Skip to content

Trust: a family is what a command does and where; production and SQL writes cost more; families nest - #43

Merged
Codestz merged 3 commits into
mainfrom
trust/family-rules
Oct 5, 2026
Merged

Codestz merged 3 commits into
mainfrom
trust/family-rules

Conversation

@Codestz

@Codestz Codestz commented Oct 5, 2026

Copy link
Copy Markdown
Owner

What

mcpx db-local … and mcpx db-prod … were one Trust family, so w on one trusted the other. Same for docker compose -p dev / -p prod, kubectl --context a / b.

  • Families for any CLI, no table. The program and up to 3 plain words, plus target flags (-p, --context, --profile, -n, --site …) with their values, and env vars and hosts that name an environment. ls, cat, grep and the like stay one family.
  • Production costs more. prod / production / prd / live in a flag, host, name or NODE_ENV= → 8 approvals, never widened.
  • SQL writes are dangerous in any argument. update … set, delete from, insert into, drop, alter, create, truncate, grant. A widened family never answers them.
  • Nested ledger. mcpx › db-local › execute_sql. Folders are read-only: w widens one family only. A closed folder shows prod / ! when anything inside is dangerous.
  • Old widenings. A family widened under the old rule matches nothing now (families match whole). It shows as old, and x removes it.

Why this rule

packages/trust/experiments/families scores 10 candidate rules on 61 made-up labelled pairs:

  • old rule: merged 23 of 32 pairs that must stay apart;
  • shipped rule (G): merges 0, splits 1 (docker compose -p dev logs web vs api).

test/families.test.ts keeps it there.

Checks

  • build, lint, typecheck, bun test --conditions browser (2285 pass);
  • 8 Trust golden previews changed (the nesting), reviewed;
  • Trust TUI smoke on OpenCode 2 passed;
  • tried by hand on a fictional test project.

🤖 Generated with Claude Code

Codestz and others added 3 commits October 5, 2026 12:49
packages/trust/experiments/families: a labelled set of made-up command pairs (must stay separate:
dev vs prod, read vs write; fine together: another file, row or id — some held out until the end),
the candidate rules, and a runner that scores them there and, as counts only, on the Trust ledgers on
the machine it runs on. Nothing from a ledger is printed or kept. Not part of the package.

Today's rule merges 23 of 32 must-separate pairs (`mcpx db-local` with `mcpx db-prod`, `compose -p dev`
with `-p prod`). Rule G — the plain words and target flags read in order, plus environments named in
env vars and hosts — merges none, splitting 6 of 29 pairs that could share a family.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
… production and SQL writes cost more

A family is what `w` ("trust any …") covers. It was a program and, for tools in a table, its
subcommand — so `mcpx db-local` and `mcpx db-prod` were one family, and so were `docker compose -p dev up`
and `-p prod up`: widening either trusted production along with dev. Measured on labelled pairs
(packages/trust/experiments/families), the old rule merged 23 of 32 that must stay apart.

Now, for any CLI: the program and the plain words after it (up to three, until the first argument),
any flag that names a target with its value (`--context`, `--profile`, `-p`, `-n`, `--host`…), and any
env var, host or name that names an environment. Standard utilities (`ls`, `cat`, `grep`…) take no
subcommand, so their family stays the program. On the same pairs: none merged, one split (a
service name), kept as test/families.test.ts.

- `mcpx db-prod execute_sql …` → `mcpx db-prod execute_sql`; `docker compose -p dev up -d` →
  `docker compose -p dev up`; `kubectl get pods -o wide -n prod` → `kubectl get pods -n prod`.
- Anything that names production (`prod`, `production`, `prd`, `live`, as a word or part of one) is
  dangerous: the higher count, and its family is never widened.
- SQL that writes, in any program's argument (`--sql "delete from …"`), is dangerous, so a widened
  `mcpx db-local execute_sql` answers reads and still asks about writes.

A family widened under the old rule matches nothing now: Trust asks again, never more.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Families sharing their first words sit in a folder (mcpx › db-local ›
execute_sql); a folder is for reading, w widens one family. A folder
holding danger shows prod or ! while closed. A widening nothing falls in
any more is marked old, out of any folder, and x removes it. The
storefront sample adds mcpx, compose and kubectl, and an old widening.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@Codestz
Codestz merged commit 6933cf5 into main Oct 5, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant