Augments LabsCrucible Code

Modes

A session runs in one mode, set by permissions.mode in configuration: ask, allowEdits or fullAccess. Nothing set means ask. Only ~/.crucible/config.json may set it: a workspace file that does is refused at startup, because a mode only ever loosens what runs without asking. That is where a session starts rather than what it stays at: Shift-Tab steps it while you type, and /mode names one outright.

A mode decides exactly one thing: what happens to a call no rule mentions. It is never a way around the engine. Every call takes the same route to running whatever the mode, a deny or ask rule holds in every one, and a read inside the workspace runs in every one.

A call that would…askallowEditsfullAccess
readrunrunrun
read outside the workspaceaskaskrun
change a fileaskrunrun
run a programaskaskrun
reach the webaskaskrun

allowEdits means what its name says: write and edit change files without asking, and anything that starts a process or leaves the machine asks. Reaching the web is not an edit; it is the one thing whose effect is not on this computer, and the one that cannot be undone from here. It is for the stretch of work where being interrupted per edit costs more than the edits do. fullAccess asks about nothing, which makes a deny rule the only thing that can say no there. Write those first.

Why allowEdits still asks before a command

bash runs a shell, and a shell reaches whatever you can. crucible reads the line closely enough to say what will run, which is what lets a rule be written about it, but reading is not containment. Whatever a word in the line was found to point at, the shell looks it up again by name when the command runs, and a symbolic link put at that name in between sends the change somewhere else, with nobody asked.

The file tools have no such gap. They keep hold of the directory the path was proved under and never look the name up a second time, which is what containment is measured by. sh cannot be made to work that way, so the mode that runs a command without a question is fullAccess, and there is no other.

That leaves allowEdits as one sentence, which is the whole of what it is for: the tools that change files change them, and anything that starts a process is put to you. Standing permission for a command you run all day is an allow rule in ~/.crucible/config.json, written down where you can read it back and take it away again.

The mode is always on screen

The row under the prompt box says which one is in force (ask mode on, allow edits on, full access mode on) every time, not once at the top. Hours in, when the opening lines have scrolled away, which mode a session is in must not depend on what you remember starting. That row is drawn in the mode's colour; the box's border keeps one colour whatever the mode, because a border that large painted in a warning hue stops reading as a warning by the second prompt.

Stepping it while you type

Shift-Tab steps to the next mode and wraps round: ask, then allowEdits, then fullAccess, then ask again. The row under the box says which mode that landed in, in that mode's colour, and the same key steps out again: a mode reached by one key is left by two more.

While a prompt is being typed, every step takes effect on the press, and it is the next call that is decided under it. While a turn is running, a step is held for the turn that starts after: the turn in flight was decided under the mode that was on screen when it began, and nothing about it is reopened mid-turn. So no call is ever decided under a mode other than the one that was on screen when its turn started. The step you make over a running turn is the mode the next one runs under, and it is in force the moment the running turn ends, so the row between turns shows it and a step made there moves on from it.

A step changes one thing and no others. The rules you wrote hold exactly as they did, and anything already allowed for the session stays allowed.

Naming the one you want

/mode allowEdits puts the session in that mode outright, spelled the way configuration spells it. It is the same change under the same conditions: between turns, nothing else about the session moving.

/mode on its own says which one is in force and lists the three to choose from. A word that names none of them is refused, and the session stays where it was.

When nobody can answer

When input has ended (a prompt piped in, a closed terminal), a question has nobody to answer it, and an unanswerable question is a refusal. There is no deny-by-default mode to select because this is not a choice; it is what asking means with nobody there. A non-interactive run that must proceed says so explicitly, with allow rules or with fullAccess.

--continue resumes the transcript, not the mode

The mode is read from configuration at every start. Continuing a session picks up its transcript; it does not pick up the mode the session last ran in (a step made with Shift-Tab included), nor a session-long allow, which lives only as long as the process it was made in.

A durable allow rule in ~/.crucible/config.json is read again on the next start. Crucible does not write one from a permission question: either workspace filename can be committed, so neither is a trusted place to remember authority for one checkout.