-
Notifications
You must be signed in to change notification settings - Fork 5
EN Course 08 Bash Tool Permission Mode
Bash is the most powerful tool, so it is classified before execution.
The policy uses four scopes:
system external network workspace
Each digit uses rwx bits:
4 = read
2 = write
1 = execute
Default:
0 4 4 7
| | | |
| | | `- workspace = read + write + execute
| | `--- network = read
| `----- external = read
`------- system = none
The scanner converts a command into required=....:
tool_classify_bash_required_mode() {
local cmd="$1" lowered
TOOL_BASH_REQUIRED_MASK=0
lowered=$(printf '%s' "$cmd" | tr '[:upper:]' '[:lower:]')
tool_bash_scan_script "$lowered"
(( TOOL_BASH_REQUIRED_MASK == 0 )) && tool_bash_add_mode 1 4
printf -v TOOL_BASH_REQUIRED_MODE '%04o' "$TOOL_BASH_REQUIRED_MASK"
}Then tool_bash_mode_allows checks whether the allowed mask covers the required mask.
Typical command outcomes under the default mode (0447):
| Command | Required scope/bit (simplified) | Default decision |
|---|---|---|
cat README.md |
workspace read | allow |
echo hi > out.txt |
workspace write | allow |
chmod +x script.sh |
workspace execute/write | allow |
curl https://example.com |
network read | allow |
git status |
workspace read | allow |
ssh host |
network execute pattern | deny |
rm -rf /tmp/x |
workspace write | allow |
rm -rf /etc/hosts |
system write | deny |
sudo apt install ... |
system write/execute | deny |
launchctl unload ... |
system control | deny |
The exact classifier is conservative and implementation-specific; the table is for mental model and review.
This is not a full Bash parser. It is a conservative scanner that recognizes common paths, redirects, network commands, execution patterns, and dangerous system operations.
The important invariant is parity: Bash, C, Go, and Rust should classify the same command the same way and return the same block message.
For deeper details, see Bash Tool Permission Mode.
Plan and Todo Workflow explains how planning and progress tracking are modeled before introducing child agent runtimes.