fix: keep $(cmd) substitutions readable under strong-key assignments
Review finding (agent/redact.py::_PATH_OR_VAR_VALUE_RE): anchoring the path/var exemption regressed `export SSH_AUTH_SOCK=$(gpgconf --list-dirs agent-ssh-socket)` vs main — the `$(gpgconf` token no longer parsed as a reference and was masked. Accept a leading `$(` as a reference atom in the grammar and pin the gpg-agent line in test_real_path_and_var_references_stay_readable.
This commit is contained in:
+3
-1
@@ -319,8 +319,10 @@ _PASSWORD_KEY_RE = re.compile(r"passwd|password|pass|pw", re.IGNORECASE)
|
||||
# Further ``$VAR`` interpolations may appear anywhere in the path (``/run/user/$UID/ssh``,
|
||||
# ``$XDG_RUNTIME_DIR/agent.$USER.sock``, ``$A:$B`` lists); crypt digests never parse as one
|
||||
# because their ``$`` fields start with a digit or carry ``=``/``,``.
|
||||
# A leading ``$(`` is a command substitution (``SSH_AUTH_SOCK=$(gpgconf --list-dirs
|
||||
# agent-ssh-socket)``): the value token stops at whitespace, so only ``$(gpgconf`` is seen.
|
||||
_SHELL_VAR_REF = r"\$(?:\{[A-Za-z_]\w*[^}]*\}|[A-Za-z_]\w*)"
|
||||
_PATH_OR_VAR_VALUE_RE = re.compile(rf"^(?:{_SHELL_VAR_REF}|~|/)(?:[\w./:-]|{_SHELL_VAR_REF})*$")
|
||||
_PATH_OR_VAR_VALUE_RE = re.compile(rf"^(?:{_SHELL_VAR_REF}|\$\(|~|/)(?:[\w./:-]|{_SHELL_VAR_REF})*$")
|
||||
|
||||
|
||||
def _is_word_start(s: str, i: int) -> bool:
|
||||
|
||||
@@ -168,6 +168,7 @@ class TestEnvAssignments:
|
||||
"SSH_AUTH_SOCK=$HOME/.ssh/agent.sock",
|
||||
"SSH_AUTH_SOCK=$XDG_RUNTIME_DIR/ssh-agent.$USER.sock",
|
||||
"SSH_AUTH_SOCK=/run/user/$UID/keyring/ssh",
|
||||
"export SSH_AUTH_SOCK=$(gpgconf --list-dirs agent-ssh-socket)",
|
||||
"DOCKER_AUTH_CONFIG=/home/u/.docker",
|
||||
"MY_KEY_PATH=~/.ssh/id_rsa",
|
||||
"SECRET_DIR=/etc",
|
||||
|
||||
Reference in New Issue
Block a user