record.decision;
            const detail =
                typeof decision === 'object'
                    ? decisionDetail(decision as Decision)
                    : renderField(decision);
            lines.push(blockLine('decision', sanitise(detail)));
        }
        if (record.fields) {
            // A field line is `  key: value`, so the colon distinguishes it from
            // a labelled block (`  label  text`); sanitising both the key and the
            // value is what keeps a caller's text from forging a second line that
            // has neither.
            const payloads = record.refs.payloads;
            const {context: _, ...fields} = record.fields;
            for (const [key, value] of Object.entries(fields)) {
                if (isSkippedField(value)) continue;
                const text = renderField(value);
                const payload = payloads?.[key];
                // A large embedded value renders as its payload reference instead
                // of inlining the whole thing (PRD R19/R20: "a reference for any
                // large embedded configuration value"). The id comes from the
                // record's own `refs.payloads`, which the logger writes exactly
                // when it retained the payload, and the *threshold* is re-checked
                // here so this is still a size rule rather than a marker. Both
                // halves are load-bearing: without the index there is no id, and
                // without the check a record that named a payload for a short
                // value would hide the value behind a reference that adds nothing.
                //
                // A value with no index entry inlines. That is the common case and
                // the honest one: a record assembled by hand, or by a build with no
                // store configured, has no retained payload, and a reference to a
                // payload nothing holds is a dead link — worse than a long line.
                const rendered =
                    payload !== undefined && text.length >= PAYLOAD_THRESHOLD
                        ? refUri('payload', payload)
                        : sanitise(text);
                lines.push(paint(ANSI.gray, `  ${sanitise(key)}: ${rendered}`));
            }
        }
        return lines.join('\n');
    } catch {
        return salvageHuman(record);
    }
}
 
/**
 * Build a replacement function that keeps `JSON.stringify` total while still
 * emitting one parseable object per record (PRD R18). A circular reference is
 * replaced by an explicit marker and a `BigInt` by its decimal text; every
 * other value is returned unchanged, so an ordinary record serialises
 * byte-identically to a plain `JSON.stringify(record)`.
 *
 * A replacer — not a `try`/`catch` — is deliberate: catching and discarding
 * would lose the record, including the failure record a process-failure hook is
 * trying to emit.
 *
 * `this` inside the replacer is the object currently being serialised, so only
 * the ancestors of that object can be the value's cycle; popping anything
 * deeper lets a value shared by two sibling keys serialise twice instead of
 * being mistaken for a cycle.
 */
function createJsonReplacer(): (this: unknown, key: string, value: unknown) => unknown {
    const ancestors: object[] = [];
    return function (this: unknown, _key: string, value: unknown): unknown {
        if (typeof value === 'bigint') {
            return value.toString();
        }
        if (typeof value !== 'object' || value === null) {
            return value;
        }
        while (ancestors.length > 0 && ancestors[ancestors.length - 1] !== this) {
            ancestors.pop();
        }
        if (ancestors.includes(value)) {
            return '[Circular]';
        }
        ancestors.push(value);
        return value;
    };
}
 
/**
 * Render a record as one JSON object — the machine-readable mode. Total: a
 * circular reference or a `BigInt` in any nested field is serialised with a
 * marker, and a value that still defeats `JSON.stringify` — a `toJSON` that
 * throws, a getter it reaches while walking — is reported through a minimal
 * reconstructed object rather than escaping the log call. The replacer alone is
 * not enough: it only rewrites the values it is handed, and `toJSON` runs before
 * it is ever called.
 */
export function renderJson(record: LogRecord): string {
    try {
        return JSON.stringify(record, createJsonReplacer());
    } catch {
        return salvageJson(record);
    }
}