Fix tracing leak and review findings in the MIL-001 script
Switch off set -x (it printed tokens), accept a byte order mark, strip the carriage return jq adds on Windows, return the first key without jq, rename the boolean keys, and cite the task in the header. Add regression tests and review record RC-016. Task: MIL-001#2 Task: MIL-001#3 Task: MIL-001#4 Task: MIL-001#6 Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
This commit is contained in:
+49
-1
@@ -123,6 +123,54 @@ test_script_uses_no_unsafe_constructs() {
|
||||
assert_not_contains "no eval" "$code" "eval "
|
||||
assert_not_contains "no source" "$code" "source "
|
||||
assert_not_contains "no dot-source" "$code" $'\n. '
|
||||
assert_not_contains "no set -x" "$code" "set -x"
|
||||
check
|
||||
if grep -Eq '^[[:space:]]*set -[A-Za-z]*x' <<<"$code"; then
|
||||
fail "the script turns tracing on"
|
||||
fi
|
||||
assert_not_contains "no fixed /tmp file" "$code" "/tmp/file"
|
||||
}
|
||||
|
||||
test_tracing_does_not_leak_secrets() {
|
||||
# bash -x would print every assignment and command, secrets included, so
|
||||
# the script switches tracing off and says so.
|
||||
write_fixtures
|
||||
STATUS=0
|
||||
PATH="$WORK/bin:$PATH" TMPDIR="$WORK/tmp" "$BASH" -x "$SCRIPT" \
|
||||
--config "$WORK/config.env" --env "$WORK/.env" <<<"$ANSWERS_GITHUB" \
|
||||
>"$WORK/out.txt" 2>"$WORK/err.txt" || STATUS=$?
|
||||
assert_status "run under bash -x" 0 "$STATUS"
|
||||
assert_contains "tracing disabled" "$(cat "$WORK/err.txt")" "tracing (set -x) is disabled"
|
||||
assert_not_contains "no Gitea token in the trace" "$(cat "$WORK/err.txt" "$WORK/out.txt")" "$FAKE_GITEA_TOKEN"
|
||||
assert_not_contains "no GitHub token in the trace" "$(cat "$WORK/err.txt" "$WORK/out.txt")" "$FAKE_GITHUB_PAT"
|
||||
}
|
||||
|
||||
test_byte_order_mark_is_accepted() {
|
||||
printf '\xef\xbb\xbfGITEA_URL=https://a.test\nGITHUB_WEB_URL=https://b.test\n' >"$WORK/c.env"
|
||||
run_lib "" "parse_env_file \"$WORK/c.env\" CONFIG_KEYS CONFIG
|
||||
echo \"\${CONFIG[GITEA_URL]}\""
|
||||
assert_status "BOM on the first line" 0 "$STATUS"
|
||||
assert_eq "first key read" "https://a.test" "$OUT"
|
||||
}
|
||||
|
||||
test_termination_removes_temp_files() {
|
||||
write_fixtures
|
||||
if ! mkfifo "$WORK/in" 2>/dev/null; then
|
||||
return 0
|
||||
fi
|
||||
PATH="$WORK/bin:$PATH" TMPDIR="$WORK/tmp" "$BASH" "$SCRIPT" \
|
||||
--config "$WORK/config.env" --env "$WORK/.env" <"$WORK/in" \
|
||||
>/dev/null 2>&1 &
|
||||
local pid=$! tries=0
|
||||
# Keep the pipe open so the script waits at its first prompt.
|
||||
exec 7>"$WORK/in"
|
||||
while [[ -z "$(find "$WORK/tmp" -mindepth 1)" ]] && ((tries < 50)); do
|
||||
sleep 0.1
|
||||
tries=$((tries + 1))
|
||||
done
|
||||
assert_eq "temp directory exists while running" 1 "$(find "$WORK/tmp" -mindepth 1 | wc -l | tr -d ' ')"
|
||||
kill -TERM "$pid"
|
||||
# wait returns the signal status (143); only the cleanup matters here.
|
||||
wait "$pid" 2>/dev/null || true
|
||||
exec 7>&-
|
||||
assert_eq "temp directory removed after SIGTERM" "" "$(find "$WORK/tmp" -mindepth 1)"
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user