Why a binary and not a prompt#

A model that is asked “may this run?” will sometimes say yes. The gate has to be a process that does not read the request as prose. This crate is that process: argv in, a one-line verdict out. The harness hook calls it. A Janet pack can deny more after this verdict.

First deny wins#

The built-in list is short on purpose. sudo, a curl pipe into a shell, recursive delete outside temporary directories, and a force push are the lines that have already destroyed a working tree or a remote. A later pack rule can deny more. It cannot allow what this binary denied.

Absence is not a deny#

A seat without the binary still sits. Doctor names the row. The hook and ljos policy print the line and any pack rule. Setting POLICYD_REQUIRED=1 is the fail-closed seat: then a missing binary is a deny. That switch belongs to the operator, not to this crate.

Reloading a pack is not a check#

A Janet file, a comment, a stamp, a ticket id written into a policy pack: none of those are a verdict on this argv. This crate does not open a pack, does not reload one, and does not write one. Pack rules live in packset and are composed by ljos policy after this verdict.

Not a store#

Remember and Prefer are speech acts in the pack. A deed is a frozen product. A ticket is a heading. A claim is a lease. This crate answers one question those habitats do not: may this command line run? Mixing that answer into a memory store is how a hook starts writing.

Where the seat puts it#

ljos doctor lists a policyd row when the binary answers. ljos policy -- argv prints the line, then this verdict, then any pack rule. ljos hook is the same answer on the runner’s PreToolUse path. The public crate is this one. https://leidarljos.github.io teaches sitting; this site teaches the binary.