diff --git a/.claude/skills/fleets-status/SKILL.md b/.claude/skills/fleets-status/SKILL.md index d34ca7a..92a15a9 100644 --- a/.claude/skills/fleets-status/SKILL.md +++ b/.claude/skills/fleets-status/SKILL.md @@ -27,9 +27,14 @@ can make every broker probe look empty. reaches the report: ```bash -sed -E 's#://[^@]*@#://@#' +sed -E 's#://[^@]*@#://@#g' ``` +**The `g` flag is not optional.** Without it `sed` replaces only the first match on each line, so a +line carrying two URIs leaks the second one. `scripts/redeploy-fleetd.sh --check` prints lines like +that. Checked on 2026-08-27: without `g`, `amqp://u1:p1@h1/mac and http://u2:p2@h2:15672/api` +redacts the first pair and prints `u2:p2` in the clear. + Keep `pipefail` on when applying that filter. Otherwise the filter can hide a failed probe. Apply the same no-print rule to the management password below, even though it is not in an AMQP URI. @@ -44,7 +49,7 @@ Do not copy those checks into new shell code. The script reads `LAVINMQ_URI`, so ```bash set -o pipefail scripts/redeploy-fleetd.sh --check 2>&1 \ - | sed -E 's#://[^@]*@#://@#' + | sed -E 's#://[^@]*@#://@#g' git rev-parse HEAD ```