◆ NFRGate / Rule Reference

L4 — Correlatable with traces

medium 📝 logs · both

Error-path logs include a correlation/trace/request ID field, so a log line can be tied back to a specific trace.

Python Implementation

L4: error-path logs include a correlation/trace/request ID field, so a
log line can be tied back to a specific trace. rubric_store/definitions/
logs.yaml tags this `both`; the static half only fires when a log call
already exists (L1's question, not this one) — it checks whether that
call's keyword arguments include a recognizable correlation-id field name
(trace_id, request_id, correlation_id, span_id, req_id and common
case/spelling variants). It cannot verify that the *value* passed is
actually a real trace ID rather than, say, a hardcoded string — that
semantic check is LLM/Sprint-3 territory, same split as L2.

Java Implementation

L4 for Java: error-path logs include a correlation/trace/request ID
field. Java has no keyword arguments, so unlike the Python version's exact
keyword-name check, this looks for a correlation-id-like marker anywhere in
the log call's argument text — covering both an SLF4J placeholder argument
named traceId/requestId and an MDC-based approach. See
ast_helpers.has_correlation_id_reference for why that's a broader, lower-
confidence signal than Python's.

Go Implementation

L4 for Go: error-path logs include a correlation/trace/request ID field.
Go has no keyword arguments, so this checks textually across the log
call's arguments for a correlation-id-like key — Go's structured loggers
(slog/zap) pass such fields as string keys in the key-value variadic list,
not as named arguments. See ast_helpers.has_correlation_id_field.

Fail-branch confidence retuned from 0.7 to 0.429, per
docs/false_positive_rate_study_v1.md: a hand-labeled sample (n=3, after
excluding 2 of the original 5 that no longer fire at all post the
find_log_call fix) scored only 1/3 correct — 2 of the 3 survivors were
startup/shutdown-lifecycle logs with no request to correlate to in the
first place, a case this rule doesn't yet distinguish from a real
request-path log. Python and Java's L4 weren't sampled and are untouched.
← All rules