Adds internal/sanitize: rewrites the customer-identifying spans that
internal/privacy detects (domain/FQDN/e-mail/AD/public-IP/timezone) with
same-length neutral fillers, in place, without changing the file format.
- Fillers keep byte length: "sigma.sbrf.ru" -> "xxxxx.xxxx.xx", IP ->
"00.000.000.00", "Europe/Moscow" -> "Etc/Universal" (same-length valid
neutral IANA zone), offset "180" -> "000". Timestamps are not recomputed.
- Lossless recursive archive walk (tar/.sds/gz/tgz/zip): entry names, modes,
and all embedded timestamps preserved; untouched zip entries copied raw;
member payload length unchanged so tar headers stay byte-identical; only the
.gz/.zip compression layer is rebuilt. 0 redactions -> byte-identical output.
- privacy.FindSpans is the one matcher shared by detection and redaction;
fillers are recognised by isRedactionFiller so a re-scan / second pass is a
no-op. New privacy FPs fixed along the way: syslog selectors (local7.info),
"MEVersion" firmware quads, *.conf_bak vendor templates, bundled viewer
domains.
- Binary members (FRU.bin, localtime, redis-dump.rdb, SOL captures) and
unreadable nested archives are reported in Result.SkippedBinary, never edited.
- Surfaces: POST /api/sanitize (+ GET /api/sanitize/download), the "Обезличить
и скачать копию" button in the Customer-data panel, and
logpile -sanitize <file> (restores mtime/atime).
Verified: re-parsing a sanitized Dell TSR / xFusion / Inspur onekeylog / H3C
.sds yields the identical hardware inventory; re-scan is clean. ADL-067,
bible-local/docs/log-sanitization.md.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Cross-checked internal/privacy against the batch companion-app report over
project/rma. Fixes for the dominant false-positive classes:
- Real-TLD gate (tld.go): FQDN/e-mail must end in a curated TLD or a
pseudo-TLD with a >=3-char label; two-letter file/code suffixes
(.sh .so .md .id .service ...) are a hard denylist. Kills "0.linux"
(45996 hits), "mountall.sh", "libc.so", "@odata.id",
"serial-getty@ttyAMA0.service".
- Clean-token boundary + Title-case reject: "auth.backend.gssapi.store-creds",
"OS.It" are code, not hosts.
- Kernel ring-buffer ("[ 8.07][ T1] ...") and Go stack-trace lines skipped.
- resolv domain/search values must contain a dot ("domain 53" -> out).
- IPv4: skip comment lines, version/spec lines (X.Org, IEEE Std, l0fw_ver),
"0."/"1."/".0" quads; allowlist Yandex resolvers + RFC3849 2001:db8::/32.
- fru_location: drop all-digit / serial-like / field-name-echo values.
- Drop the hostname rule (zero real hits, only "bmc-state-manager" noise).
- domain category: high -> low, medium at 3+ labels. Real customer signal
now comes from resolv/nsupdate/ad_ldap/mgmt, which the corpus confirms
catches every actual customer (netwell.local, tcsbank.ru).
- Allowlist smartmontools.org, openib.org, apache.org, freebsd.org,
golang.org, ipxe.org, nvidia.com and other FOSS/vendor infra; skip
LOGPile's own raw_export.json / parser_fields.json / collect.log members.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Detection-only scan (internal/privacy) attached to every AnalysisResult:
a customer-domain guess plus a findings list (category, file, line, match,
hint), ported from the KB grep playbook. Runs on archive uploads and the
serialized Redfish tree; gated by LOGPILE_PRIVACY_SCAN (default on).
Surfaced at GET /api/privacy-scan, in the "Customer data" UI panel, and as
privacy_report.json in the raw-export bundle. IP policy keeps RFC1918 and
example ranges out of findings; allowlist covers standards-body and vendor
infrastructure domains. No customer tokens in the repo. See ADL-066 and
bible-local/docs/privacy-scan.md.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>