* Validates that the command doesn't use Zsh-specific dangerous commands that * can bypass security checks. These commands provide capabilities like loading * kernel modules, raw file I/O, network access, and pseudo-terminal execution * that circumvent normal permission checks. * * Also catches
( context: ValidationContext, )
| 2184 | * and `emulate` which with `-c` is an eval-equivalent. |
| 2185 | */ |
| 2186 | function validateZshDangerousCommands( |
| 2187 | context: ValidationContext, |
| 2188 | ): PermissionResult { |
| 2189 | const { originalCommand } = context |
| 2190 | |
| 2191 | // Extract the base command from the original command, stripping leading |
| 2192 | // whitespace, env var assignments, and Zsh precommand modifiers. |
| 2193 | // e.g., "FOO=bar command builtin zmodload" -> "zmodload" |
| 2194 | const ZSH_PRECOMMAND_MODIFIERS = new Set([ |
| 2195 | 'command', |
| 2196 | 'builtin', |
| 2197 | 'noglob', |
| 2198 | 'nocorrect', |
| 2199 | ]) |
| 2200 | const trimmed = originalCommand.trim() |
| 2201 | const tokens = trimmed.split(/\s+/) |
| 2202 | let baseCmd = '' |
| 2203 | for (const token of tokens) { |
| 2204 | // Skip env var assignments (VAR=value) |
| 2205 | if (/^[A-Za-z_]\w*=/.test(token)) continue |
| 2206 | // Skip Zsh precommand modifiers (they don't change what command runs) |
| 2207 | if (ZSH_PRECOMMAND_MODIFIERS.has(token)) continue |
| 2208 | baseCmd = token |
| 2209 | break |
| 2210 | } |
| 2211 | |
| 2212 | if (ZSH_DANGEROUS_COMMANDS.has(baseCmd)) { |
| 2213 | logEvent('tengu_bash_security_check_triggered', { |
| 2214 | checkId: BASH_SECURITY_CHECK_IDS.ZSH_DANGEROUS_COMMANDS, |
| 2215 | subId: 1, |
| 2216 | }) |
| 2217 | return { |
| 2218 | behavior: 'ask', |
| 2219 | message: `Command uses Zsh-specific '${baseCmd}' which can bypass security checks`, |
| 2220 | } |
| 2221 | } |
| 2222 | |
| 2223 | // Check for `fc -e` which allows executing arbitrary commands via editor |
| 2224 | // fc without -e is safe (just lists history), but -e specifies an editor |
| 2225 | // to run on the command, effectively an eval |
| 2226 | if (baseCmd === 'fc' && /\s-\S*e/.test(trimmed)) { |
| 2227 | logEvent('tengu_bash_security_check_triggered', { |
| 2228 | checkId: BASH_SECURITY_CHECK_IDS.ZSH_DANGEROUS_COMMANDS, |
| 2229 | subId: 2, |
| 2230 | }) |
| 2231 | return { |
| 2232 | behavior: 'ask', |
| 2233 | message: |
| 2234 | "Command uses 'fc -e' which can execute arbitrary commands via editor", |
| 2235 | } |
| 2236 | } |
| 2237 | |
| 2238 | return { |
| 2239 | behavior: 'passthrough', |
| 2240 | message: 'No Zsh dangerous commands', |
| 2241 | } |
| 2242 | } |
| 2243 |