fix: keep $(cmd) substitutions readable under strong-key assignments

Review finding (agent/redact.py::_PATH_OR_VAR_VALUE_RE): anchoring the
path/var exemption regressed `export SSH_AUTH_SOCK=$(gpgconf --list-dirs
agent-ssh-socket)` vs main — the `$(gpgconf` token no longer parsed as a
reference and was masked. Accept a leading `$(` as a reference atom in the
grammar and pin the gpg-agent line in
test_real_path_and_var_references_stay_readable.
This commit is contained in:
teknium1
2026-09-15 14:29:59 -07:00
committed by Teknium
parent 93a269c026
commit 34067a7b6d
2 changed files with 4 additions and 1 deletions
+3 -1
View File
@@ -319,8 +319,10 @@ _PASSWORD_KEY_RE = re.compile(r"passwd|password|pass|pw", re.IGNORECASE)
# Further ``$VAR`` interpolations may appear anywhere in the path (``/run/user/$UID/ssh``,
# ``$XDG_RUNTIME_DIR/agent.$USER.sock``, ``$A:$B`` lists); crypt digests never parse as one
# because their ``$`` fields start with a digit or carry ``=``/``,``.
# A leading ``$(`` is a command substitution (``SSH_AUTH_SOCK=$(gpgconf --list-dirs
# agent-ssh-socket)``): the value token stops at whitespace, so only ``$(gpgconf`` is seen.
_SHELL_VAR_REF = r"\$(?:\{[A-Za-z_]\w*[^}]*\}|[A-Za-z_]\w*)"
_PATH_OR_VAR_VALUE_RE = re.compile(rf"^(?:{_SHELL_VAR_REF}|~|/)(?:[\w./:-]|{_SHELL_VAR_REF})*$")
_PATH_OR_VAR_VALUE_RE = re.compile(rf"^(?:{_SHELL_VAR_REF}|\$\(|~|/)(?:[\w./:-]|{_SHELL_VAR_REF})*$")
def _is_word_start(s: str, i: int) -> bool:
+1
View File
@@ -168,6 +168,7 @@ class TestEnvAssignments:
"SSH_AUTH_SOCK=$HOME/.ssh/agent.sock",
"SSH_AUTH_SOCK=$XDG_RUNTIME_DIR/ssh-agent.$USER.sock",
"SSH_AUTH_SOCK=/run/user/$UID/keyring/ssh",
"export SSH_AUTH_SOCK=$(gpgconf --list-dirs agent-ssh-socket)",
"DOCKER_AUTH_CONFIG=/home/u/.docker",
"MY_KEY_PATH=~/.ssh/id_rsa",
"SECRET_DIR=/etc",