Repository navigation
fix(security): use wildcard form for the root-mount deny rules - #410
Merged
Merged
Conversation
The three whole-disk docker mount rules shipped in 3.0.0 ended in `:*`, Claude Code's legacy prefix syntax. That makes the rest of the rule a literal prefix, so the `*` after `docker run` was never expanded: the rules matched nothing and Claude Code warned about each one at startup. Replace them 1:1 with `Bash(docker run*-v /:/*)` and the two `--volume` spellings. A container path is always absolute, so `/:/` follows every root mount (including `-v /:/host:ro`) while ordinary mounts such as `-v /home/me/proj:/app` stay allowed. The template stays at 170 entries. The old strings stay in DEVFLOW_HISTORICAL_DENY so `devflow init` retires them from installed settings and `security --disable` / `uninstall` still recognise them (D-SECURITY-03); the retired set grows from 9 to 12. Tests: the Bash-rule matcher model now covers the documented legacy `:*` suffix, a guard rejects any template permission rule mixing `*` with a trailing `:*`, red probes prove the retired rules never matched, and new cases pin root mounts denied and project mounts allowed.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Three deny rules added in #399 end in
:*, which Claude Code treats as legacy prefix syntax, so the*in the middle of the pattern is never expanded. Claude Code prints a warning for each rule at every startup, and the rules never matched, so whole-disk root mounts were never actually blocked. This replaces them with the wildcard form so they match.Changes
Bash(docker run*-v /:*),Bash(docker run*--volume /:*)andBash(docker run*--volume=/:*).src/targets/claude-code/templates/managed-settings.json: replaced 1:1 withBash(docker run*-v /:/*),Bash(docker run*--volume /:/*)andBash(docker run*--volume=/:/*). The template stays at 170 entries.docker run*-v /*was rejected: it would block every absolute-path mount (e.g.-v /home/u/proj:/app). A container path is always absolute, so/:/follows every root mount while ordinary mounts stay allowed.src/targets/claude-code/post-install.ts: the old strings stay inDEVFLOW_HISTORICAL_DENYand the new ones are added, sodevflow initretires the old entries from installed settings andsecurity --disable/uninstallrecognise both. TheD-SECURITY-03JSDoc records the rationale.CHANGELOG.md:### Fixedentry under[Unreleased].Breaking Changes
None.
Testing
tests/init-logic.test.ts: the test matcher model did not know the:*suffix rule, so it read the broken rules as working wildcards and masked the bug. It is corrected against the documented examples (Bash(ls:*),Bash(git:* push)); with the corrected model, 8 tests failed on the old template (5 root mounts unblocked).*before a trailing:*.-v /:/host,-v /:/host:ro, and the--volume/--volume=forms.-v $(pwd):/app,-v /home/u/proj:/app,--volume=/srv/data:/data,-v /tmp/:/scratch.init-logic281/281; 12 related files 513 passed / 4 skipped (env-gated); 4 CHANGELOG-reading files 208/208;npm run buildexit 0; Snyk code scan 0 issues.Related Issues
None. Follow-up to #399.