import type { PlanContext } from "../internals/plan.js"; import type { Check } from "../internals/verify.js"; import type { McpServer } from "./servers.js"; export interface ManagedMcpServerCommand { serverCommand: string[]; } export interface ManagedMcpAllowlistSettings { allowManagedMcpServersOnly: true; allowedMcpServers: ManagedMcpServerCommand[]; } export declare function managedMcpAllowlistSettings(servers: Record): ManagedMcpAllowlistSettings; /** Human name for a managed server command: the package spec without its version pin. */ export declare function managedServerDisplayName(command: readonly string[]): string; /** * True when `actual` is a launch shape an EARLIER aih generation produced for * the current `expected` command. Recognition is strict and fail-closed: * `expected` must carry the current hardened prefix (only aih's own generated * output is a valid attribution anchor), and `actual` may differ from it only * in the known generation evolutions — the missing prefix (pre-hardening * output) and/or an older/absent version pin of the same package. Anything * else stays unattributed so real local edits keep failing as drift. */ export declare function previousGenerationCommandForm(actual: readonly string[], expected: readonly string[]): boolean; export interface ManagedAllowlistGenerationDelta { /** On-disk commands recognized as an earlier generation's launch shape, with their current counterpart. */ previous: { actual: string[]; expected: string[]; }[]; /** Expected commands with no on-disk counterpart (introduced by a newer generation). */ added: string[][]; } /** * Attribute the difference between an on-disk managed allowlist and the * currently generated one to aih's own generation history — or refuse. * Every on-disk command must be either exactly a current command or a * recognized previous-generation form of a distinct current command, and at * least one previous-generation form must be present (a purely additive delta * has no fingerprint and could equally be a local deletion). Returns * `undefined` when any command cannot be positively attributed. */ export declare function managedAllowlistGenerationDelta(actual: readonly string[][], expected: readonly string[][]): ManagedAllowlistGenerationDelta | undefined; export declare function mcpManagedAllowlistCheck(ctx: PlanContext): Check;