mirror of
https://github.com/affaan-m/ECC.git
synced 2026-09-29 21:15:16 +02:00
Review on #2829 found the regex fix widened a false positive: matching `\bdd\s+if=` against the whole flattened line gated `echo dd if=/dev/zero` and `grep dd if=/dev/zero file`, neither of which runs dd. That class was already present before — `echo dd if=x` matched the old arm too — but the boundary fix extended it to the slash and dot spellings, so the arm now decides on text position rather than on what is being executed. dd moves to isDestructiveDd(tokens), next to isDestructiveRm and isDestructiveGit, and DESTRUCTIVE_SQL_DD goes back to SQL only. The per-segment loop already tokenizes every executable body, so the check runs where the command word is known. This resolves four things the text match could not: dd if=/dev/zero of=/dev/sda was allowed -> denied (the reported bug) sudo dd if=/dev/zero was allowed -> denied dd of=/dev/sda if=/dev/zero was allowed -> denied (operands are order-free) echo dd if=x was denied -> allowed (pre-existing false positive) Leading sudo/doas/env, their flags, and VAR=value assignment prefixes are skipped so a wrapped invocation still resolves to dd; flags are only skipped once a wrapper has been seen, so the scan cannot walk into an unrelated command's arguments. Tests: 6 fail on upstream main, 155 pass with this change. Refs #2642