From 51047848f1be917a9aa26e327d020fed506a2c01 Mon Sep 17 00:00:00 2001 From: Dai Ha Date: Thu, 27 Aug 2026 22:01:15 +0700 Subject: [PATCH] =?UTF-8?q?CB-642:=20make=20the=20fleets-status=20redactio?= =?UTF-8?q?n=20global=20=E2=80=94=20a=20non-global=20sed=20leaks=20a=20sec?= =?UTF-8?q?ond=20URI=20on=20the=20same=20line?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- .claude/skills/fleets-status/SKILL.md | 9 +++++++-- 1 file changed, 7 insertions(+), 2 deletions(-) diff --git a/.claude/skills/fleets-status/SKILL.md b/.claude/skills/fleets-status/SKILL.md index d34ca7a..92a15a9 100644 --- a/.claude/skills/fleets-status/SKILL.md +++ b/.claude/skills/fleets-status/SKILL.md @@ -27,9 +27,14 @@ can make every broker probe look empty. reaches the report: ```bash -sed -E 's#://[^@]*@#://@#' +sed -E 's#://[^@]*@#://@#g' ``` +**The `g` flag is not optional.** Without it `sed` replaces only the first match on each line, so a +line carrying two URIs leaks the second one. `scripts/redeploy-fleetd.sh --check` prints lines like +that. Checked on 2026-08-27: without `g`, `amqp://u1:p1@h1/mac and http://u2:p2@h2:15672/api` +redacts the first pair and prints `u2:p2` in the clear. + Keep `pipefail` on when applying that filter. Otherwise the filter can hide a failed probe. Apply the same no-print rule to the management password below, even though it is not in an AMQP URI. @@ -44,7 +49,7 @@ Do not copy those checks into new shell code. The script reads `LAVINMQ_URI`, so ```bash set -o pipefail scripts/redeploy-fleetd.sh --check 2>&1 \ - | sed -E 's#://[^@]*@#://@#' + | sed -E 's#://[^@]*@#://@#g' git rev-parse HEAD ```