import { z } from "zod"; import { type BindingDeclaration } from "../binding/schema.js"; import { type BaselineSourceId } from "../internals/baseline-sources.js"; /** * The committed bootstrap-intent marker. It records what `aih init` re-derivation * otherwise loses across runs: the canonical context dir and the resolved CLI * targets. It lives at the repo ROOT (sibling of `.aih-workspace.json`), NOT under * the git-ignored `.aih/` output dir — so it survives a clone and a fresh checkout * reads the same context-dir/targets the repo was bootstrapped with. * * Schema shape inspired by @blazity-atlas/ai-harness's `.ai/config.json` (idea * only; re-expressed in aih's own zod idiom). aih has exactly one context dir by * design, so the `paths`/`pathAliases`/`artifactRoot` map is deliberately dropped. */ export declare const AIH_CONFIG_FILE = ".aih-config.json"; declare const AihConfigPostureSchema: z.ZodEnum<{ enterprise: "enterprise"; vibe: "vibe"; }>; declare const KiroHookRuntimeSchema: z.ZodEnum<{ cli2: "cli2"; "ide1-cli3": "ide1-cli3"; }>; declare const ManagedMcpProjectionOwnershipSchema: z.ZodObject<{ schemaVersion: z.ZodLiteral<1>; state: z.ZodEnum<{ active: "active"; revoked: "revoked"; }>; expected: z.ZodObject<{ allowManagedMcpServersOnly: z.ZodLiteral; allowedMcpServers: z.ZodArray; }, z.core.$strict>>; }, z.core.$strict>; sha256: z.ZodString; }, z.core.$strict>; declare const KiroMcpProjectionOwnershipSchema: z.ZodObject<{ schemaVersion: z.ZodLiteral<1>; state: z.ZodEnum<{ active: "active"; revoked: "revoked"; }>; expected: z.ZodObject<{ mcpServers: z.ZodRecord; command: z.ZodString; args: z.ZodArray; description: z.ZodString; classification: z.ZodEnum<{ local: "local"; "third-party-hosted": "third-party-hosted"; }>; egress: z.ZodEnum<{ "local-only": "local-only"; none: "none"; "third-party": "third-party"; "vendor-incumbent": "vendor-incumbent"; }>; credentials: z.ZodEnum<{ none: "none"; oauth: "oauth"; token: "token"; }>; supplyChain: z.ZodEnum<{ "hosted-remote": "hosted-remote"; pinned: "pinned"; unpinned: "unpinned"; }>; env: z.ZodOptional>; skillsProvider: z.ZodOptional; serverVersion: z.ZodOptional; manifestSha256: z.ZodOptional; hotReload: z.ZodBoolean; }, z.core.$strict>>; }, z.core.$strict>>; }, z.core.$strict>; sha256: z.ZodString; }, z.core.$strict>; export type ManagedMcpProjectionOwnership = z.infer; export type ActiveManagedMcpProjectionOwnership = ManagedMcpProjectionOwnership & { state: "active"; }; export type KiroMcpProjectionOwnership = z.infer; export type ActiveKiroMcpProjectionOwnership = KiroMcpProjectionOwnership & { state: "active"; }; /** * Persisted bootstrap intent. `contextDir` reuses the SAME {@link ContextDir} * constraints settings enforce; `targets` is the resolved CLI list at bootstrap * time (defaulted to `[]` so an older/partial marker still parses). */ export declare const AihConfigSchema: z.ZodObject<{ schemaVersion: z.ZodLiteral<1>; contextDir: z.ZodString; targets: z.ZodDefault>; baseline: z.ZodOptional>; posture: z.ZodOptional>; kiroHookRuntime: z.ZodOptional>; managedMcpProjection: z.ZodOptional; state: z.ZodEnum<{ active: "active"; revoked: "revoked"; }>; expected: z.ZodObject<{ allowManagedMcpServersOnly: z.ZodLiteral; allowedMcpServers: z.ZodArray; }, z.core.$strict>>; }, z.core.$strict>; sha256: z.ZodString; }, z.core.$strict>>; kiroMcpProjection: z.ZodOptional; state: z.ZodEnum<{ active: "active"; revoked: "revoked"; }>; expected: z.ZodObject<{ mcpServers: z.ZodRecord; command: z.ZodString; args: z.ZodArray; description: z.ZodString; classification: z.ZodEnum<{ local: "local"; "third-party-hosted": "third-party-hosted"; }>; egress: z.ZodEnum<{ "local-only": "local-only"; none: "none"; "third-party": "third-party"; "vendor-incumbent": "vendor-incumbent"; }>; credentials: z.ZodEnum<{ none: "none"; oauth: "oauth"; token: "token"; }>; supplyChain: z.ZodEnum<{ "hosted-remote": "hosted-remote"; pinned: "pinned"; unpinned: "unpinned"; }>; env: z.ZodOptional>; skillsProvider: z.ZodOptional; serverVersion: z.ZodOptional; manifestSha256: z.ZodOptional; hotReload: z.ZodBoolean; }, z.core.$strict>>; }, z.core.$strict>>; }, z.core.$strict>; sha256: z.ZodString; }, z.core.$strict>>; adopt: z.ZodOptional>; }, z.core.$strip>>; binding: z.ZodOptional; framework: z.ZodObject<{ id: z.ZodEnum<{ ecc: "ecc"; superpowers: "superpowers"; }>; mode: z.ZodOptional>; host: z.ZodEnum<{ claude: "claude"; }>; features: z.ZodOptional>; }, z.core.$strict>; source: z.ZodDiscriminatedUnion<[z.ZodObject<{ kind: z.ZodLiteral<"git">; repository: z.ZodString; commitSha: z.ZodString; treeDigest: z.ZodString; }, z.core.$strict>, z.ZodObject<{ kind: z.ZodLiteral<"npm">; package: z.ZodString; exactVersion: z.ZodString; integrity: z.ZodString; }, z.core.$strict>], "kind">; }, z.core.$strict>>; }, z.core.$strip>; export type AihConfig = z.infer; export type { BindingDeclaration }; export type AihConfigReadDiagnostic = { invalid: false; present: false; } | { invalid: true; present: true; } | { config: AihConfig; invalid: false; present: true; }; /** * Read the committed bootstrap intent, or `undefined` when the marker is absent, * unreadable, or fails validation. Fail-SOFT by design for old/partial markers * (unlike {@link loadSettings}, which is fail-closed): callers fall back to * flags/env/default. The exception is `baseline`: a present invalid baseline is * a governance control value and fails closed with a clear error. */ export declare function readAihConfig(root: string): AihConfig | undefined; /** * Read the marker with enough state for advisory surfaces to distinguish "absent" * from "present but invalid" without changing the fail-soft public reader. */ export declare function readAihConfigDiagnostic(root: string): AihConfigReadDiagnostic; /** * Strictly read only the persisted baseline choice. Most marker fields are * fail-soft for old/partial markers, but `baseline` controls canon semantics; * when present and invalid, commands must fail closed rather than silently * falling back to the default. */ export declare function readAihConfigBaseline(root: string): BaselineSourceId | undefined; export declare function readAihConfigPosture(root: string): z.infer | undefined; /** * Build the marker body the bootstrap persists via * `writeJson(AIH_CONFIG_FILE, …, { merge: true })`. Non-destructive by * construction: the same inputs render byte-identical JSON, and the merge write * preserves any extra user keys already on disk. */ export declare function aihConfigJson(contextDir: string, targets: string[], baseline?: BaselineSourceId, kiroHookRuntime?: z.infer): AihConfig; export declare function managedMcpProjectionOwnership(expected: ManagedMcpProjectionOwnership["expected"]): ManagedMcpProjectionOwnership; export declare function isManagedMcpProjectionOwnership(value: ManagedMcpProjectionOwnership | undefined): value is ManagedMcpProjectionOwnership; export declare function isActiveManagedMcpProjectionOwnership(value: ManagedMcpProjectionOwnership | undefined): value is ActiveManagedMcpProjectionOwnership; export declare function revokedManagedMcpProjectionOwnership(ownership: ManagedMcpProjectionOwnership): ManagedMcpProjectionOwnership; export declare function kiroMcpProjectionOwnership(expected: KiroMcpProjectionOwnership["expected"]): KiroMcpProjectionOwnership; export declare function isKiroMcpProjectionOwnership(value: KiroMcpProjectionOwnership | undefined): value is KiroMcpProjectionOwnership; export declare function isActiveKiroMcpProjectionOwnership(value: KiroMcpProjectionOwnership | undefined): value is ActiveKiroMcpProjectionOwnership; export declare function revokedKiroMcpProjectionOwnership(ownership: KiroMcpProjectionOwnership): KiroMcpProjectionOwnership; /** * Build a merge-safe marker update for managed-MCP provenance. A malformed * existing marker is never repaired or used as ownership evidence. */ export declare function managedMcpProjectionConfigJson(root: string, contextDir: string, targets: string[], ownership: ManagedMcpProjectionOwnership): Record; /** * Render the managed-MCP ownership update from the exact marker bytes observed * while planning, so callers can bind the write to that same snapshot. */ export declare function managedMcpProjectionConfigJsonFromRaw(raw: string | undefined, contextDir: string, targets: string[], ownership: ManagedMcpProjectionOwnership): Record; /** Merge-safe marker update for Kiro workspace-MCP provenance. */ export declare function kiroMcpProjectionConfigJsonFromRaw(raw: string | undefined, contextDir: string, targets: string[], ownership: KiroMcpProjectionOwnership): Record;