3 ms·
Does that work? I've never seen it used. It seems easy to escape. The docs seem to suggest using alternate approaches. > Modern systems provide more secure wa
by 8organicbits 3mo ago
Does that work? I've never seen it used. It seems easy to escape.
The docs seem to suggest using alternate approaches.
> Modern systems provide more secure ways to implement a restricted environment, such as jails, zones, or containers.
https://www.gnu.org/software/bash/manual/html_node/The-Restricted-Shell.html https://www.gnu.org/software/bash/manual/html_node/The-Restr...
- SoftTalker 3mo agoI don't think I've ever seen it used. I think the idea was back in the day when you wanted to let a user have a shell login (because that's the only way you could use a shared computer) but wanted to confine them to a specific directory and prevent them running anything that wasn't in the pre-defined PATH that you set for them.
- ryoshu 3mo agoCan't you do that with regular Unix permissions?
- tingletech 3mo agoYou could also produce special purpose applications this way, say to provide access to the online library catalog, or a run a gopher client for use in a public terminal lab. Telnetting to a unix account running some sort of restricted shell was how these often worked. A sibling comment I can't reply to asks if you can do with with unix permissions. These were really intended for anonymous guest access, or at least often used for this purpose. You couldn't do the same things with the file permissions systems at the time.
- 4ndrewl 3mo agoBack in the day we'd use chroot to achieve something similar https://linux.die.net/man/1/chroot https://linux.die.net/man/1/chroot
- SoftTalker 3mo agoYes, in reality you might use chroot, limited filesystem permissions, and a restricted shell as a belt-and-suspenders approach.
- AdieuToLogic 3mo ago>> bash actually has a "restricted" mode ... > Does that work? I've never seen it used. It seems easy to escape. Yes, it does work for its intended purpose. It has often been used in combination with chroot[0] as well. > The docs seem to suggest using alternate approaches. >> Modern systems provide more secure ways to implement a restricted environment, such as jails, zones, or containers. These approaches are not mutually exclusive with restricted shell use. For example, one could use FreeBSD jails to secure Apache httpd and/or Nginx and still employ a restricted shell to evaluate requests. 0 - https://man.freebsd.org/cgi/man.cgi?query=chroot&apropos=0&sektion=0&manpath=FreeBSD+15.1-RELEASE+and+Ports.quarterly&format=html https://man.freebsd.org/cgi/man.cgi?query=chroot&apropos=0&s...
- 8organicbits 3mo agoI'm seeing a ton of restricted mode escapes documented online, like https://0xffsec.com/handbook/shells/restricted-shells/ https://0xffsec.com/handbook/shells/restricted-shells/ so I'm not so sure. When basic utilities like less, man, and awk can run subshells it's quite a mess. Bash restricted mode needing a chroot may suggest that Claude also needs a chroot (or restricted file permissions, jail, etc).
- AdieuToLogic 3mo ago> Bash restricted mode needing a chroot may suggest that Claude also needs a chroot (or restricted file permissions, jail, etc). I believe running coding agents within a jail/container is a "best practice" to limit their blast radius. At least, this is what people I respect have conveyed to me.