fix(permissions): narrow rm -rf deny globs to their exact forms

The trailing wildcard on the three rm -rf deny entries spanned path
separators, so Bash(rm -rf /*) matched every absolute path on the
machine rather than the filesystem root, and the ~ and $HOME entries
had the same shape. Narrowed to the exact literal forms.

These rules match literal command text, so they still stop a typo on
rm -rf /, rm -rf ~ or rm -rf $HOME exactly, but they no longer stop a
recursive delete aimed at any other path. That reduced cover is
deliberate, not an oversight.
This commit is contained in:
2026-08-25 20:31:28 +02:00
parent f04672f350
commit 52048c03ce
+3 -3
View File
@@ -62,9 +62,9 @@
"Bash(git reset --hard*)", "Bash(git reset --hard*)",
"Bash(git restore .*)", "Bash(git restore .*)",
"Bash(mkfs*)", "Bash(mkfs*)",
"Bash(rm -rf $HOME*)", "Bash(rm -rf $HOME)",
"Bash(rm -rf /*)", "Bash(rm -rf /)",
"Bash(rm -rf ~*)", "Bash(rm -rf ~)",
"Bash(su *)", "Bash(su *)",
"Bash(sudo *)", "Bash(sudo *)",
"Bash(toj)", "Bash(toj)",