diff --git a/agent/redact.py b/agent/redact.py index 6a17b5bd76..d839e6854b 100644 --- a/agent/redact.py +++ b/agent/redact.py @@ -319,8 +319,10 @@ _PASSWORD_KEY_RE = re.compile(r"passwd|password|pass|pw", re.IGNORECASE) # Further ``$VAR`` interpolations may appear anywhere in the path (``/run/user/$UID/ssh``, # ``$XDG_RUNTIME_DIR/agent.$USER.sock``, ``$A:$B`` lists); crypt digests never parse as one # because their ``$`` fields start with a digit or carry ``=``/``,``. +# A leading ``$(`` is a command substitution (``SSH_AUTH_SOCK=$(gpgconf --list-dirs +# agent-ssh-socket)``): the value token stops at whitespace, so only ``$(gpgconf`` is seen. _SHELL_VAR_REF = r"\$(?:\{[A-Za-z_]\w*[^}]*\}|[A-Za-z_]\w*)" -_PATH_OR_VAR_VALUE_RE = re.compile(rf"^(?:{_SHELL_VAR_REF}|~|/)(?:[\w./:-]|{_SHELL_VAR_REF})*$") +_PATH_OR_VAR_VALUE_RE = re.compile(rf"^(?:{_SHELL_VAR_REF}|\$\(|~|/)(?:[\w./:-]|{_SHELL_VAR_REF})*$") def _is_word_start(s: str, i: int) -> bool: diff --git a/tests/agent/test_redact.py b/tests/agent/test_redact.py index ffe2648650..ef81801368 100644 --- a/tests/agent/test_redact.py +++ b/tests/agent/test_redact.py @@ -168,6 +168,7 @@ class TestEnvAssignments: "SSH_AUTH_SOCK=$HOME/.ssh/agent.sock", "SSH_AUTH_SOCK=$XDG_RUNTIME_DIR/ssh-agent.$USER.sock", "SSH_AUTH_SOCK=/run/user/$UID/keyring/ssh", + "export SSH_AUTH_SOCK=$(gpgconf --list-dirs agent-ssh-socket)", "DOCKER_AUTH_CONFIG=/home/u/.docker", "MY_KEY_PATH=~/.ssh/id_rsa", "SECRET_DIR=/etc",