checkpoint

⚒️ Generated with [Fabro](https://fabro.sh)
This commit is contained in:
Fabro 2026-07-01 17:02:55 +00:00
parent 94846118b8
commit edc88ee06a
7 changed files with 675 additions and 261 deletions

821
run.json

File diff suppressed because one or more lines are too long

View file

@ -0,0 +1,68 @@
diff --git a/lib/crates/fabro-redact/src/secret_registry.rs b/lib/crates/fabro-redact/src/secret_registry.rs
index d28dd7873..764eb0fe5 100644
--- a/lib/crates/fabro-redact/src/secret_registry.rs
+++ b/lib/crates/fabro-redact/src/secret_registry.rs
@@ -9,7 +9,8 @@ use crate::Region;
/// This complements the crate's content-based redaction by redacting registered
/// values even when they do not look like credentials. Clones share the same
/// registry so callers can hand a redactor to another subsystem and continue to
-/// register values through the original.
+/// register values through the original. Registered values are exact substring
+/// matches and may be low-entropy strings such as environment names.
#[derive(Clone, Default)]
pub struct SecretRedactor {
values: Arc<RwLock<Vec<String>>>,
@@ -39,21 +40,19 @@ impl SecretRedactor {
/// Redact all registered secret values from `s`.
pub fn redact_into(&self, s: &str) -> String {
- let values = self.read();
- if values.is_empty() {
+ let Some(values) = self.values_snapshot() else {
return s.to_string();
- }
+ };
redact_string_values(s, &values)
}
- /// Redact registered secret values from every JSON string leaf.
+ /// Redact registered secret values from every JSON string value.
///
- /// Object keys are left unchanged.
+ /// Object keys and non-string values are left unchanged.
pub fn redact_json(&self, mut value: Value) -> Value {
- let values = self.read();
- if values.is_empty() {
+ let Some(values) = self.values_snapshot() else {
return value;
- }
+ };
redact_json_leaves(&mut value, &values);
value
@@ -66,6 +65,14 @@ impl SecretRedactor {
fn write(&self) -> RwLockWriteGuard<'_, Vec<String>> {
self.values.write().unwrap_or_else(PoisonError::into_inner)
}
+
+ fn values_snapshot(&self) -> Option<Vec<String>> {
+ let values = self.read();
+ if values.is_empty() {
+ return None;
+ }
+ Some(values.clone())
+ }
}
fn redact_json_leaves(value: &mut Value, values: &[String]) {
@@ -107,6 +114,10 @@ fn redact_string_values(s: &str, values: &[String]) -> String {
}
}
+ if regions.is_empty() {
+ return s.to_string();
+ }
+
crate::redact_regions(s, regions)
}

View file

@ -0,0 +1,26 @@
Cleanup review complete.
Fixed in `lib/crates/fabro-redact/src/secret_registry.rs`:
- Released the registry read lock before doing string/JSON redaction by snapshotting registered values first.
- Preserved an explicit empty-registry fast path.
- Added a no-match short-circuit in `redact_string_values` to avoid calling `redact_regions` unnecessarily.
- Clarified docs:
- Registered values are exact substring matches and may be low-entropy.
- JSON redaction affects string values only; object keys and non-string values are unchanged.
Skipped/left unchanged:
- Did not add minimum length / entropy filtering because the plan explicitly requires low-entropy values like `"staging"` and overlapping short values like `"abc"`.
- Did not add Aho-Corasick or `IndexSet`; current registry is intentionally small per run, and the simpler implementation matches the plan.
Verification passed:
- `cargo +nightly-2026-04-14 fmt --check --all`
- `cargo nextest run -p fabro-redact`
- `cargo +nightly-2026-04-14 clippy -q -p fabro-redact --all-targets -- -D warnings`
- `cargo dev build -- -p fabro-cli --release`
Working tree currently has only:
- `M lib/crates/fabro-redact/src/secret_registry.rs`

View file

@ -0,0 +1,6 @@
{
"outcome": "succeeded",
"notes": "Stage completed: simplify_gpt",
"failure_reason": null,
"timestamp": "2026-07-01T16:56:34.715906917Z"
}

View file

@ -0,0 +1 @@
blob://sha256/b20c5c2047eb251e79a17223df4289472642fc8577e8c7e9ed08bfd85abc1f4e

View file

@ -0,0 +1,6 @@
{
"script": "git fetch origin main 2>&1 && git merge --no-edit --no-stat origin/main 2>&1 && cargo +nightly-2026-04-14 fmt --all 2>&1 && cargo dev docs refresh 2>&1 && cargo +nightly-2026-04-14 fmt --check --all 2>&1 && { command -v rg >/dev/null 2>&1 || { echo 'rg is required for verify'; exit 127; }; } && ! rg -n 'AuthMode::Disabled|RunAuthMethod|RunSubjectProvenance|\\bActorRef\\b|\\bActorKind\\b|AuthenticatedSubject|AuthenticatedService|AuthorizeRunScoped|AuthorizeRunBlob|AuthorizeStageArtifact|AuthorizeCommandLog|auth_method\\s*==\\s*\"disabled\"' lib/crates apps lib/packages docs/public/api-reference/fabro-api.yaml 2>&1 && cargo +nightly-2026-04-14 clippy --workspace --all-targets -- -D warnings 2>&1 && cargo nextest run --workspace --status-level slow --profile ci 2>&1 && cargo dev docs check 2>&1 && bun install --frozen-lockfile 2>&1 && (cd apps/fabro-web && bun run typecheck) 2>&1 && (cd apps/fabro-web && bun run test) 2>&1 && (cd lib/packages/fabro-api-client && bun run typecheck) 2>&1 && cargo dev build -- -p fabro-cli --release 2>&1",
"command": "exec 2>&1\ngit fetch origin main 2>&1 && git merge --no-edit --no-stat origin/main 2>&1 && cargo +nightly-2026-04-14 fmt --all 2>&1 && cargo dev docs refresh 2>&1 && cargo +nightly-2026-04-14 fmt --check --all 2>&1 && { command -v rg >/dev/null 2>&1 || { echo 'rg is required for verify'; exit 127; }; } && ! rg -n 'AuthMode::Disabled|RunAuthMethod|RunSubjectProvenance|\\bActorRef\\b|\\bActorKind\\b|AuthenticatedSubject|AuthenticatedService|AuthorizeRunScoped|AuthorizeRunBlob|AuthorizeStageArtifact|AuthorizeCommandLog|auth_method\\s*==\\s*\"disabled\"' lib/crates apps lib/packages docs/public/api-reference/fabro-api.yaml 2>&1 && cargo +nightly-2026-04-14 clippy --workspace --all-targets -- -D warnings 2>&1 && cargo nextest run --workspace --status-level slow --profile ci 2>&1 && cargo dev docs check 2>&1 && bun install --frozen-lockfile 2>&1 && (cd apps/fabro-web && bun run typecheck) 2>&1 && (cd apps/fabro-web && bun run test) 2>&1 && (cd lib/packages/fabro-api-client && bun run typecheck) 2>&1 && cargo dev build -- -p fabro-cli --release 2>&1",
"language": "shell",
"timeout_ms": 1800000
}

View file

@ -0,0 +1,8 @@
{
"output": "blob://sha256/b20c5c2047eb251e79a17223df4289472642fc8577e8c7e9ed08bfd85abc1f4e",
"exit_code": 0,
"duration_ms": 376760,
"termination": "exited",
"output_bytes": 91833,
"live_streaming": true
}