M14: safe write access #14

Open
opened 2026-10-02 00:16:06 +00:00 by jhgaylor · 0 comments
Owner

Depends on: #12, #13

From PLAN.md, section "Multiplayer track → M14".


Make editor something you can hand out.

  • Guest panes run on machines. A non-owner's new pane or tab defaults to
    a VM (M3b/M3c) in your wisp, with its own quota. A local pane for a guest
    is an owner-only option.
  • Trust grants for local panes. Before a guest can drive a pane on a real
    host, the owner grants trust for that pane, for a set time (default 30
    minutes), from a prompt they can answer on the phone. It's revocable, and
    it ends when the pane closes.
  • Quotas per principal: machines, CPU and memory, and concurrent agent
    blocks. Limits are visible in the share dialog.
  • Secrets. A pane marked "private" is never shown to non-owners. Shared
    sessions warn before showing a pane whose recent output matches common
    token patterns. It's a heuristic, and it says so.
  • Agents. An editor's agent blocks act as that editor, run on their VM,
    and their approvals go to them. Owners can approve anything.
  • Done when:
    • an editor opens a tab, gets a VM, and runs claude in it;
    • they can't drive the owner's local shell until the owner approves from a
      phone notification;
    • access ends by itself after the grant expires;
    • quotas stop a fourth VM.
**Depends on:** #12, #13 _From PLAN.md, section "Multiplayer track → M14"._ --- Make `editor` something you can hand out. - **Guest panes run on machines.** A non-owner's new pane or tab defaults to a VM (M3b/M3c) in your wisp, with its own quota. A local pane for a guest is an owner-only option. - **Trust grants for local panes.** Before a guest can drive a pane on a real host, the owner grants trust for that pane, for a set time (default 30 minutes), from a prompt they can answer on the phone. It's revocable, and it ends when the pane closes. - **Quotas per principal:** machines, CPU and memory, and concurrent agent blocks. Limits are visible in the share dialog. - **Secrets.** A pane marked "private" is never shown to non-owners. Shared sessions warn before showing a pane whose recent output matches common token patterns. It's a heuristic, and it says so. - **Agents.** An editor's agent blocks act as that editor, run on their VM, and their approvals go to them. Owners can approve anything. - **Done when:** - an editor opens a tab, gets a VM, and runs `claude` in it; - they can't drive the owner's local shell until the owner approves from a phone notification; - access ends by itself after the grant expires; - quotas stop a fourth VM.
Sign in to join this conversation.
No description provided.