seatChannelPolicy<TSeat extends ModelPreference> function
- TreeContext context, {
- required String seatId,
The station permission policy in effect for ONE capability's channel, keyed
by the seat's own preference type TSeat and stamped with seatId.
Total, in strict precedence:
- an EXPLICITLY mounted AgentPermissionPolicy wins outright, returned unchanged - including AgentPermissionPolicy.unavailable, which is how a station locks a subtree down over an armed seat;
- else, an ARMED exact
TSeatis the channel's admitted identity, so it derives AgentPermissionPolicy.trustedHeadless underseatId; - else AgentPermissionPolicy.unavailable - a channel with no seat identity authorizes nothing.
THE IDENTITY IS THE EXACT TYPE (ADR-0006 D2: the TYPE is the scope), read
from the InheritedSeed the seat's own provider() seed mounts. The
GENERIC ModelPreference is deliberately NOT consulted:
it is the station's shared model default, not an arming of this seat, and
treating it as an identity would hand a grant to any channel that inherited
a default. Nothing here reads a name, a runtime type, an environment's
availability, or the model-spend axis - a permission is not a spend.
THE EFFECT VERB (getInheritedSeedOfExactType), per ADR-0008 D3: both
callers are createSession edges, not builds.
Implementation
AgentPermissionPolicy seatChannelPolicy<TSeat extends ModelPreference>(
TreeContext context, {
required String seatId,
}) {
final explicit = context.getInheritedSeedOfExactType<AgentPermissionPolicy>();
if (explicit != null) return explicit;
final seat = context.getInheritedSeedOfExactType<TSeat>();
if (seat == null) return const AgentPermissionPolicy.unavailable();
return AgentPermissionPolicy.trustedHeadless(id: seatId);
}