Skip to content

Bound REPL history storage and startup memory #503

Description

@sodejm

Problem

SecureHistory.load_history_strings() calls readlines() on the entire persisted JSON history before applying its 1,000-entry limit. store_string() only appends, so a long-lived installation accumulates commands without a storage or retention bound. Opening the REPL therefore reads the full file into memory and retains older command text indefinitely. The existing owner-only permissions, symlink refusal, and sensitive-command filtering must be preserved.

Scope

  • Read only the most recent retained entries with bounded memory, including when an existing history file is much larger than the configured limit or has an unusually long line.
  • Define and enforce a practical on-disk entry/byte retention bound during normal use, with safe migration or compaction of existing files.
  • Keep writes and compaction safe against symlinks and partial writes; preserve the existing restrictive file and directory permissions on supported platforms.
  • Keep the newest valid, non-sensitive entries in the same order expected by prompt-toolkit. Skip malformed JSON without crashing the REPL.

Acceptance criteria

  • With fictional history files substantially larger than the retained limit, startup memory and load time scale with the configured bound rather than total file size.
  • Repeated writes keep persistent history within the documented retention bound without losing the newest retained entries.
  • Tests cover oversized legacy files, long and malformed lines, interrupted compaction, symlink replacement, permissions, and sensitive-command exclusion.
  • No command contents are sent to a provider or emitted to diagnostics as part of this change.

Source

  • src/ancestryllm/console/history.py:59-87 — full-file read before applying limit.
  • src/ancestryllm/console/history.py:89-114 — append-only persistence.
  • Related: Harden REPL history, secrets, and output redaction #58 established history permissions and secret filtering; this issue covers retention and bounded loading.

Intended Feature Release iteration: v0.7 (repository milestone: 0.7.0 Genealogy Workflows).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions