Skip to content

fix(security): keep UUIDs intact through Sanitizer phone redaction - #54

Open
minerva-sky wants to merge 1 commit into
codenamev:mainfrom
minerva-sky:fix/sanitizer-uuid-guard
Open

minerva-sky wants to merge 1 commit into
codenamev:mainfrom
minerva-sky:fix/sanitizer-uuid-guard

Conversation

@minerva-sky

Copy link
Copy Markdown
Collaborator

Problem

The Ruby 3.2.4 CI job goes red at random on #40, #50, #51 and #53 — always the same example, plan_orchestrator_spec "skips transitively through the graph", with output like:

expected: "73fb9a6e-9973-4748-87aa-3aeaa0c29af2"
     got: "73fb9a6e-[REDACTED_PHONE]-87aa-3aeaa0c29af2"

Not a Ruby/Linux/ordering issue — the mask is produced inside the object under test. TaskFailure#initialize sanitizes message and context through Security::Sanitizer, whose second phone regex matches any UUID whose 2nd + 3rd groups are all digits (9973-4748). About 4% of SecureRandom.uuid values qualify, so every spec that asserts on a dependency_id or an id inside a failure message flakes at that rate. Local runs just got lucky.

Fix

  • Sanitizer#sanitize_string masks UUID spans with placeholders before the PII patterns run and restores them afterwards (PROTECTED_SPANS). Fixes message and context together.
  • Regression spec: a digit-heavy UUID next to a real phone number — the UUID survives, the phone is still redacted, hash values too.

Probe: 2000 random UUIDs through the sanitizer → 0 mangled (was ~4%).

Verified under ruby 3.2.4, --order defined: sanitizer + task_failure + plan_orchestrator specs, 57 examples, 0 failures; standardrb clean.

Once merged, rebasing #40/#50/#51/#53 (or just re-running their CI after main moves) should turn the 3.2.4 job green.

🤖 Generated with Claude Code

TaskFailure#initialize runs message and context through Security::Sanitizer.
The loose phone pattern matched any UUID whose 2nd and 3rd groups are all
digits (~4% of SecureRandom.uuid values), turning e.g.
73fb9a6e-9973-4748-87aa-… into 73fb9a6e-[REDACTED_PHONE]-87aa-… and
corrupting dependency_id / task ids. This is the random red on the Ruby
3.2.4 CI job for codenamev#40, codenamev#50, codenamev#51 and codenamev#53 (plan_orchestrator_spec 'skips
transitively through the graph').

Mask UUID spans with placeholders before applying PII patterns and restore
them after; add a regression spec with a digit-heavy UUID.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant