Skip to content

fix(security): redact range-analysis failure logs - #951

Draft
seonghobae wants to merge 4 commits into
developfrom
fix/range-analysis-log-privacy
Draft

seonghobae wants to merge 4 commits into
developfrom
fix/range-analysis-log-privacy

Conversation

@seonghobae

@seonghobae seonghobae commented Aug 20, 2026 •

Copy link
Copy Markdown
Collaborator

Security/privacy defect

Protected develop@acdbea6344fe1231c39535b575f4de35e4c607c9 had three range-analysis safe-failure logging paths that could copy dependency-controlled payloads into routine logs:

  • PitchTracker.track() interpolated the librosa.pyin ParameterError message directly;
  • analyze_range_pressure() logged arbitrary failures with exc_info=True; and
  • analyze_range_pressure_from_audio() logged pYIN failures with exc_info=True.

Those paths could expose local usernames, filesystem paths, token-shaped dependency text, and traceback paths, conflicting with BandScope's redacted-by-default logging contract in docs/security/app-security.md.

Exact current identity

  • Protected base: develop@acdbea6344fe1231c39535b575f4de35e4c607c9.
  • Exact head: 9c64ca3cd3bd2669d012f86b7f3611e7f2463583.
  • Branch: fix/range-analysis-log-privacy.
  • Open, Draft, unmerged.

Test-first repair

RED f9ba9357487ce93b10abcc123107c4e3068385b3 added test_range_logging_privacy.py, injecting realistic /Users/Alice/... token=super-secret dependency failures through all three public safe-failure boundaries and requiring the established neutral results plus stable operation-level diagnostics while rejecting the local path, filename, and secret payload from captured logs.

A concurrent writer repaired the PitchTracker.track() boundary first. Exact-current-source inspection then verified that ranges/pressure.py still violated the same committed regression through two exc_info=True paths, so the canonical branch was continued rather than opening a competing PR.

  • GREEN eab8ff66718539d20aaaefac98a943e4f6d48ced removes traceback/raw-message propagation from both pressure boundaries and retains only BandScope-owned operation context plus the exception class. Pitch/range mathematics, pYIN parameters, safe default results, and schemas are unchanged.
  • Current 9c64ca3cd3bd2669d012f86b7f3611e7f2463583 records the repaired range-analysis diagnostic boundary under CHANGELOG.md Unreleased / Fixed.

Current inline review threads: zero.

Verification boundary

Fresh repository workflows for exact head 9c64ca3cd3bd2669d012f86b7f3611e7f2463583 are dispatched. At the latest refetch, CI, release, build-baseline, SBOM, security-audit, aggregate Security Scan, Semgrep, Bandit, and secret-scan are all queued. Queued evidence is non-passing and no predecessor-head workflow result is transferred. Any terminal failure must be inspected at its exact job/log/checkout-SHA boundary before another mutation or rerun.

Scope

This lane is limited to range-analysis safe-failure diagnostics, focused privacy regressions, and truthful Unreleased documentation. It does not change pYIN parameters, pitch/range mathematics, confidence logic, result schemas, dependencies, lockfiles, models, filesystem/network/IPC authority, workflows, credentials, or vulnerability suppression.

Canonical JavaScript dependency remediation remains #783-owned; dependency-lifecycle checkout credential hardening remains #894-owned.

Security Notes

Unexpected dependency/numeric failures are untrusted diagnostic input. The repaired boundary preserves recoverable neutral results and bounded exception-class classification for operators while preventing raw exception messages and traceback payloads from becoming routine log output. Independent dependency/native logging sinks remain governed by their owning layers.

Merge gate

Keep Draft until one unchanged exact head has focused/full GREEN tests, exact required owned statement/branch coverage and public docs, every applicable repository and central CI/security/SAST/SBOM/supply-chain/release/review gate terminal-success, zero valid unresolved findings, qualifying independent non-author last-push approval, canonical dependency prerequisites integrated/revalidated where required, and ordinary protected-branch acceptance without bypass.

Queued, pending, skipped-required, cancelled, failed, predecessor-head, protected-base, model-only, self/author, rate-limited, or administrative-bypass evidence is non-passing.

@coderabbitai

coderabbitai Bot commented Aug 20, 2026 •

Copy link
Copy Markdown
Contributor

Important

Review skipped

Draft detected.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 215dd321-9854-411c-ab7e-4731fd753793

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: security Security boundary, hardening, or vulnerability prevention bug Something isn't working priority: medium Normal-priority or P2 work status: draft Draft pull request type: bug Defect or incorrect behavior

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant