From 31ebec620808a8af7f7b75a77ca64a91ca593103 Mon Sep 17 00:00:00 2001 From: Sherry <26760878+shaibearary@users.noreply.github.com> Date: Sat, 12 Sep 2026 09:15:44 +0000 Subject: [PATCH] fix(testing): guard the empty env_args splat in the mesh-lab loop Running `run-loop.sh rekey` on macOS aborts the setup subshell with "env_args[@]: unbound variable", so generate-configs.sh, the rekey inject-config step and `docker compose up -d` never run. The script carries on and runs the suite against a stack that was never started, so the failure surfaces as a bogus rekey failure rather than a setup error, and setup.log is empty because the expansion fails before the redirection is applied. run_rekey_family() declares `local env_args=()` and fills it only for the rekey-accept-off and rekey-outbound-only variants, so the plain `rekey` variant reaches the `env "${env_args[@]}"` call sites with an empty array. Under `set -u` (line 49) bash 3.2 treats an empty array expansion as unbound. Bash 4.4 stopped doing so, which is why Linux and CI never see this and only macOS's /bin/bash 3.2 is affected. Expand the array as `${env_args[@]+"${env_args[@]}"}` at those three call sites. It yields nothing for an empty array and the quoted elements otherwise, on every bash version, so the plain variant runs `env` with no assignments and the other two keep their overrides. The nat-lan call site is left as it is: its env_args is declared with an element and can never be empty. Co-authored-by: Johnathan Corgan --- testing/mesh-lab/run-loop.sh | 9 ++++++--- 1 file changed, 6 insertions(+), 3 deletions(-) diff --git a/testing/mesh-lab/run-loop.sh b/testing/mesh-lab/run-loop.sh index 5d19bb4d..a4e0c987 100755 --- a/testing/mesh-lab/run-loop.sh +++ b/testing/mesh-lab/run-loop.sh @@ -163,6 +163,9 @@ run_rekey_family() { local variant="$1" # rekey, rekey-accept-off, rekey-outbound-only local REP_DIR="$2" local compose_profile="$variant" + # Expanded below as ${env_args[@]+"${env_args[@]}"}: under set -u, + # bash 3.2 (macOS /bin/bash) rejects "${env_args[@]}" on an empty + # array, and the plain rekey variant leaves it empty. local env_args=() case "$variant" in @@ -203,9 +206,9 @@ run_rekey_family() { ( cd "$REPO_ROOT" || exit 1 - env "${env_args[@]}" bash testing/static/scripts/generate-configs.sh "$variant" \ + env ${env_args[@]+"${env_args[@]}"} bash testing/static/scripts/generate-configs.sh "$variant" \ >>"$REP_DIR/setup.log" 2>&1 - env "${env_args[@]}" bash testing/static/scripts/rekey-test.sh inject-config \ + env ${env_args[@]+"${env_args[@]}"} bash testing/static/scripts/rekey-test.sh inject-config \ >>"$REP_DIR/setup.log" 2>&1 docker compose "${compose_args[@]}" up -d \ >>"$REP_DIR/setup.log" 2>&1 @@ -240,7 +243,7 @@ run_rekey_family() { local rc=0 ( cd "$REPO_ROOT" || exit 1 - env "${env_args[@]}" bash testing/static/scripts/rekey-test.sh + env ${env_args[@]+"${env_args[@]}"} bash testing/static/scripts/rekey-test.sh ) >"$REP_DIR/test-output.log" 2>&1 || rc=$? # Capture container logs before teardown