Repository navigation
fix(audit): remove the audit ledger when the run settles - #1336
Merged
Merged
Conversation
The wizard seeds .posthog-audit-checks.json in the project before the audit agent starts, but only the agent's last skill step deleted it. A run that skipped that step left an untracked JSON file in the user's repo root. runProgramAgent now removes the ledger after it stops the ledger watcher, both in its finally and in the abort cleanup, so every exit path cleans up. This covers audit, events-audit and the audit family leaves, which all set auditLedgerFile. Part of #1326 Generated-By: PostHog Desktop Task-Id: d14e92bb-6ee1-49b5-8502-39cb80079589
🧙 Wizard CIRun the Wizard CI and test your changes against wizard-workbench example apps by replying with a GitHub comment using one of the following commands: Test all apps:
Test all apps in a directory:
Test an individual app:
Show more apps
Test against a Context Mill branch:
Add Results will be posted here when complete. |
AGENTS.md keeps new code comments to one line. Part of #1326 Generated-By: PostHog Desktop Task-Id: d14e92bb-6ee1-49b5-8502-39cb80079589
releaseLedger now refreshes the watcher before it stops it, so a write the 25 ms watch debounce hasn't read yet still reaches the session before the file is deleted. The auditLedgerFile doc and the ledger-watcher header now say the file is removed at run end, and the removal comment no longer claims the wizard seeded the ledger, since family leaves seed it through the agent. A new test covers the removal's catch path: a directory at the ledger path no longer fails a finished run. Part of #1326 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Only the TUI runner handled SIGINT and SIGTERM. A headless or --ci run that got a signal died on Node's default action, before any finally or registered cleanup ran, so an audit cancelled mid-run still left .posthog-audit-checks.json in the project. runNonInteractive now installs a handler for the run that runs the cleanups, settles the task stream as an error, and exits 130 through wizardAbort as a cancellation. The handler is removed when the run settles. Part of #1326 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
gewenyu99
added a commit
that referenced
this pull request
Sep 25, 2026
Carries main's audit ledger removal (#1336) through the adapter. Generated-By: PostHog Desktop Task-Id: d14e92bb-6ee1-49b5-8502-39cb80079589
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
Audit runs can leave
.posthog-audit-checks.jsonin the user's project root. The wizard writes that ledger before the agent starts, but only the agent's last skill step,rm -f .posthog-audit-checks.json, deletes it. In the sweep, one run skipped that step and left a 3929-byte untracked file next to the user's code. The user can commit it by accident.Part of #1326. The misleading "denied" log for the rm is a separate PR, and dropping the rm step from the audit skills is a context-mill follow-up once this ships.
Changes
removeAuditLedger. Deletes the ledger, logs instead of throwing on failure.runProgramAgent. Reads any last write, stops the watcher, then removes the ledger, infinallyand abort cleanup.Nothing flows here. The program that declares the file now removes it on success, a thrown run, and
wizardAbort. Ctrl-C and SIGINT, SIGTERM and SIGHUP run the same cleanup once #1351 lands, which sends them all through one cancel path. That coversaudit,events-auditand the audit family leaves, since they all setauditLedgerFile.Nothing reads the file after the run. The outro and the task stream read the checks from the session (
getAuditChecks(session)), which the watcher already filled. The only composed run, posthog-integration, has no ledger.Test plan
Five tests in
run-agent-legacy.test.tsseed a ledger in a temp project the way the agent does and never run therm.The failed-removal and last-write tests each fail when their fix is removed.
pnpm typecheck, ESLint on the changed files (0 errors) andvitest run(199 files, 3354 tests) pass.LLM context
Written by Claude Code while triaging the real-TUI sweep issues.
Created with PostHog Desktop