Docs: data-boundary contract v1 in EGRESS.md, guarded, with the egress tests running in CI - #5958
Conversation
✅ Drift Bot (ClawMetry): no drift detectedDrift Bot analyzed the changed files against this project's blueprints and requirements and found no drift. |
1 similar comment
✅ Drift Bot (ClawMetry): no drift detectedDrift Bot analyzed the changed files against this project's blueprints and requirements and found no drift. |
b4872cb to
e8b7b05
Compare
✅ Drift Bot (ClawMetry): no drift detectedDrift Bot analyzed the changed files against this project's blueprints and requirements and found no drift. |
1 similar comment
✅ Drift Bot (ClawMetry): no drift detectedDrift Bot analyzed the changed files against this project's blueprints and requirements and found no drift. |
6c1ed8d to
abd8983
Compare
✅ Drift Bot (ClawMetry): no drift detectedDrift Bot analyzed the changed files against this project's blueprints and requirements and found no drift. |
Non-mergeable PR sweeper — run summary (2026-09-14)vivekchand/clawmetryRebased (13 PRs): Skipped — not conflicted (mergeable_state ≠ dirty): Skipped — bot/auto-generated: Comment-only (aborted — non-trivial): none vivekchand/clawmetry-landingRebased (1 PR): Skipped: none vivekchand/clawmetry-cloudNo open conflicted PRs found. Conflict resolution approach used throughout:
Generated by Claude Code |
abd8983 to
8987304
Compare
✅ Drift Bot (ClawMetry): no drift detectedDrift Bot analyzed the changed files against this project's blueprints and requirements and found no drift. |
1 similar comment
✅ Drift Bot (ClawMetry): no drift detectedDrift Bot analyzed the changed files against this project's blueprints and requirements and found no drift. |
|
Updated to current main via Generated by Claude Code |
Test plan & review notesRepo: vivekchand/clawmetry
Smoke commands # All three test files:
python -m pytest tests/test_data_boundary_contract.py tests/test_egress_suppression.py tests/test_telemetry.py -v
# Regression proof (confirm the guard works):
git stash # temporarily restore main's EGRESS.md
python -m pytest tests/test_data_boundary_contract.py -v # should fail on test_egress_doc_declares_the_contract
git stash pop
# CI workflow sanity (confirms the new job steps reference real test files):
python -m pytest tests/test_workflow_yaml_valid.py tests/test_ci_workflow_invocations_are_real.py -vThings to check
Likely failure modes
Issue link Generated by Claude Code |
|
✨ auto-fixed: merged main into branch (was BEHIND) Generated by Claude Code |
✅ Drift Bot (ClawMetry): no drift detectedDrift Bot analyzed the changed files against this project's blueprints and requirements and found no drift. |
…ress tests in CI Cloud sync off is not offline: it stops uploads, while the install ping, the failure report and the PyPI check still run until CLAWMETRY_OFFLINE=1. EGRESS.md now says so as a versioned contract, states how the cloud stores the account key, and stops claiming the encryption key never leaves the machine: it reaches the browser, a paired device and, during a dashboard rotation, the cloud. tests/test_data_boundary_contract.py pins that behaviour. The existing test_egress_suppression.py and test_telemetry.py were named in no CI job; they now run in the MOAT verifier job alongside it. Refs vivekchand/clawmetry-landing#744 Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Jm9d7s4fN55hN3YzQo75o9
9b80e13 to
cf80c9c
Compare
|
PR sweeper: Generated by Claude Code |
✅ Drift Bot (ClawMetry): no drift detectedDrift Bot analyzed the changed files against this project's blueprints and requirements and found no drift. |
✅ Drift Bot (ClawMetry): no drift detectedDrift Bot analyzed the changed files against this project's blueprints and requirements and found no drift. |
1 similar comment
✅ Drift Bot (ClawMetry): no drift detectedDrift Bot analyzed the changed files against this project's blueprints and requirements and found no drift. |
Refs vivekchand/clawmetry-landing#744
Product record: https://factory.8090.ai/project/b415065f-ab2f-4f53-8864-0c009fd098cb/requirements/293c9122-ce60-4809-bb00-887acef0b414 (REQ-DBC-001, AC-DBC-005.3)
Why
The public site's storage and egress claims were wrong in ways a security reviewer would find on the wire: "cloud off: no network destination", "we never store the raw key", "the key never leaves your machine".
docs/EGRESS.mdis the inventory those pages summarise, and it carried one of the same errors itself ("the key never leaves your machine") while also saying the key is handed to the browser.What
docs/EGRESS.md: data-boundary contract version 1. Cloud sync off (CLAWMETRY_NO_CLOUD=1,onboard --local) is not offline.DO_NOT_TRACK=1stops the install ping and failure report but not the PyPI check;CLAWMETRY_OFFLINE=1stops every discretionary request. Adds the hosted ingest push row (readable, not sealed). States that the cloud stores the account key alongside its hash and that it cannot decrypt. Replaces "Data that never leaves the machine" with "Data ClawMetry does not store" and lists where the encryption key actually travels: browser (URL fragment), paired desk device (sealed to its key), and the cloud during a web-dashboard key rotation (/api/account/secret-keyrelays the caller-supplied key through the node command queue).tests/test_data_boundary_contract.py(7 tests): cloud sync off stops uploads, but the install ping, failure report and PyPI check are still reached; a telemetry opt-out stops the ping and failure report only; offline stops every discretionary request; content endpoints refuse without a key; EGRESS.md carries the contract and no longer says the key never leaves the machine..github/workflows/ci.yml: the new file plustests/test_egress_suppression.pyandtests/test_telemetry.py. Neither existing file was named in any job, so the offline and opt-out guards had never run in CI.No product code changes. No new routes, so no cloud route-policy entry is needed.
Verified
pytest tests/test_data_boundary_contract.py tests/test_egress_suppression.py tests/test_telemetry.py: 81 passed (Python 3.11 venv, scratch HOME).main'sdocs/EGRESS.mdrestored,test_egress_doc_declares_the_contractfails (1 failed, 6 passed); with this change, 7 passed.tests/test_workflow_yaml_valid.pyandtests/test_ci_workflow_invocations_are_real.py: 595 passed.Paired PR
Landing copy that consumes this contract, with its own claims guard: https://github.com/vivekchand/clawmetry-landing/pull/824
🤖 Generated with Claude Code
https://claude.ai/code/session_01Jm9d7s4fN55hN3YzQo75o9