1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
//! **The fail-closed lane** (bl-72bd, ruling 2 of the round-1 triage): what
//! this control answers for a name the intrinsic map does not hold.
//!
//! Almost every such name today is a **routed** one — a tool a registered
//! machine advertises, presented to the model host-qualified (`box2_shell`,
//! REMOTE §5) and executed on that machine. The rest is anything a later
//! litany adds. Neither is a name this control implements, and the answer for
//! both is the same:
//!
//! 1. **An input carrying a command line is classified by that command line,
//! exactly as the engine's own `bash` is.** A foot's shell is a shell. The
//! field is `command` — the one the engine's `bash` reads and the one every
//! thrall tool schema of that shape declares — so the two spellings have one
//! home and cannot drift.
//! 2. **Everything else is the class the operator STATED for that name, and
//! otherwise [`Opaque`](Effect::Opaque)**, which the shipped table holds. A
//! tool whose reach this control cannot read is parked for the operator,
//! never passed.
//!
//! **The row is how a nameable tool stops being opaque** (bl-b65d). An MCP tool
//! reaches this control as a routed name with an input shaped by its server's
//! schema — `box2_fetch {"url": …}` — so there is no command line to read and
//! every call of it holds. The way out is a `rules:` row keyed on the whole
//! host-qualified name:
//!
//! ```yaml
//! rules:
//! box2_fetch: open-world
//! ```
//!
//! Host-qualified because the same server on two boxes is two trust decisions
//! (REMOTE §5: locality rides in the name). The class is the **operator's own
//! statement** of what that tool on that box reaches — informed by what `thrall
//! mcp pin` printed of the server's annotations, and by nothing the wire
//! carries: an advertisement states no effect (REMOTE §5.1) and this control
//! infers none from one. That is why only the operator's rows are consulted and
//! the shipped ruleset is not ([`Policy::stated`](super::super::policy::Policy::stated)),
//! and why a row does not outrank a shell's own line — a name row is asked only
//! where there is no line to read. It is a class the operator states,
//! adjudicated per invocation, never a name allowed (bl-7fc8 stands).
//!
//! **The hold says so.** The opaque sentence names the row to write, spelled
//! with the actual name and the class words the file accepts, because a park
//! whose remedy the operator has to go and find is a park they answer by
//! reflex — the `NOT_A_REMEDY` discipline of bl-68e1, from the other direction.
//!
//! **Why the old answer was backwards.** The arm this replaces was
//! `other => OpenWorld`, and the shipped table passes open-world — so
//! `box2_shell {"command": "find /srv/data/blobs -delete"}` was passed without
//! a word while the identical line through the engine's own `bash` classified
//! destructive and was refused. The control was strictest about the machine
//! the operator is sitting at and blind about the remote boxes a foot exists
//! to administer, which is the leg whose blast radius the operator cannot see.
//!
//! **The command line is read against the LOCAL writable root, and that is the
//! point.** A `ByRoot` row resolves its operands against the agent's own
//! worktree, which is on the server; a path on the foot's machine is not in it
//! and classifies to the wider class. Ruling 2 says a routed shell is
//! classified by its command line *exactly as* the engine's bash is, and this
//! is what that costs and what it buys: the same table, and a bias toward the
//! wider class on the leg the adjudicator cannot see into (REMOTE §5's honesty
//! clause).
//!
//! **The operator can undo it in one line, which is what keeps it severable**
//! (DESIGN §8.6): a workspace that wants the old behaviour writes `table:` /
//! ` opaque: pass` into its `capability.yaml`. Absence stays the shipped
//! default, and the shipped default is now the closed one.
use ;
use ;
/// Classify one invocation of a name the intrinsic map does not hold.
pub
/// The writable root **as it stands on the other machine**: empty (bl-1772).
///
/// The doc above has always said a path on the foot classifies to the wider
/// class, and for an *absolute* operand it did. A **relative** one did not: the
/// lexer resolves it against the agent's own cwd, which is the engine's
/// worktree and inside the root — so `cd /srv/data/blobs && rm -f -- *` read as
/// `rm` on a bare `*` inside the writable root and classified target write,
/// while the identical `rm -f /srv/data/blobs/*` classified destructive. The
/// model found that spelling in three steps and deleted 115 MB from a machine
/// the operator was never asked about.
///
/// The reframe is that the special case was the root itself. **This control
/// vouches for no path on a foot**, absolute or relative, so the routed leg's
/// writable set is empty and every `ByRoot` row takes its `outside` class. A
/// `cd` chain then classifies exactly as the direct form, because both are
/// judged against the same nothing — no modelling of `cd`, no glob expansion,
/// and no new arm for either. `cwd` and `home` are kept so an operand still
/// resolves to a path a reason line can name.
/// The class the **operator stated** for this routed name, or the opaque hold
/// that says how to state one (bl-b65d).