Skip to content

Avoid xtrace in deploy install paths - #152

Closed
MoneroOcean wants to merge 1 commit into
masterfrom
codex/propose-fix-for-xtrace-secret-leakage
Closed

MoneroOcean wants to merge 1 commit into
masterfrom
codex/propose-fix-for-xtrace-secret-leakage

Conversation

@MoneroOcean

Copy link
Copy Markdown
Owner

Motivation

  • Prevent accidental disclosure of deployment secrets when operators follow the README curl-pipe install examples by disabling bash xtrace (-x).
  • Preserve existing error-fail behavior while removing the explicit advice and script flags that cause secret values (Cloudflare API token, generated MySQL root password, API keys) to be printed to stderr/logs.

Description

  • Replace the README curl-pipe single-server example to use bash -s instead of bash -x and change the leaf install example to pipe into plain bash instead of bash -x.
  • Change the deploy.bash and leaf.bash shebangs from #!/bin/bash -ex to #!/bin/bash -e so scripts still fail fast but do not enable xtrace by default.
  • Preserve all deployment logic and defaults; no secret-handling code or behavior was otherwise altered.

Testing

  • Ran rg -n "bash -x|set -x|^#!/bin/bash -.*x" README.md deployment/deploy.bash deployment/leaf.bash to verify -x recommendations and shebangs were removed, and the search returned no remaining -x occurrences in the install paths.
  • Run bash -n deployment/deploy.bash and bash -n deployment/leaf.bash for syntax checks which completed without errors.
  • Executed git diff --check to ensure no trailing whitespace or diff-check issues remained, which reported no problems.

Codex Task

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant