test: run bitcoin-cli -ipcconnect check under valgrind with -datadir
What changed, and why it matters
This is a test-only fix. It changes one functional test so that a bitcoin-cli subprocess is launched with the project's standard valgrind wrapper and uses the test node's temporary data directory instead of the developer's real default Bitcoin directory. There is no change to production code, no vulnerability, and no security risk to users.
No security action needed. Treat as a normal test-quality improvement.
Security signals we found
No strong security signals were identified.
Evidence from the diff
The commit modifies test/functional/interface_bitcoin_cli.py. Previously a subprocess.run() invoked bitcoin-cli directly, skipping the configured valgrind command and omitting -datadir, which caused the test to read the host’s default ~/.bitcoin/bitcoin.conf and fail in some environments. The patch builds the command using self.nodes[0].binaries.valgrind_cmd and passes the test node’s datadir_path. This is purely a testing-framework robustness improvement.
Changed components
test/functional/interface_bitcoin_cli.pyInspect captured patch +2 / −1
diff --git a/test/functional/interface_bitcoin_cli.py b/test/functional/interface_bitcoin_cli.py
index effd45fd..07687c5d 100755
--- a/test/functional/interface_bitcoin_cli.py
+++ b/test/functional/interface_bitcoin_cli.py
@@ -458,7 +458,8 @@ class TestBitcoinCli(BitcoinTestFramework):
# This tests behavior when ENABLE_IPC is off. When it is on,
# behavior is checked by the interface_ipc_cli.py test.
self.log.info("Test bitcoin-cli -ipcconnect triggers error if not built with IPC support")
- args = [self.binary_paths.bitcoincli, "-ipcconnect=unix", "-getinfo"]
+ # node.cli.options includes -rpcconnect which can't be combined with -ipcconnect, so pass just -datadir directly to keep bitcoin-cli on the test's bitcoin.conf
+ args = self.nodes[0].binaries.valgrind_cmd + [self.nodes[0].binaries.paths.bitcoincli, f"-datadir={self.nodes[0].datadir_path}", "-ipcconnect=unix", "-getinfo"]
result = subprocess.run(args, stdout=subprocess.PIPE, stderr=subprocess.STDOUT, text=True)
assert_equal(result.stdout, "error: bitcoin-cli was not built with IPC support\n")
assert_equal(result.stderr, None)
Why this scored 15/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.