job7 step B: redact printenv/env dumps in rtk-rewrite.sh (GITEA leak vector)

Any single-pipeline printenv/env dump now gets a redaction pipe appended
before it can reach stdout/transcript; `env VAR=x cmd` (legitimate
subprocess launch) is left intact. Compound commands (;, &, ||) bail
untouched — appending the pipe at the end would attach to the wrong
segment.

Discovered mid-implementation: rtk rewrite classifies any command
containing "env" as exit-code 2 ("deny"), with no settings.json rule
backing it — the command still reaches native evaluation and can run.
Adjusted case 2/1 handling so the redaction check runs regardless.
This commit is contained in:
Bastien Chanot
2026-07-07 12:30:30 +02:00
parent 563fbd5422
commit 3340c7d1bd
4 changed files with 137 additions and 9 deletions
+1 -1
View File
@@ -1 +1 @@
871efa28daf7c06a9c9039a2875407e2536646f5d82f7e7a9c6a80dd3742929c rtk-rewrite.sh
82369e32905a8de6dc6b2566c5992f686794a826b2310b15a96e4bd9d25ac7b6 rtk-rewrite.sh