Skip to main content

Module lockfile

Module lockfile 

Source

Structs§

CapabilityLockEntry
CatalogSource
GitSource
LocalSource
Lockfile
ManagedHook
ManagedMcpEntry
Baseline for one Tuff-managed mcpServers.<id> entry (RFC-102 stage b).
ManagedPermission
A native permission rule a policy compiled into a harness settings file, such as Bash(git push --force *) in .claude/settings.json’s permissions.deny. The rule string is its own identity: it is present in that list or it is not.
PackProvenance
Immutable pack release that delivered a capability entry.
TargetLockEntry
UnenforcedRule
A policy rule the agent does not enforce, recorded when the policy was installed with --accept-unenforced (RFC-107 D6). tuff check reports each one, and tuff check --strict fails while any are recorded.

Enums§

CapabilitySource
The origin of an installed capability. Internally tagged as kind on the wire, so a lockfile row reads [capabilities.source] kind = "git".
TargetOwnership
VersionScheme
What kind of string CapabilityLockEntry::version holds (RFC-105 D4).

Constants§

LOCKFILE_VERSION
Current on-disk schema. Older readable versions are migrated in memory by read_lockfile_at; writers always emit this version.
OLDEST_READABLE_LOCKFILE_VERSION
Oldest schema this build still reads.

Functions§

absolutize
hash_bytes
init_lockfile
init_lockfile_at
managed_hook_status
managed_hooks_from_fragment
managed_hooks_from_fragment_with_canonical
managed_mcp_entry_baseline
Hash an MCP entry value exactly as managed_mcp_entry_status will when it re-reads the file: canonical serde_json bytes, so on-disk pretty- printing never matters.
managed_mcp_entry_status
"clean", "modified", or "missing" for a managed MCP entry.
project_lockfile
The project-scope lockfile. Never falls through to the global one: the caller resolved a scope and this is the file for it (RFC-105 D3).
read_lockfile_at
Read a lockfile of any supported schema version into the current model.
read_optional_lockfile
Read a lockfile that may legitimately not exist.
relative_or_absolute_fs
render_lockfile
The bytes write_lockfile_at writes: the current schema, whatever schema the lockfile was read from.
require_lockfile
require_scoped_lockfile
scoped_lockfile
The lockfile for a resolved scope: <root>/tuff.lock for a project, the XDG state file for the global scope (where scope_root is the home directory). The scope is always passed, never inferred from the path.
write_lockfile
write_lockfile_at
write_scoped_lockfile