Skip to content

guardrails: block-root-delete-target allows an empty operand, a bare variable, and a recursive rm outside the session tree #4519

Description

@kyle-sexton

plugins/guardrails/hooks/block-root-delete-target.sh refuses a recursive Bash rm only when its operand normalizes to a filesystem root. On main (9a25314) its header declares these as gaps, and each exits 0 when fed to the hook as a JSON payload:

  • An empty operand: rm -rf "", rm -rf ''. The test suite asserts this as allowed.
  • A bare variable as the whole operand: rm -rf "$X/", rm -rf "$X/*". An unset variable expands to nothing or to /.
  • A recursive delete whose target resolves outside the session's working tree (the git top level of the payload cwd), the system temp directories, or the session scratchpad (payload scratchpad_dir). The header says "does not track cwd", yet the payload carries cwd.

Expected: all three classes are refused. rm -rf "$X/build" still defers, and targets inside the tree, temp, or scratchpad stay allowed.

PowerShell Remove-Item -Recurse and rd /s have the same hazard. That work is tracked separately because it needs a PowerShell tokenizer.

No activity

Activity on this issue will appear here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    needs-triageNot yet classified. Floor until a type and one priority tier are set.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions