import type { ToolArgumentValidationOptions } from "@caupulican/pi-ai"; import { type CapabilityGateway } from "../orchestration/capability-gateway.ts"; import type { ToolCapabilityManifest } from "../orchestration/contracts.ts"; import type { WorkerActionInspectionRequired, WorkerActionJournal } from "./worker-action-journal.ts"; /** * Code-writing workers (G2): the worker MODEL never touches the filesystem — it emits strict-JSON * actions, and this RUNNER-side module applies them deterministically through the compiled * execution grant. That keeps the structural-contract philosophy (a local model without * tool-calling templates can still write code) and makes enforcement execution-time, not * validation-only: an out-of-scope action is REFUSED with a reason, never silently dropped, and * refusals surface as blockers on the result. */ export interface WorkerAction { op: "write" | "edit"; path: string; /** write: full file content. */ content?: string; /** edit: exact string to replace (must occur in the file). */ old?: string; /** edit: replacement text. */ new?: string; } export type WorkerActionRejectionCode = "worker_actions_invalid_shape" | "worker_actions_too_many" | "worker_actions_path_too_long" | "worker_actions_field_too_large" | "worker_actions_payload_too_large"; export interface AcceptedWorkerActions { kind: "accepted"; actions: WorkerAction[]; } export interface RejectedWorkerActions { kind: "rejected"; reasonCode: WorkerActionRejectionCode; message: string; } /** The sole structured-action admission result used before execution or worker-result projection. */ export type WorkerActionParseOutcome = AcceptedWorkerActions | RejectedWorkerActions; /** Bounded model-to-filesystem mutation contract. All execution callers pass through this owner. */ export declare const MAX_WORKER_ACTIONS = 20; export declare const MAX_WORKER_ACTION_PATH_CHARS = 2048; export declare const MAX_WORKER_ACTION_TEXT_CHARS: number; /** Limits all source/replacement payloads for one atomic worker action batch. */ export declare const MAX_WORKER_ACTION_PAYLOAD_CHARS: number; /** * A structured edit only needs bounded source/replacement text. Limit the target read to 2 MiB: * this admits the largest UTF-8 text payload (512 Ki code units at four bytes each) * without letting a small edit cause an unbounded repository-file allocation. */ export declare const MAX_WORKER_ACTION_EDIT_TARGET_BYTES: number; export declare function parseWorkerActions(raw: unknown, validation?: ToolArgumentValidationOptions): WorkerActionParseOutcome; export interface AppliedActionsReport { /** Repo-relative paths actually changed. */ changedFiles: string[]; /** Grant refusals (execution-time enforcement) — surfaced, never silent. */ refused: Array<{ path: string; reason: string; }>; /** Actions that were in scope but could not be applied (missing file, old-text not found). */ failed: Array<{ path: string; reason: string; }>; /** Durable replay blocks. The parent must inspect workspace/evidence instead of re-executing. */ inspectionRequired: Array<{ path: string; actionId: string; state: WorkerActionInspectionRequired["state"]; reasonCode: string; evidencePointer?: string; }>; } export declare function applyWorkerActions(args: { actions: readonly WorkerAction[]; gateway: CapabilityGateway; toolManifests: readonly ToolCapabilityManifest[]; cwd: string; /** Optional durable mutation journal for one fenced worker attempt. */ actionJournal?: WorkerActionJournal; }): AppliedActionsReport; //# sourceMappingURL=worker-actions.d.ts.map