Report the LAVA database by name, not by the examiner's own path - #2237
Merged
Merged
Conversation
An artifact that declares no search paths is handed '<report folder>/_lava_artifacts.db' as its only files_found entry, because it reads rows an earlier artifact wrote rather than a file in the extraction. All 35 such artifacts in iLEAPP are in logarchive.py, and each returns that path back as its source_path. Context.get_relative_path stripped the data folder and nothing else. The LAVA database sits in the report folder, one level above the data folder, so the prefix never matched and the path was returned unchanged. The examiner's own output directory then reached the artifact page's "located at" line and the LAVA manifest's source_path, which travels with the report. Measured on a run over a log show export: before, 4 of 5 manifest entries and all 3 artifact pages carried the absolute path; after, none do and the manifest reads '_lava_artifacts.db', which is how the report already describes that file elsewhere. Row counts, every LAVA table, the TSV exports and the timeline database are identical before and after. Two runs of the unmodified tree differ in the same two bookkeeping tables, because the file path id is id() of a FileInfo object, so that difference is not this change. The fix is in get_relative_path rather than in the artifacts, so it covers all 35 at once and any later file the run writes into the report folder. The data folder is still tried first, because it sits inside the report folder and stripping the report folder first would leave every staged evidence path prefixed with 'data/'. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Reports the LAVA database by name instead of by the examiner's own path.
An artifact that declares no search paths is handed
<report folder>/_lava_artifacts.dbas its source file. That sits outside the data folder, which is the only prefixContext.get_relative_pathstripped, so the examiner's output directory reached the artifact page's "located at" line and the LAVA manifest'ssource_path. All 35 such artifacts are in logarchive.py.get_relative_path, so it covers all 35 and any later file the run writes into the report folder.data/.Measured on a run over a
log showexport: before, 4 of 5 manifest entries and all 3 artifact pages carried the absolute path; after, none do. Every LAVA table, row count, TSV export and the timeline database are identical. Two runs of an unmodified tree differ in the same two bookkeeping tables, because the file path id isid()of a FileInfo object.🤖 Generated with Claude Code