mirror of
https://github.com/fabro-sh/fabro.git
synced 2026-10-08 03:10:26 +00:00
parent
94846118b8
commit
edc88ee06a
7 changed files with 675 additions and 261 deletions
821
run.json
821
run.json
File diff suppressed because one or more lines are too long
68
stages/007-simplify_gpt@1/diff.patch
Normal file
68
stages/007-simplify_gpt@1/diff.patch
Normal file
|
|
@ -0,0 +1,68 @@
|
|||
diff --git a/lib/crates/fabro-redact/src/secret_registry.rs b/lib/crates/fabro-redact/src/secret_registry.rs
|
||||
index d28dd7873..764eb0fe5 100644
|
||||
--- a/lib/crates/fabro-redact/src/secret_registry.rs
|
||||
+++ b/lib/crates/fabro-redact/src/secret_registry.rs
|
||||
@@ -9,7 +9,8 @@ use crate::Region;
|
||||
/// This complements the crate's content-based redaction by redacting registered
|
||||
/// values even when they do not look like credentials. Clones share the same
|
||||
/// registry so callers can hand a redactor to another subsystem and continue to
|
||||
-/// register values through the original.
|
||||
+/// register values through the original. Registered values are exact substring
|
||||
+/// matches and may be low-entropy strings such as environment names.
|
||||
#[derive(Clone, Default)]
|
||||
pub struct SecretRedactor {
|
||||
values: Arc<RwLock<Vec<String>>>,
|
||||
@@ -39,21 +40,19 @@ impl SecretRedactor {
|
||||
|
||||
/// Redact all registered secret values from `s`.
|
||||
pub fn redact_into(&self, s: &str) -> String {
|
||||
- let values = self.read();
|
||||
- if values.is_empty() {
|
||||
+ let Some(values) = self.values_snapshot() else {
|
||||
return s.to_string();
|
||||
- }
|
||||
+ };
|
||||
redact_string_values(s, &values)
|
||||
}
|
||||
|
||||
- /// Redact registered secret values from every JSON string leaf.
|
||||
+ /// Redact registered secret values from every JSON string value.
|
||||
///
|
||||
- /// Object keys are left unchanged.
|
||||
+ /// Object keys and non-string values are left unchanged.
|
||||
pub fn redact_json(&self, mut value: Value) -> Value {
|
||||
- let values = self.read();
|
||||
- if values.is_empty() {
|
||||
+ let Some(values) = self.values_snapshot() else {
|
||||
return value;
|
||||
- }
|
||||
+ };
|
||||
|
||||
redact_json_leaves(&mut value, &values);
|
||||
value
|
||||
@@ -66,6 +65,14 @@ impl SecretRedactor {
|
||||
fn write(&self) -> RwLockWriteGuard<'_, Vec<String>> {
|
||||
self.values.write().unwrap_or_else(PoisonError::into_inner)
|
||||
}
|
||||
+
|
||||
+ fn values_snapshot(&self) -> Option<Vec<String>> {
|
||||
+ let values = self.read();
|
||||
+ if values.is_empty() {
|
||||
+ return None;
|
||||
+ }
|
||||
+ Some(values.clone())
|
||||
+ }
|
||||
}
|
||||
|
||||
fn redact_json_leaves(value: &mut Value, values: &[String]) {
|
||||
@@ -107,6 +114,10 @@ fn redact_string_values(s: &str, values: &[String]) -> String {
|
||||
}
|
||||
}
|
||||
|
||||
+ if regions.is_empty() {
|
||||
+ return s.to_string();
|
||||
+ }
|
||||
+
|
||||
crate::redact_regions(s, regions)
|
||||
}
|
||||
|
||||
26
stages/007-simplify_gpt@1/response.md
Normal file
26
stages/007-simplify_gpt@1/response.md
Normal file
|
|
@ -0,0 +1,26 @@
|
|||
Cleanup review complete.
|
||||
|
||||
Fixed in `lib/crates/fabro-redact/src/secret_registry.rs`:
|
||||
|
||||
- Released the registry read lock before doing string/JSON redaction by snapshotting registered values first.
|
||||
- Preserved an explicit empty-registry fast path.
|
||||
- Added a no-match short-circuit in `redact_string_values` to avoid calling `redact_regions` unnecessarily.
|
||||
- Clarified docs:
|
||||
- Registered values are exact substring matches and may be low-entropy.
|
||||
- JSON redaction affects string values only; object keys and non-string values are unchanged.
|
||||
|
||||
Skipped/left unchanged:
|
||||
|
||||
- Did not add minimum length / entropy filtering because the plan explicitly requires low-entropy values like `"staging"` and overlapping short values like `"abc"`.
|
||||
- Did not add Aho-Corasick or `IndexSet`; current registry is intentionally small per run, and the simpler implementation matches the plan.
|
||||
|
||||
Verification passed:
|
||||
|
||||
- `cargo +nightly-2026-04-14 fmt --check --all`
|
||||
- `cargo nextest run -p fabro-redact`
|
||||
- `cargo +nightly-2026-04-14 clippy -q -p fabro-redact --all-targets -- -D warnings`
|
||||
- `cargo dev build -- -p fabro-cli --release`
|
||||
|
||||
Working tree currently has only:
|
||||
|
||||
- `M lib/crates/fabro-redact/src/secret_registry.rs`
|
||||
6
stages/007-simplify_gpt@1/status.json
Normal file
6
stages/007-simplify_gpt@1/status.json
Normal file
|
|
@ -0,0 +1,6 @@
|
|||
{
|
||||
"outcome": "succeeded",
|
||||
"notes": "Stage completed: simplify_gpt",
|
||||
"failure_reason": null,
|
||||
"timestamp": "2026-07-01T16:56:34.715906917Z"
|
||||
}
|
||||
1
stages/008-verify@1/output.log
Normal file
1
stages/008-verify@1/output.log
Normal file
|
|
@ -0,0 +1 @@
|
|||
blob://sha256/b20c5c2047eb251e79a17223df4289472642fc8577e8c7e9ed08bfd85abc1f4e
|
||||
6
stages/008-verify@1/script_invocation.json
Normal file
6
stages/008-verify@1/script_invocation.json
Normal file
|
|
@ -0,0 +1,6 @@
|
|||
{
|
||||
"script": "git fetch origin main 2>&1 && git merge --no-edit --no-stat origin/main 2>&1 && cargo +nightly-2026-04-14 fmt --all 2>&1 && cargo dev docs refresh 2>&1 && cargo +nightly-2026-04-14 fmt --check --all 2>&1 && { command -v rg >/dev/null 2>&1 || { echo 'rg is required for verify'; exit 127; }; } && ! rg -n 'AuthMode::Disabled|RunAuthMethod|RunSubjectProvenance|\\bActorRef\\b|\\bActorKind\\b|AuthenticatedSubject|AuthenticatedService|AuthorizeRunScoped|AuthorizeRunBlob|AuthorizeStageArtifact|AuthorizeCommandLog|auth_method\\s*==\\s*\"disabled\"' lib/crates apps lib/packages docs/public/api-reference/fabro-api.yaml 2>&1 && cargo +nightly-2026-04-14 clippy --workspace --all-targets -- -D warnings 2>&1 && cargo nextest run --workspace --status-level slow --profile ci 2>&1 && cargo dev docs check 2>&1 && bun install --frozen-lockfile 2>&1 && (cd apps/fabro-web && bun run typecheck) 2>&1 && (cd apps/fabro-web && bun run test) 2>&1 && (cd lib/packages/fabro-api-client && bun run typecheck) 2>&1 && cargo dev build -- -p fabro-cli --release 2>&1",
|
||||
"command": "exec 2>&1\ngit fetch origin main 2>&1 && git merge --no-edit --no-stat origin/main 2>&1 && cargo +nightly-2026-04-14 fmt --all 2>&1 && cargo dev docs refresh 2>&1 && cargo +nightly-2026-04-14 fmt --check --all 2>&1 && { command -v rg >/dev/null 2>&1 || { echo 'rg is required for verify'; exit 127; }; } && ! rg -n 'AuthMode::Disabled|RunAuthMethod|RunSubjectProvenance|\\bActorRef\\b|\\bActorKind\\b|AuthenticatedSubject|AuthenticatedService|AuthorizeRunScoped|AuthorizeRunBlob|AuthorizeStageArtifact|AuthorizeCommandLog|auth_method\\s*==\\s*\"disabled\"' lib/crates apps lib/packages docs/public/api-reference/fabro-api.yaml 2>&1 && cargo +nightly-2026-04-14 clippy --workspace --all-targets -- -D warnings 2>&1 && cargo nextest run --workspace --status-level slow --profile ci 2>&1 && cargo dev docs check 2>&1 && bun install --frozen-lockfile 2>&1 && (cd apps/fabro-web && bun run typecheck) 2>&1 && (cd apps/fabro-web && bun run test) 2>&1 && (cd lib/packages/fabro-api-client && bun run typecheck) 2>&1 && cargo dev build -- -p fabro-cli --release 2>&1",
|
||||
"language": "shell",
|
||||
"timeout_ms": 1800000
|
||||
}
|
||||
8
stages/008-verify@1/script_timing.json
Normal file
8
stages/008-verify@1/script_timing.json
Normal file
|
|
@ -0,0 +1,8 @@
|
|||
{
|
||||
"output": "blob://sha256/b20c5c2047eb251e79a17223df4289472642fc8577e8c7e9ed08bfd85abc1f4e",
|
||||
"exit_code": 0,
|
||||
"duration_ms": 376760,
|
||||
"termination": "exited",
|
||||
"output_bytes": 91833,
|
||||
"live_streaming": true
|
||||
}
|
||||
Loading…
Add table
Reference in a new issue