Repository navigation
fix(debug-retention): collect key-log-only proxy run dirs from new runs only; existing key logs untouched - #1388
Merged
Juliusolsson05 merged 11 commits intoSep 27, 2026
Conversation
#1385 (q91 follow-up of #1380): a run dir holding only session-meta.json + sslkeylog.log was walked into and never collected, so its plaintext TLS secrets stayed on disk indefinitely (23 dirs, 5.18 MB on the owner's machine). A run dir is now recognised by either evidence file. Red before. HOLD for the owner's q91 decision: once collectable, the 48 h TTL pass removes these months-old dirs on the first prune, so this IS the sweep. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…never counts as empty (q109, q115) dirStats skipped any child it could not read, so a run whose fresh data sat in an unreadable child was dated by its oldest file and TTL-removed. A failed read of the saved-bundles ledger returned an empty manual set, so manual legacy bundles were bucketed as prunable autosave. Only ENOENT now means absent; any other failure leaves the artifact uncollected. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…y; existing key logs stay (#1385) The 23 existing key-log-only dirs are an owner decision (q91). Collection now starts at runs dated on or after 2026-09-28; earlier or undated dirs are left untouched and never walked into. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…ain's rotated-generation run marker) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…tured at run start, not a timestamp (#1385, #1388 review a r2 + b) A first-prune marker excluded runs made during the boot delay forever, and any timestamp comparison admits a pre-upgrade run after a clock step back. The baseline is the set of key-log-only dirs that existed when this build first started, captured strictly and written once; with none, no key-log-only dir is collected. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Owner
Author
|
Disposition at 35001c8 (review cap reached; B6 manual inspection, then manager-verify a/b/c MERGE-READY):
🤖 Generated with Claude Code |
Juliusolsson05
marked this pull request as ready for review
September 27, 2026 21:07
Juliusolsson05
changed the base branch from
main
to
integration/batch-2026-09-27-r
September 27, 2026 21:32
Juliusolsson05
merged commit Sep 27, 2026
b5a08b2
into
integration/batch-2026-09-27-r
2 checks passed
Merged
Juliusolsson05
added a commit
that referenced
this pull request
Sep 27, 2026
Real conflict with #1388 in debugRetention.ts, both sides kept: - imports: this PR's rmdir/sep (parent sweep) + #1388's writeFile/relative (key-log baseline); - collectArtifacts: this PR's cachedManualLegacyBundlePaths() stays the one ledger read (q118: absent or unreadable ledger = 'unknown', every legacy bundle protected, never cached), and #1388's keyLogOnlyBaseline capture is added after it. #1388 already calls this PR's loader; it keeps no loader of its own. tsc -b 0 lines; storage, conversations, paste, window, lruMap and performance suites 413/413. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #1385.
Plan:
docs/plans/2026-09-27-retention-collects-keylog-run-dirs.md.Problem
collectProxyRunDirsrecognised a proxy run dir only byproxy-events.jsonl. A run dir holding justsession-meta.json+sslkeylog.logwas walked into and never collected, budgeted or removed. Those are plaintext TLS session secrets. #1380 review c recounted names and sizes only (contents never read): 23 such dirs on the owner's machine, 5.18 MB, May–September 2026.What merges: FUTURE runs only
keyLogBaseline()captures it at run start (holdDebugStoragePruneUntilRecovered), strictly (any unlistable directory means no baseline, and nothing is written), and writes it once toSTATE_DIR/debug-retention-keylog-baseline.json. With no baseline, NO key-log-only dir is collected. Timestamps were tried twice and dropped (review a): a date constant and a first-prune marker each excluded new runs forever, and any clock comparison admits a pre-upgrade run after a clock step back._shared-confare still skipped.dirStatsno longer skips a child it cannot read. Only ENOENT means absent; any other error leaves the whole dir uncollected that pass.Tests
debugRetention.keylog.test.ts, real directory shapes:_shared-confand a metadata-only dir are not;proxy-events.jsonlORproxy-events.1.jsonlis collected as on main; a key-log-only dir only when new.npx tsc -bis clean;src/main/storagepasses, 13 files / 164 tests at35001c8a.🤖 Generated with Claude Code