6c9837036033663c7111ca5fdecb6d00839b4b8d
- Author
- TheEdgeOfRage <git@theedgeofrage.com>
- Committer
- TheEdgeOfRage <git@theedgeofrage.com>
- Date
Message
Diff
This diff is truncated to protect this page.
1diff --git a/src/rules.ts b/src/rules.ts
2index 5e4cd8471e7db7ddf8abc28fc639de7680e9cac1..4c06d239d7a29df16ef02eb7d5ad54c7a86441ce 100644
3--- a/src/rules.ts
4+++ b/src/rules.ts
5@@ -1,5 +1,5 @@
6 // Bump to invalidate all cached decisions when rules change.
7-export const POLICY_VERSION = 4;
8+export const POLICY_VERSION = 5;
9
10 // Trailing stderr redirections that are safe to strip before pattern matching.
11 // `2>&1` and `2>/dev/null` have no security implication but would otherwise
12@@ -27,6 +27,9 @@ export const HARD_ALLOW_PATTERNS: RegExp[] = [
13 /^pwd\s*$/,
14 /^whoami\s*$/,
15 /^date\s*$/,
16+ // `break` / `continue` outside a loop are no-op shell builtins (warning, exit 1) — harmless.
17+ /^break\s*$/,
18+ /^continue\s*$/,
19 /^which\s+[A-Za-z0-9._-]+\s*$/,
20 /^whereis\s+[A-Za-z0-9._-]+\s*$/,
21 /^type\s+[A-Za-z0-9._-]+\s*$/,
22@@ -115,6 +118,12 @@ export const HAIKU_POLICY_PROMPT = `You are a security policy advisor helping de
23
24 Your job is to use good judgment - not follow rigid rules. Consider the intent, context, and potential consequences.
25
26+## Important: command granularity
27+
28diff --git a/test/deterministic.test.ts b/test/deterministic.test.ts
29index 5061a8753845b4d3bcf6c75f1bb6dcef54a563fc..50836e02f4fee0e42f574df296381478b5586924 100644
30--- a/test/deterministic.test.ts
31+++ b/test/deterministic.test.ts
32@@ -13,6 +13,8 @@ describe("hard allow — accepts simple safe commands", () => {
33 "pwd",
34 "whoami",
35 "date",
36+ "break",
37+ "continue",
38 "which python",
39 "whereis ls",
40 "type node",