Diff
1diff --git a/src/rules.ts b/src/rules.ts
2index 7b8980fed2e6a52d7bbf0cf12405f742a5c05ff0..1fdf99f0c4eacd61c66b93562ab27c1878e1eb7c 100644
3--- a/src/rules.ts
4+++ b/src/rules.ts
5@@ -1,5 +1,5 @@
6 // Bump to invalidate all cached decisions when rules change.
7-export const POLICY_VERSION = "3.1.0";
8+export const POLICY_VERSION = "3.2.0";
9
10 // Matched with test() on anchored patterns (equivalent to Python fullmatch).
11 // Purely a performance optimization — these would pass LLM review anyway.
12@@ -28,7 +28,7 @@ export const HARD_ALLOW_PATTERNS: RegExp[] = [
13 // cat with relative paths only
14 /^cat\s+(?!.*\/\.)(?!.*\.\.)[A-Za-z0-9][A-Za-z0-9._/-]*(?:\s+(?!.*\/\.)(?!.*\.\.)[A-Za-z0-9][A-Za-z0-9._/-]*)*\s*$/,
15 // head/tail with relative paths and line limits
16- /^(head|tail)(?:\s+-(?:n\s*)?\d+)?(?:\s+(?!.*\/\.)(?!.*\.\.)[A-Za-z0-9][A-Za-z0-9._/-]*)+\s*$/,
17+ /^(head|tail)(?:\s+-(?:n\s*)?\d+)?(?:\s+(?!.*\/\.)(?!.*\.\.)[A-Za-z0-9][A-Za-z0-9._/-]*)*\s*$/,
18 // find read-only on relative paths
19 /^find\s+(?!.*\/\.)(?!.*\.\.)[A-Za-z0-9][A-Za-z0-9._/-]*(?:\s+(?:-name|-iname)\s+["'][^"']+["']|\s+-type\s+(?:["']?[fdlbcps]["']?))*\s*$/,
20 // grep on relative paths