Skip to content

JOS-81: Verify and release private diagnostic logging #22

Description

@jacobyoby

Verify and release the coherent non-mail privacy boundary; a package-only install cannot deliver all launchers, native binaries, configuration and rotation changes.

Candidate 37fb23e is in draft PR #23. Native CI, CodeQL analysis and the aggregate security check pass. Production is unchanged.

  • Accept the 36-file native installation/rollback, real queue/cron, scheduled maintenance, local backups, rotation, orderly restart and interrupted-start guard.
  • Pass 148 native/launcher tests,84 frozen references, Go/race/fuzz/vulnerability checks and native runtime controls.
  • Preserve customized initializer/daily/realip code with narrow verified patches and portable GNU patch context.
  • Verify both prepared target configurations with actual Nginx and compiled preflight in isolated containers.
  • Verify all 31 artifact payload/patch hashes, all 4 native binary hashes and 6 target preparations.
  • Capture stable private rollback snapshots and restore both in isolated containers with exact contents, links, ownership, modes and absence state.
  • Record protected static-tree baselines and confirm shared mail sections remain unchanged.
  • Recheck quiescent target state, install the scoped catalog and verify served/output-retention behavior.
  • Record release provenance and final outcome.

Each private snapshot records 55 paths and archives 42 files/links. Static protected-tree baselines cover 289 Forma and 291 Demo entries. User uploads and historical log contents were not copied as static trees. Preserve their contents, system syslog configuration, customized routes and original service states. Temporary verification containers used no production volumes, network or application startup and were removed.

Go mail replacement and Exim changes remain deferred; the full Dockerfile is excluded. Manual/conditional paths, unrelated NLTK alerts 35/36, blank-download logging and privacy-related metrics loss remain separate.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions