fix(guardrails): skip Git-for-Windows usertemp /tmp; judge curl/wget dests (#4251) - #4854
Merged
Merged
Conversation
…dests (#4251) On a stock Git for Windows install /tmp is a usertemp mount of %TEMP%, so blocking Bash-tool writes there was a false positive. Skip that spelling on the Bash command lane when cygpath or the mount table says so. /c/tmp, C:\tmp, PowerShell /tmp, and the file-path lane stay blocked. curl -o/--output and wget -O/--output-document destinations are judged the same way as cp/mv. Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
… probe Version sits above in-flight 0.39.1 (#4252). The usertemp probe lives once, ahead of the matchers. The cygpath stub uses the <user> placeholder so the machine-specific-paths gate stays quiet. Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
Contributor
|
PR body contract — issue linkage This PR body does not yet satisfy the issue-linkage contract:
Edit the body and this comment updates itself on the next run. |
Shellcheck wants an explicit fallthrough arm, and the portability gate flags the angle brackets that are character-class literals. Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #4251
Summary
block-windows-drive-tmpno longer treats Git for Windows'usertemp/tmp(the%TEMP%mount) as a drive-root write, and it now judgescurl -o/wget -Odestinations the same way asmkdir/cp.Fix
cygpath -w /tmpmatches%TEMP%/%TMP%, or themountline for/tmpcarriesusertemp, the Bash command lane skips the POSIX/tmparm./c/tmp,C:\tmp, drive-root\tmp, PowerShell/tmp, and the Write/Edit file-path lane stay blocked. Linux CI/tmptmpfs has nousertempflag, so existingOSTYPE=msysfixtures still deny.curl/wget-o/--outputand-O/--output-document(space,=, and glued-oFILE). A URL that merely contains/tmpis not a write target.Verification
Pins
mkdir -p /tmp/xallowed under a Git-for-Windows usertemp stub (cygpath -w /tmp→%TEMP%),/c/tmpstill blocked, PowerShell/tmpstill blocked, Write/tmpstill blocked, andcurl -o/wget -Odestinations judged (including glued-o/tmp/x).guardrails 0.39.2 (serialized above origin/main 0.38.13 and in-flight 0.39.1 on #4252).