Repository navigation
Bug: evidence-and-identity-hygiene-sweep #927
Copy link
Copy link
Closed
Labels
bugSomething isn't workingSomething isn't working
Description
Activity
The following sections were present in the promoted potential entry (
docs/features/potential/promoted/2026-09-28-evidence-and-identity-hygiene-sweep.md) but were dropped bypotential_to_issue(defect #887, now consolidated into #932). Reposted verbatim.Suspected Cause / Notes
- Evidence Markdown written by agents quotes absolute paths and tool banners verbatim.
- Raw vstest and AltCover output embeds
runUser,computerNameand a lowercasedstoragepath. - No gate checks for either.
- The redaction sweeps agents ran in the past also excluded the plan file from their own residual scan (Bug: quickfiler-coverage-filesize-evidence-debt #727 sub-finding 5, from item Bug: efcselectionguard-banner-prefix-arity-and-stale-comment #662).
Proposed Fix / Validation Ideas
-
git rmevery tracked*.trx,*cobertura*.xmland*.coveragefile.- Where a feature's figures are still needed, keep or produce the permitted projection. Otherwise rely on the committed summary.
- Removing the files does not rewrite history. History rewriting is explicitly out of scope.
- Add
.gitignorerules for the raw evidence document types. - Replace identifiers with placeholders across all tracked non-
.claudetext files:- Apply the replacements longest-first so the substitution is idempotent.
- Scan every file type, plan files included.
- Delete
test-output.txt. - Triage the
*.Testhits individually.
- Add a CI guard to
ci.yml, following the_<name>.ymlconvention, that fails on:- a tracked raw evidence document
- a Windows absolute user-profile path pattern in any tracked file outside
.claude/** - The guard must not embed the literal identifiers it searches for.
- Coordination: the other items in the same parallel run write evidence under
docs/features/active/**. They must pass the new guard, so confirm their evidence follows the convention before the guard becomes required. - Validation: all three
git ls-files/git grepcounts above return 0 outside.claude/**, and the guard fails on a deliberately introduced violation.
Next Step
- Promote to GitHub issue (bug-report template)
- Move to active fix folder / branch
Consolidates: #602 (non-
.claudeportion), #671 (remaining existing-file portion), #884, #727 sub-finding 5 (plan-file exclusion).
Metadata
Metadata
Assignees
Labels
bugSomething isn't workingSomething isn't working
Summary
Consolidates the unresolved remainder of #602, #671 and #884, and the plan-file exclusion gap from #727 sub-finding 5. The common root cause: identity-bearing test artifacts and absolute host paths were committed before the committed-evidence convention existed, and nothing rejects them at commit or CI time. PR #881 fixed prevention in the
scripts/vscodetest tooling (explicit/ResultsDirectory:andLogFileName=, projections instead of raw documents). It did not remove existing content and did not add an enforcement guard, so the counts keep growing.Environment
git ls-files,git grep -l -i <account>, measured onmainat177b6d78eon 2026-09-28docs/features/**,docs/research/**,tests/**,*.Test/**, and the root-leveltest-output.txtSteps to Reproduce
git ls-files -- "docs/features/**/*.trx"returns 332 paths.git ls-files -- "docs/features/**/*cobertura*.xml"returns 248 paths.Expected Behavior
*.trx) and no raw coverage collector document (*cobertura*.xml,*.coverage). This is the rule in the CLAUDE.md "Committed Test Evidence Format" section..claude/**contains an absolute user-profile path, the bare account name, or the bare host name. Use the placeholders<repo-root>,<user-profile>,<user>and<host>.Actual Behavior
Measured on
mainat177b6d78e(2026-09-28):.trxunderdocs/features*cobertura*.xmlunderdocs/featuresdocs/features/**.test-output.txtat the repository root (a stray run log)tests/docs/research/*.Testprojects. These may be test fixtures and must be triaged, not blindly rewritten..mcp.jsonand.codex/config.tomlmatch only through the npm package scope@<account>/drm-copilot-mcp. That is a package identifier, not a host identifier, and is out of scope..claude/**files are affected, including.claude/settings.json:75. They are push-down owned from drm-copilot and are tracked upstream in the companion upstream issue. Do not edit them here.Logs / Screenshots
Impact / Severity
The repository is out of compliance with its own committed-evidence policy across hundreds of files. The leak surface grew 25-fold for profile paths after the prevention tooling landed. That shows prevention by convention alone does not hold.
Source
From: docs/features/potential/2026-09-28-evidence-and-identity-hygiene-sweep.md