Skip to content

fix(audit): remove the audit ledger when the run settles - #1336

Merged
gewenyu99 merged 5 commits into
mainfrom
posthog/fix-1326-audit-ledger-cleanup
Sep 24, 2026
Merged

gewenyu99 merged 5 commits into
mainfrom
posthog/fix-1326-audit-ledger-cleanup

Conversation

@gewenyu99

@gewenyu99 gewenyu99 commented Sep 23, 2026 •

Copy link
Copy Markdown
Collaborator

Problem

Audit runs can leave .posthog-audit-checks.json in the user's project root. The wizard writes that ledger before the agent starts, but only the agent's last skill step, rm -f .posthog-audit-checks.json, deletes it. In the sweep, one run skipped that step and left a 3929-byte untracked file next to the user's code. The user can commit it by accident.

Part of #1326. The misleading "denied" log for the rm is a separate PR, and dropping the rm step from the audit skills is a context-mill follow-up once this ships.

Changes

  • removeAuditLedger. Deletes the ledger, logs instead of throwing on failure.
  • runProgramAgent. Reads any last write, stops the watcher, then removes the ledger, in finally and abort cleanup.

Nothing flows here. The program that declares the file now removes it on success, a thrown run, and wizardAbort. Ctrl-C and SIGINT, SIGTERM and SIGHUP run the same cleanup once #1351 lands, which sends them all through one cancel path. That covers audit, events-audit and the audit family leaves, since they all set auditLedgerFile.

Nothing reads the file after the run. The outro and the task stream read the checks from the session (getAuditChecks(session)), which the watcher already filled. The only composed run, posthog-integration, has no ledger.

Test plan

Five tests in run-agent-legacy.test.ts seed a ledger in a temp project the way the agent does and never run the rm.

  • Removal. The ledger is gone after a settled run, a thrown run, and the abort cleanup. All three failed on main.
  • Failed removal. A directory at the ledger path is logged and the finished run still resolves.
  • Last write. A write the watch debounce hasn't read yet still reaches the session.

The failed-removal and last-write tests each fail when their fix is removed. pnpm typecheck, ESLint on the changed files (0 errors) and vitest run (199 files, 3354 tests) pass.

LLM context

Written by Claude Code while triaging the real-TUI sweep issues.

Created with PostHog Desktop

The wizard seeds .posthog-audit-checks.json in the project before the
audit agent starts, but only the agent's last skill step deleted it. A
run that skipped that step left an untracked JSON file in the user's
repo root.

runProgramAgent now removes the ledger after it stops the ledger
watcher, both in its finally and in the abort cleanup, so every exit
path cleans up. This covers audit, events-audit and the audit family
leaves, which all set auditLedgerFile.

Part of #1326

Generated-By: PostHog Desktop
Task-Id: d14e92bb-6ee1-49b5-8502-39cb80079589
@github-actions

Copy link
Copy Markdown

🧙 Wizard CI

Run the Wizard CI and test your changes against wizard-workbench example apps by replying with a GitHub comment using one of the following commands:

Test all apps:

  • /wizard-ci all

Test all apps in a directory:

  • /wizard-ci ai-observability
  • /wizard-ci basic-integration
  • /wizard-ci feature-flags
  • /wizard-ci mcp-analytics
  • /wizard-ci replay-vision
  • /wizard-ci revenue
  • /wizard-ci self-driving
  • /wizard-ci warehouse
  • /wizard-ci warehouse-seeded

Test an individual app:

  • /wizard-ci ai-observability/anthropic
  • /wizard-ci ai-observability/google-adk
  • /wizard-ci ai-observability/groq
Show more apps
  • /wizard-ci ai-observability/manual-capture
  • /wizard-ci ai-observability/openai
  • /wizard-ci ai-observability/openai-agents
  • /wizard-ci ai-observability/opentelemetry
  • /wizard-ci ai-observability/vercel-ai
  • /wizard-ci basic-integration/android
  • /wizard-ci basic-integration/angular
  • /wizard-ci basic-integration/astro
  • /wizard-ci basic-integration/django
  • /wizard-ci basic-integration/fastapi
  • /wizard-ci basic-integration/flask
  • /wizard-ci basic-integration/flutter
  • /wizard-ci basic-integration/javascript-node
  • /wizard-ci basic-integration/javascript-web
  • /wizard-ci basic-integration/laravel
  • /wizard-ci basic-integration/next-js
  • /wizard-ci basic-integration/nuxt
  • /wizard-ci basic-integration/python
  • /wizard-ci basic-integration/rails
  • /wizard-ci basic-integration/react-native
  • /wizard-ci basic-integration/react-router
  • /wizard-ci basic-integration/sveltekit
  • /wizard-ci basic-integration/swift
  • /wizard-ci basic-integration/tanstack-router
  • /wizard-ci basic-integration/tanstack-start
  • /wizard-ci basic-integration/vue
  • /wizard-ci feature-flags/django
  • /wizard-ci feature-flags/next-js
  • /wizard-ci mcp-analytics/custom-dispatcher
  • /wizard-ci mcp-analytics/typescript-sdk
  • /wizard-ci replay-vision/javascript-node
  • /wizard-ci replay-vision/next-js
  • /wizard-ci replay-vision/react-vite
  • /wizard-ci revenue/stripe
  • /wizard-ci self-driving/astro
  • /wizard-ci self-driving/fastapi
  • /wizard-ci self-driving/nuxt
  • /wizard-ci self-driving/react-router
  • /wizard-ci self-driving/sveltekit
  • /wizard-ci warehouse/monorepo-env
  • /wizard-ci warehouse/multi-source-next
  • /wizard-ci warehouse/stripe-node
  • /wizard-ci warehouse/zero-source
  • /wizard-ci warehouse-seeded/next-stripe
  • /wizard-ci warehouse-seeded/next-stripe-declined

Test against a Context Mill branch:

  • /wizard-ci all context-mill:my-branch

Add context-mill:<branch> to any command above to pin the Context Mill branch. It defaults to main.

Results will be posted here when complete.

gewenyu99 and others added 3 commits September 23, 2026 18:34
AGENTS.md keeps new code comments to one line.

Part of #1326

Generated-By: PostHog Desktop
Task-Id: d14e92bb-6ee1-49b5-8502-39cb80079589
releaseLedger now refreshes the watcher before it stops it, so a write
the 25 ms watch debounce hasn't read yet still reaches the session
before the file is deleted.

The auditLedgerFile doc and the ledger-watcher header now say the file
is removed at run end, and the removal comment no longer claims the
wizard seeded the ledger, since family leaves seed it through the
agent. A new test covers the removal's catch path: a directory at the
ledger path no longer fails a finished run.

Part of #1326

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Only the TUI runner handled SIGINT and SIGTERM. A headless or --ci run
that got a signal died on Node's default action, before any finally
or registered cleanup ran, so an audit cancelled mid-run still left
.posthog-audit-checks.json in the project.

runNonInteractive now installs a handler for the run that runs the
cleanups, settles the task stream as an error, and exits 130 through
wizardAbort as a cancellation. The handler is removed when the run
settles.

Part of #1326

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
#1351 routes ctrl+c, SIGINT, SIGTERM and SIGHUP through one cancel path
for both the TUI and headless runs, so this PR keeps only the ledger
removal it registers as a cleanup.

This reverts commit f9fc462.

Part of #1326

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

@edwinyjlim edwinyjlim left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm

@gewenyu99
gewenyu99 merged commit e63b0ad into main Sep 24, 2026
20 checks passed
@gewenyu99
gewenyu99 deleted the posthog/fix-1326-audit-ledger-cleanup branch September 24, 2026 17:45
gewenyu99 added a commit that referenced this pull request Sep 25, 2026
Carries main's audit ledger removal (#1336) through the adapter.

Generated-By: PostHog Desktop
Task-Id: d14e92bb-6ee1-49b5-8502-39cb80079589
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants