Skip to main content

Agent

Enum Agent 

Source
pub enum Agent {
    ClaudeCode,
    Codex,
    Droid,
    Copilot,
    Pi,
}
Expand description

Which agent to run, by name.

It used to be a free argv, and that was the wrong shape. The grouping stage does not merely spawn a process: it hands the agent a tool allowlist, a fetch command and a prompt written for what that agent can do (ADR 0022). An arbitrary argv gets the prompt and none of the rest, so it was a knob that looked like it worked. A name selects an invocation this crate builds whole, and adding an agent is adding a variant here.

The name also answers what a reviewer is shown while they wait — the argv never could, at four times the width of the line it had.

Four of the five keep the model read-only; Pi does not (ADR 0033). Read Agent::read_only and ReadOnly::is_enforced before choosing one.

Variants§

§

ClaudeCode

Headless claude, read-only by tool allowlist (ADR 0022).

§

Codex

Headless codex exec, read-only by OS sandbox (Seatbelt, bubblewrap).

§

Droid

Headless droid exec, read-only by default — the tier is what we do not pass.

§

Copilot

Headless copilot, read-only by tool allowlist and an explicit deny.

§

Pi

Headless pi, read-only is NOT enforced (ADR 0033).

Pi ships no sandbox and no per-command allowlist, and its -t flag toggles whole tools. The model needs bash to run the fetch command and git diff, and bash also lets it write, commit and push. Nothing but the prompt stops it. Choose this agent only knowing that.

Implementations§

Source§

impl Agent

Source

pub const ALL: &'static [Agent] = <Agent as strum::VariantArray>::VARIANTS

Every variant, in declaration order, from strum’s VariantArray: the derive is what keeps the list whole, so there is no hand-kept array to forget a variant in.

Source

pub fn key(self) -> &'static str

The name this answers to in the config file. strum’s IntoStaticStr, renamed as serde renames it; every_*_name_round_trips in this module pins the two derives to the same spelling.

Source

pub fn proven(self) -> bool

Whether anyone has ever run this agent’s command line.

Not a quality judgement — a claim about provenance, and the only honest one this crate can make. Every argv here is written from its agent’s documentation, and a test can assert the string this crate builds but never that the CLI on the other end accepts it. CI cannot either: the binary is not installed and its flags move between releases.

true means dfr agents --probe passed all four checks against the real CLI, and the argv is in this repository because of that run.

false means likely wrong, not merely unchecked. Of the three checked so far, two were broken: Claude Code’s allowlist did not bind without --permission-mode default, and Codex was passing --ask-for-approval, which its exec subcommand rejects outright. Both came from documentation that was accurate about the product and wrong about the entry point. Nothing suggests the unchecked two are better.

A caller that offers a user this list must say so, for the same reason it must say what Agent::read_only answers: the person choosing is the person who carries it.

This flips when someone runs the probe and the argv lands — never because it looks right.

Source

pub fn read_only(self) -> ReadOnly

What stops this agent writing, if anything.

A caller that shows a user the list of agents MUST show this too. The person picking a name is the person who needs to know, and exactly one answer here is ReadOnly::NotEnforced.

Trait Implementations§

Source§

impl Clone for Agent

Source§

fn clone(&self) -> Self

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Copy for Agent

Source§

impl Debug for Agent

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Default for Agent

Source§

fn default() -> Self

Returns the “default value” for a type. Read more
Source§

impl<'de> Deserialize<'de> for Agent

Source§

fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>
where __D: Deserializer<'de>,

Deserialize this value from the given Serde deserializer. Read more
Source§

impl Eq for Agent

Source§

impl<'_derivative_strum> From<&'_derivative_strum Agent> for &'static str

Source§

fn from(x: &'_derivative_strum Agent) -> &'static str

Converts to this type from the input type.
Source§

impl From<Agent> for &'static str

Source§

fn from(x: Agent) -> &'static str

Converts to this type from the input type.
Source§

impl PartialEq for Agent

Source§

fn eq(&self, other: &Self) -> bool

Equality operator ==. Read more
1.0.0 (const: unstable) · Source§

fn ne(&self, other: &Rhs) -> bool

Inequality operator !=. Read more
Source§

impl Serialize for Agent

Source§

fn serialize<__S>(&self, __serializer: __S) -> Result<__S::Ok, __S::Error>
where __S: Serializer,

Serialize this value into the given Serde serializer. Read more
Source§

impl StructuralPartialEq for Agent

Source§

impl VariantArray for Agent

Source§

const VARIANTS: &'static [Self]

Auto Trait Implementations§

§

impl Freeze for Agent

§

impl RefUnwindSafe for Agent

§

impl Send for Agent

§

impl Sync for Agent

§

impl Unpin for Agent

§

impl UnsafeUnpin for Agent

§

impl UnwindSafe for Agent

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> DeserializeOwned for T
where T: for<'de> Deserialize<'de>,

Source§

impl<Q, K> Equivalent<K> for Q
where Q: Eq + ?Sized, K: Borrow<Q> + ?Sized,

Source§

fn equivalent(&self, key: &K) -> bool

Checks if this value is equivalent to the given key. Read more
Source§

impl<Q, K> Equivalent<K> for Q
where Q: Eq + ?Sized, K: Borrow<Q> + ?Sized,

Source§

fn equivalent(&self, key: &K) -> bool

Compare self to key and return true if they are equal.
Source§

impl<Q, K> Equivalent<K> for Q
where Q: Eq + ?Sized, K: Borrow<Q> + ?Sized,

Source§

fn equivalent(&self, key: &K) -> bool

Checks if this value is equivalent to the given key. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.