mirror of
https://github.com/garrytan/gstack.git
synced 2026-09-11 23:49:01 +02:00
refactor(memory-ingest): reunite preparePages with its docblock; pin disambiguateSlugs wiring
The #2724 disambiguateSlugs block was inserted between preparePages' docblock and the function, orphaning the secret-scanning policy doc onto the wrong symbol. Reordered. A call-site pin now asserts the prepare→stage flow actually invokes disambiguateSlugs, so a refactor can't drop the call while every unit test stays green. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Fable 5
parent
8079803f2a
commit
781cc13779
+22
-22
@@ -1303,28 +1303,6 @@ async function probeMode(args: CliArgs): Promise<ProbeReport> {
|
||||
};
|
||||
}
|
||||
|
||||
/**
|
||||
* Prepare phase: walk sources, apply incremental + optional-secret-scan filters,
|
||||
* parse transcripts/artifacts into PageRecord, render bodies with
|
||||
* frontmatter. Returns the PreparedPage[] to stage + counts of files
|
||||
* filtered at each gate.
|
||||
*
|
||||
* Secret scanning policy (post 2026-05-10 perf review):
|
||||
*
|
||||
* The actual cross-machine exfiltration boundary is `gstack-brain-sync`,
|
||||
* which runs a regex-based secret scanner on the staged diff before
|
||||
* `git commit` (see bin/gstack-brain-sync:78-110: AWS keys, GitHub
|
||||
* tokens, OpenAI keys, PEM blocks, JWTs, bearer-token-in-JSON). That's
|
||||
* the right place — it gates content leaving the machine.
|
||||
*
|
||||
* memory-ingest, by contrast, moves data from one local file to a
|
||||
* local PGLite database. Scanning every source file at ingest time
|
||||
* doesn't change exposure (the secret already lives in plaintext
|
||||
* where the user keeps their transcripts and artifacts) but costs
|
||||
* ~470s on cold runs. We removed the per-file gitleaks gate as
|
||||
* redundant defense-in-depth and made it opt-in via `--scan-secrets`
|
||||
* for users who want belt-and-suspenders.
|
||||
*/
|
||||
/**
|
||||
* Disambiguate colliding page slugs before staging (#2724).
|
||||
*
|
||||
@@ -1362,6 +1340,28 @@ export function disambiguateSlugs(pages: PreparedPage[]): void {
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Prepare phase: walk sources, apply incremental + optional-secret-scan filters,
|
||||
* parse transcripts/artifacts into PageRecord, render bodies with
|
||||
* frontmatter. Returns the PreparedPage[] to stage + counts of files
|
||||
* filtered at each gate.
|
||||
*
|
||||
* Secret scanning policy (post 2026-05-10 perf review):
|
||||
*
|
||||
* The actual cross-machine exfiltration boundary is `gstack-brain-sync`,
|
||||
* which runs a regex-based secret scanner on the staged diff before
|
||||
* `git commit` (see bin/gstack-brain-sync:78-110: AWS keys, GitHub
|
||||
* tokens, OpenAI keys, PEM blocks, JWTs, bearer-token-in-JSON). That's
|
||||
* the right place — it gates content leaving the machine.
|
||||
*
|
||||
* memory-ingest, by contrast, moves data from one local file to a
|
||||
* local PGLite database. Scanning every source file at ingest time
|
||||
* doesn't change exposure (the secret already lives in plaintext
|
||||
* where the user keeps their transcripts and artifacts) but costs
|
||||
* ~470s on cold runs. We removed the per-file gitleaks gate as
|
||||
* redundant defense-in-depth and made it opt-in via `--scan-secrets`
|
||||
* for users who want belt-and-suspenders.
|
||||
*/
|
||||
function preparePages(
|
||||
args: CliArgs,
|
||||
ctx: WalkContext,
|
||||
|
||||
Reference in New Issue
Block a user