Skip to main content

Module policy_eval

Module policy_eval 

Source
Expand description

tuff policy evaluate: matching one tool call against a policy at run time (RFC-107 D3).

Where a harness has no native setting for a rule, it can run a hook before each tool call and let the hook answer. The harness adapter turns its hook input into PolicyActions and the decision back into the harness’s answer; the matching lives here, once.

A shell command is read the way a shell would split it, then reduced to the programs it runs: a path becomes the program name (/usr/bin/git is git), wrappers such as env, sudo, and sh -c "..." are unwrapped, command substitutions are read as commands of their own, and options before a subcommand are skipped (git -C . push). The files a command names on its command line, as arguments of programs such as cat or as redirections, are checked against read and edit rules. A script or program that runs a command or opens a file itself is not seen, which is why coverage through the hook stays partial.

Structs§

EvalContext
Where a call happens: the project the policy governs and the directory relative paths in the call start from.
PolicyDecision
The rule a call matched.
PolicyHookAnswer
What the hook prints and the status it exits with.
PolicyHookRequest
A tool call, as a harness adapter reads it from the hook input.

Enums§

PolicyAction
One thing a tool call is about to do.
PolicyHookUse
How a harness uses the tuff policy evaluate hook for one rule.
PolicyVerdict
What tuff policy evaluate concluded about one call.

Functions§

command_matches
Whether a policy command rule, such as ["git", "push", "--force"], matches one program invocation.
evaluate
The strongest rule of policy that any of actions matches: a deny over an ask, and the first rule of that effect in the policy.
find_policy_root
Find the project a policy was installed into: the nearest directory, at or above one of starts, holding <dir_prefix>/policies/<id>/policy.toml.
load_installed_policy
Read the [policy] section of an installed policy.toml record.
path_matches
Whether a policy path pattern covers a project-relative path, read the way .gitignore reads a pattern in a file at the project root: a pattern with a / before its end is anchored at the root, one without matches at any depth, a trailing / names a directory’s contents, and a pattern that matches a directory covers everything in it. * and ? stay within one path segment; ** spans any number of them.
wildcard_matches
* for any run of characters and ? for one, within one segment.