feat: bug-report collector pseudonymises identities in two stages, opt-in via --pseudonymise (#158)
Files changed: - .gitea/workflows/ci.yml - CHANGES.md - INSTALL.md - VERSION - instructions/bug-report.md - reports/CONTRACT.md - tools/README.md - tools/bugreport.py - tools/chemenu/tests/test_bugreport.py
This commit is contained in:
1 parent
0899c670fe
commit
76d67e45ba
9 files changed
+850
-15
No files matched your search
+11
-1
@@ -50,6 +50,14 @@ session trace, the chronology and transcripts, which may hold page content and t
|
||||
removed by the collector; the rest is the reader's to check before a bundle leaves the machine.
|
||||
Nothing uploads it: the channel is the user's choice.
|
||||
|
||||
With `--pseudonymise` the collector replaces known identities by consistent, shape-preserving
|
||||
placeholders, and `--bundle`/`--candidates` applies further names a model found. Three files then
|
||||
sit **beside** the bundle directory, never inside it and never in its zip, and all three contain
|
||||
originals: `bugreport-<stamp>.pseudonyms.json` (the mapping and its salt),
|
||||
`bugreport-<stamp>.review.txt` (what stage 1 left behind) and the candidate file the agent writes.
|
||||
`MANIFEST.md` lists the placeholders, never an original. What stage 2 finds is a model's judgement,
|
||||
so the manifest and the collector's closing output name a residual uncertainty.
|
||||
|
||||
The collector's two counting `wikitool` calls (`instructions verify`, `docs verify`) run under the
|
||||
session id `bugreport-<stamp>`; its budget-exempt ones inherit the caller's. A
|
||||
`reports/telemetry/bugreport-*` directory is therefore that run's trace and belongs to no session
|
||||
@@ -62,7 +70,9 @@ retire with `wikitool rm`, because no report is ever a wiki page - `lint-report`
|
||||
contract-only type-spec with no `base_dir:` and cannot be instantiated under `kb/`.
|
||||
|
||||
**Bug-report bundles: none.** Delete them freely once they have been read or sent; nothing refers
|
||||
to one afterwards.
|
||||
to one afterwards. The mapping beside a pseudonymised bundle is needed until the last stage 2 run,
|
||||
because stage 2 refuses without it; after that it may be deleted, and it should be, since it holds
|
||||
the originals.
|
||||
|
||||
**Traces: two enforced caps, applied by the writer itself, never by a separate cleanup pass.**
|
||||
A byte cap per session trace (default 5 MiB, `WIKI_TRACE_MAX_SESSION_BYTES`) and a retention
|
||||
|
||||
Reference in new issue
Block a user