Sitelet https://github.com/anomalyco/opencode/issues/28682
Skip to content

bash permission deny rules are ignored when *: ask is present #28682

Description

@LordTasama

Description

When configuring bash permissions with specific deny rules and a catch-all *: ask, the deny rules are not being applied. Commands that should be blocked are either passing silently or falling through to ask depending on rule order.

Plugins

None

OpenCode version

1.15.7

Steps to reproduce

  1. Set the following config in opencode.json:
{
  "$schema": "https://opencode.ai/config.json",
  "permission": {
    "bash": {
      "*": "ask",
      "git checkout": "deny",
      "git checkout *": "deny"
    }
  }
}
  1. Ask the agent to run: git checkout -- path_file_here
  2. The command executes without any prompt or denial.

Expected behavior:
The command should be blocked (deny) since git checkout * should match git checkout -- backend/db/schema.py.

Actual behavior:

  • With *: ask first and deny rules after → commands pass silently with no prompt
  • With deny rules first and *: ask last → commands trigger ask instead of deny, meaning *: ask wins over the specific deny rules

In both cases the deny rules are effectively ignored. The only workaround found is putting *: ask last, which protects against accidental execution but doesn't actually block commands as deny.

Screenshot and/or share link

No response

Operating System

Windows 11

Terminal

Windows PowerShell

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions