fix(coding-agent): inspect compound Bash commands in interceptor rules
Match interceptor regexes against conservative, raw shell command segments in addition to the complete command, so anchored rules can detect commands after &&, ||, ;, |, &, and newlines without treating quoted or escaped text as commands. Add extractFlatShellCommandSegments() to preserve source text for user-configured regexes, unlike the token-based approval matcher. Add skipShellWord() and environment-assignment stripping so rules can match commands prefixed with NAME=value assignments. Preserve the original command in interception errors after extracting a leading cd command.
This commit is contained in:
@@ -32,7 +32,7 @@ There are no structured `head` or `tail` tool parameters in the current schema,
|
||||
|
||||
## 2) Optional interception (blocked-command path)
|
||||
|
||||
If `bashInterceptor.enabled` is true, `BashTool` loads rules from settings (`getBashInterceptorRules()`) and runs `checkBashInterception()` against the command — checking both the original and the cwd-normalized form (after a leading `cd … &&` is extracted) when they differ.
|
||||
If `bashInterceptor.enabled` is true, `BashTool` loads rules from settings (`getBashInterceptorRules()`) and runs `checkBashInterception()` against the command — checking both the original and the cwd-normalized form (after a leading `cd … &&` is extracted) when they differ. Rule syntax is unchanged: each rule checks the complete input first, then raw flat command fragments separated by unquoted/unescaped `&&`, `||`, `;`, `|`, `&`, or newlines, then those fragments with leading `NAME=value` assignments removed.
|
||||
|
||||
Interception behavior:
|
||||
|
||||
@@ -43,6 +43,7 @@ Interception behavior:
|
||||
- on block, `BashTool` throws `ToolError` with message:
|
||||
- `Blocked: ...`
|
||||
- original command included.
|
||||
- heredocs, command substitutions, backticks, grouping, and malformed quoting do not produce extra fragments; they retain only the complete-input check. Interception is best-effort routing to dedicated tools, not a shell-security policy.
|
||||
|
||||
Default rule patterns (defined in code) target common misuses:
|
||||
|
||||
|
||||
Reference in New Issue
Block a user