4eb720029c
Five fixes against PR #636, all verified by the lead's own review and reproduced here: 1. --set .a.b= (a forgotten value) is now refused outright instead of silently nulling the field — a null numeric config value falls back to its default rather than erroring, which widens capacity silently instead of failing loudly. A deliberate clear gets its own spelling, --set .a.b=null, which writes a literal YAML null via yq, never through strenv(). (criteria 9, 10) 2. Backups move from beside fleetd.yaml to a dedicated fleetd/.config-backups/ directory, gitignored at the repo root (so it also covers scripts/test-config-edit.sh's own throwaway fixtures) and in fleetd/.gitignore, plus a fleetd.yaml.bak.* glob backstop for any stray backup written the old way. A backup of a file that must never be committed inherits that requirement. (criterion 11) 3. The live config's file mode now survives both an edit and a restore. mv from a mktemp candidate used to carry mktemp's 0600 onto the live path forever, and cp onto an existing file keeps the destination's mode, so a restore did not undo it either. (criterion 12) 4. A global CAND + single EXIT/INT/TERM trap prevents an uninstalled .config-edit.XXXXXX candidate from leaking if the script is interrupted mid-run. No acceptance criterion is gated on this — a reproducible leak could not be made to happen on demand — but it is cheap and obviously right. 5. Acceptance criterion 7's redaction check gained a positive control: it now asserts the output actually CONTAINS the redaction marker and the changed key, not only that it lacks the secret. The prior two assertions were negative-only and passed just as happily when the diff was never printed at all — confirmed by reproducing the lead's own mutation (deleting the redacted diff print on the edit path) and watching it survive the old test and get caught by the new one. (criterion 13) All 13 acceptance criteria plus 3 extras pass in scripts/test-config-edit.sh. Criteria 9, 10, 11, 12 and 13 were each proven non-vacuous: criteria 9/10 by mutating the test's own expected value and watching it fail by name, then reverting; criteria 11/12/13 by reverting or mutating the corresponding fix in config-edit.sh and watching the matching criterion fail by name, then restoring the fix and re-confirming a clean pass.
35 lines
1.9 KiB
Plaintext
35 lines
1.9 KiB
Plaintext
# No secret belongs in this repo any more: every credential lives in one shell-level store
|
|
# (${SHARED_ENV}/tools/secrets.sh), and opencode.json reads it as {env:...}. This line stays as a
|
|
# backstop, so a workspace-scoped copy that someone re-creates by habit still cannot be committed.
|
|
.secrets/
|
|
|
|
# Settings backups inherit the env block — and secrets with it.
|
|
.claude/settings.local.json.bak*
|
|
|
|
# The default profile parityOverlay copies these primary→worktree, so they appear in EVERY worker
|
|
# worktree. Two reasons they must be ignored. They hold environment values, which is reason enough.
|
|
# And since CB-576 a release preserves any worktree that `git status --porcelain` calls dirty —
|
|
# untracked files included, deliberately. An untracked overlay file would therefore make every
|
|
# COMPLETED release preserve its worktree, and worktrees would pile up with no error to notice.
|
|
.env
|
|
.envrc
|
|
|
|
# Daemon runtime artefacts. fleetd appends its log wherever it is launched from, so both the
|
|
# repo root and fleetd/ collect one; neither belongs in git.
|
|
fleetd.out
|
|
fleetd/fleetd.out
|
|
logs/
|
|
|
|
# fleetd #635 follow-up — scripts/config-edit.sh's backup directory. No leading slash, so this is
|
|
# ignored at every depth: the real one lives under fleetd/ (also named in fleetd/.gitignore, next
|
|
# to the config it backs up), and scripts/test-config-edit.sh's own throwaway fixtures build one
|
|
# under the repo root while the suite runs. --config can point anywhere, so the directory name is
|
|
# ignored everywhere rather than only where the live daemon happens to use it.
|
|
.config-backups/
|
|
|
|
# fleetd #480: the lead rollover handover file. `leadRollover.handoverPath` points here, and the
|
|
# outgoing lead rewrites it on every rollover. It is a snapshot of one moment's live state —
|
|
# unpushed branches, running builds, open questions — so it is stale the moment it is written and
|
|
# has no business in git history.
|
|
.handover/
|