Skip to content

Forward named environment variables to remote steps (#643) - #643

Closed
lcpz wants to merge 1 commit into
mainfrom
export-D120420789
Closed

lcpz wants to merge 1 commit into
mainfrom
export-D120420789

Conversation

@lcpz

@lcpz lcpz commented Sep 17, 2026 •

Copy link
Copy Markdown
Contributor

Summary:

Context

  • Remote commands do not inherit the runner's environment. Callers need to forward selected values, such as run identifiers, across SSH without editing each TTP.
  • Forwarding is requested through a CLI flag so an older binary rejects unsupported usage before executing the TTP.
  • GitHub CI exposed an existing Go version mismatch: new("baz") in pkg/args/choices_test.go requires Go 1.26, while the module selected Go 1.25.5.

This Diff

  • Add repeatable --forward-env NAME for remote inline: and file: commands.
  • Trim and deduplicate names in argument order. Require nonempty names to match [A-Za-z_][A-Za-z0-9_]*; reject invalid names before remote command dispatch, even if unset. Skip unset variables and preserve set-but-empty values.
  • Pass forwarded values literally, including $forge. references. Continue expanding TTP-level and step-level env, with forwarded < TTP < step precedence.
  • Document the CLI interface, version requirement, validation, and precedence in the remote execution guide and schema reference.
  • Cover forwarding and precedence with 14 authenticated loopback SSH cases, 12 invalid-name helper cases, and 6 executor rejection cases across POSIX, PowerShell, and cmd configurations.
  • Set the module minimum to Go 1.26.0 and select Go 1.26.5. Have GitHub pre-commit derive its Go version from go.mod.

Reviewed By: andreizharinov, d0n601

Differential Revision: D120420789

@meta-codesync

meta-codesync Bot commented Sep 17, 2026

Copy link
Copy Markdown

@lcpz has exported this pull request. If you are a Meta employee, you can view the originating Diff in D120420789.

@github-actions

github-actions Bot commented Sep 17, 2026 •

Copy link
Copy Markdown

Coverage Report for CI Build 36721906150

Warning

No base build found for commit c79ae8f on main.
Coverage changes can't be calculated without a base build.
If a base build is processing, this comment will update automatically when it completes.

Coverage: 53.163%

Details

  • Patch coverage: 12 uncovered changes across 2 files (61 of 73 lines covered, 83.56%).

Uncovered Changes

File Changed Covered %
pkg/backends/ssh.go 43 32 74.42%
pkg/blocks/executor.go 10 9 90.0%
Total (4 files) 73 61 83.56%

Coverage Regressions

Requires a base build to compare against. How to fix this →


Coverage Stats

Coverage Status
Relevant Lines: 6245
Covered Lines: 3320
Line Coverage: 53.16%
Coverage Strength: 15.68 hits per line

💛 - Coveralls

@meta-codesync meta-codesync Bot changed the title Forward named environment variables to remote steps Forward named environment variables to remote steps (#643) Sep 17, 2026
meta-codesync Bot pushed a commit that referenced this pull request Sep 17, 2026
Summary:

## Context

Remote commands do not inherit the runner's environment. Callers need a way to explicitly select variables to pass to those commands without editing each TTP.

## This Diff

- Add repeatable `--forward-env NAME` and comma-separated `TTPFORGE_FORWARD_ENV` support for remote `inline:` and `file:` commands.
- Trim, merge, and deduplicate names from both sources. Skip unset variables and preserve values that are set but empty.
- Apply forwarded values before TTP-level and step-level `env`, so explicit TTP and step values take precedence.
- Document both forms and the precedence order in the remote execution guide and schema reference.
- Add a CLI integration test using an authenticated loopback SSH server, covering all three precedence levels for inline and file commands.

Differential Revision: D120420789
meta-codesync Bot pushed a commit that referenced this pull request Sep 17, 2026
Summary:

## Context

Remote commands do not inherit the runner's environment. Callers need a way to explicitly select variables to pass to those commands without editing each TTP.

## This Diff

- Add repeatable `--forward-env NAME` and comma-separated `TTPFORGE_FORWARD_ENV` support for remote `inline:` and `file:` commands.
- Trim, merge, and deduplicate names from both sources. Skip unset variables and preserve values that are set but empty.
- Apply forwarded values before TTP-level and step-level `env`, so explicit TTP and step values take precedence.
- Document both forms and the precedence order in the remote execution guide and schema reference.
- Add a CLI integration test using an authenticated loopback SSH server, covering all three precedence levels for inline and file commands.
- Require Go 1.26 for existing language features, select toolchain Go 1.26.5, and have the GitHub pre-commit workflow read its version from `go.mod`.

Differential Revision: D120420789
meta-codesync Bot pushed a commit that referenced this pull request Sep 17, 2026
Summary:

## Context

Remote commands do not inherit the runner's environment. Callers need a way to explicitly select variables to pass to those commands without editing each TTP.

## This Diff

- Add repeatable `--forward-env NAME` and comma-separated `TTPFORGE_FORWARD_ENV` support for remote `inline:` and `file:` commands.
- Trim, merge, and deduplicate names from both sources. Skip unset variables and preserve values that are set but empty.
- Apply forwarded values before TTP-level and step-level `env`, so explicit TTP and step values take precedence.
- Document both forms and the precedence order in the remote execution guide and schema reference.
- Add a CLI integration test using an authenticated loopback SSH server, covering all three precedence levels for inline and file commands.
- Require Go 1.26 for existing language features, select toolchain Go 1.26.5, and have the GitHub pre-commit workflow read its version from `go.mod`.
- Pass forwarded runner values literally; expand `$forge.` references only in TTP-level and step-level `env`.
- Extend SSH integration coverage for literal forwarding and expansion, and isolate helper tests from ambient forwarding settings.

Differential Revision: D120420789
meta-codesync Bot pushed a commit that referenced this pull request Sep 17, 2026
Summary:

## Context

- Remote commands do not inherit the runner's environment. Callers need to explicitly forward selected values, such as run identifiers, to preserve execution context across SSH without editing each TTP.
- Preparing this change for public release also includes fixing the Go version mismatch exposed by GitHub CI. `go vet` failed on the existing `new("baz")` expression in `pkg/args/choices_test.go`, which requires Go 1.26, while the module selected Go 1.25.5. Updating Go and deriving the pre-commit version from `go.mod` are deliberate fixes for that public CI failure.

## This Diff

- Add repeatable `--forward-env NAME` and comma-separated `TTPFORGE_FORWARD_ENV` support for remote `inline:` and `file:` commands.
- Trim, merge, and deduplicate names from both sources. Require nonempty names to match `[A-Za-z_][A-Za-z0-9_]*`; fail the remote step before command dispatch on an invalid name, even if unset. Skip valid unset variables and preserve values that are set but empty.
- Preserve forwarded values literally, including `$forge.` references. Expand TTP-level and step-level `env` values and apply forwarded < TTP < step precedence.
- Document both forwarding forms, name validation, literal-value handling, and precedence in the remote execution guide and schema reference.
- Cover precedence, literal forwarding, and continued TTP/step expansion with 14 authenticated loopback SSH integration cases. Isolate helper tests from ambient forwarding settings.
- Add 24 invalid-name helper cases and 12 executor rejection cases covering both forwarding sources and POSIX, PowerShell, and cmd executor configurations. Verify no command reaches the backend on invalid input.
- Set the module minimum to Go 1.26.0 and select toolchain Go 1.26.5 to support the language features already used by the codebase.
- Have the GitHub pre-commit workflow read its Go version from `go.mod`, keeping public validation aligned with the declared toolchain.

Differential Revision: D120420789
meta-codesync Bot pushed a commit that referenced this pull request Sep 19, 2026
Summary:

## Context

- Remote commands do not inherit the runner's environment. Callers need to explicitly forward selected values, such as run identifiers, to preserve execution context across SSH without editing each TTP.
- Preparing this change for public release also includes fixing the Go version mismatch exposed by GitHub CI. `go vet` failed on the existing `new("baz")` expression in `pkg/args/choices_test.go`, which requires Go 1.26, while the module selected Go 1.25.5. Updating Go and deriving the pre-commit version from `go.mod` are deliberate fixes for that public CI failure.

## This Diff

- Add repeatable `--forward-env NAME` and comma-separated `TTPFORGE_FORWARD_ENV` support for remote `inline:` and `file:` commands.
- Trim, merge, and deduplicate names from both sources. Require nonempty names to match `[A-Za-z_][A-Za-z0-9_]*`; fail the remote step before command dispatch on an invalid name, even if unset. Skip valid unset variables and preserve values that are set but empty.
- Preserve forwarded values literally, including `$forge.` references. Expand TTP-level and step-level `env` values and apply forwarded < TTP < step precedence.
- Document both forwarding forms, name validation, literal-value handling, and precedence in the remote execution guide and schema reference.
- Cover precedence, literal forwarding, and continued TTP/step expansion with 14 authenticated loopback SSH integration cases. Isolate helper tests from ambient forwarding settings.
- Add 24 invalid-name helper cases and 12 executor rejection cases covering both forwarding sources and POSIX, PowerShell, and cmd executor configurations. Verify no command reaches the backend on invalid input.
- Set the module minimum to Go 1.26.0 and select toolchain Go 1.26.5 to support the language features already used by the codebase.
- Have the GitHub pre-commit workflow read its Go version from `go.mod`, keeping public validation aligned with the declared toolchain.

Differential Revision: D120420789
meta-codesync Bot pushed a commit that referenced this pull request Sep 19, 2026
Summary:
Pull Request resolved: #643

## Context

- Remote commands do not inherit the runner's environment. Callers need to explicitly forward selected values, such as run identifiers, to preserve execution context across SSH without editing each TTP.
- Preparing this change for public release also includes fixing the Go version mismatch exposed by GitHub CI. `go vet` failed on the existing `new("baz")` expression in `pkg/args/choices_test.go`, which requires Go 1.26, while the module selected Go 1.25.5. Updating Go and deriving the pre-commit version from `go.mod` are deliberate fixes for that public CI failure.

## This Diff

- Add repeatable `--forward-env NAME` and comma-separated `TTPFORGE_FORWARD_ENV` support for remote `inline:` and `file:` commands.
- Trim, merge, and deduplicate names from both sources. Require nonempty names to match `[A-Za-z_][A-Za-z0-9_]*`; fail the remote step before command dispatch on an invalid name, even if unset. Skip valid unset variables and preserve values that are set but empty.
- Preserve forwarded values literally, including `$forge.` references. Expand TTP-level and step-level `env` values and apply forwarded < TTP < step precedence.
- Document both forwarding forms, name validation, literal-value handling, and precedence in the remote execution guide and schema reference.
- Cover precedence, literal forwarding, and continued TTP/step expansion with 14 authenticated loopback SSH integration cases. Isolate helper tests from ambient forwarding settings.
- Add 24 invalid-name helper cases and 12 executor rejection cases covering both forwarding sources and POSIX, PowerShell, and cmd executor configurations. Verify no command reaches the backend on invalid input.
- Set the module minimum to Go 1.26.0 and select toolchain Go 1.26.5 to support the language features already used by the codebase.
- Have the GitHub pre-commit workflow read its Go version from `go.mod`, keeping public validation aligned with the declared toolchain.

Differential Revision: D120420789
meta-codesync Bot pushed a commit that referenced this pull request Sep 22, 2026
Summary:

## Context

- Remote commands do not inherit the runner's environment. Callers need to explicitly forward selected values, such as run identifiers, to preserve execution context across SSH without editing each TTP.
- Preparing this change for public release also includes fixing the Go version mismatch exposed by GitHub CI. `go vet` failed on the existing `new("baz")` expression in `pkg/args/choices_test.go`, which requires Go 1.26, while the module selected Go 1.25.5. Updating Go and deriving the pre-commit version from `go.mod` are deliberate fixes for that public CI failure.

## This Diff

- Add repeatable `--forward-env NAME` and comma-separated `TTPFORGE_FORWARD_ENV` support for remote `inline:` and `file:` commands.
- Trim, merge, and deduplicate names from both sources. Require nonempty names to match `[A-Za-z_][A-Za-z0-9_]*`; fail the remote step before command dispatch on an invalid name, even if unset. Skip valid unset variables and preserve values that are set but empty.
- Preserve forwarded values literally, including `$forge.` references. Expand TTP-level and step-level `env` values and apply forwarded < TTP < step precedence.
- Document both forwarding forms, name validation, literal-value handling, and precedence in the remote execution guide and schema reference.
- Cover precedence, literal forwarding, and continued TTP/step expansion with 14 authenticated loopback SSH integration cases. Isolate helper tests from ambient forwarding settings.
- Add 24 invalid-name helper cases and 12 executor rejection cases covering both forwarding sources and POSIX, PowerShell, and cmd executor configurations. Verify no command reaches the backend on invalid input.
- Set the module minimum to Go 1.26.0 and select toolchain Go 1.26.5 to support the language features already used by the codebase.
- Have the GitHub pre-commit workflow read its Go version from `go.mod`, keeping public validation aligned with the declared toolchain.

Differential Revision: D120420789
meta-codesync Bot pushed a commit that referenced this pull request Sep 22, 2026
Summary:
Pull Request resolved: #643

## Context

- Remote commands do not inherit the runner's environment. Callers need to explicitly forward selected values, such as run identifiers, to preserve execution context across SSH without editing each TTP.
- Preparing this change for public release also includes fixing the Go version mismatch exposed by GitHub CI. `go vet` failed on the existing `new("baz")` expression in `pkg/args/choices_test.go`, which requires Go 1.26, while the module selected Go 1.25.5. Updating Go and deriving the pre-commit version from `go.mod` are deliberate fixes for that public CI failure.

## This Diff

- Add repeatable `--forward-env NAME` and comma-separated `TTPFORGE_FORWARD_ENV` support for remote `inline:` and `file:` commands.
- Trim, merge, and deduplicate names from both sources. Require nonempty names to match `[A-Za-z_][A-Za-z0-9_]*`; fail the remote step before command dispatch on an invalid name, even if unset. Skip valid unset variables and preserve values that are set but empty.
- Preserve forwarded values literally, including `$forge.` references. Expand TTP-level and step-level `env` values and apply forwarded < TTP < step precedence.
- Document both forwarding forms, name validation, literal-value handling, and precedence in the remote execution guide and schema reference.
- Cover precedence, literal forwarding, and continued TTP/step expansion with 14 authenticated loopback SSH integration cases. Isolate helper tests from ambient forwarding settings.
- Add 24 invalid-name helper cases and 12 executor rejection cases covering both forwarding sources and POSIX, PowerShell, and cmd executor configurations. Verify no command reaches the backend on invalid input.
- Set the module minimum to Go 1.26.0 and select toolchain Go 1.26.5 to support the language features already used by the codebase.
- Have the GitHub pre-commit workflow read its Go version from `go.mod`, keeping public validation aligned with the declared toolchain.

Differential Revision: D120420789
meta-codesync Bot pushed a commit that referenced this pull request Sep 22, 2026
Summary:
Pull Request resolved: #643

## Context

- Remote commands do not inherit the runner's environment. Callers need to explicitly forward selected values, such as run identifiers, to preserve execution context across SSH without editing each TTP.
- Preparing this change for public release also includes fixing the Go version mismatch exposed by GitHub CI. `go vet` failed on the existing `new("baz")` expression in `pkg/args/choices_test.go`, which requires Go 1.26, while the module selected Go 1.25.5. Updating Go and deriving the pre-commit version from `go.mod` are deliberate fixes for that public CI failure.

## This Diff

- Add repeatable `--forward-env NAME` and comma-separated `TTPFORGE_FORWARD_ENV` support for remote `inline:` and `file:` commands.
- Trim, merge, and deduplicate names from both sources. Require nonempty names to match `[A-Za-z_][A-Za-z0-9_]*`; fail the remote step before command dispatch on an invalid name, even if unset. Skip valid unset variables and preserve values that are set but empty.
- Preserve forwarded values literally, including `$forge.` references. Expand TTP-level and step-level `env` values and apply forwarded < TTP < step precedence.
- Document both forwarding forms, name validation, literal-value handling, and precedence in the remote execution guide and schema reference.
- Cover precedence, literal forwarding, and continued TTP/step expansion with 14 authenticated loopback SSH integration cases. Isolate helper tests from ambient forwarding settings.
- Add 24 invalid-name helper cases and 12 executor rejection cases covering both forwarding sources and POSIX, PowerShell, and cmd executor configurations. Verify no command reaches the backend on invalid input.
- Set the module minimum to Go 1.26.0 and select toolchain Go 1.26.5 to support the language features already used by the codebase.
- Have the GitHub pre-commit workflow read its Go version from `go.mod`, keeping public validation aligned with the declared toolchain.

Differential Revision: D120420789
meta-codesync Bot pushed a commit that referenced this pull request Sep 29, 2026
Summary:

## Context
- Remote commands do not inherit the runner's environment. Callers need to forward selected values, such as run identifiers, across SSH without editing each TTP.
- Forwarding is requested through a CLI flag so an older binary rejects unsupported usage before executing the TTP.
- GitHub CI exposed an existing Go version mismatch: `new("baz")` in `pkg/args/choices_test.go` requires Go 1.26, while the module selected Go 1.25.5.
## This Diff
- Add repeatable `--forward-env NAME` for remote `inline:` and `file:` commands.
- Trim and deduplicate names in argument order. Require nonempty names to match `[A-Za-z_][A-Za-z0-9_]*`; reject invalid names before remote command dispatch, even if unset. Skip unset variables and preserve set-but-empty values.
- Pass forwarded values literally, including `$forge.` references. Continue expanding TTP-level and step-level `env`, with forwarded < TTP < step precedence.
- Document the CLI interface, version requirement, validation, and precedence in the remote execution guide and schema reference.
- Cover forwarding and precedence with 14 authenticated loopback SSH cases, 12 invalid-name helper cases, and 6 executor rejection cases across POSIX, PowerShell, and cmd configurations.
- Set the module minimum to Go 1.26.0 and select Go 1.26.5. Have GitHub pre-commit derive its Go version from `go.mod`.

Differential Revision: D120420789
meta-codesync Bot pushed a commit that referenced this pull request Sep 29, 2026
Summary:

## Context
- Remote commands do not inherit the runner's environment. Callers need to forward selected values, such as run identifiers, across SSH without editing each TTP.
- Forwarding is requested through a CLI flag so an older binary rejects unsupported usage before executing the TTP.
- GitHub CI exposed an existing Go version mismatch: `new("baz")` in `pkg/args/choices_test.go` requires Go 1.26, while the module selected Go 1.25.5.
## This Diff
- Add repeatable `--forward-env NAME` for remote `inline:` and `file:` commands.
- Trim and deduplicate names in argument order. Require nonempty names to match `[A-Za-z_][A-Za-z0-9_]*`; reject invalid names before remote command dispatch, even if unset. Skip unset variables and preserve set-but-empty values.
- Pass forwarded values literally, including `$forge.` references. Continue expanding TTP-level and step-level `env`, with forwarded < TTP < step precedence.
- Document the CLI interface, version requirement, validation, and precedence in the remote execution guide and schema reference.
- Cover forwarding and precedence with 14 authenticated loopback SSH cases, 12 invalid-name helper cases, and 6 executor rejection cases across POSIX, PowerShell, and cmd configurations.
- Set the module minimum to Go 1.26.0 and select Go 1.26.5. Have GitHub pre-commit derive its Go version from `go.mod`.

Reviewed By: d0n601

Differential Revision: D120420789
meta-codesync Bot pushed a commit that referenced this pull request Sep 29, 2026
Summary:
Pull Request resolved: #643

## Context
- Remote commands do not inherit the runner's environment. Callers need to forward selected values, such as run identifiers, across SSH without editing each TTP.
- Forwarding is requested through a CLI flag so an older binary rejects unsupported usage before executing the TTP.
- GitHub CI exposed an existing Go version mismatch: `new("baz")` in `pkg/args/choices_test.go` requires Go 1.26, while the module selected Go 1.25.5.
## This Diff
- Add repeatable `--forward-env NAME` for remote `inline:` and `file:` commands.
- Trim and deduplicate names in argument order. Require nonempty names to match `[A-Za-z_][A-Za-z0-9_]*`; reject invalid names before remote command dispatch, even if unset. Skip unset variables and preserve set-but-empty values.
- Pass forwarded values literally, including `$forge.` references. Continue expanding TTP-level and step-level `env`, with forwarded < TTP < step precedence.
- Document the CLI interface, version requirement, validation, and precedence in the remote execution guide and schema reference.
- Cover forwarding and precedence with 14 authenticated loopback SSH cases, 12 invalid-name helper cases, and 6 executor rejection cases across POSIX, PowerShell, and cmd configurations.
- Set the module minimum to Go 1.26.0 and select Go 1.26.5. Have GitHub pre-commit derive its Go version from `go.mod`.

Reviewed By: d0n601

Differential Revision: D120420789
meta-codesync Bot pushed a commit that referenced this pull request Sep 29, 2026
Summary:

## Context
- Remote commands do not inherit the runner's environment. Callers need to forward selected values, such as run identifiers, across SSH without editing each TTP.
- Forwarding is requested through a CLI flag so an older binary rejects unsupported usage before executing the TTP.
- GitHub CI exposed an existing Go version mismatch: `new("baz")` in `pkg/args/choices_test.go` requires Go 1.26, while the module selected Go 1.25.5.
## This Diff
- Add repeatable `--forward-env NAME` for remote `inline:` and `file:` commands.
- Trim and deduplicate names in argument order. Require nonempty names to match `[A-Za-z_][A-Za-z0-9_]*`; reject invalid names before remote command dispatch, even if unset. Skip unset variables; retain set-but-empty values on supported remote shells.
- Pass forwarded values literally, including `$forge.` references. Continue expanding TTP-level and step-level `env`, with forwarded < TTP < step precedence.
- Document the CLI interface, version requirement, validation, and precedence in the remote execution guide and schema reference.
- Cover forwarding and precedence with 14 authenticated loopback SSH cases, 12 invalid-name helper cases, and 6 executor rejection cases across POSIX, PowerShell, and cmd configurations.
- Set the module minimum to Go 1.26.0 and select Go 1.26.5. Have GitHub pre-commit derive its Go version from `go.mod`.
- Validate forwarded, TTP-level, and step-level environment names on every SSH shell backend before opening a command session.
- Quote `cmd.exe` environment assignments so operators and trailing spaces remain literal. Reject values that cmd cannot safely preserve (empty strings, double quotes, `%`, `!`, and ASCII controls); errors omit values.

Reviewed By: d0n601

Differential Revision: D120420789
Summary:

## Context
- Remote commands do not inherit the runner's environment. Callers need to forward selected values, such as run identifiers, across SSH without editing each TTP.
- Forwarding is requested through a CLI flag so an older binary rejects unsupported usage before executing the TTP.
- GitHub CI exposed an existing Go version mismatch: `new("baz")` in `pkg/args/choices_test.go` requires Go 1.26, while the module selected Go 1.25.5.
## This Diff
- Add repeatable `--forward-env NAME` for remote `inline:` and `file:` commands.
- Trim and deduplicate names in argument order. Require nonempty names to match `[A-Za-z_][A-Za-z0-9_]*`; reject invalid names before remote command dispatch, even if unset. Skip unset variables and preserve set-but-empty values.
- Pass forwarded values literally, including `$forge.` references. Continue expanding TTP-level and step-level `env`, with forwarded < TTP < step precedence.
- Document the CLI interface, version requirement, validation, and precedence in the remote execution guide and schema reference.
- Cover forwarding and precedence with 14 authenticated loopback SSH cases, 12 invalid-name helper cases, and 6 executor rejection cases across POSIX, PowerShell, and cmd configurations.
- Set the module minimum to Go 1.26.0 and select Go 1.26.5. Have GitHub pre-commit derive its Go version from `go.mod`.

Reviewed By: andreizharinov, d0n601

Differential Revision: D120420789
@meta-codesync

meta-codesync Bot commented Sep 30, 2026

Copy link
Copy Markdown

This pull request has been merged in 508f915.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant