-
Notifications
You must be signed in to change notification settings - Fork 13
Expand file tree
/
Copy pathinstall.sh
More file actions
executable file
·361 lines (335 loc) · 12.3 KB
/
Copy pathinstall.sh
File metadata and controls
executable file
·361 lines (335 loc) · 12.3 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
#!/usr/bin/env bash
# install.sh — idempotent installer for bash-guard.
#
# What it does:
# 1. Verifies Go is installed (>= 1.21).
# 2. Creates a symlink at ~/.claude/hooks/bash-guard and/or
# ~/.codex/hooks/bash-guard pointing at this src/.
# 3. Triggers a first build (warms Go cache).
# 4. Patches Claude Code settings.json and/or Codex hooks.json to add the
# bash-guard hook entry, preserving existing hooks. Uses jq for JSON-aware
# editing.
#
# Re-running is safe: the symlink is recreated, the build is a no-op, and
# the settings.json patch is a no-op when our entry already exists.
#
# Modes:
# --shadow Add hook with BASH_GUARD_SHADOW=1 (logs only, never blocks).
# This is the default for first-time installation.
# --dry-run Add hook with BASH_GUARD_DRY_RUN=1 (logs `would_decide`).
# --live Add hook with no env override (real enforcement).
# --uninstall Remove our hook entry from settings.json AND delete the symlink.
# --claude Install for Claude Code (default).
# --codex Install for Codex CLI / Codex App.
# --both Install for both agents.
set -euo pipefail
usage() {
cat <<EOF
Usage: $0 [--shadow|--dry-run|--live|--uninstall] [--claude|--codex|--both] [--codex-native-prompts]
Default mode: --shadow (always-allow + log everything).
Default agent: --claude.
Codex note: --live is fail-closed by default. Use --codex-native-prompts
only when you intentionally want selected bash-guard ask decisions to defer
to Codex execpolicy prompt rules.
EOF
}
mode="shadow"
agent="claude"
replace_legacy=0
codex_native_prompts=0
for arg in "$@"; do
case "$arg" in
--shadow) mode="shadow" ;;
--dry-run) mode="dry-run" ;;
--live) mode="live" ;;
--uninstall) mode="uninstall" ;;
--claude) agent="claude" ;;
--codex) agent="codex" ;;
--both) agent="both" ;;
--replace-legacy) replace_legacy=1 ;;
--codex-native-prompts) codex_native_prompts=1 ;;
-h|--help) usage; exit 0 ;;
*) echo "Unknown arg: $arg"; usage; exit 2 ;;
esac
done
REPO_SRC_DIR="$(cd -- "$(dirname -- "$0")" && pwd)/src"
CLAUDE_HOOK_DIR="$HOME/.claude/hooks/bash-guard"
CLAUDE_SETTINGS="$HOME/.claude/settings.json"
CODEX_HOOK_DIR="$HOME/.codex/hooks/bash-guard"
CODEX_HOOKS="$HOME/.codex/hooks.json"
CODEX_RULES="$HOME/.codex/rules/default.rules"
require_jq() {
if ! command -v jq >/dev/null 2>&1; then
echo "error: jq is required for safe settings.json editing" >&2
echo "install: brew install jq" >&2
exit 1
fi
}
require_go() {
if ! command -v go >/dev/null 2>&1; then
if [[ -x /opt/homebrew/bin/go ]]; then
export PATH="/opt/homebrew/bin:$PATH"
else
echo "error: go toolchain not found" >&2
echo "install: brew install go" >&2
exit 1
fi
fi
}
backup_file() {
local path="$1"
if [[ -f "$path" ]]; then
local ts
ts="$(date +%Y%m%d-%H%M%S)"
cp "$path" "$path.bak.$ts"
echo " backup: $path.bak.$ts"
fi
}
create_symlink() {
local hook_dir="$1"
if [[ -e "$hook_dir" && ! -L "$hook_dir" ]]; then
echo "error: $hook_dir exists and is not a symlink." >&2
echo " Move/remove it manually before installing." >&2
exit 1
fi
if [[ -L "$hook_dir" ]]; then
local current
current="$(readlink "$hook_dir")"
if [[ "$current" != "$REPO_SRC_DIR" ]]; then
echo " replacing existing symlink ($current -> $REPO_SRC_DIR)"
rm "$hook_dir"
else
# Explicit return 0 — without it, `return` inherits the exit
# status of the preceding `[[ ... ]]` test (1 when paths match)
# and `set -e` then kills the script silently.
return 0
fi
fi
mkdir -p "$(dirname "$hook_dir")"
ln -s "$REPO_SRC_DIR" "$hook_dir"
echo " linked: $hook_dir -> $REPO_SRC_DIR"
}
first_build() {
( cd "$REPO_SRC_DIR" && go build -o bash_guard.bin . )
echo " built: $REPO_SRC_DIR/bash_guard.bin"
}
# Build the JSON snippet for our hook entry. Mode determines env vars.
# Claude Code passes the command through `sh -c`, so env-var prefix works
# verbatim. We point directly at the .bin to avoid a wrapper layer that
# costs ~50 ms per invocation; rebuilds are explicit (`make build`).
hook_entry_json() {
local target="$1"
local adapter="$2"
local env_prefix="BASH_GUARD_ADAPTER=$adapter"
local entry
if [[ "$adapter" == "codex" && "$mode" == "live" && "$codex_native_prompts" == 1 ]]; then
env_prefix="$env_prefix BASH_GUARD_CODEX_DEFER_REASON_CODES=supabase.db_push"
fi
case "$mode" in
shadow) entry="{\"type\":\"command\",\"command\":\"$env_prefix BASH_GUARD_SHADOW=1 $target\",\"timeout\":30,\"statusMessage\":\"Checking Bash command\"}" ;;
dry-run) entry="{\"type\":\"command\",\"command\":\"$env_prefix BASH_GUARD_DRY_RUN=1 $target\",\"timeout\":30,\"statusMessage\":\"Checking Bash command\"}" ;;
live) entry="{\"type\":\"command\",\"command\":\"$env_prefix $target\",\"timeout\":30,\"statusMessage\":\"Checking Bash command\"}" ;;
esac
printf '%s' "$entry"
}
patch_claude_settings_install() {
require_jq
backup_file "$CLAUDE_SETTINGS"
[[ -f "$CLAUDE_SETTINGS" ]] || { mkdir -p "$(dirname "$CLAUDE_SETTINGS")"; echo '{}' > "$CLAUDE_SETTINGS"; }
local hook_entry
hook_entry="$(hook_entry_json '~/.claude/hooks/bash-guard/bash_guard.bin' claude)"
# 1. Make sure hooks.PreToolUse exists.
# 2. Find or create the {matcher: "Bash", hooks: [...]} block.
# 3. Drop any existing bash-guard entries (idempotent re-install) and
# append our current one.
local tmp
tmp="$(mktemp)"
jq --argjson entry "$hook_entry" '
.hooks //= {} |
.hooks.PreToolUse //= [] |
.hooks.PreToolUse |=
( map( if .matcher == "Bash" then
.hooks //= [] |
.hooks |= ( map(select((.command // "") | test("bash-guard") | not)) + [$entry] )
else . end ) ) |
# If no Bash matcher block existed at all, add a new one.
( if any(.hooks.PreToolUse[]?; .matcher == "Bash") then .
else .hooks.PreToolUse += [{"matcher":"Bash","hooks":[$entry]}] end )
' "$CLAUDE_SETTINGS" > "$tmp"
mv "$tmp" "$CLAUDE_SETTINGS"
echo " patched: $CLAUDE_SETTINGS"
}
patch_codex_hooks_install() {
require_jq
backup_file "$CODEX_HOOKS"
[[ -f "$CODEX_HOOKS" ]] || { mkdir -p "$(dirname "$CODEX_HOOKS")"; echo '{"hooks":{}}' > "$CODEX_HOOKS"; }
local hook_entry tmp
hook_entry="$(hook_entry_json '~/.codex/hooks/bash-guard/bash_guard.bin' codex)"
tmp="$(mktemp)"
jq --argjson entry "$hook_entry" '
.hooks //= {} |
.hooks.PreToolUse //= [] |
.hooks.PreToolUse |=
( map( if .matcher == "^Bash$" or .matcher == "Bash" then
.hooks //= [] |
.hooks |= ( map(select((.command // "") | test("bash-guard") | not)) + [$entry] ) |
.matcher = "^Bash$"
else . end ) ) |
( if any(.hooks.PreToolUse[]?; .matcher == "^Bash$" or .matcher == "Bash") then .
else .hooks.PreToolUse += [{"matcher":"^Bash$","hooks":[$entry]}] end )
' "$CODEX_HOOKS" > "$tmp"
mv "$tmp" "$CODEX_HOOKS"
echo " patched: $CODEX_HOOKS"
}
patch_codex_rules_install() {
mkdir -p "$(dirname "$CODEX_RULES")"
touch "$CODEX_RULES"
if grep -q 'bash-guard:begin supabase.db_push' "$CODEX_RULES"; then
echo " rule present: $CODEX_RULES"
return
fi
backup_file "$CODEX_RULES"
cat >> "$CODEX_RULES" <<'EOF'
# bash-guard:begin supabase.db_push
prefix_rule(
pattern=["supabase", "db", "push"],
decision="prompt",
justification="supabase db push pushes migrations to the remote database; require explicit approval before running.",
match=["supabase db push", "supabase db push --include-all"],
not_match=["supabase db reset --linked"],
)
# bash-guard:end supabase.db_push
EOF
echo " patched: $CODEX_RULES"
}
# Remove legacy shell-hook entries that bash-guard now supersedes.
# Files on disk are NOT deleted — only the settings.json references.
# Easy rollback: restore from $SETTINGS.bak.<timestamp>.
patch_settings_remove_legacy() {
require_jq
[[ -f "$CLAUDE_SETTINGS" ]] || return
local legacy_pattern='safety-net-ask|validate-rm|supabase-safety|bw-permission-check|docker-prune-permission|infra-safety'
local tmp
tmp="$(mktemp)"
jq --arg pat "$legacy_pattern" '
if .hooks.PreToolUse then
.hooks.PreToolUse |=
map( if .matcher == "Bash" then
.hooks |= map(select((.command // "") | test($pat) | not))
else . end )
else . end
' "$CLAUDE_SETTINGS" > "$tmp"
mv "$tmp" "$CLAUDE_SETTINGS"
echo " removed legacy shell-hook entries from $CLAUDE_SETTINGS"
}
patch_claude_settings_uninstall() {
require_jq
[[ -f "$CLAUDE_SETTINGS" ]] || return
backup_file "$CLAUDE_SETTINGS"
local tmp
tmp="$(mktemp)"
jq '
if .hooks.PreToolUse then
.hooks.PreToolUse |=
map( if .matcher == "Bash" then
.hooks |= map(select((.command // "") | test("bash-guard") | not))
else . end )
else . end
' "$CLAUDE_SETTINGS" > "$tmp"
mv "$tmp" "$CLAUDE_SETTINGS"
echo " removed bash-guard from $CLAUDE_SETTINGS"
}
patch_codex_hooks_uninstall() {
require_jq
[[ -f "$CODEX_HOOKS" ]] || return
backup_file "$CODEX_HOOKS"
local tmp
tmp="$(mktemp)"
jq '
if .hooks.PreToolUse then
.hooks.PreToolUse |=
map( if .matcher == "^Bash$" or .matcher == "Bash" then
.hooks |= map(select((.command // "") | test("bash-guard") | not))
else . end )
else . end
' "$CODEX_HOOKS" > "$tmp"
mv "$tmp" "$CODEX_HOOKS"
echo " removed bash-guard from $CODEX_HOOKS"
}
patch_codex_rules_uninstall() {
[[ -f "$CODEX_RULES" ]] || return
if ! grep -q 'bash-guard:begin supabase.db_push' "$CODEX_RULES"; then
return
fi
backup_file "$CODEX_RULES"
local tmp
tmp="$(mktemp)"
awk '
/# bash-guard:begin supabase.db_push/ { skip=1; next }
/# bash-guard:end supabase.db_push/ { skip=0; next }
!skip { print }
' "$CODEX_RULES" > "$tmp"
mv "$tmp" "$CODEX_RULES"
echo " removed bash-guard rule from $CODEX_RULES"
}
install_selected_agents() {
case "$agent" in
claude|both)
create_symlink "$CLAUDE_HOOK_DIR"
patch_claude_settings_install
if [[ "$replace_legacy" == 1 ]]; then
patch_settings_remove_legacy
fi
;;
esac
case "$agent" in
codex|both)
create_symlink "$CODEX_HOOK_DIR"
patch_codex_hooks_install
if [[ "$codex_native_prompts" == 1 ]]; then
patch_codex_rules_install
fi
;;
esac
}
uninstall_selected_agents() {
case "$agent" in
claude|both)
patch_claude_settings_uninstall
if [[ -L "$CLAUDE_HOOK_DIR" ]]; then
rm "$CLAUDE_HOOK_DIR"
echo " removed symlink: $CLAUDE_HOOK_DIR"
fi
;;
esac
case "$agent" in
codex|both)
patch_codex_hooks_uninstall
patch_codex_rules_uninstall
if [[ -L "$CODEX_HOOK_DIR" ]]; then
rm "$CODEX_HOOK_DIR"
echo " removed symlink: $CODEX_HOOK_DIR"
fi
;;
esac
}
case "$mode" in
shadow|dry-run|live)
echo "Installing bash-guard ($mode mode, agent: $agent)"
require_go
first_build
install_selected_agents
echo
echo "Done."
echo " Claude verify: jq '.hooks.PreToolUse' $CLAUDE_SETTINGS"
echo " Codex verify: jq '.hooks.PreToolUse' $CODEX_HOOKS"
echo " Selftest: $REPO_SRC_DIR/bash_guard.bin --selftest"
echo " Restart the agent. In Codex CLI/App, open /hooks and trust the new hook if prompted."
echo " Codex live mode is fail-closed by default; --codex-native-prompts enables experimental execpolicy prompts."
;;
uninstall)
echo "Uninstalling bash-guard (agent: $agent)"
uninstall_selected_agents
echo "Done."
;;
esac