import { type Runner } from "../internals/proc.js"; interface RuntimeFileReceipt { path: string; rawSha256: string; bytes: number; fileType: "regular"; modeIntent: string; } export declare const PLAN_CANVAS_RUNTIME_PIN: { readonly package: "ecc-universal"; readonly exactVersion: "2.1.0"; readonly integrity: "sha512-+WiK+Ray5/xUtPbzrNkiNCG90ZeKXXSOXGMUPkcPAt1U473jSkSiurH69Kqy4AWZDvKRWZ6ZeA6Vx3cNsMOiCg=="; readonly sourceRepository: "https://github.com/affaan-m/ECC"; readonly releaseAncestorCommit: "4da6deac1888690e7fb8572d097ee23db630f7a0"; readonly license: "MIT"; readonly entrypoint: "scripts/plan-canvas.js"; readonly sourceClosureSha256: "ffafd7303cff4728bbe39b0921d03b3e2d5e63c1f8afe4116b9f8297bb96a947"; readonly closureSha256: "5f096b2e8678c1daad44268001cab5e73b0eb1bf13a4bf7b283cffb2d90339ac"; readonly hardeningOverlay: { readonly sourceCommit: "0c1d7be9a750627fb2a6534c78a998cc46d03f9c"; readonly path: "scripts/lib/loopback-guard.js"; readonly rawSha256: "3efcc93c9c631876f824e61f97945a8260fba9ad7ea14baffee3de0781b74bcb"; readonly reason: "Reject malformed and out-of-range Host-header ports before URL parsing."; }; readonly serverHardening: { readonly sourcePath: "scripts/lib/plan-canvas/server.js"; readonly sourceSha256: "cf60c4a2f295355bf1173a9cd2beb043a76a4e09322471572316d8b1eb95db5b"; readonly outputSha256: "31dc01d3f5911afe92a5b46b7386bc644d05944429527593d95cc2ab88f16d9d"; readonly behavior: "Require every session artifact and served asset to remain a regular, non-linked file under the managed review root."; }; readonly sourceFiles: readonly [{ readonly path: "package.json"; readonly rawSha256: "ef40426f722f4492b51308672e569f7cc38597f8e3722b60193527db9841a458"; readonly bytes: 16913; readonly fileType: "regular"; readonly modeIntent: "package-metadata"; }, { readonly path: "scripts/plan-canvas.js"; readonly rawSha256: "5717add7a61b33833be3d2a542354ca9e8118ac46c0070da3f98eeb3e4ba550e"; readonly bytes: 13587; readonly fileType: "regular"; readonly modeIntent: "node-entrypoint"; }, { readonly path: "scripts/lib/loopback-guard.js"; readonly rawSha256: "3efcc93c9c631876f824e61f97945a8260fba9ad7ea14baffee3de0781b74bcb"; readonly bytes: 1801; readonly fileType: "regular"; readonly modeIntent: "commonjs-module"; }, { readonly path: "scripts/lib/plan-canvas/markdown.js"; readonly rawSha256: "bb68dda565690e3830c93c64fb502dc4dc1ecf036c0cfdbd6d38d78022b58d72"; readonly bytes: 9657; readonly fileType: "regular"; readonly modeIntent: "commonjs-module"; }, { readonly path: "scripts/lib/plan-canvas/sdk.js"; readonly rawSha256: "26c0618591cbf6aac5cebf1b9555dc364ba87ad8213876a886318712b0324359"; readonly bytes: 10531; readonly fileType: "regular"; readonly modeIntent: "commonjs-module"; }, { readonly path: "scripts/lib/plan-canvas/server.js"; readonly rawSha256: "cf60c4a2f295355bf1173a9cd2beb043a76a4e09322471572316d8b1eb95db5b"; readonly bytes: 19290; readonly fileType: "regular"; readonly modeIntent: "commonjs-module"; }, { readonly path: "scripts/lib/plan-canvas/sessions.js"; readonly rawSha256: "12c0d16b99910bbaff7d462f4fab6865e92426fc2b179f577bb920011ead7d32"; readonly bytes: 8219; readonly fileType: "regular"; readonly modeIntent: "commonjs-module"; }, { readonly path: "scripts/lib/plan-canvas/ui.js"; readonly rawSha256: "806bb5efd86b8336769da7532e83208c852ff65afbf30166562a8c5e4b45b685"; readonly bytes: 28040; readonly fileType: "regular"; readonly modeIntent: "commonjs-module"; }]; readonly files: readonly RuntimeFileReceipt[]; }; export declare const PLAN_CANVAS_LIMITS: { readonly maxArtifactBytes: number; readonly maxOutputBytes: number; readonly maxReplyBytes: number; readonly maxReplyCharacters: 4000; readonly maxCommandTimeoutMs: number; readonly idleTimeoutMs: number; }; export interface VerifiedPlanCanvasRuntime { readonly root: string; readonly entrypoint: string; readonly integrity: typeof PLAN_CANVAS_RUNTIME_PIN.integrity; readonly closureSha256: typeof PLAN_CANVAS_RUNTIME_PIN.closureSha256; } export interface PlanCanvasReview { version: 1; id: string; originalPath: string; snapshotPath: string; reviewRoot: string; revisionSha256: string; bytes: number; } interface ArtifactSnapshotOptions { artifactRoot: string; artifactPath: string; stateRoot: string; } interface AdapterOptions { runtime: VerifiedPlanCanvasRuntime; stateRoot: string; nodeCommand?: string; run?: Runner; renderingEgress?: "disabled" | "pinned-mermaid"; port?: number; } interface OpenOptions { launchBrowser?: boolean; } export interface PlanCanvasFeedback { status: "feedback" | "ended" | "missing" | "waiting"; revisionSha256: string; items?: readonly Record[]; sessionEnded?: boolean; endedBy?: string; note?: string; } export interface PlanCanvasAdapter { open(review: Readonly, options?: OpenOptions): Promise>; awaitFeedback(review: Readonly, reply?: string): Promise; end(review: Readonly): Promise; stop(): Promise; } /** * Apply the reviewed deterministic text transform. Production always reaches * this through the source-hash-bound wrapper below; the string seam keeps the * transform independently testable without vendoring the upstream runtime. */ export declare function applyReviewedPlanCanvasServerTransform(source: string): string; /** Apply only reviewed, deterministic transport hardening to pinned runtime files. */ export declare function applyReviewedPlanCanvasRuntimeTransform(path: string, source: string): string; export declare function materializePlanCanvasRuntime(options: { sourceRoot: string; verifiedIntegrity: string; destinationRoot: string; }): VerifiedPlanCanvasRuntime; /** * Re-authenticate the minimal runtime closure after the npm acquisition boundary * has SRI-verified and unpacked the exact tarball. No caller-owned digest can * replace the independently recorded package SRI or file receipt. */ export declare function verifyPlanCanvasRuntimeRoot(runtimeRoot: string, verifiedIntegrity: string): VerifiedPlanCanvasRuntime; /** Copy one reviewed artifact into an immutable, content-addressed state slot. */ export declare function createPlanCanvasArtifactSnapshot(options: ArtifactSnapshotOptions): PlanCanvasReview; /** * AIH-owned transport over the pinned CLI. It never exposes `server --host`, * operates only on managed snapshots, and defaults rendering to no network egress. */ export declare function createPlanCanvasAdapter(options: AdapterOptions): PlanCanvasAdapter; export declare const PLAN_CANVAS_RENDERING_POLICY: { readonly default: "disabled"; readonly pinnedMermaidUrl: "https://cdn.jsdelivr.net/npm/mermaid@11.4.1/dist/mermaid.esm.min.mjs"; readonly behavior: "Remote Mermaid rendering is disabled by default and may use only the reviewed exact URL when explicitly enabled."; }; export declare function planCanvasReviewLabel(review: Readonly): string; export {};