Skip to main content
← Back to list
01Issue
BugShippedSwamp CLIPublic
Assigneesstack72

Relationships

#3101 Shell steps: a vault.get on a continuation line of a multi-line double-quoted string inside a here-doc is wrapped in quotes

Opened by stack72 · 10/6/2026· Shipped 10/6/2026

Problem

swamp-club#3089 (PR #2881) places each vault.get() reference by its own quote context. Inside an unquoted here-document body it reads only the quotes earlier on the same line. When the secret sits on a continuation line of a double-quoted string that spans lines, that line has no open quote, so the reference is wrapped in quotes.

Reproduction

Run string:

cat <<EOF
echo ~line1
${{ vault.get(v,k) }}~
EOF

(with ~ standing for a double quote)

  • Before #2881: the here-doc output is the string with the value inside the original quotes.
  • After #2881: the reference becomes a quoted reference inside the user's open quote, so the generated text closes and reopens the string and the value sits unquoted in the script the here-doc produces (word-splitting and globbing move one level down).

Found by the CI adversarial review on PR #2881; reproduced against merge-base c4c1ed56.

Expected

Inside an unquoted here-doc body, a vault.get reference takes the form main gave it: quote characters counted from the start of the command, evaluated at each use. Double means a bare reference, anything else a quoted one.

Fix

In posixVaultQuote (src/domain/vaults/vault_secret_bag.ts), for heredoc and heredoc-literal contexts use getQuoteContext over the whole command at that position instead of the line prefix. Add the multi-line case to the unit tests and the main-vs-fix matrix.

02Bog Flow
✓OPEN✓TRIAGED✓IN PROGRESS✓SHIPPED+ 1 MOREASSIGNED+ 2 MOREREVIEW+ 22 MOREPR_MERGED+ 2 MORESESSION_SUMMARIZED

Shipped

10/6/2026, 8:54:45 PM

Click a lifecycle step above to view its details.

03Sludge Pulse
stack72 assigned stack7210/6/2026, 7:35:23 PM

Sign in to post a ripple.