(context: ValidationContext)
| 1015 | } |
| 1016 | |
| 1017 | function validateIFSInjection(context: ValidationContext): PermissionResult { |
| 1018 | const { originalCommand } = context |
| 1019 | |
| 1020 | // Detect any usage of IFS variable which could be used to bypass regex validation |
| 1021 | // Check for $IFS and ${...IFS...} patterns (including parameter expansions like ${IFS:0:1}, ${#IFS}, etc.) |
| 1022 | // Using ${[^}]*IFS to catch all parameter expansion variations with IFS |
| 1023 | if (/\$IFS|\$\{[^}]*IFS/.test(originalCommand)) { |
| 1024 | logEvent('tengu_bash_security_check_triggered', { |
| 1025 | checkId: BASH_SECURITY_CHECK_IDS.IFS_INJECTION, |
| 1026 | subId: 1, |
| 1027 | }) |
| 1028 | return { |
| 1029 | behavior: 'ask', |
| 1030 | message: |
| 1031 | 'Command contains IFS variable usage which could bypass security validation', |
| 1032 | } |
| 1033 | } |
| 1034 | |
| 1035 | return { behavior: 'passthrough', message: 'No IFS injection detected' } |
| 1036 | } |
| 1037 | |
| 1038 | // Additional hardening against reading environment variables via /proc filesystem. |
| 1039 | // Path validation typically blocks /proc access, but this provides defense-in-depth. |
nothing calls this directly
no test coverage detected