diff --git a/scripts/config-edit.sh b/scripts/config-edit.sh index 7d47d63..6e1c8e8 100755 --- a/scripts/config-edit.sh +++ b/scripts/config-edit.sh @@ -159,7 +159,13 @@ done # The fix is structural, not another name to match: once a key line is masked, every following # line indented STRICTLY DEEPER than that key is masked too, by indentation alone, until the # indentation returns to the key's own level or shallower. This needs no knowledge of the key's -# name and so protects a block scalar under any masked key, present or future. +# name, so it covers a block scalar under any masked key — but ONLY while that key's own line is +# itself inside the hunk being printed. `diff -u` prints just three lines of context, so a block +# scalar's body often reaches this function with its key line left out; there is then nothing to +# anchor to, `masked` is never set, and the body prints in full. A blank line inside a block +# scalar loses the anchor the same way, because a blank diff line measures as indent 0. Both are +# measured and filed as fleetd #639 — do not read this paragraph as a guarantee that a masked +# key's value can never be printed. # # `redact` is always fed `diff -u` output, and every line of a unified diff starts with exactly # one of ' ', '+', '-' (the three body markers; '@'/'-'/'+' for the three header-line kinds too).