Skip to content

Audit integrity verification silently excludes retained rotated segments #390

Description

@Calmingstorm

Confirmed audit-verification coverage gap

Reviewed master at 886c36d8ebe861aa987059a1744d45b78797baae (v4.7.0). Suggested priority: P2.

Audit rotation retains signed .1….N segments with independent chain roots, but verify_integrity verifies only the active file. The UI's “Verify integrity” result reports a valid chain without stating that rotated retained history was excluded.

Isolated reproduction

With a temporary AuditLogger, synthetic HMAC key, max_bytes=1 and max_files=2, write two records to force rotation. Verify, alter only a field in audit.jsonl.1, and verify again.

rotated_exists: true
before_valid: true
after_valid: true
verified: 1

Independently reproduced twice with disposable files. No live audit data or signing material was used. Current-file integrity checking itself still works; the claim is omitted history coverage.

Acceptance criteria

  • Verify every retained signed segment independently and aggregate failure, or explicitly scope the current operation to the active file and offer a retained-history verification action.
  • Show verified/skipped files, unsigned prefixes, missing/unreadable segments and per-segment failure locations.
  • Preserve existing independent per-file chain semantics; do not imply verification proves completeness of deleted history.
  • Add a rotated-only tampering regression and rotation-during-verification handling.

Behavior change: tampered retained segments become visible or current coverage is made explicit. No source changes were made.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions