feat(settings): deny-list hardening pass (audit #20)

- rm -r / rm -fr denied (only -rf was; flag-order variants passed).
- python3 -c / python -c ask → deny: aligned with node -e / perl -e /
  ruby -e (arbitrary-interpreter class was incoherently split).
- git push <remote> +<ref> denied (refspec force carried no flag).
- --force-with-lease un-over-blocked: --force* split into --force /
  --force *, so the safer variant now falls to the git push ASK gate.
Deny 99 → 105, ask 19 → 18. Second curtain unchanged (auto-mode
classifier, BDR-004). doctor's deny sentinel tracks HEAD (LOT 1).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016zA3Qh2Q1QpcGXzXxKeDHR
This commit is contained in:
Bastien Chanot
2026-07-02 14:16:36 +02:00
co-authored by Claude Fable 5
parent 45a387c1dd
commit 9e534241f9
+7 -2
View File
@@ -63,9 +63,13 @@
"deny": [
"Bash(rm -rf *)",
"Bash(rm -rf /*)",
"Bash(rm -r *)",
"Bash(rm -fr *)",
"Bash(rmdir *)",
"Bash(git push --force*)",
"Bash(git push --force)",
"Bash(git push --force *)",
"Bash(git push -f*)",
"Bash(git push * +*)",
"Bash(git reset --hard*)",
"Bash(git clean -fd*)",
"Bash(sudo rm*)",
@@ -156,6 +160,8 @@
"Bash(source /dev/stdin)",
"Bash(mkfifo *)",
"Bash(node -e *)",
"Bash(python3 -c *)",
"Bash(python -c *)",
"Bash(xargs * .env*)",
"Bash(tar * .env*)",
"Bash(zip * .env*)",
@@ -177,7 +183,6 @@
"WebFetch",
"Bash(xargs *)",
"Bash(sed *)",
"Bash(python3 -c *)",
"Bash(git stash pop*)",
"Bash(git stash drop*)",
"Bash(git stash clear)"