# nash operator policy (docs/NASH.md §4.3) — baked into the narOS image. # # nash reads its levers ONLY from this file. They used to live in the environment # (NUCLEIC_NASH_DISABLE, NUCLEIC_REAL_BASH), which meant the process nash exists to # observe could turn that observation off in one word, silently. This file is root-owned # and not group/other-writable; nash checks that ownership before honoring a single line, # so an agent-created copy is ignored. # # Nucleic rewrites this file when it starts a container, carrying the `legacyShell` # rollback lever into `disable`. Editing it by hand is an operator action. # Observation may not be switched off by the observed process: a shell whose transport # env has been stripped, or which was handed NUCLEIC_SHELL_CAPTURE=off, still records and # spools to /var/spool/nucleic-nash for the drain. require_observation=1 # Exec target for the parse-failure fallback and the break-glass below. real_bash=/usr/bin/bash.real # Break-glass (NASH.md §4.1): 1 makes nash re-exec the real bash with identical argv. # The one lever that turns the agent shell off, and it lives here precisely so that an # agent cannot reach it. disable=0