Disk-device destruction is now a protected category at every safety level, so commands that erase, reformat, or repartition a disk are blocked instead of allowed. Read-only disk inspection and disk-image targets stay allowed, and dd writes to /dev/null, /dev/zero, and /dev/full are no longer blocked.
Highlights
- Blocked disk erase, repartition, and output redirects onto a disk device at every safety level, closing a gap where only
dd of=/dev/…andmkfs* /dev/…were caught. (#236)
Added
- Added the
disk.eraserule, which blocksdiskutilerase and partition verbs (eraseDisk,eraseVolume,reformat,partitionDisk,zeroDisk,randomDisk,secureErase),wipefs -a/-o,sgdiskwrite options, andparted mklabel/mktable/mkpart/rm/resizepart. (#237)- Read-only inspection and disk-image targets stay allowed, such as
diskutil list,diskutil info disk4,wipefs /dev/sdb,sgdisk -p /dev/sda,parted /dev/sda print,parted -l, andparted disk.img mklabel gpt.
- Read-only inspection and disk-image targets stay allowed, such as
- Added the
redirect.block-devicerule, which blocks>,>|,>>,<>, and>&redirects whose literal target is a disk device such as/dev/sda,/dev/nvme0n1, or/dev/disk4, including inside a nestedsh -cbody. Non-disk device paths such as/dev/null,/dev/tty, and/dev/cu.*stay allowed. (#237)
Changed
- Changed the
mkfs.devicerule to also covermke2fs,newfs, andnewfs_*on a/dev/target. - Changed disk-tool dry runs and the RAM-disk idiom to be blocked by the new rules, including
wipefs -n -a,sgdisk --pretendwith a write option, anddiskutil erasevolume HFS+ RAMDisk $(hdiutil attach -nomount ram://…). Setdisk.eraseto"off"underdestructive_command_protection.overridesto allow them.
Fixed
- Fixed
ddbeing blocked when writing to a discard sink:of=/dev/null,of=/dev/zero, andof=/dev/fullare now allowed, so read-speed tests such asdd if=big.bin of=/dev/null bs=1Mrun again. (#237)