Skip to content

fix(security): redact temporal detector failure logs - #950

Draft
seonghobae wants to merge 5 commits into
developfrom
fix/temporal-detector-log-privacy
Draft

seonghobae wants to merge 5 commits into
developfrom
fix/temporal-detector-log-privacy

Conversation

@seonghobae

@seonghobae seonghobae commented Aug 20, 2026 •

Copy link
Copy Markdown
Collaborator

Security/privacy defect

Protected develop@acdbea6344fe1231c39535b575f4de35e4c607c9 used raw exception logging in the public safe-failure wrappers for groove, stop-time, and shared-hit detection. Those routines intentionally swallow third-party failures, but logger.exception(...) serialized dependency-controlled exception messages and traceback paths into routine logs, conflicting with the redacted-by-default diagnostic contract in docs/security/app-security.md.

Exact current identity

  • Protected base: develop@acdbea6344fe1231c39535b575f4de35e4c607c9.
  • Exact head: 396d42017bd32c9b7215ec8bf8f5bf8669139e85.
  • PR merge checkout observed by exact-head workflows: 470a9808b5f1ee6d8881ffbf9a6d0d236275c92a.
  • Branch: fix/temporal-detector-log-privacy.
  • Open, Draft, mergeable, unmerged.

Test-first repair

RED regressions were committed before production changes:

  • 9224fc2925297018f892f5d2d770a6f9411f818e injects /Users/Alice/private-groove.wav token=super-secret through groove onset detection and requires the established neutral result plus a payload-free routine diagnostic.
  • 414ceb36d9fbfb9af580ae29c4685caa40b39a67 adds the same realistic sensitive shapes through stop-time and shared-hit wrapper failures and requires empty safe results without local username/path/file/secret leakage.

The current head is a direct three-commit descendant of that RED boundary. Exact-current-source inspection verifies the intended GREEN behavior:

  • detect_groove() catches unexpected failures, returns the unchanged neutral groove result, and logs only the BandScope-owned operation text plus type(error).__name__;
  • detect_stop_time() returns [] and logs only the operation plus exception class;
  • detect_shared_hits() returns [] and logs only the operation plus exception class;
  • the committed privacy regressions remain present and continue to reject the injected path, filename, and secret payloads; and
  • module security documentation plus CHANGELOG.md describe the same executable boundary.

No groove classification, onset analysis, stop-time/shared-hit mathematics, public result schema, dependency, lockfile, model, filesystem/network/IPC authority, workflow, credential, or vulnerability-suppression behavior changed.

Exact-current-head verification

Repository workflows on unchanged exact head 396d42017bd32c9b7215ec8bf8f5bf8669139e85 are terminal:

  • terminal-success: ci run 32318440119, release 32318440098, build-baseline 32318440123, sbom 32318440090, SAST Semgrep 32318440107, bandit 32318440101, and secret-scan-gate 32318440147;
  • terminal-failure/non-passing: security-audit 32318440094 and aggregate Security Scan 32318440082.

The two failures were inspected at exact job/log level rather than inferred from predecessor evidence.

security-audit job 96275581581 checks out merge 470a9808..., completes setup and npm ci, then fails first at npm audit --workspaces --audit-level=high on the protected-base JavaScript set nanoid <3.3.18, pdfjs-dist >=5.6.83 <6.2.108, and undici 7.0.0-7.28.0. Python and Rust audit stages are skipped after that npm failure and are not counted as success.

Aggregate Security Scan has terminal-success Dependency Review, OSV base-vs-head comparison, and Scorecard. Its only failed substantive job is Trivy 96275584568; the scan/SARIF generation succeeds, then the finding gate reports exactly one HIGH whole-tree finding: CVE-2026-16633 for pdfjs-dist at package-lock.json:6370, and explicitly directs remediation to the shared base.

This PR changes no JavaScript dependency/root lock or suppression policy, so those failures remain canonical #783-owned protected-base evidence. They are neither suppressed nor duplicated here.

Current formal reviews: none. Current inline review threads: zero. CodeRabbit skipped automated review because the PR is Draft; skipped review is non-passing and there is no qualifying independent non-author exact-head approval.

Security Notes

Unexpected third-party/numeric failures while temporal detectors process untrusted decoded audio and beat/stem evidence are untrusted diagnostic input. The repaired wrappers retain stable recoverable results and bounded exception-class classification for operators while preventing raw exception messages and traceback payloads from becoming routine logs. Independent native/dependency logging sinks remain separately governed.

Merge gate

Keep Draft and unmerged until one unchanged resulting exact head has every applicable repository and central CI/security/SAST/SBOM/supply-chain/coverage/review gate terminal-success, exact required owned statement/branch coverage and public docs, canonical dependency prerequisites integrated and revalidated, zero valid unresolved findings, a qualifying independent non-author last-push approval, and ordinary protected-branch acceptance without bypass.

Queued, pending, skipped-required, cancelled, failed, predecessor-head, protected-base, model-only, self/author, rate-limited, or administrative-bypass evidence is non-passing.

@coderabbitai

coderabbitai Bot commented Aug 20, 2026 •

Copy link
Copy Markdown
Contributor

Important

Review skipped

Draft detected.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 811bce2b-ef9a-4ac4-8c0a-c86ad5b08b51

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@opencode-agent opencode-agent Bot added area: security Security boundary, hardening, or vulnerability prevention priority: medium Normal-priority or P2 work status: draft Draft pull request type: bug Defect or incorrect behavior labels Aug 22, 2026
@seonghobae seonghobae added the bug Something isn't working label Sep 7, 2026 — with ChatGPT Codex Connector
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: security Security boundary, hardening, or vulnerability prevention bug Something isn't working priority: medium Normal-priority or P2 work status: draft Draft pull request type: bug Defect or incorrect behavior

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant