Copy, from origin/master 0a63474 (site audit). The home and miner pages named "PC 1" in the figure captions, the
page-by-page lead, two alt texts, the Ember Tune table title, the Ember row's source line and the home pill; they now
say "a Windows rig with an RTX 5090, RTX 4070 and RX 9070 XT" at the first mention on each page and "the Windows rig"
after. The generated pages carried the same names from the bench-log (80 on /bench, 7 on /evidence, the inlined
journey on the home page): site/scrub.mjs now maps PC 1 to "the three-card Windows rig (RTX 5090, RTX 4070, RX 9070
XT)" and PC 2 to "the RTX 5090 Windows rig", build.mjs re-scrubs the stored journey entries, two /bench anchors on the
miner page follow the renamed headings, and \bPC [12]\b joins site/forbidden-strings.txt so the build fails if a number
returns. The scrub also covers the audit's other page-leak shapes (a pid, 0.0.0.0:port, ~/.config paths, --rpclisten=),
which the bench page carried and which now fail the build if they return.
CI: tools/ci/forbidden-strings.txt's appended audit block sat on one physical line with literal \n text, so none of its
patterns was active; \bPC [12]\b is now a real line there and the identity check's export scrub maps the two machines
the same way (igneum-public/tools/sync.sh must carry the same two rules). The other four audit patterns moved to
site/forbidden-strings.txt, since the public export carries simulator schedule logs where a pid is a pid. The identity
check gains a second pass over every served file under site/ (html, json, txt, xml, webmanifest, css, js; not api/ or
the build scripts), unscrubbed, with both pattern lists; dl\.igneum is narrowed to the tokened path so the public
download buttons pass. Shown to fire on a page naming PC 1 (exit 1) and to pass on the tree (0 hits over 232 export
files and 32 served site files).
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
29 lines
1.5 KiB
Text
29 lines
1.5 KiB
Text
# Patterns that must never appear in the public export (grep -E, one per line, # comments ignored).
|
|
# This is the committed, non-secret subset of the public mirror's identity list (igneum-public/tools/identity.local,
|
|
# which stays private because its remaining entries would themselves name what must stay out). Machine names, LAN
|
|
# and overlay addresses, home paths, local time zones and the log-intake key pattern. Never a key, never a name.
|
|
# Checked by tools/ci/identity-check.sh over the export list of igneum-public/tools/sync.sh after its generic scrub.
|
|
# Not forbidden (decision of 5 October 2026): the registered address of Igneum Labs LTD, Innovation One, Dubai International
|
|
# Financial Centre (DIFC). It is the one location that may appear in public text. The founder and the earlier entity stay in
|
|
# the private list.
|
|
DESKTOP-[A-Z0-9]{7}
|
|
MacBook
|
|
192\.168\.
|
|
100\.[0-9]+\.[0-9]+\.[0-9]+
|
|
\+0100
|
|
\bBST\b
|
|
/Users/
|
|
C:\\Users
|
|
~/Desktop
|
|
log-intake
|
|
LOG_INTAKE
|
|
intake[_-]?key
|
|
Tailscale
|
|
tailscale
|
|
ts\.net
|
|
|
|
# 6 October 2026, the public ledger page leak (site audit): the two Windows machines are described, never numbered. The
|
|
# audit's other patterns (config paths, process ids, listen addresses, --rpclisten=) live in site/forbidden-strings.txt:
|
|
# they are for the served pages, and the public export carries simulator schedule logs where a pid is a pid. (The block
|
|
# had been appended as one line with literal \n text, so none of it was active until the evening of 6 October 2026.)
|
|
\bPC [12]\b
|