Skip to content

fix(debug): keep SHELFMARK_API_KEY_READONLY out of the debug bundle - #1432

Open
splitsec2 wants to merge 1 commit into
calibrain:mainfrom
splitsec2:fix/genDebug-readonly-key
Open

splitsec2 wants to merge 1 commit into
calibrain:mainfrom
splitsec2:fix/genDebug-readonly-key

Conversation

@splitsec2

@splitsec2 splitsec2 commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

Kept small on purpose so it's easy to review.

genDebug.sh filters secrets out of environment.txt by matching _KEY=, _SECRET=, _PASSWORD= and _TOKEN=, which only catches names that end in those words. SHELFMARK_API_KEY_READONLY ends in _READONLY, so its value lands in the file, and people attach these bundles to issues. That key only reads counters, so the impact is small, but any variable like DB_PASSWORD_FILE would leak the same way.

The pattern now matches the secret word anywhere in the variable name. The new test runs the real filter line from the script against a made-up environment, and it fails on the old pattern.

The one red check is the existing clock-dependent test test_a_queued_torrent_asks_for_a_grace_once, which fails on any runner that booted recently. It is fixed in #1426 and is not caused by this change.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant