Skip to content

feat: hexdump/od/strings/xxd defaults, denied_flags, after_first - #12

Merged
grams merged 1 commit into
mainfrom
feat/add-binary-inspection-tools
Apr 27, 2026
Merged

grams merged 1 commit into
mainfrom
feat/add-binary-inspection-tools

Conversation

@grams

@grams grams commented Apr 27, 2026

Copy link
Copy Markdown
Contributor

Summary

Three deny-by-default additions:

  • Binary inspection tools in a dedicated binary-inspection.toml (hexdump, od, strings, xxd). sha*sum family completed in utilities.toml.
  • write_target = "after_first" for tools where the first positional is a read-only input and subsequent ones are destinations (xxd in [out]). Existing "last"/"all" can't express this without false positives on read-only invocations.
  • denied_flags TOML option that blocks listed flags outright, regardless of allowed = ["*"]. Exact match (no short-flag prefix to avoid -d matching -delete); long flags also match --flag=value. Applied to:
    • find: -exec, -execdir, -ok, -okdir, -delete, -fprint, -fprintf, -fls
    • curl: -O, --remote-name, --remote-name-all, -J, --remote-header-name

Helpers factored out along the way: MatchFlag / MatchFlagOrShortPrefix / FirstMatchingFlag unify the flag-scanning patterns; validateFlagPrefix / validateWriteTarget dedupe the extend/replace validation paths; spec.WriteTarget{Last,All,AfterFirst} constants; standardized Deny message format; cmp.Or, slices.Sorted+maps.Keys, slices.Contains where applicable.

Docs updated: README.md, SAMPLE_CLAUDE.md, internal/config/help.txt, and the LLM skill plugins/agent-callable/skills/configure.md.

Test plan

  • make test passes — table-driven tests for MatchFlag, MatchFlagOrShortPrefix, FirstMatchingFlag, after_first, denied_flags, and the new defaults
  • make install produces a working binary
  • Smoke-tested locally: xxd /etc/hostname, xxd /etc/hostname /tmp/out.bin, find . -name '*.go', blocked: find . -exec rm {} \;, curl -O https://...

🤖 Generated with Claude Code

Three deny-by-default additions:

- New binary-inspection.toml with hexdump, od, strings, xxd; the
  utilities.toml sha*sum family is completed in passing (sha224sum,
  sha384sum, sha512sum).
- write_target = "after_first" mode for tools where the first
  positional is a read-only input and subsequent positionals are
  destinations (xxd in [out]). Existing "last"/"all" can't express
  this without false positives on read-only invocations.
- denied_flags TOML option that blocks listed flags outright,
  regardless of allowed = ["*"]. Exact match (no short-flag prefix
  to avoid -d colliding with -delete); long flags also match
  --flag=value; tokens after -- are ignored. Applied to:
    find: -exec, -execdir, -ok, -okdir, -delete, -fprint, -fprintf, -fls
    curl: -O, --remote-name, --remote-name-all, -J, --remote-header-name

Common helpers factored out along the way:
- MatchFlag, MatchFlagOrShortPrefix, FirstMatchingFlag in args.go
  unify the flag-scanning patterns previously duplicated between
  matchDeniedFlag and hasWriteFlag. ContainsFlag now reuses MatchFlag.
- validateFlagPrefix / validateWriteTarget helpers in config.go
  dedupe the extend-mode and replace-mode validation paths.
- spec.WriteTarget{Last,All,AfterFirst} constants replace raw strings
  in switches and validators.
- checkWriteTarget collapses the three cases into a single targets-slice
  loop.
- Deny messages in ConfigToolSpec all follow "<tool>: <reason>".
- cmp.Or, slices.Sorted+maps.Keys, slices.Contains where applicable.

Docs: README.md, SAMPLE_CLAUDE.md, internal/config/help.txt and the
LLM skill plugins/agent-callable/skills/configure.md cover the new
knobs. Table-driven tests for the new helpers and the new defaults.
@grams grams self-assigned this Apr 27, 2026
@grams
grams merged commit b1a9f67 into main Apr 27, 2026
2 checks passed
@grams
grams deleted the feat/add-binary-inspection-tools branch April 27, 2026 13:22
@grams grams added the transverse Transverse plateforme (plusieurs BUs ou outillage plateforme) label Apr 30, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

transverse Transverse plateforme (plusieurs BUs ou outillage plateforme)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant