deepseek-harness/docs
kingwl 1fe2f99580 refactor(mode): drop the per-mode tool allowlist — enforce where an enforcer exists
A ModeDefinition is now exactly { section, access? }; unknown keys (a
tools list included) fail loud at load. What plan mode still does: the
guidance section, the exit_plan_mode visibility rule (plan only, both
soft surfaces), the access cap's bash/resolve-mode clamp, and the two
cap-derived pre-execute guards (the bash trio is withheld when no
confining executor can honor the cap; sandbox escalation is denied
while it holds). The general deny-by-default gate and the assemble
allowlist filter are gone: which tools a mode admits is an effects
question, and a hand-maintained name list mislabels it — it must track
every composed tool and rots silently as tools arrive. The dimension
returns as a consumer of effects self-declaration on tool definitions
(MCP ToolAnnotations as the template) — rationale and restart trigger
archived in the RFC's Alternatives/Deferred; the interim guidance-only
non-shell restraint is priced in Consequences.

Exiting plan is now a pure removal (the exit tool + section), which the
delta encoding CAN express: the re-recorded plan-mode fixture pins one
plan-shaped initial header snapshot plus one header-delta instead of
two snapshots.
2026-07-12 23:20:36 +08:00
..
cookbook refactor(mode): drop the per-mode tool allowlist — enforce where an enforcer exists 2026-07-12 23:20:36 +08:00
cordis-catalog refactor(mode): drop the per-mode tool allowlist — enforce where an enforcer exists 2026-07-12 23:20:36 +08:00
core-data-structures Merge remote-tracking branch 'origin/master' into codex/skill-system 2026-07-11 22:31:28 +08:00
i18n docs: equal-authority pairing with sidecar consistency records 2026-07-03 07:41:24 -07:00
postmortem fix(docs): address Codex review round 3 — last three moved-policy citations 2026-07-04 16:02:39 +08:00
rfc refactor(mode): drop the per-mode tool allowlist — enforce where an enforcer exists 2026-07-12 23:20:36 +08:00
agent-lifecycle.md docs: address graph review placement 2026-07-05 02:54:01 +08:00
AGENTS.md make wordcount budget guidance clearer and dedup docs 2026-07-10 00:20:35 +08:00
architecture.md Merge branch 'worktree-session-modes-rfc' (master: sandbox stack #169, skills #109, prompt snapshots #254) 2026-07-12 20:08:09 +08:00
capability-seams.md Merge branch 'worktree-session-modes-rfc' (master: sandbox stack #169, skills #109, prompt snapshots #254) 2026-07-12 20:08:09 +08:00
config-catalog.md refactor(mode): drop the per-mode tool allowlist — enforce where an enforcer exists 2026-07-12 23:20:36 +08:00
cordis-primer.md a human touch 2026-07-09 23:48:29 +08:00
defensive-patterns.md docs(AGENTS): rewrite the root standing orders to the 1,500-word budget 2026-07-04 14:22:47 +08:00
development.i18n.yaml Merge remote-tracking branch 'origin/master' into worktree-node-22-18-compat 2026-07-07 21:33:40 +08:00
development.md Merge remote-tracking branch 'origin/master' into worktree-node-22-18-compat 2026-07-07 21:33:40 +08:00
development.zh.md Merge remote-tracking branch 'origin/master' into worktree-node-22-18-compat 2026-07-07 21:33:40 +08:00
event-producer-consumer.md feat(mode): the access cap — plan mode composes with the sandbox instead of banning bash 2026-07-12 22:51:09 +08:00
graph-atlas.md feat(mode): exit_plan_mode + the ACP session-mode picker + scriptable review answers 2026-07-10 02:57:40 +08:00
module-graph.md feat(mode): the access cap — plan mode composes with the sandbox instead of banning bash 2026-07-12 22:51:09 +08:00
persistence-catalog.md refactor(mode): drop the per-mode tool allowlist — enforce where an enforcer exists 2026-07-12 23:20:36 +08:00
testing.md Add keyless snapshot refresh mode 2026-07-10 00:48:27 +08:00
tool-catalog.md refactor(mode): drop the per-mode tool allowlist — enforce where an enforcer exists 2026-07-12 23:20:36 +08:00
tool-execution-pipeline.md feat(approval): the approval seam — one-shot permission decisions over a waterfall of answerers 2026-07-10 15:43:02 +08:00