Skip to content

Bug: evidence-and-identity-hygiene-sweep #927

Description

@drmoisan
  • Work Mode: full-bug

Summary

Consolidates the unresolved remainder of #602, #671 and #884, and the plan-file exclusion gap from #727 sub-finding 5. The common root cause: identity-bearing test artifacts and absolute host paths were committed before the committed-evidence convention existed, and nothing rejects them at commit or CI time. PR #881 fixed prevention in the scripts/vscode test tooling (explicit /ResultsDirectory: and LogFileName=, projections instead of raw documents). It did not remove existing content and did not add an enforcement guard, so the counts keep growing.

Environment

  • OS/version: Windows 11 Pro 10.0.26200
  • Python version: not applicable (repository hygiene; tracked Markdown, TRX and Cobertura files)
  • Command/flags used: git ls-files, git grep -l -i <account>, measured on main at 177b6d78e on 2026-09-28
  • Data source or fixture: tracked files under docs/features/**, docs/research/**, tests/**, *.Test/**, and the root-level test-output.txt

Steps to Reproduce

  1. git ls-files -- "docs/features/**/*.trx" returns 332 paths.
  2. git ls-files -- "docs/features/**/*cobertura*.xml" returns 248 paths.
  3. Search tracked files for the developer account name, host name, and absolute user-profile path.

Expected Behavior

  • No tracked raw test-platform document (*.trx) and no raw coverage collector document (*cobertura*.xml, *.coverage). This is the rule in the CLAUDE.md "Committed Test Evidence Format" section.
  • No tracked file outside .claude/** contains an absolute user-profile path, the bare account name, or the bare host name. Use the placeholders <repo-root>, <user-profile>, <user> and <host>.
  • A CI check rejects new violations, so the cleanup does not regress.

Actual Behavior

Measured on main at 177b6d78e (2026-09-28):

Condition Tracked files At filing
Raw .trx under docs/features 332 333 (#884)
Raw *cobertura*.xml under docs/features 248 248 (#671)
Contains the account name 1,222 991 (#602)
Contains an absolute user-profile path 1,217 45 (#602)
Contains the host name 183 146 (#602)
  • Nearly all hits are under docs/features/**.
  • Other locations:
    • test-output.txt at the repository root (a stray run log)
    • one file under tests/
    • one file under docs/research/
    • about 13 files in *.Test projects. These may be test fixtures and must be triaged, not blindly rewritten.
  • .mcp.json and .codex/config.toml match only through the npm package scope @<account>/drm-copilot-mcp. That is a package identifier, not a host identifier, and is out of scope.
  • About 8 .claude/** files are affected, including .claude/settings.json:75. They are push-down owned from drm-copilot and are tracked upstream in the companion upstream issue. Do not edit them here.

Logs / Screenshots

  • Attached minimal logs or snippet
  • Snippet: counts above. The identifiers themselves are deliberately not reproduced.

Impact / Severity

  • Blocker
  • High
  • Medium
  • Low

The repository is out of compliance with its own committed-evidence policy across hundreds of files. The leak surface grew 25-fold for profile paths after the prevention tooling landed. That shows prevention by convention alone does not hold.

Source

From: docs/features/potential/2026-09-28-evidence-and-identity-hygiene-sweep.md

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions