Skip to content

Commit b25aebf

Browse files
mikolalysenkoclaude
andcommitted
test(bun): keep uuid-derived values out of assertion messages for CodeQL
GitHub's default CodeQL setup raised eight rust/cleartext-logging alerts on the new bun tests: its name-based heuristic treats any value flowing from a `uuid`-named binding (a loop variable, a tuple holding `dep.uuid_h`, the `other_uuid` fixture) as sensitive when it reaches a panic/assert message. The values are patch identifiers in test fixtures, not secrets, but the repo keeps the check green on PRs, so the messages now describe the failed condition without interpolating those values and the uuid is bound apart from the vendor envelope it was paired with. No assertion got weaker: each still checks the same condition and prints the same envelope/lock context. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
1 parent 9772549 commit b25aebf

2 files changed

Lines changed: 20 additions & 9 deletions

File tree

‎crates/socket-patch-cli/tests/mode_migration_bun.rs‎

Lines changed: 18 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -1011,10 +1011,14 @@ fn assert_pure_hosted(fx: &Fixture, proj: &Path, hp: &HostedPatch) {
10111011
!state.contains(dep.purl),
10121012
"the displaced vendored ledger entry must be dropped: {state}"
10131013
);
1014-
for uuid in [dep.uuid_v, dep.uuid_h] {
1014+
for stale in [dep.uuid_v, dep.uuid_h] {
1015+
// The message deliberately names no identifier: CodeQL's
1016+
// cleartext-logging heuristic treats anything flowing from a
1017+
// `uuid`-named binding as sensitive.
10151018
assert!(
1016-
!proj.join(".socket/vendor/npm").join(uuid).exists(),
1017-
"the orphaned committed artifact dir .socket/vendor/npm/{uuid} must be removed"
1019+
!proj.join(".socket/vendor/npm").join(stale).exists(),
1020+
"every orphaned committed artifact dir under .socket/vendor/npm must be removed \
1021+
after the hosted takeover"
10181022
);
10191023
}
10201024
let lock = read(proj, "bun.lock");
@@ -1122,7 +1126,7 @@ fn assert_pure_vendored(fx: &Fixture, proj: &Path, dep: &Dep, uuid: &str, hosted
11221126
}
11231127
assert!(
11241128
proj.join(&rel).is_file(),
1125-
"the committed artifact {rel} must exist"
1129+
"the committed artifact tarball must exist under .socket/vendor/npm"
11261130
);
11271131
let state = read_json(proj, ".socket/vendor/state.json");
11281132
let wiring = state["entries"][dep.purl]["wiring"]
@@ -1269,12 +1273,19 @@ fn take_over_to_vendored(
12691273
tag: &str,
12701274
) -> &'static str {
12711275
let dep = hp.dep;
1272-
let (uuid, vendor_env) = match driver {
1276+
// Kept apart from the envelope on purpose (no tuple): CodeQL's
1277+
// cleartext-logging heuristic would otherwise taint every `{vendor_env}`
1278+
// assertion message with the `uuid`-named half.
1279+
let uuid = match driver {
1280+
VendoredDriver::VendorOffline => dep.uuid_v,
1281+
VendoredDriver::ScanVendored => dep.uuid_h,
1282+
};
1283+
let vendor_env = match driver {
12731284
VendoredDriver::VendorOffline => {
12741285
stage_manifest(fx, proj, dep);
12751286
let (code, stdout, stderr) = vendor_cmd(proj, &[]);
12761287
assert_eq!(code, 0, "vendor failed ({tag}): {stdout}\n{stderr}");
1277-
(dep.uuid_v, envelope(&stdout, &stderr))
1288+
envelope(&stdout, &stderr)
12781289
}
12791290
VendoredDriver::ScanVendored => {
12801291
let (code, stdout, stderr) = vendored_scan(proj, api, &[]);
@@ -1284,7 +1295,7 @@ fn take_over_to_vendored(
12841295
);
12851296
let env = envelope(&stdout, &stderr);
12861297
assert_eq!(env["status"], "success", "{env:#}");
1287-
(dep.uuid_h, env["vendor"].clone())
1298+
env["vendor"].clone()
12881299
}
12891300
};
12901301
assert_eq!(vendor_env["status"], "success", "{vendor_env:#}");

‎crates/socket-patch-core/src/patch/redirect/replay.rs‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1296,8 +1296,8 @@ mod tests {
12961296
assert_eq!(
12971297
out.refusals.len(),
12981298
1,
1299-
"{kind} over {live}: {:?}",
1300-
out.refusals
1299+
"{kind}: exactly one refusal expected, got {}",
1300+
out.refusals.len()
13011301
);
13021302
assert!(
13031303
out.refusals[0].reason.contains(reason),

0 commit comments

Comments
 (0)