From 9711a90bdecb7b20cddf9cbc2ef2c5c991a90494 Mon Sep 17 00:00:00 2001 From: jochen Date: Mon, 31 Aug 2026 00:48:00 +0200 Subject: [PATCH] A command with no marker is a failure, not a success MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Two faults in one line of the harness, and the second is the serious one. Every command was wrapped as ` 2>&1; echo "__exit=$?"` on a single line, so any command containing a heredoc broke: the terminator line became `MARKER 2>&1; echo ...`, matched nothing, and the heredoc swallowed the rest of the script — the echo with it. `exec 2>&1` on its own first line fixes that: a heredoc then terminates where it says it does. And when the marker was gone, `Number("")` is 0, so the missing exit status read as exit 0. A command whose output was swallowed reported that it worked, which is the one answer a test harness must never give. It is now a failure, with whatever was said returned so the reason is visible. Found because the firewall test's listener is written with a heredoc and never started, and the test failed on its own setup — which reads exactly like the firewall working. --- test/integration/mesh.test.ts | 17 +++++++++++++++-- 1 file changed, 15 insertions(+), 2 deletions(-) diff --git a/test/integration/mesh.test.ts b/test/integration/mesh.test.ts index a3c3705..3522d55 100644 --- a/test/integration/mesh.test.ts +++ b/test/integration/mesh.test.ts @@ -66,11 +66,24 @@ function quote(s: string): string { } async function on(machine: string, command: string, timeoutMs?: number): Promise<{ out: string; ok: boolean }> { + // Each part on its own line, and stderr redirected once for the whole script. + // + // It was `${command} 2>&1; echo ...` on a single line, which quietly broke every command + // containing a heredoc: the terminator line became `MARKER 2>&1; echo ...`, matched nothing, and + // the heredoc swallowed the rest of the script — including the echo. `exec 2>&1` needs no + // trailing text on the command's last line, so a heredoc terminates where it says it does. const { stdout } = await exec(instanceId, machine, [ - "sh", "-c", `${command} 2>&1; echo "__exit=$?"`, + "sh", "-c", `exec 2>&1\n${command}\necho "__exit=$?"`, ], timeoutMs); const marker = stdout.lastIndexOf("__exit="); - return { out: stdout.slice(0, marker), ok: Number(stdout.slice(marker + 7).trim()) === 0 }; + if (marker < 0) { + // **Never success.** `Number("")` is 0, so a missing marker used to read as exit 0 — a + // command whose output was swallowed reported that it worked, which is the one answer a test + // harness must never give. + return { out: stdout, ok: false }; + } + const said = stdout.slice(marker + 7).trim(); + return { out: stdout.slice(0, marker), ok: said === "0" }; } async function must(machine: string, command: string, timeoutMs?: number): Promise {