fix: close server bypass edge cases

This commit is contained in:
2026-08-05 12:09:32 +02:00
parent a94affd6ac
commit fc349e634c
9 changed files with 296 additions and 148 deletions
@@ -45,8 +45,8 @@ const (
ExitClassInvocation ExitClass = "invocation-failure"
)
// OperationError reports only allowlisted operation metadata from Error. Detail remains bounded
// and is exposed separately so the CLI can redact declared secrets before displaying it.
// OperationError reports only allowlisted operation metadata from Error. Complete subprocess
// detail is exposed separately so the CLI can redact it before applying its display bound.
type OperationError struct {
stage Stage
class ExitClass
@@ -384,24 +384,7 @@ func runDocker(ctx context.Context, runner Runner, stage Stage, args []string) (
if strings.TrimSpace(detail) == "" {
detail = err.Error()
}
return result, &OperationError{stage: stage, class: class, detail: boundedDetail(detail)}
return result, &OperationError{stage: stage, class: class, detail: detail}
}
return result, nil
}
func boundedDetail(detail string) string {
detail = strings.Join(strings.Fields(detail), " ")
const maximumBytes = 512
if len(detail) <= maximumBytes {
return detail
}
var bounded strings.Builder
for _, character := range detail {
encoded := string(character)
if bounded.Len()+len(encoded) > maximumBytes {
break
}
bounded.WriteString(encoded)
}
return bounded.String()
}