mirror of
https://github.com/shareAI-lab/analysis_claude_code.git
synced 2026-09-20 12:13:38 +08:00
fix(s03): match Windows del as a command word
This commit is contained in:
@@ -57,6 +57,15 @@ def check_deny_list(command: str) -> str | None:
|
||||
**ゲート 2**:ルールマッチング — 「いつユーザーに聞くべきか」を記述する。各ルールはツールとチェック条件を指定する。
|
||||
|
||||
```python
|
||||
import re
|
||||
|
||||
DESTRUCTIVE_COMMAND_WORD = re.compile(
|
||||
r"(?i)(?:^|[;&|()\n])\s*(?:rm|del)(?=\s|$|[;&|()])"
|
||||
)
|
||||
|
||||
def contains_destructive_command(command: str) -> bool:
|
||||
return bool(DESTRUCTIVE_COMMAND_WORD.search(command))
|
||||
|
||||
PERMISSION_RULES = [
|
||||
{
|
||||
"tools": ["read_file", "write_file", "edit_file"],
|
||||
@@ -65,7 +74,9 @@ PERMISSION_RULES = [
|
||||
},
|
||||
{
|
||||
"tools": ["bash"],
|
||||
"check": lambda args: any(kw in args.get("command", "") for kw in ["rm ", "> /etc/", "chmod 777"]),
|
||||
"check": lambda args: contains_destructive_command(args.get("command", "")) or any(
|
||||
kw in args.get("command", "") for kw in ["> /etc/", "chmod 777"]
|
||||
),
|
||||
"message": "Potentially destructive command",
|
||||
},
|
||||
]
|
||||
@@ -141,6 +152,7 @@ python s03_permission/code.py
|
||||
2. `Delete the file test.txt`(bash + rm でゲート 2 が発動)
|
||||
3. `What files are in the current directory?`(読み取り専用、すべて通過)
|
||||
4. `Try to write a file to /etc/something`(作業ディレクトリ外への書き込みでゲート 2 が発動)
|
||||
5. Windows では `del test.txt` と `DEL test.txt` がゲート 2 を発動し、`model`、`delimiter`、`echo del test.txt` は発動しない。
|
||||
|
||||
観察のポイント:どの操作がそのまま通過するか? どれに確認が必要か? どれが即座に拒否されるか?
|
||||
|
||||
|
||||
@@ -57,6 +57,15 @@ def check_deny_list(command: str) -> str | None:
|
||||
**Gate 2**: Rule matching — describes "when to ask the user." Each rule specifies a tool and a check condition.
|
||||
|
||||
```python
|
||||
import re
|
||||
|
||||
DESTRUCTIVE_COMMAND_WORD = re.compile(
|
||||
r"(?i)(?:^|[;&|()\n])\s*(?:rm|del)(?=\s|$|[;&|()])"
|
||||
)
|
||||
|
||||
def contains_destructive_command(command: str) -> bool:
|
||||
return bool(DESTRUCTIVE_COMMAND_WORD.search(command))
|
||||
|
||||
PERMISSION_RULES = [
|
||||
{
|
||||
"tools": ["read_file", "write_file", "edit_file"],
|
||||
@@ -65,7 +74,9 @@ PERMISSION_RULES = [
|
||||
},
|
||||
{
|
||||
"tools": ["bash"],
|
||||
"check": lambda args: any(kw in args.get("command", "") for kw in ["rm ", "> /etc/", "chmod 777"]),
|
||||
"check": lambda args: contains_destructive_command(args.get("command", "")) or any(
|
||||
kw in args.get("command", "") for kw in ["> /etc/", "chmod 777"]
|
||||
),
|
||||
"message": "Potentially destructive command",
|
||||
},
|
||||
]
|
||||
@@ -141,6 +152,7 @@ Try these prompts:
|
||||
2. `Delete the file test.txt` (bash + rm triggers Gate 2)
|
||||
3. `What files are in the current directory?` (read-only, all pass)
|
||||
4. `Try to write a file to /etc/something` (writing outside workspace triggers Gate 2)
|
||||
5. On Windows, `del test.txt` and `DEL test.txt` trigger Gate 2, while `model`, `delimiter`, and `echo del test.txt` do not.
|
||||
|
||||
What to watch for: Which operations pass through? Which need your confirmation? Which are denied outright?
|
||||
|
||||
|
||||
@@ -57,6 +57,15 @@ def check_deny_list(command: str) -> str | None:
|
||||
**闸门 2**负责规则匹配,用来描述"什么时候需要问用户"。每条规则指定工具和检查条件。
|
||||
|
||||
```python
|
||||
import re
|
||||
|
||||
DESTRUCTIVE_COMMAND_WORD = re.compile(
|
||||
r"(?i)(?:^|[;&|()\n])\s*(?:rm|del)(?=\s|$|[;&|()])"
|
||||
)
|
||||
|
||||
def contains_destructive_command(command: str) -> bool:
|
||||
return bool(DESTRUCTIVE_COMMAND_WORD.search(command))
|
||||
|
||||
PERMISSION_RULES = [
|
||||
{
|
||||
"tools": ["read_file", "write_file", "edit_file"],
|
||||
@@ -65,7 +74,9 @@ PERMISSION_RULES = [
|
||||
},
|
||||
{
|
||||
"tools": ["bash"],
|
||||
"check": lambda args: any(kw in args.get("command", "") for kw in ["rm ", "> /etc/", "chmod 777"]),
|
||||
"check": lambda args: contains_destructive_command(args.get("command", "")) or any(
|
||||
kw in args.get("command", "") for kw in ["> /etc/", "chmod 777"]
|
||||
),
|
||||
"message": "Potentially destructive command",
|
||||
},
|
||||
]
|
||||
@@ -141,6 +152,7 @@ python s03_permission/code.py
|
||||
2. `Delete the file test.txt`(bash + rm 会触发闸门 2)
|
||||
3. `What files are in the current directory?`(只读,全部通过)
|
||||
4. `Try to write a file to /etc/something`(写工作区外,触发闸门 2)
|
||||
5. 在 Windows 上,`del test.txt` 和 `DEL test.txt` 会触发闸门 2,而 `model`、`delimiter` 和 `echo del test.txt` 不会。
|
||||
|
||||
观察重点:哪些操作直接通过?哪些需要你确认?哪些被直接拒绝?
|
||||
|
||||
|
||||
@@ -32,6 +32,7 @@ Builds on s02 (multi-tool). Usage:
|
||||
"""
|
||||
|
||||
import os
|
||||
import re
|
||||
import subprocess
|
||||
from pathlib import Path
|
||||
|
||||
@@ -152,12 +153,22 @@ def check_deny_list(command: str) -> str | None:
|
||||
|
||||
|
||||
# Gate 2: Rule matching - context-dependent checks
|
||||
DESTRUCTIVE_COMMAND_WORD = re.compile(
|
||||
r"(?i)(?:^|[;&|()\n])\s*(?:rm|del)(?=\s|$|[;&|()])"
|
||||
)
|
||||
|
||||
|
||||
def contains_destructive_command(command: str) -> bool:
|
||||
return bool(DESTRUCTIVE_COMMAND_WORD.search(command))
|
||||
|
||||
|
||||
PERMISSION_RULES = [
|
||||
{"tools": ["read_file", "write_file", "edit_file"],
|
||||
"check": lambda args: not (WORKDIR / args.get("path", "")).resolve().is_relative_to(WORKDIR),
|
||||
"message": "Writing outside workspace"},
|
||||
{"tools": ["bash"],
|
||||
"check": lambda args: any(kw in args.get("command", "") for kw in ["rm ", "> /etc/", "chmod 777"]),
|
||||
"check": lambda args: contains_destructive_command(args.get("command", "")) or
|
||||
any(kw in args.get("command", "") for kw in ["> /etc/", "chmod 777"]),
|
||||
"message": "Potentially destructive command"},
|
||||
]
|
||||
|
||||
|
||||
Reference in New Issue
Block a user