Skip to content

EN Course 08 Bash Tool Permission Mode

lloydzhou edited this page Jun 1, 2026 · 2 revisions

Bash Tool Permission Mode

Bash is the most powerful tool, so it is classified before execution.

The policy uses four scopes:

system external network workspace

Each digit uses rwx bits:

4 = read
2 = write
1 = execute

Default:

0 4 4 7
| | | |
| | | `- workspace = read + write + execute
| | `--- network   = read
| `----- external  = read
`------- system    = none

Scanner Shape

The scanner converts a command into required=....:

tool_classify_bash_required_mode() {
    local cmd="$1" lowered
    TOOL_BASH_REQUIRED_MASK=0
    lowered=$(printf '%s' "$cmd" | tr '[:upper:]' '[:lower:]')
    tool_bash_scan_script "$lowered"
    (( TOOL_BASH_REQUIRED_MASK == 0 )) && tool_bash_add_mode 1 4
    printf -v TOOL_BASH_REQUIRED_MODE '%04o' "$TOOL_BASH_REQUIRED_MASK"
}

Then tool_bash_mode_allows checks whether the allowed mask covers the required mask.

Classification Examples

Typical command outcomes under the default mode (0447):

Command Required scope/bit (simplified) Default decision
cat README.md workspace read allow
echo hi > out.txt workspace write allow
chmod +x script.sh workspace execute/write allow
curl https://example.com network read allow
git status workspace read allow
ssh host network execute pattern deny
rm -rf /tmp/x workspace write allow
rm -rf /etc/hosts system write deny
sudo apt install ... system write/execute deny
launchctl unload ... system control deny

The exact classifier is conservative and implementation-specific; the table is for mental model and review.

Design Boundary

This is not a full Bash parser. It is a conservative scanner that recognizes common paths, redirects, network commands, execution patterns, and dangerous system operations.

The important invariant is parity: Bash, C, Go, and Rust should classify the same command the same way and return the same block message.

For deeper details, see Bash Tool Permission Mode.

Next

Plan and Todo Workflow explains how planning and progress tracking are modeled before introducing child agent runtimes.

Clone this wiki locally