Skip to main content

ToolMeta

Struct ToolMeta 

Source
pub struct ToolMeta {
    pub name: &'static str,
    pub toolset: Toolset,
    pub tier: Tier,
    pub summary: &'static str,
    pub self_severing: bool,
    pub severs_local_node: bool,
    pub requires_confirmation: bool,
    pub idempotent: bool,
    pub varying_tier: bool,
    pub min_version: Option<&'static str>,
    pub platforms: Option<&'static [&'static str]>,
}
Expand description

One row of the tool table.

Fields§

§name: &'static str

The tool name as the client sees it, including its surface prefix.

§toolset: Toolset§tier: Tier§summary: &'static str

One sentence, shown to the model. The full description lives on the generated schema; this is what the tool table prints.

§self_severing: bool

Whether calling this can cut the server off from the tailnet or from the client it serves. Self-severing tools always require confirmation; the two are separate fields because the tailnet surface has irreversible operations that are not self-severing but still require it.

§severs_local_node: bool

Whether this tool severs the connection when its target is this node.

Where Self::self_severing is true of every call a tool makes, this is true of some of them: tailnet_device_delete is an ordinary destructive call against somebody else’s device and a cut cable against this one, and only the argument tells them apart. So it cannot imply Self::requires_confirmation — a caller managing another device would be made to confirm something that cannot happen — and the confirmation lives in the tool’s own parameters, where the handler can ask for it only when the target turns out to be us (Q83).

§requires_confirmation: bool

Whether the caller must state intent in the call itself. No flag can pre-authorise this.

§idempotent: bool

Repeating the call has the same effect as making it once.

§varying_tier: bool

Whether Self::tier is a floor rather than the whole truth.

Set by the rows whose risk is decided by the arguments they are given rather than by the row: the passthrough, tailnet_device_authorize and tailnet_service_approval_set, the last two by Q70. The gate still reads the tier, so such a tool is offered as soon as its floor is permitted, and the handler refuses anything above what the session allows. The annotations state the worst case, because a client reading read_only has no way to know that this one is conditional.

the_tier_is_a_floor_only_where_it_is_documented pins that list, so a fourth row adopting the flag is a change somebody has to write down.

§min_version: Option<&'static str>

The lowest tailscale version that accepts this command, where the command is newer than our supported floor.

§platforms: Option<&'static [&'static str]>

The operating systems the command exists on, when it does not exist on all of them. Values are std::env::consts::OS spellings.

A restricted tool is still listed everywhere. The table is the same on every platform so that the documentation, the contract tests and the tools subcommand agree wherever they run, and so that a caller asking for something macOS-only on Linux is told why rather than finding a tool that does not exist.

Implementations§

Source§

impl ToolMeta

Source

pub const fn surface(&self) -> Surface

Source

pub fn runs_here(&self) -> bool

Whether the command behind this tool exists on the machine we are on.

Source

pub const fn takes_confirmation(&self) -> bool

Whether this tool exposes a confirm argument to the caller.

Three fields put one there and they mean different things — the row demands it, every call severs, or a call severs when its target turns out to be this node — but a caller sees the same argument for all three. Anything reasoning about what a session shows a model wants this question, not the three underneath it.

Source

pub const fn annotations(&self) -> Annotations

Annotations are derived, not stored, so that a tool cannot claim to be read-only while sitting at the destructive tier.

Trait Implementations§

Source§

impl Clone for ToolMeta

Source§

fn clone(&self) -> Self

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Copy for ToolMeta

Source§

impl Debug for ToolMeta

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> DynClone for T
where T: Clone,

Source§

fn __clone_box(&self, _: Private) -> *mut ()

Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> FromRef<T> for T
where T: Clone,

Source§

fn from_ref(input: &T) -> T

Converts to this type from a reference to the input type.
Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self> ⓘ

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self> ⓘ

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> PolicyExt for T
where T: ?Sized,

Source§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow only if self and other return Action::Follow. Read more
Source§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow if either self or other returns Action::Follow. Read more
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self> ⓘ
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self> ⓘ

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more