P2: Remove private User paths from Tag rebuild warnings #939

Open
opened 2026-10-02 17:41:45 +00:00 by kayg · 1 comment
Owner

Read-only review of #664 at 884cc8ba6e1d275d14844187ed16e65f4b20a354. No builds or tests ran.

Evidence: crates/calternal-tags/src/source.rs:455–458 logs folder = %folder; :536–549 logs sidecar = %path.as_str(). These fields include private User folder and file names. The warnings have generic messages but the fields retain private data.

tests/adversarial/attack.py:3077–3085 checks only for the complete damaged source body in server.log. It does not check the folder or file name and therefore accepts these events.

Rule: the #664 independent review requires logs without private data. docs/audits/cross-user-inventory.md:92 requires routine logs to redact User content and paths.

Expected behavior: log the source kind and an opaque identifier that contains no User name or path. Extend the same probe to check private name markers as well as source body markers.

Focused test idea: put distinct fixture markers in the folder name, file name, and source body. Capture the newly emitted warnings. Require a generic warning and require all private markers to be absent.

Searches before filing: private paths and logging; no matching issue for the new warning fields found. Keep warning changes and their probe under one owner.

Read-only review of #664 at `884cc8ba6e1d275d14844187ed16e65f4b20a354`. No builds or tests ran. Evidence: `crates/calternal-tags/src/source.rs:455–458` logs `folder = %folder`; `:536–549` logs `sidecar = %path.as_str()`. These fields include private User folder and file names. The warnings have generic messages but the fields retain private data. `tests/adversarial/attack.py:3077–3085` checks only for the complete damaged source body in server.log. It does not check the folder or file name and therefore accepts these events. Rule: the #664 independent review requires logs without private data. `docs/audits/cross-user-inventory.md:92` requires routine logs to redact User content and paths. Expected behavior: log the source kind and an opaque identifier that contains no User name or path. Extend the same probe to check private name markers as well as source body markers. Focused test idea: put distinct fixture markers in the folder name, file name, and source body. Capture the newly emitted warnings. Require a generic warning and require all private markers to be absent. Searches before filing: `private paths` and `logging`; no matching issue for the new warning fields found. Keep warning changes and their probe under one owner.
Author
Owner

Fixed in commit 0699665e1: Tag rebuild warnings now log the User ID and source kind only. They no longer include folder or Sidecar paths. The adversarial probe captures the log offset before each reconcile request and rejects distinct private folder, filename, and source-body markers in newly emitted events.

Verification: python3 -c 'import ast, pathlib; ast.parse(pathlib.Path("tests/adversarial/attack.py").read_text())' completed with exit status 0. The API-only adversarial round is reserved for the merge round by the verification policy.

Fixed in commit `0699665e1`: Tag rebuild warnings now log the User ID and source kind only. They no longer include folder or Sidecar paths. The adversarial probe captures the log offset before each reconcile request and rejects distinct private folder, filename, and source-body markers in newly emitted events. Verification: `python3 -c 'import ast, pathlib; ast.parse(pathlib.Path("tests/adversarial/attack.py").read_text())'` completed with exit status 0. The API-only adversarial round is reserved for the merge round by the verification policy.
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
kayg/calternal#939
No description provided.