From 5137720aa7bd3d4f5077c88a9195084d6d63550a Mon Sep 17 00:00:00 2001 From: jochen Date: Tue, 1 Sep 2026 09:52:28 +0200 Subject: [PATCH] A path is not a secret, and the check said it was MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The last failure of the run: `MESH_BROKER_FILE=/var/lib/mesh/builder/broker` reported as "something secret-shaped, which the broker would see". `/` is in the base64 alphabet, so any absolute path of 24 characters or more matched the pattern meant to catch a sealed value. An absolute path is a *reference* to a secret and naming one is the whole design — the mesh delivers a credential as a file and a module says where. Excluded explicitly rather than by loosening the pattern, and checked both ways: a real sealed value and a base64 blob are still flagged, a relative path still is, only an absolute path is passed over. Worth the words in the comment. A check that fires on the right shape for the wrong reason is worse than none — it is the one that gets suppressed, and then it is not there when it is right. It surfaced now because tests in this file share one mesh: the builder was assigned by an earlier test and appears in this one's declaration. --- test/integration/mesh.test.ts | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/test/integration/mesh.test.ts b/test/integration/mesh.test.ts index 32d35bd..a836877 100644 --- a/test/integration/mesh.test.ts +++ b/test/integration/mesh.test.ts @@ -1787,6 +1787,15 @@ test("the real modules resolve together, and compose a declaration a host accept `only ${containers.length} containers; mailu alone is nine`); for (const c of containers) { for (const [key, value] of Object.entries(c.env ?? {})) { + // **An absolute path is a reference to a secret, not a secret**, and naming one is the + // whole design: the mesh delivers a credential as a file and a module says where. + // + // Excluded because `/` is in the base64 alphabet, so any path of 24 characters or more + // matched — `MESH_BROKER_FILE=/var/lib/mesh/builder/broker` was reported as a credential + // the broker would see. A check that fires on the right shape for the wrong reason is + // worse than none: it is the one that gets suppressed, and then it is not there when it + // is right. + if (String(value).startsWith("/")) continue; assert.doesNotMatch(String(value), /^[A-Za-z0-9+/]{24,}={0,2}$/, `${c.name} carries something secret-shaped in env.${key}, which the broker would see`); }