forked from heavy-duty/box
wipe.sh piped `ufw status` straight into `grep -q "Status: active"`. That is closes the pipe, ufw takes SIGPIPE, and the pipeline yields 141. It was correct today, and only by accident — the file is `set -u` with no `pipefail`, so the 141 was discarded and grep's 0 carried the branch. It was one line from wrong: adding `set -o pipefail` for unrelated robustness would have silently skipped every UFW removal on a host the operator was told is wiped, with no error and no red X. Measured on a shim: 5/5 runs took the wrong branch under pipefail, 3/3 the right one without. Transplant #106's pattern verbatim from host/teardown-host.sh: capture ufw_status once and match with `[[ ]]`; rewrite the numbered-delete loop — whose condition was itself an early-exit reader, plus an un-captured re-read to get the number — as a `while :` that reads one capture per iteration and breaks on absence. The re-scan stays per-delete, since numbers shift after each removal; it just no longer races. Removals keep the file's `cmd && say "did X"` idiom. Generalize the test/cli.sh pin from the one site to the class: sweep every host/*.sh and drill/*.sh for the racing shape and name the offenders, so a new script in either directory inherits the pin instead of being one more site to remember. Comment lines are stripped before matching — each fix's own commentary quotes the racing shape to explain it, and a prose-blind pin would fail on the comment documenting why it exists. The positive pins (the capture, the break-on-absence) now run per file over both, so the sweep cannot be satisfied by deleting a block instead of fixing it. drill/doctor.sh was checked and needs nothing: it already reads into `ufw_out` and is safe by construction, not by absent pipefail. Refs #107 |
||
|---|---|---|
| .. | ||
| cli.sh | ||
| labels-reconcile.sh | ||
| release.sh | ||