Skip to content

Commit e10f3c2

Browse files
committed
test(core): pin the false deny this split declares as its tradeoff
bash runs one command in `git commit -m 'x' # saved to 'C:\'⏎rm draft`, but the pre-fix reading splits inside the comment and a `Bash(rm *)` deny refuses it. Pin that, the `monitor` spelling, and the single-line spelling QwenLM#12096's comment fast path allows again.
1 parent f0bc4fc commit e10f3c2

1 file changed

Lines changed: 29 additions & 0 deletions

File tree

‎packages/core/src/permissions/permission-manager.test.ts‎

Lines changed: 29 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2583,6 +2583,35 @@ describe('PermissionManager', () => {
25832583
).toBe(expected);
25842584
});
25852585

2586+
// The declared tradeoff: bash runs one command here, since everything from
2587+
// `#` on is a comment, but the pre-fix reading splits inside it and a
2588+
// `Bash(rm *)` deny refuses a commit the user cannot see an `rm` in. Only
2589+
// shapes that bail out of #12096's comment fast path still reach it — a
2590+
// newline here, or `monitor` — while the single-line spelling stays one
2591+
// segment for `Bash(...)` rules and is allowed again.
2592+
it.each<[string, string, string]>([
2593+
[
2594+
'run_shell_command',
2595+
"git commit -m 'x' # saved to 'C:\\'\nrm draft",
2596+
'deny',
2597+
],
2598+
['monitor', "git commit -m 'x' # saved to 'C:\\' ; rm draft", 'deny'],
2599+
[
2600+
'run_shell_command',
2601+
"git commit -m 'x' # saved to 'C:\\' ; rm draft",
2602+
'allow',
2603+
],
2604+
])('%s %j is %s', async (toolName, command, expected) => {
2605+
pm = new PermissionManager(
2606+
makeConfig({
2607+
permissionsAllow: ['Bash(git *)'],
2608+
permissionsDeny: ['Bash(rm *)'],
2609+
}),
2610+
);
2611+
pm.initialize();
2612+
expect(await pm.evaluate({ toolName, command })).toBe(expected);
2613+
});
2614+
25862615
it('|| compound: all allowed → allow', async () => {
25872616
pm = new PermissionManager(
25882617
makeConfig({

0 commit comments

Comments
 (0)