explain.vfs has the same 24 calls as session.vfs.
From any door
Every door answers the same JSON. Explain reads the line only, so stdin,
cwd, runtime and a background job are refused with it.
What it asks
Explain stops before anything runs, so it asks only the hooks that answer first:
The post hooks need a result, and on a line
pre_session and pre_vfs
fire only as it runs. So export AWS_SECRET=x explains as allow even
when a pre_session policy refuses it. Explain the VFS call to see a
pre_vfs answer.
What comes back
With a profile that denies/data/keys/*:
A line adds
exit_code and stderr, what the agent would read, and
node, the line as a tree of commands. Each command in the tree has its
own outcome, exit_code, stderr, argv, operands and runtime.
A line
mirage shell --explain prints the tree:
Deny(reason) on any command
refuses the whole line, and the first such command gives the line its
answer. A command missing from the allow list, or a Deny with operand
scope, fails only itself:
Limits
- A hidden path explains like any path no rule names, so explain never reveals a hide.
- A policy that reads a file to decide still reads it.
- In a browser,
explain.vfsthrows andexplain.shellruns its policies for real.