pub enum SafetyMode {
Plan,
ReadOnly,
Ask,
Auto,
FullAccess,
}Variants§
Plan
A plan is being drafted: a read-only floor plus the plan-mode
carve-outs the policy gate layers on (the plan file is writable,
[plan] permissions may re-open memory/builds/web).
Plan is a MODE, not a flag alongside one. It used to be a separate
Session.plan: Option<_> orthogonal to safety_mode, which meant the
two could disagree: Shift+Tab while planning set full_access and the
harness then told the model “safety mode changed to full_access” while
the plan read-only floor was still in force — a contradiction the model
resolved by attempting mutations and collecting denials. With one mode
value that state is unrepresentable. Session.plan still carries the
plan DATA (path, saved overrides), never the fact of being in plan mode.
ReadOnly
Ask
Auto
FullAccess
Implementations§
Source§impl SafetyMode
impl SafetyMode
Sourcepub fn as_str(self) -> &'static str
pub fn as_str(self) -> &'static str
Canonical serialized name — matches the serde snake_case rename.
Sourcepub fn parse(s: &str) -> Option<SafetyMode>
pub fn parse(s: &str) -> Option<SafetyMode>
Parse a canonical mode name. Accepts ONLY the canonical snake_case
names — no legacy aliases (the old "auto_review" is gone).
Sourcepub fn is_planning(self) -> bool
pub fn is_planning(self) -> bool
Is a plan being drafted? The single source of truth — never infer this
from Session.plan, which is the plan’s DATA and outlives nothing.
Sourcepub fn permissiveness(self) -> u8
pub fn permissiveness(self) -> u8
Permissiveness rank for combining modes: plan/read_only are strictest, full_access loosest. Plan ranks below read-only because its carve-outs only ever open paths the gate re-checks, and a subagent must never inherit “planning” as a ceiling (children explore, they don’t plan).
Sourcepub fn least_permissive(a: SafetyMode, b: SafetyMode) -> SafetyMode
pub fn least_permissive(a: SafetyMode, b: SafetyMode) -> SafetyMode
The stricter of two modes. Used to apply an agent type’s safety ceiling to a session’s live mode — a ceiling can only tighten what the parent already allows, never loosen it.
Trait Implementations§
Source§impl Clone for SafetyMode
impl Clone for SafetyMode
Source§fn clone(&self) -> SafetyMode
fn clone(&self) -> SafetyMode
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read moreimpl Copy for SafetyMode
Source§impl Debug for SafetyMode
impl Debug for SafetyMode
Source§impl Default for SafetyMode
impl Default for SafetyMode
Source§fn default() -> SafetyMode
fn default() -> SafetyMode
Source§impl<'de> Deserialize<'de> for SafetyMode
impl<'de> Deserialize<'de> for SafetyMode
Source§fn deserialize<__D>(
__deserializer: __D,
) -> Result<SafetyMode, <__D as Deserializer<'de>>::Error>where
__D: Deserializer<'de>,
fn deserialize<__D>(
__deserializer: __D,
) -> Result<SafetyMode, <__D as Deserializer<'de>>::Error>where
__D: Deserializer<'de>,
impl Eq for SafetyMode
Source§impl PartialEq for SafetyMode
impl PartialEq for SafetyMode
Source§impl Serialize for SafetyMode
impl Serialize for SafetyMode
Source§fn serialize<__S>(
&self,
__serializer: __S,
) -> Result<<__S as Serializer>::Ok, <__S as Serializer>::Error>where
__S: Serializer,
fn serialize<__S>(
&self,
__serializer: __S,
) -> Result<<__S as Serializer>::Ok, <__S as Serializer>::Error>where
__S: Serializer,
impl StructuralPartialEq for SafetyMode
Auto Trait Implementations§
impl Freeze for SafetyMode
impl RefUnwindSafe for SafetyMode
impl Send for SafetyMode
impl Sync for SafetyMode
impl Unpin for SafetyMode
impl UnsafeUnpin for SafetyMode
impl UnwindSafe for SafetyMode
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> DeserializeOwned for Twhere
T: for<'de> Deserialize<'de>,
Source§impl<T> Downcast for Twhere
T: Any,
impl<T> Downcast for Twhere
T: Any,
Source§fn into_any(self: Box<T>) -> Box<dyn Any>
fn into_any(self: Box<T>) -> Box<dyn Any>
Box<dyn Trait> (where Trait: Downcast) to Box<dyn Any>. Box<dyn Any> can
then be further downcast into Box<ConcreteType> where ConcreteType implements Trait.Source§fn into_any_rc(self: Rc<T>) -> Rc<dyn Any>
fn into_any_rc(self: Rc<T>) -> Rc<dyn Any>
Rc<Trait> (where Trait: Downcast) to Rc<Any>. Rc<Any> can then be
further downcast into Rc<ConcreteType> where ConcreteType implements Trait.Source§fn as_any(&self) -> &(dyn Any + 'static)
fn as_any(&self) -> &(dyn Any + 'static)
&Trait (where Trait: Downcast) to &Any. This is needed since Rust cannot
generate &Any’s vtable from &Trait’s.Source§fn as_any_mut(&mut self) -> &mut (dyn Any + 'static)
fn as_any_mut(&mut self) -> &mut (dyn Any + 'static)
&mut Trait (where Trait: Downcast) to &Any. This is needed since Rust cannot
generate &mut Any’s vtable from &mut Trait’s.Source§impl<T> DowncastSync for T
impl<T> DowncastSync for T
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§fn equivalent(&self, key: &K) -> bool
fn equivalent(&self, key: &K) -> bool
key and return true if they are equal.Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self>
fn instrument(self, span: Span) -> Instrumented<Self>
Source§fn in_current_span(self) -> Instrumented<Self>
fn in_current_span(self) -> Instrumented<Self>
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self>
fn into_either(self, into_left: bool) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more