Fix unbound-variable crash in the nightly sweep tier-1 loop

scan_scanners referenced ${slug} inside the SAME local statement that defines it
(local target=... slug=$2 result_json=...${slug}...). bash expands the local's
arguments before the builtin assigns them, so under set -u ${slug} is unbound and
the sweep died right after the canary, before tier 1 ever ran. Split the local so
slug exists first. Fix the same latent self-reference in mirror_repo (dir=...$name),
which only worked by accident because the discovery loop left a global $name.
This commit is contained in:
Adam Moussa 2026-06-16 16:00:21 -04:00
parent 86ad29dcc2
commit 6d65c54b58

View file

@ -136,7 +136,8 @@ discover_repos() {
# failed fetch cannot leave GH_TOKEN at rest on disk. (Residual: the token is briefly visible
# in process args to a local `ps`; acceptable on this single-user unattended box.)
mirror_repo() { # name clone_url default_branch -> 0 ok / 1 fail
local name="$1" url="$2" branch="$3" dir="$MIRROR_DIR/$name"
local name="$1" url="$2" branch="$3"
local dir="$MIRROR_DIR/$name"
local auth_url="https://x-access-token:${GH_TOKEN}@${url#https://}"
if [ -d "$dir/.git" ]; then
git -C "$dir" fetch --depth=1 "$auth_url" "$branch" >/dev/null 2>&1 || return 1
@ -188,7 +189,8 @@ xmodel_check_criticals() {
# Sets T1_BLOCK/T1_CRIT/T1_HIGH. review.sh exit 0 pass / 1 BLOCK / 2 setup.
T1_BLOCK=0; T1_CRIT=0; T1_HIGH=0
scan_scanners() { # target slug
local target="$1" slug="$2" result_json="$REPORT_DIR/${slug}.scanners.json"
local target="$1" slug="$2"
local result_json="$REPORT_DIR/${slug}.scanners.json"
T1_BLOCK=0; T1_CRIT=0; T1_HIGH=0
local sup=()
[ -f "$target/.security-review/suppressions.json" ] && sup=(--suppressions "$target/.security-review/suppressions.json")