From 9e534241f91434ea55bd53c2c85da74a9d4c26a0 Mon Sep 17 00:00:00 2001 From: Bastien Chanot Date: Thu, 2 Jul 2026 14:16:36 +0200 Subject: [PATCH] feat(settings): deny-list hardening pass (audit #20) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit - rm -r / rm -fr denied (only -rf was; flag-order variants passed). - python3 -c / python -c ask → deny: aligned with node -e / perl -e / ruby -e (arbitrary-interpreter class was incoherently split). - git push + denied (refspec force carried no flag). - --force-with-lease un-over-blocked: --force* split into --force / --force *, so the safer variant now falls to the git push ASK gate. Deny 99 → 105, ask 19 → 18. Second curtain unchanged (auto-mode classifier, BDR-004). doctor's deny sentinel tracks HEAD (LOT 1). Co-Authored-By: Claude Fable 5 Claude-Session: https://claude.ai/code/session_016zA3Qh2Q1QpcGXzXxKeDHR --- settings.json | 9 +++++++-- 1 file changed, 7 insertions(+), 2 deletions(-) diff --git a/settings.json b/settings.json index 8ecbde7..cba2210 100644 --- a/settings.json +++ b/settings.json @@ -63,9 +63,13 @@ "deny": [ "Bash(rm -rf *)", "Bash(rm -rf /*)", + "Bash(rm -r *)", + "Bash(rm -fr *)", "Bash(rmdir *)", - "Bash(git push --force*)", + "Bash(git push --force)", + "Bash(git push --force *)", "Bash(git push -f*)", + "Bash(git push * +*)", "Bash(git reset --hard*)", "Bash(git clean -fd*)", "Bash(sudo rm*)", @@ -156,6 +160,8 @@ "Bash(source /dev/stdin)", "Bash(mkfifo *)", "Bash(node -e *)", + "Bash(python3 -c *)", + "Bash(python -c *)", "Bash(xargs * .env*)", "Bash(tar * .env*)", "Bash(zip * .env*)", @@ -177,7 +183,6 @@ "WebFetch", "Bash(xargs *)", "Bash(sed *)", - "Bash(python3 -c *)", "Bash(git stash pop*)", "Bash(git stash drop*)", "Bash(git stash clear)"