Modes
A session runs in one mode, set by permissions.mode in
configuration: ask, allowEdits or
fullAccess. Nothing set means ask. Only ~/.crucible/config.json may set
it: a workspace file that does is refused at startup, because a mode only ever
loosens what runs without asking. That is where a session starts rather
than what it stays at: Shift-Tab steps it while you type, and
/mode names one outright.
A mode decides exactly one thing: what happens to a call no
rule mentions. It is never a way around the engine. Every call
takes the same route to running whatever the mode, a deny or ask rule
holds in every one, and a read inside the workspace runs in every one.
| A call that would… | ask | allowEdits | fullAccess |
|---|---|---|---|
| read | run | run | run |
| read outside the workspace | ask | ask | run |
| change a file | ask | run | run |
| run a program | ask | ask | run |
| reach the web | ask | ask | run |
allowEdits means what its name says: write and edit change files without
asking, and anything that starts a process or leaves the machine asks. Reaching
the web is not an edit; it is the one thing whose effect is not on this
computer, and the one that cannot be undone from here. It is for the stretch
of work where being interrupted per edit costs more than the edits do.
fullAccess asks about nothing, which makes a deny rule the only thing that
can say no there. Write those first.
Why allowEdits still asks before a command
bash runs a shell, and a shell reaches whatever you can. crucible reads the
line closely enough to say what will run, which is what lets a rule
be written about it, but reading is not containment. Whatever a word in the
line was found to point at, the shell looks it up again by name when the command
runs, and a symbolic link put at that name in between sends the change somewhere
else, with nobody asked.
The file tools have no such gap. They keep hold of the directory the path was
proved under and never look the name up a second time, which is what
containment is measured
by. sh cannot be made to work that way, so the mode that runs a command
without a question is fullAccess, and there is no other.
That leaves allowEdits as one sentence, which is the whole of what it is for:
the tools that change files change them, and anything that starts a process is
put to you. Standing permission for a command you run all day is an
allow rule in ~/.crucible/config.json, written down where you can
read it back and take it away again.
The mode is always on screen
The row under the prompt box says which one is in force (ask mode on,
allow edits on, full access mode on) every time, not once at the top.
Hours in, when the opening lines have scrolled away, which mode a session is in
must not depend on what you remember starting. That row is drawn in the mode's
colour; the box's border keeps one colour whatever the mode, because a border
that large painted in a warning hue stops reading as a warning by the second
prompt.
Stepping it while you type
Shift-Tab steps to the next mode and wraps round: ask, then
allowEdits, then fullAccess, then ask again. The row under the box says
which mode that landed in, in that mode's colour, and the same key
steps out again: a mode reached by one key is left by two more.
While a prompt is being typed, every step takes effect on the press, and it is the next call that is decided under it. While a turn is running, a step is held for the turn that starts after: the turn in flight was decided under the mode that was on screen when it began, and nothing about it is reopened mid-turn. So no call is ever decided under a mode other than the one that was on screen when its turn started. The step you make over a running turn is the mode the next one runs under, and it is in force the moment the running turn ends, so the row between turns shows it and a step made there moves on from it.
A step changes one thing and no others. The rules you wrote hold exactly as they did, and anything already allowed for the session stays allowed.
Naming the one you want
/mode allowEdits puts the session in that mode outright, spelled the way
configuration spells it. It is the same
change under the same conditions: between turns, nothing else about the
session moving.
/mode on its own says which one is in force and lists the three to choose
from. A word that names none of them is refused, and the session stays where it
was.
When nobody can answer
When input has ended (a prompt piped in, a closed terminal), a question has
nobody to answer it, and an unanswerable question is a refusal. There is no
deny-by-default mode to select because this is not a choice; it is what asking
means with nobody there. A non-interactive run that must proceed says so
explicitly, with allow rules or with fullAccess.
--continue resumes the transcript, not the mode
The mode is read from configuration at every start. Continuing a session picks up its transcript; it does not pick up the mode the session last ran in (a step made with Shift-Tab included), nor a session-long allow, which lives only as long as the process it was made in.
A durable allow rule in ~/.crucible/config.json is read again on
the next start. Crucible does not write one from a permission question: either
workspace filename can be committed, so neither is a trusted place to remember
authority for one checkout.