mirror of
https://github.com/shareAI-lab/analysis_claude_code.git
synced 2026-09-20 12:13:38 +08:00
436 lines
15 KiB
Python
436 lines
15 KiB
Python
#!/usr/bin/env python3
|
|
"""
|
|
s03_permission.py - Permission System
|
|
|
|
Three gates inserted before tool execution:
|
|
|
|
Gate 1: Hard deny list (rm -rf /, sudo, ...)
|
|
Gate 2: Rule matching (write outside workspace? destructive cmd?)
|
|
Gate 3: User approval (pause and wait for confirmation)
|
|
|
|
+----------+ +-------+ +--------------+ +---------------+
|
|
| User | ---> | LLM | ---> | Permission | ---> | Tool Dispatch |
|
|
| prompt | | | | 1. deny list | | execute |
|
|
+----------+ +---+---+ | 2. rules | +-------+-------+
|
|
^ | 3. approval | |
|
|
| +------+-------+ |
|
|
| | deny |
|
|
| v v
|
|
| +-------------------------------+
|
|
+----------+ tool_result: denied or output |
|
|
+-------------------------------+
|
|
|
|
Only one line added to the agent loop:
|
|
|
|
if not check_permission(block):
|
|
continue
|
|
|
|
Builds on s02 (multi-tool). Usage:
|
|
|
|
python s03_permission/code.py
|
|
Needs: pip install anthropic python-dotenv + ANTHROPIC_API_KEY in .env
|
|
"""
|
|
|
|
import os
|
|
import re
|
|
import shlex
|
|
import subprocess
|
|
from pathlib import Path
|
|
|
|
try:
|
|
import readline
|
|
readline.parse_and_bind('set bind-tty-special-chars off')
|
|
readline.parse_and_bind('set input-meta on')
|
|
readline.parse_and_bind('set output-meta on')
|
|
readline.parse_and_bind('set convert-meta off')
|
|
except ImportError:
|
|
pass
|
|
|
|
from anthropic import Anthropic
|
|
from dotenv import load_dotenv
|
|
|
|
load_dotenv(override=True)
|
|
if os.getenv("ANTHROPIC_BASE_URL"):
|
|
os.environ.pop("ANTHROPIC_AUTH_TOKEN", None)
|
|
|
|
WORKDIR = Path.cwd()
|
|
client = Anthropic(base_url=os.getenv("ANTHROPIC_BASE_URL"))
|
|
MODEL = os.environ["MODEL_ID"]
|
|
|
|
SYSTEM = f"You are a coding agent at {WORKDIR}. All destructive operations require user approval."
|
|
|
|
|
|
# -- From s02: tool implementations --
|
|
|
|
def run_bash(command: str) -> str:
|
|
try:
|
|
r = subprocess.run(command, shell=True, cwd=WORKDIR,
|
|
capture_output=True, text=True, errors="replace", timeout=120)
|
|
out = (r.stdout + r.stderr).strip()
|
|
return out[:50000] if out else "(no output)"
|
|
except subprocess.TimeoutExpired:
|
|
return "Error: Timeout (120s)"
|
|
|
|
|
|
def run_read(path: str, limit: int | None = None) -> str:
|
|
try:
|
|
lines = (WORKDIR / path).resolve().read_text(encoding="utf-8").splitlines()
|
|
if limit and limit < len(lines):
|
|
lines = lines[:limit] + [f"... ({len(lines) - limit} more lines)"]
|
|
return "\n".join(lines)
|
|
except Exception as e:
|
|
return f"Error: {e}"
|
|
|
|
|
|
def run_write(path: str, content: str) -> str:
|
|
try:
|
|
file_path = (WORKDIR / path).resolve()
|
|
file_path.parent.mkdir(parents=True, exist_ok=True)
|
|
file_path.write_text(content, encoding="utf-8")
|
|
return f"Wrote {len(content)} bytes to {path}"
|
|
except Exception as e:
|
|
return f"Error: {e}"
|
|
|
|
|
|
def run_edit(path: str, old_text: str, new_text: str) -> str:
|
|
try:
|
|
file_path = (WORKDIR / path).resolve()
|
|
text = file_path.read_text(encoding="utf-8")
|
|
if old_text not in text:
|
|
return f"Error: text not found in {path}"
|
|
file_path.write_text(text.replace(old_text, new_text, 1), encoding="utf-8")
|
|
return f"Edited {path}"
|
|
except Exception as e:
|
|
return f"Error: {e}"
|
|
|
|
|
|
def run_glob(pattern: str) -> str:
|
|
import glob as g
|
|
try:
|
|
matches = sorted({
|
|
match for match in g.glob(
|
|
pattern, root_dir=WORKDIR, recursive=True)
|
|
if (WORKDIR / match).resolve().is_relative_to(WORKDIR)
|
|
})
|
|
shown = matches[:200]
|
|
if len(matches) > 200:
|
|
shown.append("... (more matches omitted; narrow the pattern)")
|
|
return "\n".join(shown) if shown else "(no matches)"
|
|
except Exception as e:
|
|
return f"Error: {e}"
|
|
|
|
|
|
# -- From s02 (unchanged): tool definitions and dispatch --
|
|
|
|
TOOLS = [
|
|
{"name": "bash", "description": "Run a shell command.",
|
|
"input_schema": {"type": "object", "properties": {"command": {"type": "string"}}, "required": ["command"]}},
|
|
{"name": "read_file", "description": "Read file contents.",
|
|
"input_schema": {"type": "object", "properties": {"path": {"type": "string"}, "limit": {"type": "integer"}}, "required": ["path"]}},
|
|
{"name": "write_file", "description": "Write content to a file.",
|
|
"input_schema": {"type": "object", "properties": {"path": {"type": "string"}, "content": {"type": "string"}}, "required": ["path", "content"]}},
|
|
{"name": "edit_file", "description": "Replace exact text in a file once.",
|
|
"input_schema": {"type": "object", "properties": {"path": {"type": "string"}, "old_text": {"type": "string"}, "new_text": {"type": "string"}}, "required": ["path", "old_text", "new_text"]}},
|
|
{"name": "glob", "description": "Find files matching a glob pattern; ** matches recursively.",
|
|
"input_schema": {"type": "object", "properties": {"pattern": {"type": "string"}}, "required": ["pattern"]}},
|
|
]
|
|
|
|
TOOL_HANDLERS = {
|
|
"bash": run_bash, "read_file": run_read, "write_file": run_write,
|
|
"edit_file": run_edit, "glob": run_glob,
|
|
}
|
|
|
|
|
|
# -- New in s03: three-gate permission pipeline --
|
|
|
|
# Gate 1: Hard deny list - always forbidden
|
|
DENY_LIST = ["rm -rf /", "sudo", "shutdown", "reboot", "mkfs", "dd if=", "> /dev/sda"]
|
|
|
|
def check_deny_list(command: str) -> str | None:
|
|
for pattern in DENY_LIST:
|
|
if pattern in command:
|
|
return f"Blocked: '{pattern}' is on the deny list"
|
|
return None
|
|
|
|
|
|
# Gate 2: Rule matching - context-dependent checks
|
|
SHELL_SEPARATORS = ";&|\n"
|
|
DESTRUCTIVE_COMMANDS = {"rm", "del"}
|
|
SHELL_WRAPPERS = {"sh", "bash", "zsh", "dash", "cmd", "cmd.exe"}
|
|
COMMAND_PREFIXES = {"command", "call"}
|
|
CONTROL_PREFIXES = {"then", "do", "else", "!", "{"}
|
|
COMPARE_OPERATORS = {"equ", "neq", "lss", "leq", "gtr", "geq"}
|
|
MAX_COMMAND_NESTING = 16
|
|
DESTRUCTIVE_SUBCOMMAND = re.compile(
|
|
r"(?i)(?:\$\(|[<>]\(|\x60)\s*(?:rm|del)"
|
|
r"(?=\s|$|[;&|()])"
|
|
)
|
|
|
|
|
|
def shell_tokens(command: str) -> list[str]:
|
|
lexer = shlex.shlex(
|
|
command, posix=False, punctuation_chars=SHELL_SEPARATORS
|
|
)
|
|
lexer.whitespace = " \t\r"
|
|
lexer.whitespace_split = True
|
|
lexer.commenters = ""
|
|
return list(lexer)
|
|
|
|
|
|
def shell_syntax_outside_single_quotes(command: str) -> str:
|
|
visible = []
|
|
single_quoted = double_quoted = escaped = False
|
|
for char in command:
|
|
if escaped:
|
|
visible.append(" ")
|
|
escaped = False
|
|
elif char == "\\" and not single_quoted:
|
|
visible.append(" ")
|
|
escaped = True
|
|
elif char == '"' and not single_quoted:
|
|
double_quoted = not double_quoted
|
|
visible.append(char)
|
|
elif char == "'" and not double_quoted:
|
|
single_quoted = not single_quoted
|
|
visible.append(" ")
|
|
else:
|
|
visible.append(" " if single_quoted else char)
|
|
return "".join(visible)
|
|
|
|
|
|
def unquote_shell_token(token: str) -> str:
|
|
if len(token) >= 2 and token[0] in "'\"" and token[-1] == token[0]:
|
|
return token[1:-1]
|
|
return token
|
|
|
|
|
|
def command_name(token: str) -> str:
|
|
value = unquote_shell_token(token).lstrip("@").strip("()").casefold()
|
|
if value.startswith("del/"):
|
|
return "del"
|
|
return value.replace("\\", "/").rsplit("/", 1)[-1]
|
|
|
|
|
|
def is_shell_separator(token: str) -> bool:
|
|
return bool(token) and all(char in SHELL_SEPARATORS for char in token)
|
|
|
|
|
|
def is_shell_assignment(token: str) -> bool:
|
|
name, separator, _ = unquote_shell_token(token).partition("=")
|
|
return bool(
|
|
separator
|
|
and name
|
|
and not name[0].isdigit()
|
|
and name.replace("_", "a").isalnum()
|
|
)
|
|
|
|
|
|
def segment_has_destructive_command(
|
|
tokens: list[str], depth: int = 0
|
|
) -> bool:
|
|
if depth >= MAX_COMMAND_NESTING:
|
|
return True
|
|
|
|
index = 0
|
|
while index < len(tokens) and is_shell_assignment(tokens[index]):
|
|
index += 1
|
|
if index >= len(tokens):
|
|
return False
|
|
|
|
name = command_name(tokens[index])
|
|
if name in DESTRUCTIVE_COMMANDS:
|
|
return True
|
|
if name in CONTROL_PREFIXES:
|
|
return segment_has_destructive_command(tokens[index + 1:], depth + 1)
|
|
if name == "env":
|
|
index += 1
|
|
while index < len(tokens) and (
|
|
unquote_shell_token(tokens[index]).startswith("-")
|
|
or is_shell_assignment(tokens[index])
|
|
):
|
|
index += 1
|
|
return segment_has_destructive_command(tokens[index:], depth + 1)
|
|
if name in COMMAND_PREFIXES:
|
|
index += 1
|
|
options = []
|
|
while (
|
|
index < len(tokens)
|
|
and unquote_shell_token(tokens[index]).startswith("-")
|
|
):
|
|
options.append(unquote_shell_token(tokens[index]))
|
|
index += 1
|
|
if name == "command" and any(
|
|
"v" in option.lstrip("-").casefold() for option in options
|
|
):
|
|
return False
|
|
return segment_has_destructive_command(tokens[index:], depth + 1)
|
|
if name in SHELL_WRAPPERS:
|
|
for flag_index in range(index + 1, len(tokens)):
|
|
flag = unquote_shell_token(tokens[flag_index]).casefold()
|
|
is_command_flag = (
|
|
flag in {"/c", "/k"}
|
|
if name.startswith("cmd")
|
|
else flag.startswith("-")
|
|
and not flag.startswith("--")
|
|
and "c" in flag[1:]
|
|
)
|
|
if is_command_flag:
|
|
nested = " ".join(
|
|
unquote_shell_token(token)
|
|
for token in tokens[flag_index + 1:]
|
|
)
|
|
return contains_destructive_command(nested, depth + 1)
|
|
return False
|
|
if name == "if":
|
|
index += 1
|
|
while (
|
|
index < len(tokens)
|
|
and command_name(tokens[index]) in {"/i", "not"}
|
|
):
|
|
index += 1
|
|
if index >= len(tokens):
|
|
return False
|
|
condition = command_name(tokens[index])
|
|
if condition in {"exist", "defined", "errorlevel", "cmdextversion"}:
|
|
return segment_has_destructive_command(
|
|
tokens[index + 2:], depth + 1
|
|
)
|
|
if "==" in unquote_shell_token(tokens[index]):
|
|
return segment_has_destructive_command(
|
|
tokens[index + 1:], depth + 1
|
|
)
|
|
if (
|
|
index + 2 < len(tokens)
|
|
and command_name(tokens[index + 1]) in COMPARE_OPERATORS
|
|
):
|
|
return segment_has_destructive_command(
|
|
tokens[index + 3:], depth + 1
|
|
)
|
|
return False
|
|
if name == "for":
|
|
for do_index, token in enumerate(tokens[index + 1:], index + 1):
|
|
if command_name(token) == "do":
|
|
return segment_has_destructive_command(
|
|
tokens[do_index + 1:], depth + 1
|
|
)
|
|
return False
|
|
|
|
|
|
def contains_destructive_command(command: str, depth: int = 0) -> bool:
|
|
if depth >= MAX_COMMAND_NESTING:
|
|
return True
|
|
|
|
try:
|
|
tokens = shell_tokens(command)
|
|
except ValueError:
|
|
return True
|
|
if DESTRUCTIVE_SUBCOMMAND.search(
|
|
shell_syntax_outside_single_quotes(command)
|
|
):
|
|
return True
|
|
|
|
segment = []
|
|
for token in tokens:
|
|
if is_shell_separator(token):
|
|
if segment_has_destructive_command(segment, depth):
|
|
return True
|
|
segment = []
|
|
else:
|
|
segment.append(token)
|
|
return segment_has_destructive_command(segment, depth)
|
|
|
|
|
|
PERMISSION_RULES = [
|
|
{"tools": ["read_file", "write_file", "edit_file"],
|
|
"check": lambda args: not (WORKDIR / args.get("path", "")).resolve().is_relative_to(WORKDIR),
|
|
"message": "Writing outside workspace"},
|
|
{"tools": ["bash"],
|
|
"check": lambda args: contains_destructive_command(args.get("command", "")) or
|
|
any(kw in args.get("command", "") for kw in ["> /etc/", "chmod 777"]),
|
|
"message": "Potentially destructive command"},
|
|
]
|
|
|
|
def check_rules(tool_name: str, args: dict) -> str | None:
|
|
for rule in PERMISSION_RULES:
|
|
if tool_name in rule["tools"] and rule["check"](args):
|
|
return rule["message"]
|
|
return None
|
|
|
|
|
|
# Gate 3: User approval - wait for confirmation after rule match
|
|
def ask_user(tool_name: str, args: dict, reason: str) -> str:
|
|
print(f"\n\033[33m[permission] {reason}\033[0m")
|
|
print(f" Tool: {tool_name}({args})")
|
|
choice = input(" Allow? [y/N] ").strip().lower()
|
|
return "allow" if choice in ("y", "yes") else "deny"
|
|
|
|
|
|
# Pipeline: all three gates chained
|
|
def check_permission(block) -> bool:
|
|
if block.name == "bash":
|
|
reason = check_deny_list(block.input.get("command", ""))
|
|
if reason:
|
|
print(f"\n\033[31m[blocked] {reason}\033[0m")
|
|
return False
|
|
reason = check_rules(block.name, block.input)
|
|
if reason:
|
|
decision = ask_user(block.name, block.input, reason)
|
|
if decision == "deny":
|
|
return False
|
|
return True
|
|
|
|
|
|
# -- Agent loop: same as s02, with check_permission() inserted --
|
|
|
|
def agent_loop(messages: list):
|
|
while True:
|
|
response = client.messages.create(
|
|
model=MODEL, system=SYSTEM, messages=messages,
|
|
tools=TOOLS, max_tokens=8000,
|
|
)
|
|
messages.append({"role": "assistant", "content": response.content})
|
|
|
|
tool_calls = [
|
|
block for block in response.content if block.type == "tool_use"
|
|
]
|
|
if not tool_calls:
|
|
return
|
|
|
|
results = []
|
|
for block in tool_calls:
|
|
print(f"\033[36m> {block.name}\033[0m")
|
|
|
|
# s03 change: run through permission pipeline before executing
|
|
if not check_permission(block):
|
|
results.append({"type": "tool_result", "tool_use_id": block.id,
|
|
"content": "Permission denied."})
|
|
continue
|
|
|
|
handler = TOOL_HANDLERS.get(block.name)
|
|
output = handler(**block.input) if handler else f"Unknown: {block.name}"
|
|
print(str(output)[:200])
|
|
results.append({"type": "tool_result", "tool_use_id": block.id, "content": output})
|
|
|
|
messages.append({"role": "user", "content": results})
|
|
|
|
|
|
if __name__ == "__main__":
|
|
print("s03: Permission")
|
|
print("Enter a question, press Enter to send. Type q to quit.\n")
|
|
|
|
history = []
|
|
while True:
|
|
try:
|
|
# \001/\002 tell Readline the ANSI escapes have zero display width.
|
|
query = input("\001\033[36m\002s03 >> \001\033[0m\002")
|
|
except (EOFError, KeyboardInterrupt):
|
|
break
|
|
if query.strip().lower() in ("q", "exit", ""):
|
|
break
|
|
history.append({"role": "user", "content": query})
|
|
agent_loop(history)
|
|
for block in history[-1]["content"]:
|
|
if getattr(block, "type", None) == "text":
|
|
print(block.text)
|
|
print()
|