From e0106b6902c0b81b5b8613c906767c89541d231d Mon Sep 17 00:00:00 2001 From: TING Date: Fri, 11 Sep 2026 19:47:54 +0800 Subject: [PATCH] fix(privacy): net the .tmp_qa scratch root, which held two whole coach homes A dogfood or grounding run started with an inline TRADE_COACH_HOME under the repository rather than an isolated one outside it left `.tmp_qa/` behind with `home/` and `dogfood/` inside -- each a complete coach home carrying ledger.jsonl, theses.jsonl, revisit.jsonl, rules.jsonl, problems.jsonl, projections and rendered cards. `ledger.jsonl` and `card-private.*` / `card-public.*` already netted two of those files at any depth. The rest of the tree carried the same tickers, amounts and dates with nothing stopping it, and showed as untracked in `git status` for six weeks. Nothing in the repository writes this path -- it was ad hoc -- so this is a backstop in the same shape as the #214 and #409 entries above it, not a convention being introduced. Privacy lint (17), repository hygiene (17) and documentation/agent workflow (38) suites pass. Co-Authored-By: Claude Opus 5 --- .gitignore | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/.gitignore b/.gitignore index 25966ec1..192657ef 100644 --- a/.gitignore +++ b/.gitignore @@ -33,3 +33,13 @@ card-public.* # Generated Claude Design bundle (rebuild with tools/design_bundle.py) skills/fomo-kernel/tools/ds-bundle/ + +# Ad-hoc QA scratch root. A dogfood or grounding run started with an inline +# TRADE_COACH_HOME under the repository (rather than an isolated one outside +# it, per docs/qa-runbook.md) drops whole coach homes here -- `.tmp_qa/home/` +# and `.tmp_qa/dogfood/` each held ledger.jsonl, theses.jsonl, revisit.jsonl, +# rules.jsonl, projections and rendered cards. `ledger.jsonl` and `card-*` +# above already net two of those files; this nets the rest of the tree, which +# carries the same tickers, amounts and dates. No leading slash: matches at +# any path depth. +.tmp_qa/