Skip to main content

ShellEnvMode

Enum ShellEnvMode 

Source
pub enum ShellEnvMode {
    Filtered,
    Strict,
    Custom,
    Inherit,
}
Expand description

How much of the daemon’s environment a shell tool inherits.

A fourth question again, and a fourth shape. A shell tool is a child we hand over to, like an MCP server - but unlike one, it must keep behaving like the user’s own shell, so child_env_allowed’s 28-name allowlist is wrong here: it would strip CARGO_HOME, JAVA_HOME, NVM_DIR, VIRTUAL_ENV, GOPATH and break every real toolchain. The name-shape denylist is the right instrument, and the only real question is how far it reaches.

Be honest about what this buys. With cat and grep on the default safe list, a granted shell can read ~/.leviath/config.toml and find the provider key anyway. This is defence in depth against accidental leakage - an env dump in tool output, a printenv in a log, a subprocess that phones home - and it closes the seed-command case, where nothing was ever approved. It is not a boundary.

Variants§

§

Filtered

Withhold credential-shaped names, but hand over SSH_AUTH_SOCK.

The carve-out is deliberate and is why this can be the default: the agent socket is on the credential-name list, and withholding it breaks git push over agent keys, which is one of the most ordinary things an agent does in a shell.

§

Strict

The full name-shape denylist, SSH_AUTH_SOCK included - and with it AWS_PROFILE, AWS_REGION, KUBECONFIG, NETRC. Breaks git push, aws and kubectl in a shell tool until those names are listed in [security] allow_env_vars.

§

Custom

Ignore the shape heuristic entirely: withhold exactly what [security] shell_env_withhold names, and nothing else. For an environment whose variable names the heuristic reads wrong in either direction.

§

Inherit

Hand the whole environment over, as before this setting existed.

Trait Implementations§

Source§

impl Clone for ShellEnvMode

Source§

fn clone(&self) -> ShellEnvMode

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Copy for ShellEnvMode

Source§

impl Debug for ShellEnvMode

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Default for ShellEnvMode

Source§

fn default() -> ShellEnvMode

Returns the “default value” for a type. Read more
Source§

impl<'de> Deserialize<'de> for ShellEnvMode

Source§

fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>
where __D: Deserializer<'de>,

Deserialize this value from the given Serde deserializer. Read more
Source§

impl Eq for ShellEnvMode

Source§

impl PartialEq for ShellEnvMode

Source§

fn eq(&self, other: &ShellEnvMode) -> bool

Equality operator ==. Read more
1.0.0 (const: unstable) · Source§

fn ne(&self, other: &Rhs) -> bool

Inequality operator !=. Read more
Source§

impl Serialize for ShellEnvMode

Source§

fn serialize<__S>(&self, __serializer: __S) -> Result<__S::Ok, __S::Error>
where __S: Serializer,

Serialize this value into the given Serde serializer. Read more
Source§

impl StructuralPartialEq for ShellEnvMode

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> DeserializeOwned for T
where T: for<'de> Deserialize<'de>,

Source§

impl<Q, K> Equivalent<K> for Q
where Q: Eq + ?Sized, K: Borrow<Q> + ?Sized,

Source§

fn equivalent(&self, key: &K) -> bool

Checks if this value is equivalent to the given key. Read more
Source§

impl<Q, K> Equivalent<K> for Q
where Q: Eq + ?Sized, K: Borrow<Q> + ?Sized,

Source§

fn equivalent(&self, key: &K) -> bool

Compare self to key and return true if they are equal.
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more