import { type ResolvedHookRegistration } from "./schema.js"; /** * A1 — adoption: the only path from an entry AIH did not emit to a policy * registration it can later revoke. Split out of the projector because capture * is a self-contained act with its own refusals. */ export interface HookAdoptionProvenance { repository: string; commit: string; path: string; runtimeVersion: string; } /** * What AIH offers to take ownership of. Its `event` and `command` are the * ORIGINAL captured bytes, not display text: an administrator answers an offer * by naming it, and the lookup below keys on those bytes. Neutralizing them * would make an offer that can never be matched and then blame the declaration * for a mismatch AIH introduced. Rendering neutralizes; identity does not. */ export interface HookAdoptionOffer { event: string; command: string; commandSha256: string; } /** * An administrator's answer to an adoption offer. It names the offered entry by * event and captured-byte hash — never by launcher text, because an * administrator never hand-types a launcher; a hand-typed launcher means * adoption was not run. Everything AIH must not infer is declared here: * identity, function tags, the spawn measurement, and provenance. Declaring no * provenance leaves the owner `unknown`. The native fields around the launcher * are NOT declared — they are captured, like the launcher itself. */ export interface HookAdoptionDeclaration { event: string; commandSha256: string; id: string; functionTags: readonly string[]; spawns: number; timeout?: number; sourceDisabled?: boolean; owner: { kind: "third-party"; framework: string; declaredControls?: readonly string[]; pin: HookAdoptionProvenance; } | { kind: "unknown"; }; } /** * Capture each named launcher byte-for-byte from the destination, hash those * exact bytes, and emit the policy entries the grammar accepts. Adoption is a * transfer of ownership: once emitted and projected, the entry is revocable * through the receipt and never comes back on uninstall. * * The capture takes the WHOLE native entry, not just its command. An entry * adopted without its `matcher` would be re-projected unscoped — silently * widening a hook that fired on one tool into one that fires on everything. */ export declare function adoptedHookRegistrations(root: string, declarations: readonly HookAdoptionDeclaration[]): ResolvedHookRegistration[];