Files
ECC/tests/hooks
Nguyen Thanh Dat 76786616f8 fix(gateguard): deny dd whose input path is not word-initial
DESTRUCTIVE_SQL_DD shared one trailing \b across every alternation arm.
`dd\s+if=` ends in `=`, and a \b after a non-word character only holds when
the NEXT character is a word character, so the arm matched `dd if=x` and
missed every path starting with `/`, `.` or a quote:

  dd if=/dev/zero of=/dev/sda    allowed
  dd if=./disk.img of=/dev/sdb   allowed
  dd if="/dev/zero" of=/dev/sda  allowed

The word-boundary suffix now applies only to the arms that end in a word
character. The split is what keeps the widening bounded: dropping the
trailing \b outright would let `truncate` match `truncated`, and dropping the
leading \b would let `dd if=` match inside `add if=`. Both are covered.

This is the half of #2642 that survived the structural findGitSubcommand()
parser, which already handles `git checkout -- .`.

Not addressed here: `dd of=/dev/sda if=/dev/zero` with the operands reversed
is still allowed, before and after, because the pattern requires `if=`
immediately after `dd`. That is a different defect from the boundary bug and
widening a P0 gate's pattern shape is a maintainer call.

Refs #2642
2026-09-07 15:47:37 +07:00
..