fix(thothctl): fail closed on partial secret loads

This commit is contained in:
2026-08-11 05:10:32 +02:00
parent 69cc47c13f
commit 783cc3bb34
7 changed files with 60 additions and 18 deletions
+6
View File
@@ -307,6 +307,12 @@ func containsDeclaredSecretBytes(contents []byte, secrets []string) bool {
// deterministic safe line exists it emits empty stderr rather than risk a
// declared-secret collision.
func writeWorkspaceError(stderr io.Writer, err error, secrets []string, code int) int {
// A nil set means the complete declared-secret set was not loaded. No
// nonempty diagnostic is safe because a successfully read secret may equal
// the fixed error chrome. Callers must fail closed without output.
if secrets == nil {
return code
}
message := "workspace operation failed"
if err != nil {
message = output.Sanitize(err.Error(), secrets)
+17
View File
@@ -218,6 +218,23 @@ func TestRunWorkspaceRejectsDeclaredSecretInHumanChrome(t *testing.T) {
}
}
func TestRunWorkspacePartialSecretLoadEmitsNoOutput(t *testing.T) {
fixture := newCLIFixture(t, "")
firstSecret := filepath.Join(fixture.root, "first-secret")
missingSecret := filepath.Join(fixture.root, "missing-secret")
if err := os.WriteFile(firstSecret, []byte("workspace operation failed"), 0o600); err != nil {
t.Fatal(err)
}
fixture.setEnvContents(t, "FIRST_SECRET_FILE="+firstSecret+"\nSECOND_SECRET_FILE="+missingSecret+"\n")
var stdout, stderr bytes.Buffer
code := run(context.Background(), []string{"--installation", fixture.installationPath, "workspace", "inspect", "--workspace", "psd"}, &stdout, &stderr)
if code != 2 || stdout.Len() != 0 || stderr.Len() != 0 {
t.Fatalf("exit=%d stdout=%q stderr=%q, want exit 2 and no output", code, stdout.String(), stderr.String())
}
assertDockerNotInvoked(t, fixture)
}
func TestRunWorkspaceErrorPrefixNeverLeaksDeclaredSecret(t *testing.T) {
fixture := newCLIFixture(t, "UNLABELLED_SECRET_FILE=%s\n")
secretPath := filepath.Join(fixture.root, "secret")