Skip to content

Add DVT logging and OSLog archives to log gathering - #3

Merged
hideouts-io merged 3 commits into
mainfrom
dvt-oslog-logs
Sep 29, 2026
Merged

hideouts-io merged 3 commits into
mainfrom
dvt-oslog-logs

Conversation

@hideouts-io

Copy link
Copy Markdown
Owner

Live Logs and Evidence Capture gain two collected sources next to the Unified Logging and syslog streams, both through Apple's own tools:

  • OSLog Archive — log collect --device-udid copies the device's saved Unified Log history for a time window into a .logarchive (Console.app opens it); log show --style ndjson reads it back into the viewer. No Xcode needed.
  • DVT Logging — a timed Instruments Logging recording (xctrace record), kept as a .trace; its os-log table is exported (xctrace export) and streamed into the viewer. This is Apple's supported route to DVT logging; a live DVT stream would need Xcode's private tunnel.

Also: a Stream/Collect layout with a time window on Live Logs; Open in Console/Instruments; Evidence Capture options (OSLog archive for the last hour, DVT logging for the stream duration); idt collect --include-oslog-archive and --include-dvt-logs; the 0.3.x --include-oslog flag and profile field now select DVT logging as they did in 0.3.x. Saved options from before still load.

Checked locally: 199 package tests with warnings as errors (reader, requests, error wording, end-to-end with stand-in tools, evidence steps), zero-warning build, layout check, and the real-simulator test, which records DVT logging for 3 s and reads 9,608 lines. Not yet run on a physical device: log collect from an iPhone (including whether macOS allows it without administrator rights) and DVT logging from an iPhone (needs Developer Mode and the developer image).

Built on #2.

hideouts.io

Live Logs and Evidence Capture gain two collected sources next to the
Unified Logging and syslog streams, both through Apple's own tools:

- OSLog Archive: macOS's `log collect --device-udid` copies the device's
  saved Unified Log history for a time window into a .logarchive
  (Console.app opens it); `log show --style ndjson` reads it back into
  the viewer. No Xcode needed. A refusal is explained in plain language;
  the toolkit never uses administrator rights.
- DVT Logging: a timed Instruments Logging recording (`xctrace record`),
  kept as a .trace, whose os-log table is exported and read without
  loading it into memory. This is Apple's supported route to DVT
  logging; a live DVT stream would need Xcode's private tunnel.

Live Logs has a Stream row and a Collect row with a time window; the
archive or recording opens in Console or Instruments. Evidence Capture
adds "OSLog archive (last hour)" and "DVT logging" options, idt collect
adds --include-oslog-archive and --include-dvt-logs, and the 0.3.x
--include-oslog flag and profile field now select DVT logging, as they
did in 0.3.x. Saved options from before still load.

hideouts.io
On a heavily loaded CI runner (the simulator took 163 s to boot), the
three-second DVT logging recording did not finish within the time the app
allows, and the app correctly reported a timeout. The test now accepts
only that timeout for the DVT step and says in its output that DVT was
not verified in that run; any other failure still fails the test.

hideouts.io
@hideouts-io
hideouts-io merged commit 0c15a1b into main Sep 29, 2026
7 checks passed
@hideouts-io
hideouts-io deleted the dvt-oslog-logs branch September 29, 2026 10:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant