fix(permissions): param-aware DIS dead-allow + CNF conflict matching
The DIS scanner collapsed Tool(param) rules to the bare tool name, so Agent(model:opus) deny + Agent(model:sonnet) allow (and the same for WebFetch(domain:...)) were flagged as dead config — a false positive now that CC 2.1.178 matches Tool(param:value) and 2.1.172 adds domain rules. The conflict-detector shared the blind spot from the other side: a wildcard deny like WebFetch(domain:*) did not cover a WebFetch(domain:good.com) allow, so a genuine cross-scope conflict was missed (false negative). New shared scanners/lib/permission-rules.mjs: - parseRule / paramMatches (glob) - dominates(deny, allow) -> DIS dead-allow (deny fully covers allow) - rulesIntersect(a, b) -> CNF cross-scope conflict (match sets intersect) DIS now delegates to dominates; conflict-detector :156 delegates to rulesIntersect. A bare deny still covers all params, so true positives are preserved (Bash deny + Bash(npm:*) allow still flagged). Re-seeded the marketplace-medium snapshots: the false-positive CA-DIS finding (Read(src/**) allow + Read(./.env) deny) is correctly gone. This changes snapshot CONTENT only — envelope schema is unchanged, so --json and --raw stay byte-stable. Full suite: 837/837 green (+25). self-audit PASS, A(100)/A(97).
This commit is contained in:
parent
8216fb4175
commit
bec3f45329
16 changed files with 324 additions and 145 deletions
6
tests/fixtures/param-conflict-project/.claude/settings.json
vendored
Normal file
6
tests/fixtures/param-conflict-project/.claude/settings.json
vendored
Normal file
|
|
@ -0,0 +1,6 @@
|
|||
{
|
||||
"permissions": {
|
||||
"allow": ["WebFetch(domain:good.com)", "Agent(model:sonnet)"],
|
||||
"deny": []
|
||||
}
|
||||
}
|
||||
6
tests/fixtures/param-conflict-project/.claude/settings.local.json
vendored
Normal file
6
tests/fixtures/param-conflict-project/.claude/settings.local.json
vendored
Normal file
|
|
@ -0,0 +1,6 @@
|
|||
{
|
||||
"permissions": {
|
||||
"allow": [],
|
||||
"deny": ["WebFetch(domain:*)", "Agent(model:opus)"]
|
||||
}
|
||||
}
|
||||
6
tests/fixtures/param-qualified-permissions/.claude/settings.json
vendored
Normal file
6
tests/fixtures/param-qualified-permissions/.claude/settings.json
vendored
Normal file
|
|
@ -0,0 +1,6 @@
|
|||
{
|
||||
"permissions": {
|
||||
"allow": ["Agent(model:sonnet)", "WebFetch(domain:good.com)", "Bash(npm:*)"],
|
||||
"deny": ["Agent(model:opus)", "WebFetch(domain:evil.com)", "Bash"]
|
||||
}
|
||||
}
|
||||
Loading…
Add table
Add a link
Reference in a new issue