From 34067a7b6d7c9f6e728e6d8e2baa9ed4e4b0ea73 Mon Sep 17 00:00:00 2001 From: teknium1 <127238744+teknium1@users.noreply.github.com> Date: Tue, 15 Sep 2026 14:29:59 -0700 Subject: [PATCH] fix: keep $(cmd) substitutions readable under strong-key assignments MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Review finding (agent/redact.py::_PATH_OR_VAR_VALUE_RE): anchoring the path/var exemption regressed `export SSH_AUTH_SOCK=$(gpgconf --list-dirs agent-ssh-socket)` vs main — the `$(gpgconf` token no longer parsed as a reference and was masked. Accept a leading `$(` as a reference atom in the grammar and pin the gpg-agent line in test_real_path_and_var_references_stay_readable. --- agent/redact.py | 4 +++- tests/agent/test_redact.py | 1 + 2 files changed, 4 insertions(+), 1 deletion(-) diff --git a/agent/redact.py b/agent/redact.py index 6a17b5bd76..d839e6854b 100644 --- a/agent/redact.py +++ b/agent/redact.py @@ -319,8 +319,10 @@ _PASSWORD_KEY_RE = re.compile(r"passwd|password|pass|pw", re.IGNORECASE) # Further ``$VAR`` interpolations may appear anywhere in the path (``/run/user/$UID/ssh``, # ``$XDG_RUNTIME_DIR/agent.$USER.sock``, ``$A:$B`` lists); crypt digests never parse as one # because their ``$`` fields start with a digit or carry ``=``/``,``. +# A leading ``$(`` is a command substitution (``SSH_AUTH_SOCK=$(gpgconf --list-dirs +# agent-ssh-socket)``): the value token stops at whitespace, so only ``$(gpgconf`` is seen. _SHELL_VAR_REF = r"\$(?:\{[A-Za-z_]\w*[^}]*\}|[A-Za-z_]\w*)" -_PATH_OR_VAR_VALUE_RE = re.compile(rf"^(?:{_SHELL_VAR_REF}|~|/)(?:[\w./:-]|{_SHELL_VAR_REF})*$") +_PATH_OR_VAR_VALUE_RE = re.compile(rf"^(?:{_SHELL_VAR_REF}|\$\(|~|/)(?:[\w./:-]|{_SHELL_VAR_REF})*$") def _is_word_start(s: str, i: int) -> bool: diff --git a/tests/agent/test_redact.py b/tests/agent/test_redact.py index ffe2648650..ef81801368 100644 --- a/tests/agent/test_redact.py +++ b/tests/agent/test_redact.py @@ -168,6 +168,7 @@ class TestEnvAssignments: "SSH_AUTH_SOCK=$HOME/.ssh/agent.sock", "SSH_AUTH_SOCK=$XDG_RUNTIME_DIR/ssh-agent.$USER.sock", "SSH_AUTH_SOCK=/run/user/$UID/keyring/ssh", + "export SSH_AUTH_SOCK=$(gpgconf --list-dirs agent-ssh-socket)", "DOCKER_AUTH_CONFIG=/home/u/.docker", "MY_KEY_PATH=~/.ssh/id_rsa", "SECRET_DIR=/etc",