deepseek-harness/scripts
kingwl 95635dfa66 feat(permission): user-facing permission presets — one Permissions select over the two knobs
A preset names a bundle of the two mechanism knobs — request =
workspace-write + ask, yolo = danger-full-access + never — so the editor
shows ONE 'Permissions' select where the sandbox-mode and approval-policy
tiers stay orthogonal capabilities (the Codex /approvals shape: presets over
two dials). ctx.permission (dsh-permission) owns the config-defined table,
validates the default preset's bundle against the composed knob defaults at
load (fails loud), and writes a switch THROUGH: one log-only
permission/preset event (the audit fact reverse-mapping cannot recover —
the planned 'agent' preset shares request's knob values and differs only in
composed policy) plus each knob event via its own setter, deduped — a
net-zero switch appends nothing. Every knob consumer keeps reading its own
fold, untouched.

The current preset DERIVES from the effective knob values — the fold breaks
bundle ties, a knob state outside the table is the reserved 'custom' value
(a state, not an error: shown while it holds, switchable FROM, never a
target), and defaultPreset disappears (zero-event state reverse-maps from
the composition defaults).

The ACP bridge drops the two per-knob selects for the one preset select
(advertised only when ctx.permission is composed); pending/anchor/no-op
semantics carry over unchanged, with the no-op echo acknowledged before
vocabulary validation so a client re-pushing a derived 'custom' current
never errors. The sandbox variant example composes the
service with a workspace-write default; the permission-switching,
escalation-approved and escalation-rejected scenarios are re-recorded under
it (escalations now target an outside-workspace /tmp path under
danger-full-access, self-cleaning) and config-options is re-authored on the
single-select wire.
2026-07-13 14:38:26 +08:00
..
check-vendor-manifest.sh Add lefthook git hooks with a vendor-manifest guard 2026-06-11 15:07:55 +08:00
check-workspace-constraints.ts workflow: swap the engine's internals to node:worker_threads 2026-07-09 19:31:14 +08:00
demo-code-mode.mjs refactor: unify the Code Mode demos on base-plus-overlay 2026-07-09 13:02:19 +08:00
doc-budgets.manifest.json Merge remote-tracking branch 'origin/master' into codex/pr224-rfc-rewrite 2026-07-11 23:14:09 +08:00
doc-typecheck.ts fix(scripts): replace async fs glob with globSync (failed on Node 22.18) 2026-07-07 17:15:41 +08:00
gen-config-catalog.ts feat(example): sandbox-acp-agent — the live composition; RFCs to implemented 2026-07-10 15:44:38 +08:00
gen-cordis-api.ts scripts: gen-cordis-api — the generated runtime API catalog pipeline 2026-07-09 13:57:03 +08:00
gen-cordis-catalog.ts docs(rfc): align scoped runtime contracts 2026-07-12 22:49:46 +08:00
gen-doc-graphs.ts feat(permission): user-facing permission presets — one Permissions select over the two knobs 2026-07-13 14:38:26 +08:00
gen-module-graph.ts feat(skill): move catalogs into session prefixes 2026-07-10 14:19:06 +08:00
gen-persistence-catalog.ts docs: flatten single-file catalog dirs to docs/tool-catalog.md and docs/persistence-catalog.md 2026-07-06 22:26:06 +08:00
gen-rfc-index.ts docs(rfc): define and enforce a uniform RFC format; adopt it across the corpus 2026-07-05 22:58:25 +08:00
gen-tool-catalog.ts refactor(core): remove owner-final assembly machinery 2026-07-13 13:09:41 +08:00
install-lefthook.mjs fix(dev): make hooks and bash seams safer 2026-06-17 21:26:44 +08:00
jsdoc.ts Merge remote-tracking branch 'origin/master' into worktree-export-jsdoc-gate 2026-07-07 09:34:12 +08:00
publint-all.ts chore: parallelize pre-push gates 2026-07-06 00:52:00 +08:00
rfc-index.ts docs(rfc): define and enforce a uniform RFC format; adopt it across the corpus 2026-07-05 22:58:25 +08:00
run-gates.ts fix(workflow): bootstrap source worker transforms 2026-07-12 06:19:53 +08:00
translation-pairing.manifest.json fix: retarget the i18n pairing exclusions to the flattened catalog paths 2026-07-07 00:08:55 +08:00
type-equiv.manifest.json docs(rfc): align scoped runtime contracts 2026-07-12 22:49:46 +08:00
verify-doc-budgets.ts docs(budgets): ceilings carry at least 5% working headroom 2026-07-04 17:20:18 +08:00
verify-doc-refs.ts fix(scripts): replace async fs glob with globSync (failed on Node 22.18) 2026-07-07 17:15:41 +08:00
verify-export-jsdoc.ts fix review findings: CI leaf-gate wiring, heritage return surface, AGENTS.md self-containedness 2026-07-07 20:30:34 +08:00
verify-md-links.ts fix(scripts): replace async fs glob with globSync (failed on Node 22.18) 2026-07-07 17:15:41 +08:00
verify-md-wrap.ts fix(review): lint prompt Markdown paragraphs 2026-07-11 22:33:33 +08:00
verify-mermaid.ts fix(scripts): replace async fs glob with globSync (failed on Node 22.18) 2026-07-07 17:15:41 +08:00
verify-node-next-types.ts docs: update rewriteRelativeImportExtensions to current rfc 2026-06-22 09:03:28 +08:00
verify-package-paths.ts fix(scripts): replace async fs glob with globSync (failed on Node 22.18) 2026-07-07 17:15:41 +08:00
verify-rfc-classification.ts docs(rfc): define and enforce a uniform RFC format; adopt it across the corpus 2026-07-05 22:58:25 +08:00
verify-rfc-format.ts docs(rfc): address Codex review — fence-aware format gate, exact corpus counts 2026-07-05 23:45:34 +08:00
verify-scoped-dispatch.ts feat(dx): scopeHost, agent-aware ACP presentation, and the scoped-dispatch drift gate 2026-07-09 02:38:54 +08:00
verify-translation-pairing.ts fix(scripts): replace async fs glob with globSync (failed on Node 22.18) 2026-07-07 17:15:41 +08:00
verify-type-equiv.ts fix(scripts): replace async fs glob with globSync (failed on Node 22.18) 2026-07-07 17:15:41 +08:00