Fix tracing leak and review findings in the MIL-001 script

Switch off set -x (it printed tokens), accept a byte order mark, strip the
carriage return jq adds on Windows, return the first key without jq, rename
the boolean keys, and cite the task in the header. Add regression tests and
review record RC-016.

Task: MIL-001#2
Task: MIL-001#3
Task: MIL-001#4
Task: MIL-001#6

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
This commit is contained in:
2026-10-05 14:17:04 +08:00
co-authored by Claude Sonnet 5.5
parent 102dd2473d
commit f4a397c1ec
7 changed files with 160 additions and 13 deletions
+1 -1
View File
@@ -83,7 +83,7 @@ new_workdir() {
# first, then the now empty directories from the bottom up.
remove_workdir() {
if [[ -n $WORK && -d $WORK ]]; then
find "$WORK" -type f -delete
find "$WORK" \( -type f -o -type p \) -delete
find "$WORK" -depth -type d -exec rmdir {} +
fi
WORK=""
+3 -3
View File
@@ -54,17 +54,17 @@ EOF
test_collect_details_with_github() {
run_lib $'my-app\nA test app\npublic\nTirSystem\ny\nmy-org\n\ny\n' \
'collect_project_details
for k in name description visibility gitea_owner use_github github_owner directory plan_gate; do
for k in name description visibility gitea_owner has_github github_owner directory is_plan_gate_enabled; do
printf "%s=%s\n" "$k" "${PROJECT[$k]}"
done'
assert_status "details collected" 0 "$STATUS"
assert_eq "details" $'name=my-app\ndescription=A test app\nvisibility=public\ngitea_owner=TirSystem\nuse_github=1\ngithub_owner=my-org\ndirectory=./my-app\nplan_gate=1' "$OUT"
assert_eq "details" $'name=my-app\ndescription=A test app\nvisibility=public\ngitea_owner=TirSystem\nhas_github=1\ngithub_owner=my-org\ndirectory=./my-app\nis_plan_gate_enabled=1' "$OUT"
}
test_collect_details_without_github() {
run_lib $'my-app\n\n\nTirSystem\nn\n\nn\n' \
'collect_project_details
printf "%s|%s|%s|%s\n" "${PROJECT[visibility]}" "${PROJECT[use_github]}" "[${PROJECT[github_owner]}]" "${PROJECT[plan_gate]}"'
printf "%s|%s|%s|%s\n" "${PROJECT[visibility]}" "${PROJECT[has_github]}" "[${PROJECT[github_owner]}]" "${PROJECT[is_plan_gate_enabled]}"'
assert_status "GitHub skipped" 0 "$STATUS"
assert_eq "defaults and no GitHub owner" "private|0|[]|0" "$OUT"
assert_not_contains "no GitHub owner prompt" "$ERR" "GitHub owner"
+49 -1
View File
@@ -123,6 +123,54 @@ test_script_uses_no_unsafe_constructs() {
assert_not_contains "no eval" "$code" "eval "
assert_not_contains "no source" "$code" "source "
assert_not_contains "no dot-source" "$code" $'\n. '
assert_not_contains "no set -x" "$code" "set -x"
check
if grep -Eq '^[[:space:]]*set -[A-Za-z]*x' <<<"$code"; then
fail "the script turns tracing on"
fi
assert_not_contains "no fixed /tmp file" "$code" "/tmp/file"
}
test_tracing_does_not_leak_secrets() {
# bash -x would print every assignment and command, secrets included, so
# the script switches tracing off and says so.
write_fixtures
STATUS=0
PATH="$WORK/bin:$PATH" TMPDIR="$WORK/tmp" "$BASH" -x "$SCRIPT" \
--config "$WORK/config.env" --env "$WORK/.env" <<<"$ANSWERS_GITHUB" \
>"$WORK/out.txt" 2>"$WORK/err.txt" || STATUS=$?
assert_status "run under bash -x" 0 "$STATUS"
assert_contains "tracing disabled" "$(cat "$WORK/err.txt")" "tracing (set -x) is disabled"
assert_not_contains "no Gitea token in the trace" "$(cat "$WORK/err.txt" "$WORK/out.txt")" "$FAKE_GITEA_TOKEN"
assert_not_contains "no GitHub token in the trace" "$(cat "$WORK/err.txt" "$WORK/out.txt")" "$FAKE_GITHUB_PAT"
}
test_byte_order_mark_is_accepted() {
printf '\xef\xbb\xbfGITEA_URL=https://a.test\nGITHUB_WEB_URL=https://b.test\n' >"$WORK/c.env"
run_lib "" "parse_env_file \"$WORK/c.env\" CONFIG_KEYS CONFIG
echo \"\${CONFIG[GITEA_URL]}\""
assert_status "BOM on the first line" 0 "$STATUS"
assert_eq "first key read" "https://a.test" "$OUT"
}
test_termination_removes_temp_files() {
write_fixtures
if ! mkfifo "$WORK/in" 2>/dev/null; then
return 0
fi
PATH="$WORK/bin:$PATH" TMPDIR="$WORK/tmp" "$BASH" "$SCRIPT" \
--config "$WORK/config.env" --env "$WORK/.env" <"$WORK/in" \
>/dev/null 2>&1 &
local pid=$! tries=0
# Keep the pipe open so the script waits at its first prompt.
exec 7>"$WORK/in"
while [[ -z "$(find "$WORK/tmp" -mindepth 1)" ]] && ((tries < 50)); do
sleep 0.1
tries=$((tries + 1))
done
assert_eq "temp directory exists while running" 1 "$(find "$WORK/tmp" -mindepth 1 | wc -l | tr -d ' ')"
kill -TERM "$pid"
# wait returns the signal status (143); only the cleanup matters here.
wait "$pid" 2>/dev/null || true
exec 7>&-
assert_eq "temp directory removed after SIGTERM" "" "$(find "$WORK/tmp" -mindepth 1)"
}