feat: bug-report collector pseudonymises identities in two stages, opt-in via --pseudonymise (#158)
CI / verify (push) Successful in 2m5s
Release / release (push) Successful in 39s

Files changed:
- .gitea/workflows/ci.yml
- CHANGES.md
- INSTALL.md
- VERSION
- instructions/bug-report.md
- reports/CONTRACT.md
- tools/README.md
- tools/bugreport.py
- tools/chemenu/tests/test_bugreport.py
This commit is contained in:
torben committed 2026-09-30 19:03:59 +02:00
1 parent 0899c670fe
commit 76d67e45ba
9 files changed
+850 -15

No files matched your search

+11 -1
View File
@@ -50,6 +50,14 @@ session trace, the chronology and transcripts, which may hold page content and t
removed by the collector; the rest is the reader's to check before a bundle leaves the machine.
Nothing uploads it: the channel is the user's choice.
With `--pseudonymise` the collector replaces known identities by consistent, shape-preserving
placeholders, and `--bundle`/`--candidates` applies further names a model found. Three files then
sit **beside** the bundle directory, never inside it and never in its zip, and all three contain
originals: `bugreport-<stamp>.pseudonyms.json` (the mapping and its salt),
`bugreport-<stamp>.review.txt` (what stage 1 left behind) and the candidate file the agent writes.
`MANIFEST.md` lists the placeholders, never an original. What stage 2 finds is a model's judgement,
so the manifest and the collector's closing output name a residual uncertainty.
The collector's two counting `wikitool` calls (`instructions verify`, `docs verify`) run under the
session id `bugreport-<stamp>`; its budget-exempt ones inherit the caller's. A
`reports/telemetry/bugreport-*` directory is therefore that run's trace and belongs to no session
@@ -62,7 +70,9 @@ retire with `wikitool rm`, because no report is ever a wiki page - `lint-report`
contract-only type-spec with no `base_dir:` and cannot be instantiated under `kb/`.
**Bug-report bundles: none.** Delete them freely once they have been read or sent; nothing refers
to one afterwards.
to one afterwards. The mapping beside a pseudonymised bundle is needed until the last stage 2 run,
because stage 2 refuses without it; after that it may be deleted, and it should be, since it holds
the originals.
**Traces: two enforced caps, applied by the writer itself, never by a separate cleanup pass.**
A byte cap per session trace (default 5 MiB, `WIKI_TRACE_MAX_SESSION_BYTES`) and a retention