fix(runner): a secure field's value does not reach state.lastAction either

folio extracts lastAction, and extractor values are persisted as
extractor_changes, so the password still reached the run directory
through the spec after the three render sites were closed.

The wrap sits in the runner rather than in lastActionFields because the
hosts hold the next step's tree, not the one the action was chosen
against: a field that stops being secure between the two would publish
what the trace withheld. Live and replay now agree byte for byte.
This commit is contained in:
pj committed 2026-08-18 17:32:28 +05:30
1 parent 38d328df90
commit 66fd5bce5d
7 files changed
+181 -8

No files matched your search

+2 -2
View File
@@ -451,7 +451,7 @@ func Run(ctx context.Context, options Options) (Summary, error) {
// the effect committed. Reporting no action here would let a
// property convict the app for an effect with no cause, so the
// action is reported with its fate unknown instead.
unconfirmed := nextAction
unconfirmed := verifier.RecordedAction(nextAction, tree)
lastAction = &unconfirmed
} else if notDispatched != "" {
// The action was chosen but nothing reached the driver, so the
@@ -466,7 +466,7 @@ func Run(ctx context.Context, options Options) (Summary, error) {
lastAction = nil
} else {
consecutiveApplyFailures = 0
applied := nextAction
applied := verifier.RecordedAction(nextAction, tree)
applied.Applied = true
lastAction = &applied
}