Skip to content

Commit fcd6f57

Browse files
brannnhermes-agent
andauthored
fix: redact reflector stderr on failure (#1)
Co-authored-by: Hermes Agent <hermes-agent@users.noreply.github.com>
1 parent 69041ea commit fcd6f57

2 files changed

Lines changed: 22 additions & 1 deletion

File tree

‎internal/reflector/reflector.go‎

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -68,7 +68,8 @@ func (ExecRunner) Run(ctx context.Context, command string, args []string) (strin
6868
cmd.Stdout = &stdout
6969
cmd.Stderr = &stderr
7070
if err := cmd.Run(); err != nil {
71-
return "", fmt.Errorf("run reflector command: %w: %s", err, truncate(stderr.String(), 2048))
71+
redactedStderr := truncate(Redact(stderr.String()), 2048)
72+
return "", fmt.Errorf("run reflector command: %w: %s", err, redactedStderr)
7273
}
7374
return stdout.String(), nil
7475
}

‎internal/reflector/reflector_test.go‎

Lines changed: 20 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -174,6 +174,26 @@ func TestExecRunnerMarksReflectorActive(t *testing.T) {
174174
}
175175
}
176176

177+
func TestExecRunnerRedactsStderrOnFailure(t *testing.T) {
178+
_, err := ExecRunner{}.Run(context.Background(), "sh", []string{
179+
"-c",
180+
"printf 'reflector failed with CUSTOM_SECRET=not-for-logs and API_KEY=test-api-key-value' >&2; exit 7",
181+
})
182+
if err == nil {
183+
t.Fatal("Run returned nil error, want failure")
184+
}
185+
186+
errorText := err.Error()
187+
for _, leaked := range []string{"not-for-logs", "test-api-key-value"} {
188+
if strings.Contains(errorText, leaked) {
189+
t.Fatalf("error leaked %q: %s", leaked, errorText)
190+
}
191+
}
192+
if !strings.Contains(errorText, "CUSTOM_SECRET=<redacted>") || !strings.Contains(errorText, "API_KEY=<redacted>") {
193+
t.Fatalf("error did not preserve redacted stderr context: %s", errorText)
194+
}
195+
}
196+
177197
type fakeRunner struct {
178198
command string
179199
args []string

0 commit comments

Comments
 (0)