From c88b3f879ab0e8ff3c2bd41afd250dafbcbdb4ca Mon Sep 17 00:00:00 2001 From: Nguyen Thanh Dat Date: Fri, 21 Aug 2026 08:41:11 +0700 Subject: [PATCH] test(gateguard): cover dd with an intervening option before if= Named in review on #2829: `dd bs=1M if=/dev/zero of=/dev/sda` is the same class as the reversed-operand case and is denied by the token-based check, but nothing pinned it. --- tests/hooks/gateguard-fact-force.test.js | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/tests/hooks/gateguard-fact-force.test.js b/tests/hooks/gateguard-fact-force.test.js index f83677b0d..323981096 100644 --- a/tests/hooks/gateguard-fact-force.test.js +++ b/tests/hooks/gateguard-fact-force.test.js @@ -270,8 +270,10 @@ function runTests() { 'dd if="/dev/zero" of=/dev/sda', // Wrapped invocations must still resolve to the dd command word. 'sudo dd if=/dev/zero of=/dev/sda', - // dd operands are order-free; a text pattern anchored on `dd if=` missed this. - 'dd of=/dev/sda if=/dev/zero' + // dd operands are order-free; a text pattern anchored on `dd if=` missed + // both the reversed and the intervening-option spellings. + 'dd of=/dev/sda if=/dev/zero', + 'dd bs=1M if=/dev/zero of=/dev/sda' ]) { clearState(); if (