fleetd #639: redact()'s comment claimed more than the code does #640
Reference in New Issue
Block a user
Delete Branch "lead/config-edit-redact-anchor-wording"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Comment text only. No behaviour change, no test change.
Follow-up to PR #636, which I merged at
ea6896f. That PR'sd7f94cafixed defect 7 (a blockscalar's value leaking past a masked key line) by masking continuation lines on indentation. The
fix is real and is a strict improvement. The paragraph documenting it, however, ended with:
That claims more than the code delivers, and I measured two ways it fails.
The anchor can be missing.
redact()is feddiff -uoutput, which prints three lines ofcontext. A block scalar's body often arrives with its key line left out of the hunk. With no key
line,
maskedis never set and the body prints in full — and no<redacted>appears anywhere, sonothing signals that redaction was even attempted.
The anchor can be dropped mid-block. A blank line inside a block scalar measures as indent 0,
so
indent > masked_indentis false,maskedresets, and the rest of the value prints raw. Thisone prints directly under a
<redacted>marker.Both reproduced through the real script with
--dry-run, each with a positive control runfirst proving the secret's lines actually reached the output. Without that control, "the secret
never entered the diff" and "it entered and was correctly redacted" are indistinguishable — which
is exactly how the previous lead's first attempt at this reproduction came back clean.
Full evidence, the reachability check, and the two candidate fix directions are in #639. In
short: latent, not live — today's
fleetd.yamlholds 5 block scalars and all 5 sit undernon-secret keys, and secrets in this config are referenced by env-var name rather than written
inline.
Why this is a commit and not just a ticket
#635 exists because an incomplete redactor that looks complete is worse than one that visibly
does nothing — the marker stops a reviewer from looking further. A comment that overstates the
guarantee is that same defect in prose. A future session reading
redact()has no other source,and this paragraph is the thing it would trust.
Test plan
scripts/test-config-edit.shin a clean copy of the edited tree: 16 criteria + 3 extras, exit 0.bash -n scripts/config-edit.shclean.grep -c 'present or future'→ 0) and the newtext is present (
grep -c 'fleetd #639'→ 1)..java,pom.xmlor.yamltouched, so no Maven gate.PR #636's body carries the same overstated sentence. I cannot edit it as cleanly from here, so
#639 records it as an open ask instead.