Skip to content

Audit fixes: silent-failure class (#60, #61, #62) - #71

Merged
max06 merged 2 commits into
mainfrom
fix/audit-silent-failures
Aug 12, 2026
Merged

max06 merged 2 commits into
mainfrom
fix/audit-silent-failures

Conversation

@max06

@max06 max06 commented Aug 12, 2026

Copy link
Copy Markdown
Owner

The three dangerous-silent-failure findings from the 2026-08-11 template audit.

#60 — helmfile.single circular ctx

Mirrors the documented Release-first + deepCopy-snapshot pattern from helmfile.instance and _values_loader (self-referencing map = stack overflow in fmt.printValue on any error/debug format path; also aligns snapshot semantics across stages).

#61 — convertPaths silent drop

Missing strategicMergePatches/jsonPatches/transformers files now fail with the field name and resolved path. A dropped patch previously deployed the release unpatched, indistinguishable from success.

#62 — values-loader silent skips

All four explicit reference sites (template values:, instance values:, release.secrets, apps[].secrets) now fail on missing files. Hierarchy files stay optional-by-convention.

Tests

6 new bats tests (missing-file-errors.bats) with three new negative fixtures via the existing error-paths harness. Full suite: 453/453 on helm 4.2.3 / helmfile 1.7.3 and the baseline pins.

Note: the self-review comment will flag the known deployment47 Secret ghost — that is #70 (baseline double-redaction), unrelated.

🤖 Generated with Claude Code

max06 and others added 2 commits August 12, 2026 12:03
Set .Release first, then snapshot .Values via deepCopy — mirroring
helmfile.instance and _values_loader. The previous self-referencing map
crashes Go's fmt.printValue with a stack overflow whenever an error or
debug path formats the context, and its snapshot semantics differed from
the other two stages.

Fixes #60

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
- convertPaths: a strategicMergePatches/jsonPatches/transformers entry
  whose file does not exist now fails with the field name and resolved
  path instead of being dropped (release would deploy unpatched).
- values-loader: all four explicit reference sites (template values,
  instance values, release secrets, instance secrets) fail on missing
  files instead of rendering without them (secrets typo = deploying
  without credentials). Hierarchy files stay optional-by-convention.

New negative fixtures + 6 bats tests via the existing error-paths
harness. Full suite 453/453.

Fixes #61
Fixes #62

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@github-actions

Copy link
Copy Markdown

ATLAS Review

Changes detected in 1 resource(s) across 1 release(s).
Please review before merging.

Affected releases

cluster1 / deployment47 / secret-app (1 resources)
Secret/secret-app-secret (15 lines)
@@ data.generatedCert @@
! ± value change
- REDACTED:sha256:64c2cc8965eb
+ REDACTED:sha256:0531e6a12023

@@ stringData.fromSops @@
! ± value change
- REDACTED:sha256:9dacb914694b
+ REDACTED:sha256:9fab3a1ed1c3

@@ stringData.note @@
! ± value change
- REDACTED:sha256:be359b14f3f4
+ REDACTED:sha256:531854cef641

Generated by ATLAS Review — Re-run

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant