Skip to content

test: review workflow - #52

Closed
Zfinix wants to merge 1 commit into
mainfrom
test/review-ci
Closed

Zfinix wants to merge 1 commit into
mainfrom
test/review-ci

Conversation

@Zfinix

@Zfinix Zfinix commented Oct 5, 2026

Copy link
Copy Markdown
Owner

Deliberate one-line logic bug (inverted bash prefix boundary check) to exercise the Aster review workflow end to end.

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Aster reviewed this PR: 1 finding(s) survived adversarial verification.

Match::CommandPrefix(prefix) => match line.strip_prefix(prefix.as_str()) {
Some("") => true,
Some(rest) => rest.starts_with(char::is_whitespace),
Some(rest) => !rest.starts_with(char::is_whitespace),

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

CommandPrefix match condition inverted, bypassing prefix rules — critical/security · 98% confident

The rule meant to catch commands starting with rm ignores a real rm -rf / command, so dangerous commands can slip through, while it also flags unrelated commands like rmdir.

Fix: Revert the negation: Some(rest) => rest.starts_with(char::is_whitespace), so a prefix only matches when followed by whitespace (or end-of-string via the Some("") arm).

@Zfinix Zfinix closed this Oct 5, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant