fix(smoke): keep prose out of the single-quoted exec_test body
The agent-browser execution guard added on 2026-09-07 carried its explanation
INSIDE the single-quoted script body, and the explanation contained an
apostrophe ("the fleet\'s only recurring amd64 runtime proof"). Inside '...'
bash treats a backslash as literal, so \' does not escape the quote -- it CLOSES
the string. The body truncated at that point and the remaining lines were parsed
by the calling shell.
Consequences, both measured rather than inferred:
- exec_test received 12 arguments instead of 2 (verified two-sided: the fixed
tree yields argc=2, HEAD yields argc=12).
- the leaked `v=$(agent-browser --version)` ran on the CI RUNNER instead of
inside the image. The runner has no agent-browser, so smoke and
smoke-studio both failed with "line 770: command not found" after
build-base had already spent ~46 minutes. Every downstream job was skipped.
- the truncated body still passed inside the container and printed its green
tick first, so the log shows a PASS immediately followed by the failure --
the tick was real, it just no longer covered the assertion.
The prose now sits above the exec_test call, where an apostrophe cannot
terminate anything, and a comment at that spot records why it must stay there.
Not a new failure class: shellcheck flagged it as SC2289 at severity error the
same day, so the lint job has been red since run 186 (2026-09-07 21:21) and was
not read. The gate did its job; nobody looked.
This commit is contained in:
@@ -13,6 +13,29 @@ Pre-v1.0.0 tags followed the pi npm version (`v{pi_version}[letter]`).
|
||||
|
||||
## v1.8.14 — 2026-09-08
|
||||
|
||||
> **First release attempt failed; fixed in this same entry.** The `smoke` and
|
||||
> `smoke-studio` jobs both failed at `scripts/smoke-test.sh:770` with
|
||||
> `agent-browser: command not found`, after `build-base` had already succeeded
|
||||
> (~46 min spent). Root cause was in the agent-browser execution guard added the
|
||||
> day before: the explanatory comment inside the **single-quoted** `exec_test`
|
||||
> body contained an apostrophe (`the fleet\'s`). Inside `'...'` bash treats a
|
||||
> backslash literally, so `\'` does not escape — it **closes the string**. The
|
||||
> body silently truncated (measured: `exec_test` received **12** arguments
|
||||
> instead of 2), and the remaining lines, including the `agent-browser --version`
|
||||
> assertion, were parsed by the **runner's** shell instead of executing inside
|
||||
> the image — and the runner has no agent-browser. The prose now lives above the
|
||||
> call, where an apostrophe is harmless.
|
||||
>
|
||||
> **The lint job had already caught this, and it went unread for 24 hours.**
|
||||
> `shellcheck` flagged it as `SC2289` at severity *error*, so the `actionlint`
|
||||
> job went red at run 186 on 2026-09-07 21:21 — the exact push that introduced
|
||||
> the guard — and stayed red for runs 187 and 188. `lint.yml` deliberately
|
||||
> excludes tag pushes (documented: the tagged tree was already linted on main,
|
||||
> and a tag-ref lint run would sort above the publish run), which is sound; the
|
||||
> broken assumption was different, namely that a tree whose lint FAILED would not
|
||||
> then be released. `docker-publish.yml` has no dependency on lint, so it built
|
||||
> for 50 minutes on a tree known to be defective.
|
||||
|
||||
**A test that was quietly checking nothing, and a version number that was wrong.**
|
||||
Both found by delegating a read-only audit of this repo to a headless worker
|
||||
(`pi-toolkit` `bin/pi-task`) and then spot-checking its pointers from the
|
||||
|
||||
Reference in New Issue
Block a user