docs(tasks): accept the report density round and remove birth data from its brief

Acceptance of f968cb21 against TASK-report-density-20260922. Tasks 1, 2, 4
and 5 pass; task 3 does not. Under Node 22, the gate's version, the frontend
suite goes from 3,698 tests / 26 failing to 3,730 / 26 with an identical
failure list; / stays static and first-load gzip moves by 0.007%.

Task 3 renders the ordinary report's fact tables as 948 key/value rows whose
labels are engine paths: 447 carry snake_case keys and 521 carry array
indices, down to a Julian day. The brief never specified columns, so the fix
brief does.

The quick gate's new failure is the privacy scan, and two thirds of it is
mine: the brief pushed in baeec66f carried the comparison chart's real birth
date, time and coordinates. They are removed here and recorded as BUG-1008.
The copy in baeec66f's history stays until the product owner decides whether
to rewrite staging. The remaining hit is a five-character collision inside an
engine timestamp of the fictional fixture, reproduced by regenerating from its
declared fictional input.

Privacy scan on this tree before push: one finding, the fixture collision.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017eEAG8HD3mm8gsKXgk8uU8
This commit is contained in:
Jesse_Chen
2026-09-23 14:07:20 +08:00
co-authored by Claude Opus 5.5
parent bbd96d3b6b
commit abf2832180
3 changed files with 214 additions and 1 deletions
+17
View File
@@ -13295,3 +13295,20 @@
- 相关记录:BUG-936
- 复发自:无
- 修复版本:本分支,尚未部署
## BUG-1008 | 任务书写入真实个人出生资料并推到 staging
- 状态:mitigated(HEAD 已清除;staging 历史仍含该资料,是否重写由产品负责人决定)
- 首次发现:2026-09-23
- 最近更新:2026-09-23
- 影响面:`docs/tasks/TASK-report-density-20260922.md`,自 staging `baeec66f` 起;Gitea staging 历史。GitHub 只读镜像最后同步于 2026-08-14(`12414971`,落后 1,314 个提交),**尚未包含**这份资料。
- 用户现象:无用户界面现象。隐私门 `tests/test_repo_privacy_markers.py::test_tracked_repository_has_no_privacy_markers` 在下一次代码推送 `f968cb21` 上命中 R001 / R003,指向该任务书第 13 行,使该实现的门禁变红。
- 触发条件:撰写任务书的对照实测段落时,把对照报告那张盘的出生日期、时刻与经纬度原样写入;同一文件第 7 行还写入了含个人姓名的本机路径。
- 根因:纯文档推送不触发门禁(`docs/**` 不在 `deploy/gated-paths.txt`),隐私扫描只在之后第一次含门禁路径的推送时运行。撰写者推送前没有自跑扫描。任务书的硬红线第 6 条写了"出生资料不进仓",但撰写者自己的实测段落没有过同一把尺。
- 修复:两处改为不含资料的描述(`TASK-report-density-fix-20260923` 同一提交)。
- 验证:修复后在 staging-docs 树上重跑同一扫描,只剩 1 处,为新 fixture 的数值碰撞(已独立重跑确认是虚构输入的引擎时间戳,见 BUG-1010)。
- 防复发:凡是写入实测数字的文档,推送前必须跑 `python3 -m pytest tests/test_repo_privacy_markers.py -q`,结果写进提交说明。实测段落只写"真实个人资料"或虚构 / 公开名人输入,不写具体值。建议(需产品负责人决定,涉及 `.gitea/workflows/**`):让纯文档推送也跑隐私扫描。
- 未决:`baeec66f` 的 blob 仍在 staging 历史里。清除需要强推重写 staging,会连带改写 `f968cb21`。在决定之前 GitHub 镜像不得重新同步。
- 相关记录:BUG-999
- 复发自:无(与 2026-09-20 的本仓个人案例清除属同一类资料)
- 修复版本:`docs(tasks)` 验收提交(本条所在提交)