Merge nucleic/keen-glass-marten-ddlf into dev

This commit is contained in:
2026-07-18 20:31:23 -07:00
parent 30c905dcb0
commit ac5ac7cecd
2 changed files with 32 additions and 0 deletions
+28
View File
@@ -10,6 +10,34 @@ stays open until fixed in the fork (or upstream) and re-verified by the corpus.
## Closed (recent)
### D3 — errexit re-triggered by a compound command's aggregated status (fixed in fork)
- **Found**: narOS N2 first agent-tier CI build (run 29669891162): with
`/bin/sh → nash` baked into naros-base, trixie's `tzdata` postinst exited 1
under dpkg configure, cascading into unconfigured python3/nodejs and failing
the whole `naros-agent` image build — exactly the loud-in-CI dogfood failure
mode the agent Dockerfile courts on purpose.
- **Repro**: `set -e; if true; then false && true; fi; echo hi` → bash prints
`hi` (exit 0), nash exited 1. In tzdata's postinst the trigger was
`which restorecon >/dev/null 2>&1 && restorecon …` (restorecon absent) as
the last statement of an `if` body under `set -e`.
- **Root cause**: brush applies errexit at `Pipeline::execute`, and an
`if`/brace-group/`case`/`for` compound is itself a (single-command) pipeline
— so a failure that was already exempt *inside* the compound (short-circuited
AND-OR list, `!`-negated pipeline) re-triggered errexit on the compound's
aggregated status. bash never re-adjudicates a grouping/looping compound's
status; it does re-trigger for simple commands (incl. function calls),
subshells, `[[ ]]`, and `(( ))`.
- **Fix**: `errexit_applies_to_pipeline` in `brush-core/src/interp.rs` — the
pipeline-level errexit/ERR-trap application now fires only for multi-command
pipelines, simple commands, subshells, extended tests, and arithmetic
commands. Verified against bash on a 15-case matrix (if/brace/case/for/while
bodies, function calls, subshells, cmdsub assignment, `!`, `||`, pipe-to-cat,
`[[ ]]`, compound redirect failures) — all matching; trixie tzdata postinst
green under nash; corpus 101/101 = 100%; candidate for upstreaming.
- **Regression tests**: corpus `errexit-if-andlist`, `errexit-brace-andlist`,
`errexit-if-bang`, `errexit-fn-status`.
### D2 — non-ASCII bytes re-encoded through `read`/`echo` under C/empty locale (fixed in fork)
- **Found**: narOS N0 rootfs validation (first real-world install run under the