Fix Import Redaction Config for Checkpoints

Claude Code·Opus 4.8·computermode·3mo ago·18min·1 Checkpoint·7 file changes·+105/-23·43.8K tokens

Fix only the selected review findings. Do not rewrite unrelated code. Run targeted tests where practical, then report what changed and what verification passed.

Reviewed commit: c4bfa4f340d3cb60a025920aee7c5a812d05bb60 Worktree: /Users/ninawork/entire/devenv/cli

Selected findings

Codex findings: High:** entire import claude-code bypasses configured redaction initialization before...

High:** entire import claude-code bypasses configured redaction initialization before writing imported transcripts. The command calls agentimport.Run directly (import_cmd.go), and the importer redacts with redact.JSONLBytes (agentimport.go), but it never calls strategy.EnsureRedactionConfigured(), which is documented as required before checkpoint writes and loads opt-in PII, custom_redactions, and redactor packs (common.go). Always-on redaction still runs, but repo/user-configured rules are skipped for imported history. Add the initialization before import writes and cover it with a custom-redaction test.

Codex findings: Medium:** Imported provenance persists local absolute transcript paths, and also stores...

Medium:** Imported provenance persists local absolute transcript paths, and also stores a SHA-256 over the raw turn slice. The metadata schema explicitly stores transcript_path as “absolute path at import time” (metadata.go), and writeTurn writes sf.Path into checkpoint metadata (agentimport.go). ContentHash is computed from raw, unredacted turn bytes before redaction (claude.go). Since imported checkpoints live on the normal v1 metadata branch, this can publish local usernames/repo paths and enables confirmation attacks against guessed raw content. Prefer omitting the path, storing only basename/source/session/line bounds, and hashing redacted content if a hash is needed.

Codex findings: Medium:** The working tree includes untracked raw transcript/debug artifacts and Mach-O...

Medium:** The working tree includes untracked raw transcript/debug artifacts and Mach-O binaries in review scope. For example, full-example.jsonl contains raw Claude transcript data with local paths and prompt content (full-example.jsonl); transcript-output.jsonl, metadata-example.json, compact-debug, and migrate-v2-checkpoints are also untracked. These should be removed, ignored, or sanitized before any PR/commit.

Codex findings: Low:** Imported checkpoints are read-only and --generate is refused ([explain.go](/Us...

Low:** Imported checkpoints are read-only and --generate is refused (explain.go), but normal explain output still tells users to run entire explain --generate <id> when no summary exists (explain.go). Gate that hint on summary.Imported. Verification

  • go test ./cmd/entire/cli/agentimport ./cmd/entire/cli/checkpoint ./api/checkpoint
  • go test ./cmd/entire/cli
  • git diff --check origin/HEAD...HEAD No code changes made.
3mo ago·17m

All five files deleted (the ls error just confirms they're gone). All four findings are addressed.

What changed

Finding 1 (High) — redaction config bypass · cmd/entire/cli/import_cmd.go Added strategy.EnsureRedactionConfigured() before agentimport.Run, so imported transcripts get repo/user-configured opt-in PII, custom_redactions, and redactor packs — not just always-on secret scanning. Covered by a new test (TestRun_AppliesConfiguredCustomRedaction) that configures an inline custom rule, imports a transcript containing the marker, and asserts the stored transcript is redacted.

Finding 2 (Medium) — provenance leaks · api/checkpoint/metadata.go, cmd/entire/cli/agentimport/{agentimport,claude}.go

  • Renamed Provenance.TranscriptPath (absolute path) → TranscriptFile (json transcript_file), now storing only filepath.Base(sf.Path) — no more local usernames/repo layout published to the v1 branch.
  • Moved ContentHash computation out of claude.go (where it hashed raw bytes) into Run, where it hashes the redacted turn slice via a new contentHash helper — closing the confirmation-attack vector against guessed raw content. Dropped the now-unused Turn.ContentHash field and crypto/sha256/encoding/hex imports from claude.go.

Finding 4 (Low) — misleading explain hint · cmd/entire/cli/explain.go Gated the --generate hint on summary.Imported; imported checkpoints now show "Imported history is read-only, so summaries cannot be generated." instead of pointing at a command that errors out.

Finding 3 (Medium) — untracked artifacts Deleted (per your choice): full-example.jsonl, transcript-output.jsonl, metadata-example.json, compact-debug, migrate-v2-checkpoints. Note: other untracked debug files remain (e.g. pr864-*.json/txt, deadcode-all.txt, err.log, review-0*.md, entire-checkpoints-playground.html) — the finding named only these five; say the word if you want those handled too.

Verification passed

  • go test ./cmd/entire/cli/agentimport ./cmd/entire/cli/checkpoint ./api/checkpoint — ok
  • go test ./cmd/entire/cli — ok
  • mise run fmt && mise run lint — 0 issues
  • git diff --check — clean (exit 0)

E2E tests not run (real API calls; not requested).

push up the changes

3mo ago·47.9s

Pushed. c4bfa4f34..1747e427b on import-existing-claude-projects.

Commit 1747e427b — the four review fixes (redaction config init, provenance basename, redacted-content hashing, gated explain hint) plus the custom-redaction test. Lint clean and the targeted tests passed before push. The five deleted artifacts were untracked, so they're not part of the commit.