cliOnlySettings top-level constant

Set<SharedSetting> const cliOnlySettings

Settings that are currently CLI-only.

Each entry MUST have a comment explaining WHY the app cannot support it, and a matching user-readable justification in cliOnlyJustifications (the app surfaces the reason instead of silently omitting the setting).

Implementation

const cliOnlySettings = <SharedSetting>{
  // MCP servers require spawning external processes — impossible on web and
  // not yet wired in the Flutter app's sandbox.
  SharedSetting.mcpServers,

  // Host-process sandboxing primitives + a host shell: the app's mobile
  // shells are already WASI/memory-confined and web has no shell at all.
  SharedSetting.cubeSandbox,

  // The app's agent surfaces compile their prompt templates in
  // (flutter_app/lib/prompts.g.dart, generated from flutter_app/prompts/);
  // there is no runtime prompt-override file for them to read.
  SharedSetting.promptOverrides,

  // Agent modes are REPL prompt presets (builtInAgentModes) driving the
  // coding agent's system prompt; the app composes its own per-surface
  // prompts and has no mode-preset concept to switch.
  SharedSetting.agentMode,

  // Memory store locations are host filesystem paths (project-relative and
  // ~/ user roots). The app's sandbox owns its storage layout and resolves
  // the section read-only (memory_config_loader); editing host paths from
  // inside the sandbox would point the CLI at paths the app cannot see.
  SharedSetting.memoryStores,

  // Spilling is boot wiring INSIDE the CLI host process's agent loop
  // (hook attach + boot notes, issue #678); the app composes its own
  // agent loop and has no hook chain to attach to. File-tuned section.
  SharedSetting.spillHooks,

  // The image registry is process-wide state inside the CLI host's agent
  // loop (the request-build rewrite reads a global published at boot);
  // the app composes its own requests and consumes the section read-only
  // per #288's umbrella (issue #395 is the CLI half).
  SharedSetting.imageRegistry,

  // The sleep-prevention assertion lifecycle (run-start/settle and
  // session-open/close hooks) lives in the CLI host process; the app's
  // power_guard only loads the section read-only and has no controller
  // to re-arm live (issue #397 is the CLI half — per #288's umbrella).
  SharedSetting.sleepPrevention,
  // The context cap feeds the CLI's compaction math, ctx meter and the
  // loop's over-window guard — all running in the CLI host process; the
  // app has no agent loop to re-cap live (issue #394 is the CLI half —
  // the app keeps consuming the section read-only per #288's umbrella).
  SharedSetting.contextWindowCap,
  // The TUI palette colors a terminal: the app renders through Flutter's
  // own theming stack (separate system by design — issue #279 non-goal).
  SharedSetting.tuiTheme,
  // The harness benchmark mode (issue #679) presets the CLI REPL boot —
  // the tool-scope pin and the bare prompt composition run in the CLI
  // host process (`fa --pi`); the app has no fa benchmark runner.
  SharedSetting.harnessMode,
};