import type { CapabilityEnvelope } from "./contracts.ts"; export declare const PI_WORKER_ALLOWED_PATHS_ENV = "PI_WORKER_ALLOWED_PATHS"; export declare function parseWorkerSessionAllowedPaths(raw: string | undefined): readonly string[]; export declare function encodeWorkerSessionAllowedPaths(paths: readonly string[]): string; /** * Structural filesystem envelope for a standalone worker process (for example a Pi child launched * in tmux). An empty allow list deliberately preserves the worker's host-wide project access while * the private harness roots remain denied. Process tools are not path-confined by this envelope: * bash/python are explicit host-trust boundaries and retain their OS-visible filesystem surface. */ export declare function buildWorkerSessionPrivatePathEnvelope(cwd: string, agentDir: string, allowedPaths?: readonly string[]): CapabilityEnvelope; //# sourceMappingURL=worker-session-private-scope.d.ts.map