Skip to content

Filter Bash read only config vars such as UID in export_env - #2152

Open
Hashim1999164 wants to merge 1 commit into
heroku:mainfrom
Hashim1999164:fix/blacklist-bash-readonly-config-vars
Open

Hashim1999164 wants to merge 1 commit into
heroku:mainfrom
Hashim1999164:fix/blacklist-bash-readonly-config-vars

Conversation

@Hashim1999164

@Hashim1999164 Hashim1999164 commented Oct 2, 2026 •

Copy link
Copy Markdown

Summary

Fixes #1751

When an app sets a config var named like UID, export_env tried to overwrite a Bash read only variable and the build aborted with UID: readonly variable.

This adds the Bash read only names from the Bash Variables manual (UID, EUID, PPID, BASHOPTS, BASHPID, BASH_VERSINFO, GROUPS, SHELLOPTS) to the default _env_blacklist used by export_env / sub_env.

Normal config vars still export as before.

Test plan

  • Local check: ENV_DIR with UID and MY_APP_VAR files; export_env succeeds, MY_APP_VAR is set, UID is not overwritten
  • CI / hatchet on this PR

App config vars named like UID aborted the build when export_env
tried to overwrite Bash read-only variables. Blacklist those names
alongside the existing unsafe path related variables.

Fixes heroku#1751
@Hashim1999164
Hashim1999164 requested review from a team and edmorley as code owners October 2, 2026 21:49
@edmorley
edmorley removed the request for review from a team October 5, 2026 13:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Filter out Bash read-only env vars in export_env() (such as UID)

1 participant