Repository navigation
feat(v1.10): audit-log entries for manual-flag writes - #75
Merged
Merged
Conversation
mark_mqg_complete and clear_mqg_flag write one audit entry per book through the existing audit_log choke point: source="flag", step="flag:<command>", new_value True (mark) / null (clear), no confidence. The "flag:" namespace is load-bearing: regrade staleness filters on exact AI step names, so a bare command name would make a flagged book look freshly enriched. No confidence keeps flag entries out of the calibration pool. Both reader contracts are locked by tests, plus the regrade-marker ride-along case. New autouse conftest fixture redirects CALIBRE_TOOLKIT_AUDIT_LOG to tmp_path so db-level tests stop short of the real audit log. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Item 3 of the v1.10 preflight (
docs/planning/v1.10-charter.md). Closes the one live correctness gap from the v1.9 known-limitations list: flag writes left no trail, and the campaign will generate thousands of them.What changed
db.py— logging at the choke point.mark_mqg_completeandclear_mqg_flagnow write one audit entry per book through the existingaudit_logchoke point, after the SQLite commit. Entry shape:field= the column,new_value=true(mark) /null(clear),source="flag",step="flag:<command>", noconfidence. Putting it in the db methods (rather than the 11 call sites) means every current and future caller — includingtags-review's per-book lock — is covered for free; callers pass their command name via a newaudit_stepkeyword.The
flag:step namespace is load-bearing. The charter's design constraint was that neither audit reader confuses a flag event with an AI write — confirmed against both filters:load_audit_records,commands/audit.py:102) keeps only records with non-emptyconfidenceANDsourceANDstep. Flag entries carry no confidence → excluded.find_stale_books,commands/regrade.py:56) filters on exact step name only (lcc-enrichetc.). A flag entry with a bare command-name step would have made a flagged book look freshly enriched and silently dropped it from regrade.flag:lcc-enrich≠lcc-enrich, so flag writes never refresh staleness.Callers — all 11 sites across 8 commands pass their command name (
clean-titles,comments-enrich×2,enrich-identifiers×2,lcc-enrich×2,tags-enrich×2,tags-review×2,unflag-manual). Bulk marks write per-book entries deliberately (charter: history must be reconstructible per book; accept the volume).Regrade marker ride-along. A flag write inside a
regrade_auditcontext picks up theregrademarker at the choke point — harmless per the charter (both readers exclude the entry on other fields), and locked by a test.Test isolation. New autouse conftest fixture redirects
CALIBRE_TOOLKIT_AUDIT_LOGtotmp_pathfor every test — without it, the existingtest_clear_mqg_flag.pydb-level tests would now append to the real~/.calibre-toolkit/audit.logon every suite run.Verification
python -m pytest -q— 647 passed (8 new contract tests: per-book entry shape for mark and clear, bare-flagdefault, no entry on the unknown-column no-op/raise paths, calibration exclusion, regrade-staleness exclusion, regrade-marker ride-along).#mqg_identifiers_manual) throughmark_mqg_complete, cleared it with the realunflag-manual id:=2 --auto-apply, andaudit-log --book-id 2shows both entries (flag:smoke,flag:unflag-manual). Library state net-unchanged (row deleted, back to undefined).🤖 Generated with Claude Code