import { type NativeHookEntry, type ProjectedHookGroup } from "./hook-registrar-native.js"; import { HOOK_REGISTRAR_RECEIPT_FORMAT } from "./hook-registrar-read.js"; import { type HookRegistration, type ResolvedHookRegistration, type ThirdPartyLauncherPin } from "./schema.js"; /** * The hook registrar receipt: what AIH records about the entries it owns, and * the only removal authority a projected third-party entry has. Split out of the * projector because the shape, its schema and its parse are one cohesive unit. */ export interface HookReceiptEntry { id: string; event: string; owner: "aih" | "third-party" | "unknown"; ownerId: string; command: string; commandSha256: string; spawns: number; functionTags: string[]; sourceDisabled: boolean; declaredControls?: string[]; pin?: ThirdPartyLauncherPin; timeout?: number; /** Captured native fields, recorded so the entry can be re-emitted verbatim. */ nativeGroup?: Record; nativeHook?: Record; } export type HookReceiptPrior = { state: "absent"; } | { state: "present"; sha256: string; contents: string; }; export interface HookRegistrarReceipt { format: typeof HOOK_REGISTRAR_RECEIPT_FORMAT; version: 1; destination: string; policyVersion?: string; /** * The bytes found before AIH first projected. EVIDENCE ONLY — the record of * what was there, readable during an investigation. Revocation subtracts the * owned key and never replays these bytes, which would reinstate every * adopted entry (governing ADR, A4). */ prior: HookReceiptPrior; entries: HookReceiptEntry[]; /** * Groups found in the destination that yield no entry — content AIH did not * author and does not own, carried through the whole-key write so the replace * cannot delete it. Recorded here so the expectation below reproduces exactly * what was written, and so revocation can put it back instead of subtracting * it along with what AIH did own. */ carriedThrough?: Record; } export declare function hookRegistrationOwnerId(registration: ResolvedHookRegistration): string; export declare function receiptEntry(registration: ResolvedHookRegistration): HookReceiptEntry; /** * The registration a receipt entry proves AIH owns, owner partition intact. * The schema below refuses a third-party entry with no pin before this runs, so * the `aih` fallback can only be reached by an entry that genuinely records AIH * ownership — never by a third-party claim whose pin went missing. */ export declare function receiptRegistration(entry: HookReceiptEntry): ResolvedHookRegistration; /** Parse receipt bytes a caller has already read, so one read can serve every use. */ export declare function parseHookRegistrarReceipt(raw: string): HookRegistrarReceipt; export declare function readHookRegistrarReceipt(root: string): HookRegistrarReceipt | undefined; /** The entry shape a receipt entry describes, for keying and re-emission. */ export declare function receiptNativeEntry(entry: HookReceiptEntry): NativeHookEntry; /** * Rebuild the exact hook value the projection wrote: the entries AIH owns plus * the content it carried through. Both come from the ONE composer the * projection uses, so the expectation cannot drift from what was written. */ export declare function expectedHooksFromReceipt(receipt: HookRegistrarReceipt): Record; export type { HookRegistration };