2602270669
A session mode is a named, logged, per-agent policy state: mode/set as a log-only SessionEventMap member (todo/write shape), a foldMode over the log, soft enforcement at system-prompt/assemble (filtered schemas + mode section, auto-logged as request/header-delta), hard enforcement at tools/pre-execute (deny-by-default against the mode allowlist), and a thin ctx.modes service with turn-boundary pending-intent flush for user flips. One new product package dsh-mode (packages/mode/mode, the approval-group shape); plan is the only shipped definition. Lands as ONE feature — a plan mode without a model-driven, approvable exit is not a smaller version of the feature. The roadmap's two stages are build-and- review order for a single stacked landing: the mode core, then exit_plan_mode (ask-gated through the approval seam; the plan text rides the tool args as the reviewable log artifact), the stdio readline answerer, and the ACP session-mode surface (session/set_mode, current_mode_update, available modes). Hard prerequisite: the approval seam lands first; the stack bases on feat/sandbox-support meanwhile.