Skip to content

fix: scan recent files recursively instead of one level deep - #14

Merged
pd241008 merged 7 commits into
mainfrom
feature/production-structure
Sep 23, 2026
Merged

pd241008 merged 7 commits into
mainfrom
feature/production-structure

Conversation

@pd241008

Copy link
Copy Markdown
Owner

No description provided.

Report kept duplicate state (rendered `lines` plus structured `entries`)
that could drift apart, and only exposed a raw epoch timestamp.

- derive rendered output from entries at join()/to_json() time instead
  of maintaining a parallel `lines` vec
- expose findings()/entries()/severity_counts() accessors; fields are
  now private
- record a human-readable ISO-8601 timestamp alongside the epoch value
- merge duplicate section headers on render so interleaved section()
  calls can no longer split a section in the output
- update diff.rs and main.rs to the accessor API
Files dropped in subdirectories of temp/download folders (e.g.
/tmp/subdir/payload) were never seen by the recent-files check.

- walk scanned roots to a fixed depth cap (4) so deeply nested or
  adversarially constructed trees cannot blow up the scan
- do not follow symlinks during traversal to avoid cycles and escapes
  outside the scanned directory
- unit-test that nested files are found and beyond-cap files are not
The pattern list included "com.", so virtually every macOS bundle ID
( nearly all start with com. ) produced a finding — the check reported
noise instead of signal.

- match generic fragments like "com." via allowlist instead: bundle IDs
  containing any allowlisted fragment are skipped before patterns are
  applied
- seed the allowlist with common vendor prefixes so the default config
  is usable out of the box
- make patterns configurable via [macos] network_extension_patterns /
  network_extension_allowlist in sentrix.toml
- document both keys in sentrix.example.toml
…rectly

wmic is deprecated and removed from recent Windows 11 builds, so the
service/WMI checks silently did nothing; CSV splitting on commas broke
paths that contain commas; and UTF-16 output decoded as UTF-8 produced
mojibake that no pattern could match.

- fall back to PowerShell CIM (Get-CimInstance) queries when wmic is
  absent for process, service, scheduled-task and WMI event-consumer
  checks
- decode command output via BOM sniffing (UTF-8 / UTF-16LE / UTF-16BE),
  falling back to lossy UTF-8
- parse CSV with a quote-aware parser and select columns by header name
  instead of fixed positions, so values containing commas and reordered
  columns both work
- unit-test decoding and CSV parsing (cfg(windows), run on CI Windows
  runners)
cargo clippy without --all-targets skipped #[test] code, letting lints
like boolean-comparison violations (== true asserts) into the tree.

- run clippy with --all-targets so tests are linted
- replace the assert_eq!(x, true) in diff tests with a plain assert!
PROGRESS.md marked coverage tooling and a badge as complete, but CI had
no coverage job and the repo carried no coverage tooling at all.

- add a coverage job to CI: cargo-llvm-cov generates an lcov report and
  uploads it to Codecov (non-blocking)
- correct the PROGRESS.md roadmap item to reflect the newly added
  tooling instead of claiming it already existed
- README used target/release/Sentrix while the binary is lowercase
  target/release/sentrix per Cargo.toml
- sync README sample output with the new human-readable scan-time line
  and update the config override table for the new macOS keys
- refresh ARCHITECTURE.md's report module section, which still described
  the removed lines field and duplicated-state design
@pd241008
pd241008 merged commit 45748cd into main Sep 23, 2026
2 of 4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant