Files
chanora/docs/security/diagnostic-redaction-audit-report.md
T
EdisonJwa 271d23faf7 docs(governance): record PoC outcomes, owner decisions, and audit evidence
Closes Phases A and D of the post-PoC sequencing.

Decision register (v0.9.2 → v0.9.3):
  - DEC-014 Accepted: flutter_rust_bridge 2.x pinned (closed by
    poc/flutter_rust_bridge_hello).
  - DEC-013.1 Accepted: rusqlite (bundled) (closed by
    poc/sqlite-storage-spike).
  - DEC-013.2 Accepted: Linux secure-storage backend policy —
    Secret Service preferred, keyutils fallback (closed by
    poc/secure-storage-spike; resolves SysRS-053 / SysRS-162
    ambiguity).
  - DEC-011.1 Accepted (desktop: cpal) / Deferred (mobile)
    (closed by poc/audio-capture-playback-spike desktop half only).
  - DEC-022 Accepted: canonical implementation directory layout per
    the README sketch and SAD §7.2.
  - DEC-020 explicitly Deferred by owner; remains a public-release
    blocker.

Audit reports updated with empirical evidence:
  - docs/security/secure-storage-audit-report.md v0.9.3:
    SS-AUD-001/002/003/005/006 = PoC Pass with evidence pointers;
    SS-TC-003 (Linux) Actual Result populated and Status = PoC Pass;
    SS-AUD-004 cross-referenced to diagnostics-redaction PoC;
    findings SS-FIND-001 (closed by DEC-013.2), SS-FIND-002 (keyutils
    session caveat), SS-FIND-003 (non-Linux adapters still open).
  - docs/security/diagnostic-redaction-audit-report.md v0.9.3:
    REDACT-TC-001..010 = PoC Pass with evidence pointers; export
    bundle policy §5 populated for every row; findings
    REDACT-FIND-001 (regex coverage), REDACT-FIND-002
    (tracing-layer integration), REDACT-FIND-003 (cross-spike
    KnownSecretRegistry contract).

PoC plan (v0.1.0 → v0.2.0):
  - Status column added to §2; outcomes recorded.

New doc:
  - docs/governance/poc-results-summary.md v0.1.0 — single-page
    reviewer-facing summary listing each spike's status, the
    toolchain exercised, the owner decisions taken, the audit
    coverage table, and open risks RISK-PoC-001..005 (mobile audio,
    non-Linux secure-storage adapters, license, remaining
    Proposed decisions, no product code yet).

This completes the post-PoC documentation work. Repo is at a clean
pause point: PoC code is committed, owner decisions are recorded,
audit reports carry empirical evidence, and the residual risks are
named in the summary doc.
2026-05-14 12:34:13 +08:00

8.0 KiB

Sec Diagnostic Redaction Audit Report V0.9.3.0.0

Document type: Security / Diagnostic Redaction Audit Report
Version: 0.9.3
Status: Baseline Candidate
Language: English
Product: Chanora
Repo path: docs/security/diagnostic-redaction-audit-report.md ---

1. Purpose

This report records evidence that Chanora logs and diagnostic exports do not leak sensitive information.

2. Sensitive Data Redaction Policy

Data category Default diagnostic behavior
Server password Must redact
Identity private key / identity secret Must redact
Authentication tokens if later added Must redact
Secure-storage keys Must redact
Server address Redact or minimize according to release policy
Channel names Redact or include only with explicit user consent
Client nicknames Redact or include only with explicit user consent
Chat messages Exclude by default unless a future explicit opt-in policy is approved
Local file paths Minimize or redact user-identifying segments
Device IDs Redact or hash if collected
IP addresses Redact or minimize according to release policy

3. Diagnostic Surfaces

Surface Risk Required control
Application log Secret leakage Redaction filter and structured logging discipline
Protocol log Hostile or sensitive server content Redaction and length limits
Audio diagnostics Device privacy Device name minimization if needed
Export bundle Aggregated sensitive data Redaction audit before release
Error report Stack trace or secret context User-safe error mapping
User support copy/paste Over-sharing Explicit review and confirmation

4. Redaction Test Matrix

Test ID Input Expected output Status Evidence
REDACT-TC-001 Server password in connection data Password replaced by [REDACTED] PoC Pass poc/diagnostics-redaction-spike/tests/redaction.rs::redact_tc_001_server_password_in_connection_data
REDACT-TC-002 Identity secret in storage error Secret absent PoC Pass poc/diagnostics-redaction-spike/tests/redaction.rs::redact_tc_002_identity_secret_in_storage_error (via KnownSecretRegistry)
REDACT-TC-003 Server URL with password-like field Secret part redacted PoC Pass poc/diagnostics-redaction-spike/tests/redaction.rs::redact_tc_003_server_url_with_password_field — only the password value is redacted, the host and other query params keep flowing
REDACT-TC-004 Chat text in diagnostic export Excluded by default PoC Pass poc/diagnostics-redaction-spike/tests/redaction.rs::redact_tc_004_chat_text_excluded_by_default — default policy sets include_chat = false
REDACT-TC-005 Channel name with Unicode Preserved only if permitted; otherwise redacted safely PoC Pass poc/diagnostics-redaction-spike/tests/redaction.rs::redact_tc_005_channel_name_with_unicode_excluded_by_default — default policy excludes; UTF-8 preservation verified in TC-010
REDACT-TC-006 Nickname with Unicode Preserved only if permitted; otherwise redacted safely PoC Pass poc/diagnostics-redaction-spike/tests/redaction.rs::redact_tc_006_nickname_with_unicode_preserved_in_safe_field
REDACT-TC-007 Local file path User-identifying segments redacted or minimized PoC Pass poc/diagnostics-redaction-spike/tests/redaction.rs::redact_tc_007_local_file_paths_user_segment_minimized — Linux /home/<user>/, Windows C:\Users\<user>\, macOS /Users/<user>/ all minimized
REDACT-TC-008 Diagnostic bundle with mixed sensitive fields All sensitive fields redacted PoC Pass poc/diagnostics-redaction-spike/tests/redaction.rs::redact_tc_008_diagnostic_bundle_with_mixed_sensitive_fields — whole-bundle JSON scan finds no plaintext
REDACT-TC-009 Long hostile protocol string Truncated or safely escaped PoC Pass poc/diagnostics-redaction-spike/tests/redaction.rs::redact_tc_009_long_hostile_protocol_string_truncatedMAX_PROTOCOL_STRING_LEN = 256 cap with …[truncated] marker
REDACT-TC-010 Multilingual safe diagnostic text Unicode preserved PoC Pass poc/diagnostics-redaction-spike/tests/redaction.rs::redact_tc_010_multilingual_safe_text_preserved — Chinese, Japanese, Korean, and Latin-diacritic text preserved verbatim

5. Export Bundle Contents

Bundle item Included? Redaction rule Status
App version Yes None PoC Pass (DiagnosticBundle.app_version preserved verbatim)
Build number Yes None PoC Pass (DiagnosticBundle.build_number preserved verbatim)
Platform info Yes Minimize device details PoC Pass — flows through Redactor::redact_text, so embedded paths/usernames are minimized
Connection state Yes No secrets PoC Pass — flows through Redactor::redact_text
Server address Yes (redacted) Redact/minimize PoC Pass — passwords inside ts3server:// URLs redacted
Channel tree No by default Redact/minimize PoC Pass — default include_channel_tree = false
Chat history No by default Exclude unless explicit policy changes PoC Pass — default include_chat = false
Logs Yes Redacted PoC Pass — each log line flows through Redactor::redact_text
Audio diagnostics Yes No audio content PoC Pass — only device names are exported; no PCM
Secure storage data No Never include PoC Pass by construction — the redactor has no path that reads from SecretStorageRepository; the host application must never put secret material into the bundle in the first place

6. Findings

Finding ID Severity Description Status Owner
REDACT-FIND-001 Informational The PoC regex catalogue covers the documented audit matrix but is not exhaustive. Production chanora_diagnostics should add fuzz testing and adversarial inputs (e.g. base64 lookalikes, unicode confusables, regex evasion). Open Security Reviewer + chanora_diagnostics owner
REDACT-FIND-002 Informational The PoC redactor is a post-processor over strings. Production code should wire the redactor as a tracing-subscriber layer so redaction happens at write-time, not by re-walking text afterward. Open — to be addressed when chanora_diagnostics is scaffolded chanora_diagnostics owner
REDACT-FIND-003 Informational The KnownSecretRegistry defence-in-depth requires the secure-storage layer to register secrets when they materialise. The cross-spike contract is documented but not yet enforced by any product code. Open — to be enforced by chanora_storage calling into chanora_diagnostics. chanora_storage + chanora_diagnostics owners

7. Approval

Role Name Decision Date
Security Reviewer TBD Pending TBD
Privacy Reviewer TBD Pending TBD
QA / Verification Owner TBD Pending TBD

8. Change History

Version Date Description
0.9.0 2026-05-14 Initial diagnostic redaction audit report template.

Baseline Candidate 0.9.1 Update

Version Date Description
0.9.1 2026-05-14 Updated baseline after product decision closure: Apple App Store SDK gate uses Xcode 26+ and iOS 26 / iPadOS 26 SDK+ since 2026-04-28, platform baselines and decision traceability propagated across the document set.

Baseline Candidate 0.9.2 Update

Version Date Description
0.9.2 2026-05-14 Corrected Apple App Store Connect upload gate to 2026-04-28 and checked full-package naming, references, and coverage.

Baseline Candidate 0.9.3 Update

Version Date Description
0.9.3 2026-05-14 Recorded PoC empirical evidence: REDACT-TC-001..010 status set to PoC Pass with evidence pointers to poc/diagnostics-redaction-spike/tests/redaction.rs. Export bundle policy §5 populated for every row. Findings REDACT-FIND-001..003 added (regex coverage limits, tracing-layer integration gap, KnownSecretRegistry cross-spike contract).