#!/usr/bin/env python3 """ s03_permission.py - Permission System Three gates inserted before tool execution: Gate 1: Hard deny list (rm -rf /, sudo, ...) Gate 2: Rule matching (write outside workspace? destructive cmd?) Gate 3: User approval (pause and wait for confirmation) +----------+ +-------+ +--------------+ +---------------+ | User | ---> | LLM | ---> | Permission | ---> | Tool Dispatch | | prompt | | | | 1. deny list | | execute | +----------+ +---+---+ | 2. rules | +-------+-------+ ^ | 3. approval | | | +------+-------+ | | | deny | | v v | +-------------------------------+ +----------+ tool_result: denied or output | +-------------------------------+ Only one line added to the agent loop: if not check_permission(block): continue Builds on s02 (multi-tool). Usage: python s03_permission/code.py Needs: pip install anthropic python-dotenv + ANTHROPIC_API_KEY in .env """ import os import re import shlex import subprocess from pathlib import Path try: import readline readline.parse_and_bind('set bind-tty-special-chars off') readline.parse_and_bind('set input-meta on') readline.parse_and_bind('set output-meta on') readline.parse_and_bind('set convert-meta off') except ImportError: pass from anthropic import Anthropic from dotenv import load_dotenv load_dotenv(override=True) if os.getenv("ANTHROPIC_BASE_URL"): os.environ.pop("ANTHROPIC_AUTH_TOKEN", None) WORKDIR = Path.cwd() client = Anthropic(base_url=os.getenv("ANTHROPIC_BASE_URL")) MODEL = os.environ["MODEL_ID"] SYSTEM = f"You are a coding agent at {WORKDIR}. All destructive operations require user approval." # -- From s02: tool implementations -- def run_bash(command: str) -> str: try: r = subprocess.run(command, shell=True, cwd=WORKDIR, capture_output=True, text=True, errors="replace", timeout=120) out = (r.stdout + r.stderr).strip() return out[:50000] if out else "(no output)" except subprocess.TimeoutExpired: return "Error: Timeout (120s)" def run_read(path: str, limit: int | None = None) -> str: try: lines = (WORKDIR / path).resolve().read_text(encoding="utf-8").splitlines() if limit and limit < len(lines): lines = lines[:limit] + [f"... ({len(lines) - limit} more lines)"] return "\n".join(lines) except Exception as e: return f"Error: {e}" def run_write(path: str, content: str) -> str: try: file_path = (WORKDIR / path).resolve() file_path.parent.mkdir(parents=True, exist_ok=True) file_path.write_text(content, encoding="utf-8") return f"Wrote {len(content)} bytes to {path}" except Exception as e: return f"Error: {e}" def run_edit(path: str, old_text: str, new_text: str) -> str: try: file_path = (WORKDIR / path).resolve() text = file_path.read_text(encoding="utf-8") if old_text not in text: return f"Error: text not found in {path}" file_path.write_text(text.replace(old_text, new_text, 1), encoding="utf-8") return f"Edited {path}" except Exception as e: return f"Error: {e}" def run_glob(pattern: str) -> str: import glob as g try: matches = sorted({ match for match in g.glob( pattern, root_dir=WORKDIR, recursive=True) if (WORKDIR / match).resolve().is_relative_to(WORKDIR) }) shown = matches[:200] if len(matches) > 200: shown.append("... (more matches omitted; narrow the pattern)") return "\n".join(shown) if shown else "(no matches)" except Exception as e: return f"Error: {e}" # -- From s02 (unchanged): tool definitions and dispatch -- TOOLS = [ {"name": "bash", "description": "Run a shell command.", "input_schema": {"type": "object", "properties": {"command": {"type": "string"}}, "required": ["command"]}}, {"name": "read_file", "description": "Read file contents.", "input_schema": {"type": "object", "properties": {"path": {"type": "string"}, "limit": {"type": "integer"}}, "required": ["path"]}}, {"name": "write_file", "description": "Write content to a file.", "input_schema": {"type": "object", "properties": {"path": {"type": "string"}, "content": {"type": "string"}}, "required": ["path", "content"]}}, {"name": "edit_file", "description": "Replace exact text in a file once.", "input_schema": {"type": "object", "properties": {"path": {"type": "string"}, "old_text": {"type": "string"}, "new_text": {"type": "string"}}, "required": ["path", "old_text", "new_text"]}}, {"name": "glob", "description": "Find files matching a glob pattern; ** matches recursively.", "input_schema": {"type": "object", "properties": {"pattern": {"type": "string"}}, "required": ["pattern"]}}, ] TOOL_HANDLERS = { "bash": run_bash, "read_file": run_read, "write_file": run_write, "edit_file": run_edit, "glob": run_glob, } # -- New in s03: three-gate permission pipeline -- # Gate 1: Hard deny list - always forbidden DENY_LIST = ["rm -rf /", "sudo", "shutdown", "reboot", "mkfs", "dd if=", "> /dev/sda"] def check_deny_list(command: str) -> str | None: for pattern in DENY_LIST: if pattern in command: return f"Blocked: '{pattern}' is on the deny list" return None # Gate 2: Rule matching - context-dependent checks SHELL_SEPARATORS = ";&|\n" DESTRUCTIVE_COMMANDS = {"rm", "del"} SHELL_WRAPPERS = {"sh", "bash", "zsh", "dash", "cmd", "cmd.exe"} COMMAND_PREFIXES = {"command", "call"} CONTROL_PREFIXES = {"then", "do", "else", "!", "{"} COMPARE_OPERATORS = {"equ", "neq", "lss", "leq", "gtr", "geq"} MAX_COMMAND_NESTING = 16 DESTRUCTIVE_SUBCOMMAND = re.compile( r"(?i)(?:\$\(|[<>]\(|\x60)\s*(?:rm|del)" r"(?=\s|$|[;&|()])" ) def shell_tokens(command: str) -> list[str]: lexer = shlex.shlex( command, posix=False, punctuation_chars=SHELL_SEPARATORS ) lexer.whitespace = " \t\r" lexer.whitespace_split = True lexer.commenters = "" return list(lexer) def shell_syntax_outside_single_quotes(command: str) -> str: visible = [] single_quoted = double_quoted = escaped = False for char in command: if escaped: visible.append(" ") escaped = False elif char == "\\" and not single_quoted: visible.append(" ") escaped = True elif char == '"' and not single_quoted: double_quoted = not double_quoted visible.append(char) elif char == "'" and not double_quoted: single_quoted = not single_quoted visible.append(" ") else: visible.append(" " if single_quoted else char) return "".join(visible) def unquote_shell_token(token: str) -> str: if len(token) >= 2 and token[0] in "'\"" and token[-1] == token[0]: return token[1:-1] return token def command_name(token: str) -> str: value = unquote_shell_token(token).lstrip("@").strip("()").casefold() if value.startswith("del/"): return "del" return value.replace("\\", "/").rsplit("/", 1)[-1] def is_shell_separator(token: str) -> bool: return bool(token) and all(char in SHELL_SEPARATORS for char in token) def is_shell_assignment(token: str) -> bool: name, separator, _ = unquote_shell_token(token).partition("=") return bool( separator and name and not name[0].isdigit() and name.replace("_", "a").isalnum() ) def segment_has_destructive_command( tokens: list[str], depth: int = 0 ) -> bool: if depth >= MAX_COMMAND_NESTING: return True index = 0 while index < len(tokens) and is_shell_assignment(tokens[index]): index += 1 if index >= len(tokens): return False name = command_name(tokens[index]) if name in DESTRUCTIVE_COMMANDS: return True if name in CONTROL_PREFIXES: return segment_has_destructive_command(tokens[index + 1:], depth + 1) if name == "env": index += 1 while index < len(tokens) and ( unquote_shell_token(tokens[index]).startswith("-") or is_shell_assignment(tokens[index]) ): index += 1 return segment_has_destructive_command(tokens[index:], depth + 1) if name in COMMAND_PREFIXES: index += 1 options = [] while ( index < len(tokens) and unquote_shell_token(tokens[index]).startswith("-") ): options.append(unquote_shell_token(tokens[index])) index += 1 if name == "command" and any( "v" in option.lstrip("-").casefold() for option in options ): return False return segment_has_destructive_command(tokens[index:], depth + 1) if name in SHELL_WRAPPERS: for flag_index in range(index + 1, len(tokens)): flag = unquote_shell_token(tokens[flag_index]).casefold() is_command_flag = ( flag in {"/c", "/k"} if name.startswith("cmd") else flag.startswith("-") and not flag.startswith("--") and "c" in flag[1:] ) if is_command_flag: nested = " ".join( unquote_shell_token(token) for token in tokens[flag_index + 1:] ) return contains_destructive_command(nested, depth + 1) return False if name == "if": index += 1 while ( index < len(tokens) and command_name(tokens[index]) in {"/i", "not"} ): index += 1 if index >= len(tokens): return False condition = command_name(tokens[index]) if condition in {"exist", "defined", "errorlevel", "cmdextversion"}: return segment_has_destructive_command( tokens[index + 2:], depth + 1 ) if "==" in unquote_shell_token(tokens[index]): return segment_has_destructive_command( tokens[index + 1:], depth + 1 ) if ( index + 2 < len(tokens) and command_name(tokens[index + 1]) in COMPARE_OPERATORS ): return segment_has_destructive_command( tokens[index + 3:], depth + 1 ) return False if name == "for": for do_index, token in enumerate(tokens[index + 1:], index + 1): if command_name(token) == "do": return segment_has_destructive_command( tokens[do_index + 1:], depth + 1 ) return False def contains_destructive_command(command: str, depth: int = 0) -> bool: if depth >= MAX_COMMAND_NESTING: return True try: tokens = shell_tokens(command) except ValueError: return True if DESTRUCTIVE_SUBCOMMAND.search( shell_syntax_outside_single_quotes(command) ): return True segment = [] for token in tokens: if is_shell_separator(token): if segment_has_destructive_command(segment, depth): return True segment = [] else: segment.append(token) return segment_has_destructive_command(segment, depth) PERMISSION_RULES = [ {"tools": ["read_file", "write_file", "edit_file"], "check": lambda args: not (WORKDIR / args.get("path", "")).resolve().is_relative_to(WORKDIR), "message": "Writing outside workspace"}, {"tools": ["bash"], "check": lambda args: contains_destructive_command(args.get("command", "")) or any(kw in args.get("command", "") for kw in ["> /etc/", "chmod 777"]), "message": "Potentially destructive command"}, ] def check_rules(tool_name: str, args: dict) -> str | None: for rule in PERMISSION_RULES: if tool_name in rule["tools"] and rule["check"](args): return rule["message"] return None # Gate 3: User approval - wait for confirmation after rule match def ask_user(tool_name: str, args: dict, reason: str) -> str: print(f"\n\033[33m[permission] {reason}\033[0m") print(f" Tool: {tool_name}({args})") choice = input(" Allow? [y/N] ").strip().lower() return "allow" if choice in ("y", "yes") else "deny" # Pipeline: all three gates chained def check_permission(block) -> bool: if block.name == "bash": reason = check_deny_list(block.input.get("command", "")) if reason: print(f"\n\033[31m[blocked] {reason}\033[0m") return False reason = check_rules(block.name, block.input) if reason: decision = ask_user(block.name, block.input, reason) if decision == "deny": return False return True # -- Agent loop: same as s02, with check_permission() inserted -- def agent_loop(messages: list): while True: response = client.messages.create( model=MODEL, system=SYSTEM, messages=messages, tools=TOOLS, max_tokens=8000, ) messages.append({"role": "assistant", "content": response.content}) tool_calls = [ block for block in response.content if block.type == "tool_use" ] if not tool_calls: return results = [] for block in tool_calls: print(f"\033[36m> {block.name}\033[0m") # s03 change: run through permission pipeline before executing if not check_permission(block): results.append({"type": "tool_result", "tool_use_id": block.id, "content": "Permission denied."}) continue handler = TOOL_HANDLERS.get(block.name) output = handler(**block.input) if handler else f"Unknown: {block.name}" print(str(output)[:200]) results.append({"type": "tool_result", "tool_use_id": block.id, "content": output}) messages.append({"role": "user", "content": results}) if __name__ == "__main__": print("s03: Permission") print("Enter a question, press Enter to send. Type q to quit.\n") history = [] while True: try: # \001/\002 tell Readline the ANSI escapes have zero display width. query = input("\001\033[36m\002s03 >> \001\033[0m\002") except (EOFError, KeyboardInterrupt): break if query.strip().lower() in ("q", "exit", ""): break history.append({"role": "user", "content": query}) agent_loop(history) for block in history[-1]["content"]: if getattr(block, "type", None) == "text": print(block.text) print()