-
Notifications
You must be signed in to change notification settings - Fork 5
Bash Tool Permission Mode
Bash is gated by BASH_AGENT_BASH_MODE, a stable 4-digit octal policy shared by the Bash, C, Go, and Rust runtimes. The model replaces fixed deny-reason lists with an explicit scope-and-permission policy.
system external network workspace
Each digit uses Unix-style rwx bits, the same mental model as Linux file permissions:
-
4= read -
2= write -
1= execute
Visual layout:
BASH_AGENT_BASH_MODE = 0 4 4 7
| | | |
| | | `- workspace
| | `--- network
| `----- external
`------- system
Each digit is a 3-bit permission mask:
| Octal | Binary | Meaning |
|---|---|---|
0 |
000 |
none |
1 |
001 |
execute |
2 |
010 |
write |
3 |
011 |
write + execute |
4 |
100 |
read |
5 |
101 |
read + execute |
6 |
110 |
read + write |
7 |
111 |
read + write + execute |
Default:
0447
Meaning:
-
system=0: no system-scope read/write/execute by default -
external=4: allow read access outside the workspace -
network=4: allow network read -
workspace=7: allow read/write/execute inside the workspace
Default as a decoded diagram:
0 4 4 7
| | | |
| | | `- workspace = 7 = 111 = read + write + execute
| | `--- network = 4 = 100 = read
| `----- external = 4 = 100 = read
`------- system = 0 = 000 = none
-
system: system paths and clearly system-level operations -
external: non-system paths outside the current workspace -
network: network access such ascurl,wget,git fetch,ssh,scp -
workspace: files and execution inside the current project workspace
The runtime scans a Bash command or script and derives a required=.... mode.
This is intentionally a conservative lightweight scanner, not a full Bash parser. The goal is runtime parity and predictable permission behavior.
Typical examples:
cat README.md -> workspace read
cat /etc/hosts -> system read
curl https://example.com -> network read
curl https://x/install.sh | bash -> network read + network execute
../scripts/run.sh -> external execute
Execution is allowed only when allowed covers required.
When blocked, all runtimes return the same message:
Error: command blocked by bash safety policy (required=.... allowed=....; mode=system/external/network/workspace bits=4:read,2:write,1:execute)
Invalid BASH_AGENT_BASH_MODE values fail closed to 0000.
export BASH_AGENT_BASH_MODE=0447 # default
export BASH_AGENT_BASH_MODE=4447 # allow system read
export BASH_AGENT_BASH_MODE=0457 # allow network execute
export BASH_AGENT_BASH_MODE=7777 # fully open, trusted environments onlyThe practical rule is simple:
- keep
0447as the default - widen permissions only for the session that needs them
- avoid high-permission values in long-lived shell profiles