{"version":3,"file":"remote-transport.d.ts","sourceRoot":"","sources":["../../../src/core/remote-execution/remote-transport.ts"],"names":[],"mappings":"AAAA;;;;;;;;GAQG;AAEH,OAAO,KAAK,EAAE,2BAA2B,EAAE,MAAM,uCAAuC,CAAC;AACzF,OAAO,KAAK,EAAE,qBAAqB,EAAE,kBAAkB,EAAE,MAAM,0BAA0B,CAAC;AAM1F;;;GAGG;AACH,MAAM,WAAW,iBAAiB;IACjC,OAAO,EAAE,MAAM,CAAC;IAChB,IAAI,EAAE,SAAS,MAAM,EAAE,CAAC;IACxB,GAAG,EAAE,MAAM,CAAC;IACZ,GAAG,CAAC,EAAE,MAAM,CAAC,MAAM,EAAE,MAAM,GAAG,SAAS,CAAC,CAAC;CACzC;AAED,qEAAqE;AACrE,MAAM,WAAW,gBAAgB;IAChC,WAAW,EAAE,MAAM,CAAC;IACpB,QAAQ,EAAE,MAAM,CAAC;IACjB,cAAc,EAAE,MAAM,CAAC;IACvB,qFAAqF;IACrF,OAAO,CAAC,EAAE;QAAE,OAAO,EAAE,MAAM,CAAC;QAAC,YAAY,EAAE,MAAM,CAAA;KAAE,CAAC;IACpD,+EAA+E;IAC/E,WAAW,CAAC,EAAE,2BAA2B,CAAC;IAC1C,8EAA8E;IAC9E,YAAY,EAAE,MAAM,CAAC;IACrB,oFAAoF;IACpF,QAAQ,EAAE,MAAM,CAAC;IACjB,iFAAiF;IACjF,UAAU,EAAE,MAAM,CAAC;IACnB,2DAA2D;IAC3D,cAAc,CAAC,EAAE,MAAM,CAAC;IACxB,kBAAkB,CAAC,EAAE,MAAM,CAAC;IAC5B,gFAAgF;IAChF,cAAc,CAAC,EAAE;QAAE,IAAI,EAAE,MAAM,CAAC;QAAC,UAAU,EAAE,MAAM,CAAA;KAAE,EAAE,CAAC;IACxD,+CAA+C;IAC/C,MAAM,EAAE,iBAAiB,CAAC;IAC1B,+CAA+C;IAC/C,WAAW,CAAC,EAAE,MAAM,CAAC;IACrB,sCAAsC;IACtC,SAAS,CAAC,EAAE,MAAM,CAAC;IACnB,6EAA6E;IAC7E,aAAa,CAAC,EAAE,MAAM,EAAE,CAAC;IACzB,2EAA2E;IAC3E,SAAS,CAAC,EAAE;QACX,OAAO,CAAC,EAAE,CAAC,KAAK,EAAE;YAAE,IAAI,EAAE,MAAM,CAAC;YAAC,OAAO,EAAE,OAAO,CAAA;SAAE,KAAK,IAAI,CAAC;QAC9D,OAAO,CAAC,EAAE,CAAC,KAAK,EAAE,oBAAoB,KAAK,IAAI,CAAC;KAChD,CAAC;IACF;;;;;;OAMG;IACH,eAAe,CAAC,EAAE;QAAE,SAAS,EAAE,MAAM,CAAC;QAAC,UAAU,EAAE,MAAM,CAAA;KAAE,CAAC;CAC5D;AAMD,MAAM,WAAW,oBAAoB;IACpC,OAAO,EAAE,MAAM,CAAC;IAChB,IAAI,EACD,WAAW,GACX,qBAAqB,GACrB,gBAAgB,GAChB,eAAe,GACf,OAAO,GACP,eAAe,GACf,aAAa,GACb,kBAAkB,GAClB,iBAAiB,GACjB,SAAS,GACT,WAAW,CAAC;IACf,OAAO,CAAC,EAAE,OAAO,CAAC;IAClB,IAAI,EAAE,MAAM,CAAC;CACb;AAED,MAAM,WAAW,sBAAsB;IACtC,QAAQ,EAAE,MAAM,GAAG,IAAI,CAAC;IACxB,MAAM,CAAC,EAAE,MAAM,CAAC;IAChB,SAAS,CAAC,EAAE,OAAO,CAAC;IACpB,QAAQ,CAAC,EAAE,OAAO,CAAC;IACnB,WAAW,CAAC,EAAE,MAAM,CAAC;IACrB,kEAAkE;IAClE,MAAM,EAAE,MAAM,CAAC;IACf,MAAM,EAAE,MAAM,CAAC;IACf,8DAA8D;IAC9D,QAAQ,CAAC,EAAE;QACV,IAAI,EAAE,MAAM,CAAC;QACb,IAAI,EAAE,MAAM,CAAC;QACb,GAAG,EAAE,MAAM,CAAC;QACZ,GAAG,EAAE,MAAM,CAAC;QACZ,QAAQ,EAAE,MAAM,CAAC;KACjB,CAAC;IACF,QAAQ,CAAC,EAAE,OAAO,EAAE,CAAC;IACrB,6DAA6D;IAC7D,YAAY,CAAC,EAAE;QAAE,OAAO,EAAE,OAAO,CAAC;QAAC,OAAO,CAAC,EAAE,MAAM,CAAA;KAAE,CAAC;IACtD,oDAAoD;IACpD,SAAS,CAAC,EAAE,MAAM,CAAC;CACnB;AAED,MAAM,WAAW,qBAAqB;IACrC,WAAW,EAAE,MAAM,CAAC;IACpB,QAAQ,EAAE,MAAM,CAAC;IACjB,cAAc,EAAE,OAAO,CAAC,sBAAsB,CAAC,CAAC;IAChD,MAAM,EAAE,CAAC,MAAM,CAAC,EAAE,MAAM,KAAK,OAAO,CAAC,IAAI,CAAC,CAAC;CAC3C;AAED,MAAM,WAAW,2BAA2B;IAC3C,MAAM,CAAC,EAAE,WAAW,CAAC;CACrB;AAED,MAAM,WAAW,4BAA4B;IAC5C,MAAM,CAAC,EAAE,WAAW,CAAC;CACrB;AAED,iFAAiF;AACjF,MAAM,WAAW,mBAAmB;IACnC,UAAU,CACT,MAAM,EAAE,qBAAqB,EAC7B,OAAO,EAAE,MAAM,EACf,GAAG,EAAE,MAAM,EACX,OAAO,CAAC,EAAE;QAAE,SAAS,CAAC,EAAE,MAAM,CAAC;QAAC,MAAM,CAAC,EAAE,WAAW,CAAA;KAAE,GACpD,OAAO,CAAC;QAAE,QAAQ,EAAE,MAAM,GAAG,IAAI,CAAC;QAAC,MAAM,EAAE,MAAM,CAAC;QAAC,MAAM,EAAE,MAAM,CAAC;QAAC,QAAQ,CAAC,EAAE,OAAO,CAAC;QAAC,WAAW,CAAC,EAAE,MAAM,CAAA;KAAE,CAAC,CAAC;CAClH;AAMD,MAAM,WAAW,wBAAwB;IACxC,QAAQ,CAAC,WAAW,EAAE,MAAM,CAAC;IAE7B,6EAA6E;IAC7E,KAAK,CAAC,MAAM,EAAE,qBAAqB,EAAE,OAAO,CAAC,EAAE,2BAA2B,GAAG,OAAO,CAAC,kBAAkB,CAAC,CAAC;IAEzG;;;;OAIG;IACH,MAAM,CACL,MAAM,EAAE,qBAAqB,EAC7B,IAAI,EAAE,gBAAgB,EACtB,OAAO,CAAC,EAAE,4BAA4B,GACpC,OAAO,CAAC,qBAAqB,CAAC,CAAC;CAClC","sourcesContent":["/**\n * Remote Execution — transport port (2.14.0).\n *\n * A transport-independent remote execution seam. SSH is the first transport;\n * future transports (container, cloud worker, ...) implement the same contract.\n * The port is platform-neutral: target-specific command building lives in the\n * concrete SSH implementation, never in this interface or in the mission\n * executor.\n */\n\nimport type { MissionExecutionCorrelation } from \"../mission-domain/mission-executor.js\";\nimport type { RemoteExecutionTarget, RemoteTargetHealth } from \"./remote-target-types.js\";\n\n// =============================================================================\n// Launch spec\n// =============================================================================\n\n/**\n * A concrete remote child launch. `argv` is an argument vector (never a shell\n * string) so untrusted mission data is never concatenated into a shell.\n */\nexport interface RemoteChildLaunch {\n\tcommand: string;\n\targs: readonly string[];\n\tcwd: string;\n\tenv?: Record<string, string | undefined>;\n}\n\n/** Everything needed to materialise + start one remote execution. */\nexport interface RemoteLaunchSpec {\n\texecutionId: string;\n\tlaunchId: string;\n\tremoteTargetId: string;\n\t/** Fencing identity carried for correlation; the durable authority stays central. */\n\tfencing?: { leaseId: string; fencingToken: number };\n\t/** Stable mission/assignment/attempt/session attribution for remote events. */\n\tcorrelation?: MissionExecutionCorrelation;\n\t/** Remote temp root for the execution-scoped workspace (already resolved). */\n\tworkspaceDir: string;\n\t/** The remote agent directory to materialise (models.json, child-sessions, ...). */\n\tagentDir: string;\n\t/** Remote models.json content (ephemeral protected config; cleaned up after). */\n\tmodelsJson: string;\n\t/** Remote session file content keyed by childSessionId. */\n\tchildSessionId?: string;\n\tsessionFileContent?: string;\n\t/** Initial workspace files to materialise (remote-relative to workspaceDir). */\n\tworkspaceFiles?: { path: string; contentB64: string }[];\n\t/** The actual child launch to run remotely. */\n\tlaunch: RemoteChildLaunch;\n\t/** Protocol runner heartbeat interval (ms). */\n\theartbeatMs?: number;\n\t/** Bounded execution timeout (ms). */\n\ttimeoutMs?: number;\n\t/** Remote-relative files to hash before/after execution (location proof). */\n\tevidenceFiles?: string[];\n\t/** Optional framing/adapter callback hooks for tests and observability. */\n\tcallbacks?: {\n\t\tonFrame?: (frame: { type: string; payload: unknown }) => void;\n\t\tonEvent?: (event: RemoteTransportEvent) => void;\n\t};\n\t/**\n\t * Optional reverse port-forward for the duration of the remote child\n\t * execution: the remote child reaches `127.0.0.1:<remotePort>` and it is\n\t * tunnelled back to `127.0.0.1:<localPort>` on the control host (the central\n\t * shared-inference admission service). The tunnel lives exactly as long as\n\t * this SSH session, so it closes when the remote child exits.\n\t */\n\tadmissionTunnel?: { localPort: number; remotePort: number };\n}\n\n// =============================================================================\n// Events + handle\n// =============================================================================\n\nexport interface RemoteTransportEvent {\n\teventId: string;\n\ttype:\n\t\t| \"connected\"\n\t\t| \"launch_acknowledged\"\n\t\t| \"remote_started\"\n\t\t| \"remote_active\"\n\t\t| \"frame\"\n\t\t| \"remote_result\"\n\t\t| \"remote_exit\"\n\t\t| \"transport_closed\"\n\t\t| \"transport_error\"\n\t\t| \"timeout\"\n\t\t| \"cancelled\";\n\tpayload?: unknown;\n\tatMs: number;\n}\n\nexport interface RemoteTransportOutcome {\n\texitCode: number | null;\n\tsignal?: string;\n\tcancelled?: boolean;\n\ttimedOut?: boolean;\n\tlaunchError?: string;\n\t/** Bounded raw child stdout (already framed during streaming). */\n\tstdout: string;\n\tstderr: string;\n\t/** Location + evidence proof emitted by the remote runner. */\n\tlocation?: {\n\t\thost: string;\n\t\tuser: string;\n\t\tcwd: string;\n\t\tpid: number;\n\t\tplatform: string;\n\t};\n\tevidence?: unknown[];\n\t/** Whether the runner produced a structured result frame. */\n\tremoteResult?: { success: boolean; summary?: string };\n\t/** Last structured transport error code, if any. */\n\terrorCode?: string;\n}\n\nexport interface RemoteExecutionHandle {\n\texecutionId: string;\n\tlaunchId: string;\n\toutcomePromise: Promise<RemoteTransportOutcome>;\n\tcancel: (reason?: string) => Promise<void>;\n}\n\nexport interface RemoteTransportProbeOptions {\n\tsignal?: AbortSignal;\n}\n\nexport interface RemoteTransportLaunchOptions {\n\tsignal?: AbortSignal;\n}\n\n/** Narrow command runner shared by the SSH transport and remote verification. */\nexport interface RemoteCommandRunner {\n\trunCommand(\n\t\ttarget: RemoteExecutionTarget,\n\t\tcommand: string,\n\t\tcwd: string,\n\t\toptions?: { timeoutMs?: number; signal?: AbortSignal },\n\t): Promise<{ exitCode: number | null; stdout: string; stderr: string; timedOut?: boolean; launchError?: string }>;\n}\n\n// =============================================================================\n// Port\n// =============================================================================\n\nexport interface RemoteExecutionTransport {\n\treadonly transportId: string;\n\n\t/** Non-mutating reachability/auth/runtime probe. Never fabricates health. */\n\tprobe(target: RemoteExecutionTarget, options?: RemoteTransportProbeOptions): Promise<RemoteTargetHealth>;\n\n\t/**\n\t * Materialise + start a remote execution. Returns a handle immediately after\n\t * the remote child is acknowledged, without waiting for terminal state.\n\t * The transport must not close without a terminal result signalling success.\n\t */\n\tlaunch(\n\t\ttarget: RemoteExecutionTarget,\n\t\tspec: RemoteLaunchSpec,\n\t\toptions?: RemoteTransportLaunchOptions,\n\t): Promise<RemoteExecutionHandle>;\n}\n"]}