Skip to content

feat(patterns): opt-in typed Drain3 masking for template slots - #4

Merged
catinspace-au merged 3 commits into
mainfrom
feat/typed-masking
Aug 18, 2026
Merged

catinspace-au merged 3 commits into
mainfrom
feat/typed-masking

Conversation

@catinspace-au

Copy link
Copy Markdown
Contributor

The DFE synthetic-data generator inverts logreducer templates, and typed slots make that inversion reliable - tells the generator exactly what to synthesise where a bare <*> forces guessing.

typed_masking=False (the default) is byte-identical to today: no masking instructions are configured and every existing test passes unchanged. On, a curated ordered set masks IPv4, UUID, MAC, best-effort IPv6, hex tokens and numbers before clustering. Order is load-bearing (instructions run sequentially over already-masked text) so the specific shapes precede the greedy ones, IPv6 requires the full form or a :: so timestamps stay unmasked, and HEX requires 0x or an a-f letter so long decimals stay NUM. Pattern examples still carry the original unmasked lines.

Done when: 46 touched-file tests green, full suite green apart from one pre-existing throughput flake (passes in isolation) and lint/type baselines A/B-verified identical to main. Drain3 masking API verified from the installed 0.9.11 source.

typed_masking=False stays byte-identical to today. On, a curated
ordered masking set (IP, UUID, MAC, IPv6 best-effort, HEX, NUM) runs
before clustering so templates carry typed slots (<IP>, <NUM>, ...)
instead of the bare <*> - the DFE synthetic-data generator inverts
those templates and typed slots make slot classification reliable.
Opt-in because masking normalises lines BEFORE Drain3 clusters them,
so cluster boundaries can differ from the unmasked default. Examples
still carry the original unmasked lines.
docs/JIRA_OAUTH_SETUP.md shows a curl example with the literal
ACCESS_TOKEN placeholder in an Authorization header (committed
2025-08-26); gitleaks' curl-auth-header rule flags it on every scan of
history. Documentation, not a credential - path-allowlisted.
pip-audit blocks the Quality gate on the lock's 49.0.0 - the PKCS#7
Bleichenbacher oracle already bumped across the fleet. Security fix,
cooldown bypassed per the pinning rules; unit suite green on 50.0.0.
@catinspace-au
catinspace-au merged commit 253064b into main Aug 18, 2026
15 checks passed
@catinspace-au
catinspace-au deleted the feat/typed-masking branch August 18, 2026 01:16
@github-actions

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant