') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ', 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ', 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ', 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); })(); fix(deploy.sh): initialise ENABLE_MODEL_ARMOR_FLAG so IL4/IL5 don't abort on an empty jq argument by AloysJehwin · Pull Request #204 · google/stellar-engine · GitHub
Skip to content

fix(deploy.sh): initialise ENABLE_MODEL_ARMOR_FLAG so IL4/IL5 don't abort on an empty jq argument - #204

Open
AloysJehwin wants to merge 1 commit into
google:mainfrom
AloysJehwin:fix/model-armor-flag-uninitialized
Open

fix(deploy.sh): initialise ENABLE_MODEL_ARMOR_FLAG so IL4/IL5 don't abort on an empty jq argument#204
AloysJehwin wants to merge 1 commit into
google:mainfrom
AloysJehwin:fix/model-armor-flag-uninitialized

Conversation

@AloysJehwin

Copy link
Copy Markdown
Contributor

ENABLE_MODEL_ARMOR_FLAG is only ever assigned inside the FEDRAMP_HIGH/NONE branch, but it's read unconditionally a few lines later as --argjson model_armor "\$ENABLE_MODEL_ARMOR_FLAG". Under IL4 or IL5 the branch never runs, jq is handed an empty argument, and since the script runs under set -e it aborts right there — after the operator has already answered every other prompt in the app loop.

Initialised it to false just before the gate. Doing it inside the loop rather than once at the top also means a previous app's answer can't leak into the next iteration, which would have been a quieter version of the same bug.

This is the same code path #179 touches from the other side — that one is about option 4 leaving the regime empty; this is about IL4/IL5, which stay broken regardless of that fix.

Fixes#177

…gate
The only two assignments were inside the FEDRAMP_HIGH/NONE branch, but the
value is consumed unconditionally by jq --argjson. Under IL4/IL5 the variable
was unset, so jq got an empty argument and set -e aborted the script part-way
through configuring applications. Initialising per iteration also stops a
previous app's answer leaking into the next one.
Fixesgoogle#177
Signed-off-by: Aloys Jehwin <aloysjehwin@gmail.com>
@aghassemloueiaghassemlouei added bug Something isn't working Priority - High Critical issues blocking development or users; urgent bugs or core features for release Level of Effort - Low Quick, well-defined tasks with no unknowns; takes a few hours up to one day to complete gemini for government Gemini for Government (G4G) related gemini enterprise Gemini Enterprise (GE) related labels Aug 28, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bugSomething isn't workinggemini enterpriseGemini Enterprise (GE) relatedgemini for governmentGemini for Government (G4G) relatedLevel of Effort - LowQuick, well-defined tasks with no unknowns; takes a few hours up to one day to completePriority - HighCritical issues blocking development or users; urgent bugs or core features for release

Projects

None yet

2 participants

@AloysJehwin@aghassemlouei