[fix] nopy: spawn the pyinfra argv, never a shell string

Closes DOCS-AUDIT §4.2 (point 3, the last one open) and §1.3.

`executeCall` joined `DeployCall.command` and ran it through
`execa({shell: true})`, which made every value on that command line shell
syntax. The finding framed it as a quoting problem "in the password"; it was
wider than that. `--data` values were interpolated inside double quotes, so a
backtick or a `$(…)` in *any* variable value was command substitution and a `;`
ended the command and began another.

`buildDeployCall` now emits a true argv — one element per argument, nothing
pre-quoted — and the executor spawns `execa(command[0], command.slice(1))` with
no `shell` option at all. pyinfra is still found on PATH and stdio stays
inherited, so live output is unchanged.

`maskCommand()` walks the argv by position instead of pattern-matching a joined
string, which closes a leak of its own: it used to bound a secret's value on the
closing `"` the builder had written two modules away, so a value containing a
`"` leaked its own tail. It is now the only thing that turns the command back
into a string, for display, and it shell-quotes as it goes so `--print-only`
output stays pasteable.

Also in `buildDeployCall`: `logConfigToFlags()` finally has a caller (§1.3). It
was exported and unit-tested with nothing consuming it, so `log.verbosity` and
`log.debug` in `.nopyrc.json` did nothing at all. The flags are prefixed onto
the argv right after `-y`. Consequence worth knowing rather than discovering:
`packages/nopy/.nopyrc.json` has always asked for `"verbosity": "trace",
"debug": true`, so a run from that directory now really does get `-vvv --debug`.

The tests move with it — the mock is `execa(file, args, opts)` with no factory
to unwrap, and the new cases are the ones that would have caught this: an argv
element holding `$(id); rm -rf /` stays one element, a secret whose value
contains a quote is masked whole, and `execa` is asserted never to be asked for
a shell.

What remains is not fixable here: the value still reaches pyinfra on its command
line, so it is visible in `ps`. That is pyinfra's `--data` interface.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DCzYTAm9QUhvLNr2EpdagJ
This commit is contained in:
Benjamin Diedrichsen
2026-09-01 12:47:50 +02:00
co-authored by Claude Opus 5
parent 2019626618
commit 4daf27a3cd
5 changed files with 189 additions and 38 deletions
@@ -61,6 +61,45 @@ describe('BuildContext error handling', () => {
});
});
describe('BuildContext log configuration', () => {
const build = (log: NopyConfig['log']) =>
new BuildContext(
{ 'cube-a': testCube('cube-a') },
new Variables(),
session(),
{ env: {}, log } as NopyConfig,
{ method: 'ssh' },
{ useDefaults: true }
);
it('passes the configured verbosity and debug flags to pyinfra', async () => {
const context = build({ verbosity: 'verbose', debug: true });
await context.resolveCube('cube-a', 'host1');
expect(context.deployCalls[0].command.slice(0, 5)).toEqual([
'pyinfra',
'host1',
'-y',
'-vv',
'--debug',
]);
});
it('adds nothing when no log config is set', async () => {
const context = build(undefined);
await context.resolveCube('cube-a', 'host1');
expect(context.deployCalls[0].command.slice(0, 4)).toEqual([
'pyinfra',
'host1',
'-y',
'--chdir',
]);
});
});
describe('BuildContext session replay', () => {
it('takes variables from the session instead of prompting', async () => {
const cube = testCube('cube-a', z.object({ PORT: z.string().default('3000') }));
@@ -344,7 +383,7 @@ describe('BuildContext --use-defaults', () => {
await context.resolveCube('cube-a', 'host1');
expect(context.deployCalls[0].command.join(' ')).toContain('--data "PORT=8080"');
expect(context.deployCalls[0].command).toContain('PORT=8080');
});
it('refuses to run a cube whose variable nothing can supply', async () => {
@@ -485,14 +524,30 @@ describe('BuildContext command construction', () => {
});
await context.resolveCube('cube-a', 'host1');
const command = context.deployCalls[0].command.join(' ');
const command = context.deployCalls[0].command;
expect(command).toContain('--data "PORT=3000"');
expect(command).toContain('--chdir /test/cube-a');
// argv, not a shell string: each flag and its value are separate elements,
// and nothing is pre-quoted.
expect(command).toContain('PORT=3000');
expect(command.join(' ')).toContain('--data PORT=3000');
expect(command.join(' ')).toContain('--chdir /test/cube-a');
expect(command).toContain('/test/cube-a/deploy.py');
expect(context.deployCalls[0].cwd).toBe('/test/cube-a');
});
it('keeps a value with shell metacharacters in one argv element', async () => {
// The whole point of dropping `shell: true`. Joined and handed to a shell,
// this value would have run `id` and swallowed the rest of the command.
const cube = testCube('cube-a', z.object({ MOTD: z.string().default('$(id); rm -rf /') }));
const context = new BuildContext({ 'cube-a': cube }, new Variables(), session(), config, {
method: 'ssh',
});
await context.resolveCube('cube-a', 'host1');
expect(context.deployCalls[0].command).toContain('MOTD=$(id); rm -rf /');
});
it('builds a separate call per host but records the cube session once', async () => {
const context = new BuildContext(
{ 'cube-a': testCube('cube-a') },