pub enum SafetyMode {
Plan,
ReadOnly,
Ask,
Auto,
FullAccess,
}Variants§
Plan
A plan is being drafted: a read-only floor plus the plan-mode
carve-outs the policy gate layers on (the plan file is writable,
[plan] permissions may re-open memory/builds/web).
Plan is a MODE, not a flag alongside one, and it is a full position in
the Shift+Tab cycle — the strictest one. It used to be a separate
Session.plan: Option<_> orthogonal to safety_mode, which meant the
two could disagree: Shift+Tab while planning set full_access and the
harness then told the model “safety mode changed to full_access” while
the plan read-only floor was still in force — a contradiction the model
resolved by attempting mutations and collecting denials. With one mode
value that state is unrepresentable. Session.plan still carries the
plan DATA (path, saved overrides), never the fact of being in plan mode,
and it never carries a mode to “restore”: leaving plan means picking
another mode, like leaving any other.
ReadOnly
Ask
Auto
FullAccess
Implementations§
Source§impl SafetyMode
impl SafetyMode
Sourcepub fn as_str(self) -> &'static str
pub fn as_str(self) -> &'static str
Canonical serialized name — matches the serde snake_case rename.
Sourcepub fn parse(s: &str) -> Option<SafetyMode>
pub fn parse(s: &str) -> Option<SafetyMode>
Parse a canonical mode name. Accepts ONLY the canonical snake_case
names — no legacy aliases (the old "auto_review" is gone).
Sourcepub fn is_planning(self) -> bool
pub fn is_planning(self) -> bool
Is a plan being drafted? The single source of truth — never infer this
from Session.plan, which is the plan’s DATA and outlives nothing.
Sourcepub fn permissiveness(self) -> u8
pub fn permissiveness(self) -> u8
Permissiveness rank for combining modes: plan/read_only are strictest,
full_access loosest. Plan ranks below read-only because its carve-outs
only ever open paths the gate re-checks, and a subagent must never
inherit “planning” as a ceiling (children explore, they don’t plan).
Sourcepub fn least_permissive(a: SafetyMode, b: SafetyMode) -> SafetyMode
pub fn least_permissive(a: SafetyMode, b: SafetyMode) -> SafetyMode
The stricter of two modes. Used to apply an agent type’s safety ceiling to a session’s live mode — a ceiling can only tighten what the parent already allows, never loosen it.
Trait Implementations§
Source§impl Clone for SafetyMode
impl Clone for SafetyMode
Source§fn clone(&self) -> SafetyMode
fn clone(&self) -> SafetyMode
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read more