e6f66bc0f0
patch_tool extracts V4A patch paths so _check_sensitive_path can refuse writes to /etc/*, /boot/*, etc. before they reach the low-level file ops. The extraction regex had two gaps: 1. `*** Move File: src -> dst` was never extracted (regex only matched Update/Add/Delete), so a Move targeting /etc/crontab skipped the pre-check and fell back on the narrower file_operations deny list. 2. The regex required `\\s+` after `***` but patch_parser uses `\\s*`, so `***Update File: /etc/hosts` (no space) parsed + applied while skipping the check. Loosen the leading whitespace to \\s* and add a Move regex that checks both endpoints. Move endpoints also run through the same '..' traversal rejection as the other V4A headers (closes the sibling gap on current main, which gained that traversal guard after this PR was opened).