A native permission rule a policy compiled into a harness settings file,
such as Bash(git push --force *) in .claude/settings.json’s
permissions.deny. The rule string is its own identity: it is present
in that list or it is not.
A policy rule the agent does not enforce, recorded when the policy was
installed with --accept-unenforced (RFC-107 D6). tuff check reports
each one, and tuff check --strict fails while any are recorded.
Hash an MCP entry value exactly as managed_mcp_entry_status will when
it re-reads the file: canonical serde_json bytes, so on-disk pretty-
printing never matters.
The lockfile for a resolved scope: <root>/tuff.lock for a project,
the XDG state file for the global scope (where scope_root is the home
directory). The scope is always passed, never inferred from the path.