[fix] nopy: spawn the pyinfra argv, never a shell string
Closes DOCS-AUDIT §4.2 (point 3, the last one open) and §1.3.
`executeCall` joined `DeployCall.command` and ran it through
`execa({shell: true})`, which made every value on that command line shell
syntax. The finding framed it as a quoting problem "in the password"; it was
wider than that. `--data` values were interpolated inside double quotes, so a
backtick or a `$(…)` in *any* variable value was command substitution and a `;`
ended the command and began another.
`buildDeployCall` now emits a true argv — one element per argument, nothing
pre-quoted — and the executor spawns `execa(command[0], command.slice(1))` with
no `shell` option at all. pyinfra is still found on PATH and stdio stays
inherited, so live output is unchanged.
`maskCommand()` walks the argv by position instead of pattern-matching a joined
string, which closes a leak of its own: it used to bound a secret's value on the
closing `"` the builder had written two modules away, so a value containing a
`"` leaked its own tail. It is now the only thing that turns the command back
into a string, for display, and it shell-quotes as it goes so `--print-only`
output stays pasteable.
Also in `buildDeployCall`: `logConfigToFlags()` finally has a caller (§1.3). It
was exported and unit-tested with nothing consuming it, so `log.verbosity` and
`log.debug` in `.nopyrc.json` did nothing at all. The flags are prefixed onto
the argv right after `-y`. Consequence worth knowing rather than discovering:
`packages/nopy/.nopyrc.json` has always asked for `"verbosity": "trace",
"debug": true`, so a run from that directory now really does get `-vvv --debug`.
The tests move with it — the mock is `execa(file, args, opts)` with no factory
to unwrap, and the new cases are the ones that would have caught this: an argv
element holding `$(id); rm -rf /` stays one element, a secret whose value
contains a quote is masked whole, and `execa` is asserted never to be asked for
a shell.
What remains is not fixable here: the value still reaches pyinfra on its command
line, so it is visible in `ps`. That is pyinfra's `--data` interface.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DCzYTAm9QUhvLNr2EpdagJ
This commit is contained in:
co-authored by
Claude Opus 5
parent
2019626618
commit
4daf27a3cd
@@ -1,9 +1,9 @@
|
||||
/**
|
||||
* Tests for the executeDeployCalls path of nopy.executor.
|
||||
*
|
||||
* execa is mocked so no pyinfra process is ever spawned. Note the shape:
|
||||
* the module calls execa({ shell: true })(command, opts), so the mock is a
|
||||
* factory returning the runner.
|
||||
* execa is mocked so no pyinfra process is ever spawned. The module calls
|
||||
* `execa(file, args, opts)` directly — no shell, so no factory call to unwrap
|
||||
* as there was while it went through `execa({ shell: true })`.
|
||||
*/
|
||||
|
||||
import { beforeEach, describe, expect, it, vi } from 'vitest';
|
||||
@@ -11,7 +11,7 @@ import { beforeEach, describe, expect, it, vi } from 'vitest';
|
||||
const runner = vi.fn();
|
||||
|
||||
vi.mock('execa', () => ({
|
||||
execa: vi.fn(() => runner),
|
||||
execa: vi.fn((...args: unknown[]) => runner(...args)),
|
||||
}));
|
||||
|
||||
import { execa } from 'execa';
|
||||
@@ -50,16 +50,27 @@ describe('executeDeployCalls', () => {
|
||||
logSpy.mockRestore();
|
||||
});
|
||||
|
||||
it('runs the joined command in the call cwd with inherited stdio', async () => {
|
||||
it('spawns the argv directly in the call cwd with inherited stdio', async () => {
|
||||
await executeDeployCalls([call('cube-a')]);
|
||||
|
||||
expect(execa).toHaveBeenCalledWith({ shell: true });
|
||||
expect(runner).toHaveBeenCalledWith('pyinfra web-1 -y cube-a.deploy.py', {
|
||||
expect(execa).toHaveBeenCalledWith('pyinfra', ['web-1', '-y', 'cube-a.deploy.py'], {
|
||||
cwd: '/cubes/cube-a',
|
||||
stdio: 'inherit',
|
||||
});
|
||||
});
|
||||
|
||||
it('never asks execa for a shell', async () => {
|
||||
// The regression that matters: with `shell: true` every `--data` value was
|
||||
// shell syntax, so a password or a variable containing `;` or `$(…)` ran.
|
||||
await executeDeployCalls([
|
||||
{ ...call('cube-a'), command: ['pyinfra', 'web-1', '--data', 'MOTD=$(id); rm -rf /'] },
|
||||
]);
|
||||
|
||||
const [, , options] = vi.mocked(execa).mock.calls[0] as unknown[];
|
||||
expect(options).not.toHaveProperty('shell');
|
||||
expect(vi.mocked(execa).mock.calls[0][1]).toContain('MOTD=$(id); rm -rf /');
|
||||
});
|
||||
|
||||
it('reports success with a non-negative duration', async () => {
|
||||
const [result] = await executeDeployCalls([call('cube-a')]);
|
||||
|
||||
|
||||
Reference in New Issue
Block a user