§
    øžyj  ã                  ó2   — d Z ddlmZ ddlZddlmZ d
d	„ZdS )zÌ``hermes approvals`` subcommand parser.

Follows the cron/security pattern: parser construction lives here, the
handler is injected by ``main.py`` so this module never imports ``main``
(cycle avoidance).
é    )ÚannotationsN)ÚCallableÚcmd_approvalsr   ÚreturnÚNonec               ó6  — |                       ddd¬¦  «        }|                     dd¬¦  «        }|                      dd	d
¬¦  «        }|                     dddd¬¦  «         |                     ddd¬¦  «         |                     dt          dd¬¦  «         |                     ddt          dd¬¦  «         |                     dt          dd¬¦  «         |                     d d!¬"¦  «         |                     |¬#¦  «         |                      d$d%d&¬¦  «        }|                     d'd(d)d*¬+¦  «         |                     ddd¬¦  «         |                     d,t
          j        d-d.¬/¦  «         |                     |¬#¦  «         |                     |¬#¦  «         d0S )1z6Attach the ``approvals`` subcommand to ``subparsers``.Ú	approvalsz=Approval-prompt tools (mine history into allowlist proposals)zÚTools for the dangerous-command approval system. `hermes approvals suggest` mines past approval decisions from the session database and proposes command_allowlist entries so repeatedly-approved commands stop prompting.)ÚhelpÚdescriptionÚapprovals_commandz<subcommand>)ÚdestÚmetavarÚsuggestz5Propose command_allowlist entries from past approvalsa/  Scan the session database for dangerous-classified commands that ran with user approval, rank the recurring patterns, and print a numbered allowlist proposal. Nothing is written unless --apply is given. Destructive classes (recursive delete, sudo, disk writes, credential edits, ...) are never proposed.z--applyÚapply_indiceszN[,M...]zUMerge the numbered proposals (from a prior run) into command_allowlist in config.yaml)r   r   r
   z--jsonÚ
store_truez9Emit machine-readable JSON instead of human-readable text)Úactionr
   z--dayséZ   z;How far back to scan session history (default: 90; 0 = all))ÚtypeÚdefaultr
   z--min-countÚ	min_counté   z@Minimum approval count for a pattern to be proposed (default: 2))r   r   r   r
   z--limité   z1Maximum number of proposals to show (default: 20)z--dbzCPath to an alternate session database (default: ~/.hermes/state.db))r
   )ÚfuncÚtestz>Dry-run the approval verdict for a command (never executes it)uñ  Evaluate a command against the REAL runtime approval guards â€” hardline blocklist, user approvals.deny rules, dangerous-pattern detection, allowlist, yolo/off bypass â€” and print the verdict, the matching rule, and the normalized-command trace, without executing the command, prompting anyone, or persisting anything. Exit codes: 0 allow, 2 ask-approval, 3 deny (hardline or user deny rule). Tip: use `--` before the command so its own flags aren't parsed: hermes approvals test -- rm -rf /tmp/xz
--env-typeÚenv_typeÚlocalzsTerminal backend type to evaluate against (default: local; isolated container backends like docker skip the guards))r   r   r
   Úcommand_wordsÚcommandz=The command to evaluate (prefix with -- to protect its flags))Únargsr   r
   N)Ú
add_parserÚadd_subparsersÚadd_argumentÚintÚset_defaultsÚargparseÚ	REMAINDER)Ú
subparsersr   Úapprovals_parserÚapprovals_subparsersÚsuggest_parserÚtest_parsers         úF/home/ragecks/.hermes/hermes-agent/hermes_cli/subcommands/approvals.pyÚbuild_approvals_parserr-      sm  € à!×,Ò,ØØLð;ð	 -ñ 	ô 	Ðð ,×:Ò:Ø Øð ;ñ ô Ðð
 *×4Ò4ØØDðFð	 5ñ 
ô 
€Nð ×ÒØØØð+ð	  ñ ô ð ð ×ÒØØØHð  ñ ô ð ð
 ×ÒØÝØØJð	  ñ ô ð ð ×ÒØØÝØØOð  ñ ô ð ð ×ÒØÝØØ@ð	  ñ ô ð ð ×ÒØØRð  ñ ô ð ð ×Ò ]ÐÑ3Ô3Ð3à&×1Ò1ØØMðDð	 2ñ ô €Kð ×ÒØØØðCð	 ñ ô ð ð ×ÒØØØHð ñ ô ð ð
 ×ÒØÝÔ Øð Mð ñ ô ð ð ×Ò -ÐÑ0Ô0Ð0à×!Ò! }Ð!Ñ5Ô5Ð5Ð5Ð5ó    )r   r   r   r   )Ú__doc__Ú
__future__r   r%   Útypingr   r-   © r.   r,   ú<module>r3      sb   ððð ð #Ð "Ð "Ð "Ð "Ð "à €€€Ø Ð Ð Ð Ð Ð ðe6ð e6ð e6ð e6ð e6ð e6r.   