Skip to content

fix(security): read AMD credentials from environment variables - #1018

Closed
gHashTag wants to merge 1 commit into
mainfrom
security/redact-credentials-2026-09-15
Closed

gHashTag wants to merge 1 commit into
mainfrom
security/redact-credentials-2026-09-15

Conversation

@gHashTag

Copy link
Copy Markdown
Owner

Removes hard-coded AMD account credentials from fpga/fly-vivado/setup_and_synth.exp. The expect script now reads AMD_USER and AMD_PASS from the environment.

This only cleans the current tree. The values remain in git history and must be treated as compromised: change the AMD password.

🤖 Generated with Claude Code

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@gHashTag gHashTag added the bee-reviewed A reviewer bee reviewed and verified this PR after its head commit; required to merge label Oct 2, 2026
@gHashTag

gHashTag commented Oct 2, 2026

Copy link
Copy Markdown
Owner Author

Reviewer bee Y: code is sound, not merged.

  • origin/main still sends a hardcoded AMD account e-mail and password in fpga/fly-vivado/setup_and_synth.exp. This PR replaces both with $env(AMD_USER) / $env(AMD_PASS) (valid Tcl/expect inside double quotes). 1 file, +3/-2, matches the title.
  • Blocker: required status T27 work report is FAILURE ('Missing, stale or invalid work report'). The author must add a valid work report to the body; a reviewer writing it would become its author.
  • The password is public in history: it must be rotated at AMD regardless.

@gHashTag

gHashTag commented Oct 2, 2026

Copy link
Copy Markdown
Owner Author

bee review (closing as superseded). Head 539c028, CONFLICTING.

The change is already on main: #1258 (7511cc7, "fix(security): strip plaintext credentials from the tree") rewrote fpga/fly-vivado/setup_and_synth.exp to read AMD_ACCOUNT_EMAIL / AMD_ACCOUNT_PASSWORD from the environment and to refuse to run without them. This PR's AMD_USER/AMD_PASS variant would now only conflict.

Security note: the removed lines of this diff carry a plaintext account e-mail and password (values not repeated here). Removing them from the tree does not remove them from git history or from this PR's diff, so the AMD account password must be treated as exposed and rotated. Not merged for that reason as well.

@gHashTag gHashTag closed this Oct 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bee-reviewed A reviewer bee reviewed and verified this PR after its head commit; required to merge

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant