github kenryu42/cc-safety-net v2.6.8

3 hours ago

Disk-device destruction is now a protected category at every safety level, so commands that erase, reformat, or repartition a disk are blocked instead of allowed. Read-only disk inspection and disk-image targets stay allowed, and dd writes to /dev/null, /dev/zero, and /dev/full are no longer blocked.

Highlights

  • Blocked disk erase, repartition, and output redirects onto a disk device at every safety level, closing a gap where only dd of=/dev/… and mkfs* /dev/… were caught. (#236)

Added

  • Added the disk.erase rule, which blocks diskutil erase and partition verbs (eraseDisk, eraseVolume, reformat, partitionDisk, zeroDisk, randomDisk, secureErase), wipefs -a/-o, sgdisk write options, and parted mklabel/mktable/mkpart/rm/resizepart. (#237)
    • Read-only inspection and disk-image targets stay allowed, such as diskutil list, diskutil info disk4, wipefs /dev/sdb, sgdisk -p /dev/sda, parted /dev/sda print, parted -l, and parted disk.img mklabel gpt.
  • Added the redirect.block-device rule, which blocks >, >|, >>, <>, and >& redirects whose literal target is a disk device such as /dev/sda, /dev/nvme0n1, or /dev/disk4, including inside a nested sh -c body. Non-disk device paths such as /dev/null, /dev/tty, and /dev/cu.* stay allowed. (#237)

Changed

  • Changed the mkfs.device rule to also cover mke2fs, newfs, and newfs_* on a /dev/ target.
  • Changed disk-tool dry runs and the RAM-disk idiom to be blocked by the new rules, including wipefs -n -a, sgdisk --pretend with a write option, and diskutil erasevolume HFS+ RAMDisk $(hdiutil attach -nomount ram://…). Set disk.erase to "off" under destructive_command_protection.overrides to allow them.

Fixed

  • Fixed dd being blocked when writing to a discard sink: of=/dev/null, of=/dev/zero, and of=/dev/full are now allowed, so read-speed tests such as dd if=big.bin of=/dev/null bs=1M run again. (#237)

Don't miss a new cc-safety-net release

NewReleases is sending notifications on new releases.