fix(db-access): keep database URLs out of argv (ISS-41) #262
No reviewers
Labels
No labels
severity/s2
severity/s3
No milestone
No project
No assignees
2 participants
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
janpeter/Ops-dashboard!262
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "fix/iss41-no-dsn-argv"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
ISS-41 (S-2026-09-28-1 / T-122).
Problem:
prisma_as_deployerandrun_policyinops-agent/wrappers/db-access/prisma-operator.shstarted their children with[runuser -u ops-agent --] env -i … DATABASE_URL=<dsn> …. That put the migrator/superuser DSN in argv:ps//proc/<pid>/cmdline;_CMDLINE. Measured: the rotated superuser password was there 4× since 2026-09-28 01:51Z.Fix:
exec_with_only_env NAME=VALUE … -- cmdbuilds exactly the same environment asenv -i(in a subshell: remove all inherited exports, export the pairs, thenexec), without the values ever appearing in an argv. The root launcher becomesrunuser -m -u ops-agent --, so that environment is kept (verified on srv: the child gets exactly PATH/HOME/USER/LOGNAME/DATABASE_URL, id = ops-agent, runuser cmdline without a secret).Test: new case in
test/db-access-operator.test.ts, with a recordingenvshim first in PATH and recorders around the Prisma and policy children. It fails on the old wrapper: the shim sawDATABASE_URL/DIRECT_URL/DB_ACCESS_OPERATOR_URLwith the password. It passes on the new one, and the children still get the credentials through their env.db-access suites (umask 022): main 101/101 → this branch 102/102.
Rollout: after merge,
install-db-access-module.shon srv, then live proof (T-123):prisma_migrate_status+adoption_precheckwith a /proc sampler and a journal scan. After that, the superuser rotation again (T-124).🤖 Generated with Claude Code
Verdict: APPROVED
Geen blocking findings aangetroffen.
git diff --checkenbash -n ops-agent/wrappers/db-access/prisma-operator.shzijn geslaagd. De gerichte Vitest-test kon in de reviewomgeving niet draaien doordat de native rolldown-binding niet gemapt kan worden; de toegevoegde regressietest dekt het Prisma- en policy-argv-pad.