Relationships
↔ sibling #2815#2814 sensitive_data_delivery_test fails where /bin/sh is bash: the final ps is exec'd and reports its own argv
Opened by hammz · 9/30/2026· Shipped 9/30/2026
Summary
integration/sensitive_data_delivery_test.ts, test 'sensitive data: a shell step receives data.latest values through the environment' (line ~297), fails deterministically on hosts where /bin/sh is bash (e.g. Arch/CachyOS). It fails on clean origin/main (fdd49f4d) too, so it blocks verify-build there for every branch.
Cause
The shell step's command ends with ps -o args= -p followed by the shell's own pid. bash exec-optimizes the last command of a -c string, so that pid is the ps process itself by the time it runs, and ps prints its own argv (ps -o args= -p 12345) instead of the sh -c command line. The test then finds no line containing 'sh -c' and fails with AssertionError: STEP=consume ... dash does not replace itself here, so the test passes where /bin/sh is dash.
bash -c 'ps -o args= -p $$' -> ps -o args= -p 3086907
bash -c 'ps -o args= -p $$; true' -> bash -c ps -o args= -p $$; trueThe same ps pattern appears at lines ~311, ~343, ~474 and ~629 of that file.
Fix direction
Keep ps from being the last command of the step (append '; true' or an echo after it), so the shell is still the process being inspected on every /bin/sh. Test-only change.
Shipped
Click a lifecycle step above to view its details.