fabro/bin/dev/check-env-mutation.sh
Bryan Helmkamp 37cd8ff45f
Merge remote-tracking branch 'origin/main'
# Conflicts:
#	lib/crates/fabro-server/src/lib.rs
#	lib/crates/fabro-server/src/serve.rs
#	lib/crates/fabro-server/src/server.rs
2026-04-23 08:34:44 -04:00

43 lines
1.1 KiB
Bash
Executable file

#!/usr/bin/env bash
set -euo pipefail
cd "$(dirname "$0")/../.."
if command -v rg >/dev/null 2>&1; then
matches=$(rg -n 'std::env::(set_var|remove_var)' --glob '*.rs' || true)
else
matches=$(grep -R -n -E 'std::env::(set_var|remove_var)' . --include='*.rs' --exclude-dir=target --exclude-dir=.git || true)
fi
fail=0
while IFS= read -r match; do
[[ -z "$match" ]] && continue
path=${match%%:*}
rest=${match#*:}
line=${rest#*:}
line=${line#"${line%%[![:space:]]*}"}
case "$path:$line" in
"lib/crates/fabro-telemetry/src/spawn.rs:std::env::set_var(key, value);" | \
"lib/crates/fabro-telemetry/src/spawn.rs:std::env::remove_var(key);" | \
'lib/crates/fabro-server/src/install.rs:std::env::set_var("FABRO_TEST_IN_MEMORY_STORE", "1");')
continue
;;
esac
echo "process env mutation check failed: $match" >&2
fail=1
done <<< "$matches"
if [[ $fail -ne 0 ]]; then
cat >&2 <<'EOF'
Do not mutate process-wide env with std::env::set_var/remove_var.
Inject env at construction time or on child-process Command values instead.
See docs-internal/server-secrets-strategy.md.
EOF
exit 1
fi
echo "Process env mutation checks passed."