Share and Secret redact str() and repr() so logs don't disclose recovery text. CorrectionEdit was a plain dataclass, so repr(candidate) printed each edit's observed and replacement characters.
BIP-93 vector 1 with one substitution could therefore render the corrected character even while the artifact itself remained redacted; filling many erasures rendered many restored characters. Impact is low because the CLI does not log candidates, but the behavior violated the project's accidental-disclosure boundary.
Focused fix: #132 marks only CorrectionEdit.observed and .replacement as excluded from generated dataclass repr. Explicit field access, equality, hashing, correction ranking, and CLI behavior are unchanged. The regression repairs eight erasures and verifies that enclosing candidate rendering does not disclose the restored characters.
Current #132 head f64da6f has a successful exact-head Python-package matrix and a Codex no-major-issue review. Focused local verification also passed 903 tests normally and under python -O, Ruff check/format, strict mypy, correction-constant re-derivation, and all 57 frozen differential correction cases. Responsible-human review/authorship and integration remain.
Found by Codex review of #94 after the four supplied external audit reports; it is narrower than the Kimi/consolidated complete-artifact repr finding and should not be retroactively attributed to those reviewers.
ShareandSecretredactstr()andrepr()so logs don't disclose recovery text.CorrectionEditwas a plain dataclass, sorepr(candidate)printed each edit'sobservedandreplacementcharacters.BIP-93 vector 1 with one substitution could therefore render the corrected character even while the artifact itself remained redacted; filling many erasures rendered many restored characters. Impact is low because the CLI does not log candidates, but the behavior violated the project's accidental-disclosure boundary.
Focused fix: #132 marks only
CorrectionEdit.observedand.replacementas excluded from generated dataclassrepr. Explicit field access, equality, hashing, correction ranking, and CLI behavior are unchanged. The regression repairs eight erasures and verifies that enclosing candidate rendering does not disclose the restored characters.Current #132 head
f64da6fhas a successful exact-head Python-package matrix and a Codex no-major-issue review. Focused local verification also passed 903 tests normally and underpython -O, Ruff check/format, strict mypy, correction-constant re-derivation, and all 57 frozen differential correction cases. Responsible-human review/authorship and integration remain.Found by Codex review of #94 after the four supplied external audit reports; it is narrower than the Kimi/consolidated complete-artifact
reprfinding and should not be retroactively attributed to those reviewers.