bash-permissions: prove read-only sed commands #18

Open
hermes wants to merge 3 commits from coop/pi:feature/provably-read-only-sed into main
First-time contributor

Summary

  • add conservative readOnly and mayWrite sed command-policy modes
  • parse a deliberately small, portable sed subset and detect in-place edits, w/W, substitution writes, and GNU command execution
  • fail closed for dynamic, external, malformed, shell-expanded, implementation-dependent, and otherwise ambiguous invocations
  • inspect commands executed through builtin, command, env, and exec, including dynamic wrapper paths and bounded recursive expansion
  • apply restrictive legacy and effect policies to ambiguous executable/wrapper cases without letting allow policies widen authorization
  • retain the existing normal and inPlace modes for compatibility
  • document the new policy and add unit, storage, wrapper, and integration coverage

Verification

  • npm run test — 11 test files, 262 tests passed
  • npm run typecheck passed
  • git diff --check passed
  • independent adversarial reviews covered GNU/BSD options, shell-word decoding, sed grammar, execution wrappers, expansion limits, dynamic executables, and malformed programs
## Summary - add conservative `readOnly` and `mayWrite` sed command-policy modes - parse a deliberately small, portable sed subset and detect in-place edits, `w`/`W`, substitution writes, and GNU command execution - fail closed for dynamic, external, malformed, shell-expanded, implementation-dependent, and otherwise ambiguous invocations - inspect commands executed through `builtin`, `command`, `env`, and `exec`, including dynamic wrapper paths and bounded recursive expansion - apply restrictive legacy and effect policies to ambiguous executable/wrapper cases without letting allow policies widen authorization - retain the existing `normal` and `inPlace` modes for compatibility - document the new policy and add unit, storage, wrapper, and integration coverage ## Verification - `npm run test` — 11 test files, 262 tests passed - `npm run typecheck` passed - `git diff --check` passed - independent adversarial reviews covered GNU/BSD options, shell-word decoding, sed grammar, execution wrappers, expansion limits, dynamic executables, and malformed programs
This pull request has changes conflicting with the target branch.
  • extensions/bash-permissions/storage.ts
View command line instructions

Manual merge helper

Use this merge commit message when completing the merge manually.

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u feature/provably-read-only-sed:coop-feature/provably-read-only-sed
git switch coop-feature/provably-read-only-sed
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
things/pi!18
No description provided.