Security + upstream fixes
- Network core moves to a root-only folder; BroV talks to a narrow root helper (netctl.py) over a user-only socket; install script verifies the mihomo SHA256 and migrates keys (scripts/netcore) - Hardened runtime, no get-task-allow; bypassPermissions removed from the chat; concealed clipboard items are not restored; DangerCheck knows core, LaunchAgents and hook paths; dropped-file copies expire after 7 days - Ported from upstream Coucou: 1h crash fix (d05f22b), safe settings.json writes (918d30e), Escape/fold for pending approvals (6012900, 40e3ba8), auto-close delay + reopen (74984f2, ea244a7), full AskUserQuestion (52b1562) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
@@ -56,12 +56,25 @@ enum DangerCheck {
|
||||
(#"/\.(zshrc|bashrc|zprofile|bash_profile|gitconfig)$"#, "правит конфиг оболочки или git"),
|
||||
(#"/\.git/"#, "правит внутренности репозитория (.git)"),
|
||||
(#"(id_rsa|id_ed25519|\.pem|\.key|credentials|secrets?)(\.|$)"#, "трогает ключи или секреты"),
|
||||
(#"/(NotchBuddy|BroV)/netcore(/|$)|\.vpnkey$"#, "меняет сетевое ядро BroV или его ключи"),
|
||||
(#"/Library/Launch(Agents|Daemons)/"#, "меняет автозапуск (LaunchAgents / LaunchDaemons)"),
|
||||
(#"/NotchBuddy/nb-hook"#, "меняет хуки BroV"),
|
||||
]
|
||||
|
||||
/// The same sensitive places when a shell command writes, moves or deletes there.
|
||||
static let shellPathRules: [Rule] = [
|
||||
Rule(pattern: #"(>|\btee\b|\bcp\b|\bmv\b|\brm\b|\bln\b|\bchmod\b|\bchown\b|sed\s+-i|\bpython3?\b|\bperl\b).*(NotchBuddy/netcore|BroV/netcore|\.vpnkey)"#,
|
||||
reason: "меняет сетевое ядро BroV или его ключи"),
|
||||
Rule(pattern: #"(>|\btee\b|\bcp\b|\bmv\b|\brm\b|\bln\b|\blaunchctl\b|\bplutil\b).*Library/Launch(Agents|Daemons)"#,
|
||||
reason: "меняет автозапуск (LaunchAgents / LaunchDaemons)"),
|
||||
Rule(pattern: #"(>|\btee\b|\bcp\b|\bmv\b|\brm\b|sed\s+-i).*(\.claude/settings(\.local)?\.json|NotchBuddy/nb-hook)"#,
|
||||
reason: "меняет настройки или хуки Claude Code"),
|
||||
]
|
||||
|
||||
static func reasons(tool: String, input: [String: Any]) -> [String] {
|
||||
var out: [String] = []
|
||||
if let command = input["command"] as? String {
|
||||
for rule in shellRules where matches(rule.pattern, command) && !out.contains(rule.reason) {
|
||||
for rule in shellRules + shellPathRules where matches(rule.pattern, command) && !out.contains(rule.reason) {
|
||||
out.append(rule.reason)
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user