From faefea14c43b0dd3c000235c13bf7297378ce0ed Mon Sep 17 00:00:00 2001 From: Dai Ha Date: Thu, 1 Oct 2026 19:00:29 +0200 Subject: [PATCH] fleetd #639: redact()'s comment claimed more than the code does MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The paragraph added in d7f94ca ended with "This needs no knowledge of the key's name and so protects a block scalar under any masked key, present or future." The continuation masking is real and it is an improvement, but that sentence is too strong: the masking only holds while the masked key's own line is inside the hunk being printed. redact() is fed `diff -u` output, which prints three lines of context. A block scalar's body therefore often arrives with its key line left out. With no key line, `masked` is never set and the body prints in full, with no "" anywhere. A blank line inside a block scalar loses the anchor the same way: a blank diff line measures as indent 0, so `indent > masked_indent` is false and the mask ends early — this time directly under a "" marker. Both were reproduced through the real script with --dry-run, each with a positive control run first to prove the secret's lines actually reached the output (without that control, "the secret never entered the diff" and "it entered and was redacted" are indistinguishable). Filed as fleetd #639, which also records that this is latent rather than live: today's fleetd.yaml holds 5 block scalars and all 5 sit under non-secret keys. Comment text only. No change to redact() or to any other function, and no change to the test suite. scripts/test-config-edit.sh still passes in a clean copy (16 criteria + 3 extras, exit 0); bash -n clean. The reason this is worth its own commit: #635 exists because an incomplete redactor that looks complete is worse than one that visibly does nothing. A comment that overstates the guarantee is the same defect in prose, and the next session to read it has no other source. --- scripts/config-edit.sh | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/scripts/config-edit.sh b/scripts/config-edit.sh index 7d47d63..6e1c8e8 100755 --- a/scripts/config-edit.sh +++ b/scripts/config-edit.sh @@ -159,7 +159,13 @@ done # The fix is structural, not another name to match: once a key line is masked, every following # line indented STRICTLY DEEPER than that key is masked too, by indentation alone, until the # indentation returns to the key's own level or shallower. This needs no knowledge of the key's -# name and so protects a block scalar under any masked key, present or future. +# name, so it covers a block scalar under any masked key — but ONLY while that key's own line is +# itself inside the hunk being printed. `diff -u` prints just three lines of context, so a block +# scalar's body often reaches this function with its key line left out; there is then nothing to +# anchor to, `masked` is never set, and the body prints in full. A blank line inside a block +# scalar loses the anchor the same way, because a blank diff line measures as indent 0. Both are +# measured and filed as fleetd #639 — do not read this paragraph as a guarantee that a masked +# key's value can never be printed. # # `redact` is always fed `diff -u` output, and every line of a unified diff starts with exactly # one of ' ', '+', '-' (the three body markers; '@'/'-'/'+' for the three header-line kinds too).