import type { CapabilityEnvelope, GateOutcome, WorkerClaim, WorkerRequest } from "../autonomy/contracts.ts"; export declare const MAX_WORKER_CLAIM_SUMMARY_CHARS: number; export declare const MAX_WORKER_CLAIM_SUMMARY_BYTES: number; export declare const MAX_WORKER_CLAIM_BLOCKERS = 32; export declare const MAX_WORKER_CLAIM_BLOCKER_CHARS = 1000; export declare const MAX_WORKER_CLAIM_CHANGED_FILES = 128; export declare const MAX_WORKER_CLAIM_CHANGED_FILE_CHARS = 2048; export declare const MAX_WORKER_CLAIM_REQUEST_ID_CHARS = 256; export declare const MAX_WORKER_CLAIM_TERMINAL_ATTEMPT_ID_CHARS = 256; export declare const MAX_WORKER_CLAIM_USAGE_REPORT_ID_CHARS = 256; export declare const MAX_WORKER_CLAIM_TIMESTAMP_CHARS = 128; export declare const MAX_WORKER_CLAIM_VERIFICATION_SUBJECT_ID_CHARS = 256; export declare const MAX_WORKER_CLAIM_REASON_CODES = 32; export declare const MAX_WORKER_CLAIM_REASON_CODE_CHARS = 128; export interface BoundedWorkerClaimStrings { values: string[]; overflowed: boolean; } /** Native host observations may be reduced for terminal storage, but callers must surface overflow. */ export declare function collectBoundedWorkerClaimBlockers(values: readonly string[]): BoundedWorkerClaimStrings; /** Changed paths preserve their exact spelling; trimming a real path could change its meaning. */ export declare function collectBoundedWorkerClaimChangedFiles(values: readonly string[]): BoundedWorkerClaimStrings; /** Bound a host-produced claim summary without splitting a UTF-8 code point. */ export declare function clipWorkerClaimSummary(value: string, suffix?: string): string; export declare function boundedWorkerClaimStrings(values: readonly string[], maximumCount: number, maximumChars: number): string[]; export declare function boundedWorkerClaimBlockers(values: readonly string[]): string[]; export declare function boundedWorkerClaimChangedFiles(values: readonly string[]): string[]; /** * Applies the one mandatory bounded claim contract before persistence, review, finalization, or * artifact inspection. Host-built/native reports have already bounded their model output; foreign * reports must fit the exact same envelope and are rejected before cloning or getter invocation. */ export declare function normalizeWorkerClaimForHost(value: unknown): WorkerClaim; export declare function normalizeWorkerClaimReasonCode(value: unknown, fallback: string): string; export declare function cloneWorkerClaimForStorage(claim: WorkerClaim): WorkerClaim; export declare function isWorkerClaim(value: unknown): value is WorkerClaim; export declare function requiresParentReview(claim: WorkerClaim): boolean; /** * True iff {@link validateWorkerClaim}'s gate would flag this claim "ask-user" / * "parent_review_required" (the two branches at :110 and :178 below) — an otherwise-completed * claim the parent must explicitly look at because it reports blockers, or reports file mutations * that passed path-scope validation. Reuses `validateWorkerClaim` itself rather than a * separately-maintained heuristic, so a persisted review marker can never drift from the * gate's actual verdict. */ export declare function isParentReviewRequired(args: { request: WorkerRequest; claim: WorkerClaim; cwd?: string; }): boolean; export declare function validateWorkerClaim(args: { request: WorkerRequest; claim: WorkerClaim; /** * Baseline for relative paths — BOTH the runner's cwd-relative `changedFiles` and the * envelope's possibly-relative path scopes resolve against this. Defaults to process.cwd() * for callers whose session cwd is the process cwd. */ cwd?: string; }): GateOutcome; /** * Path-scope-only re-review for a SELF-REPORTED (out-of-process) worker's claimed `changedFiles` * -- e.g. a tmux worker's own completion report, which (unlike an in-process worker's) never * passed through this process's `applyWorkerActions` envelope enforcement before the write * happened; the tmux worker's tool loop runs in a separate process this session does not gate. * Reuses {@link validateWorkerClaim}'s exact symlink-safe scope check verbatim -- never * reimplement path resolution: synthesizes a minimal, always-"completed" request/claim pair * carrying only the reported `changedFiles` and the scope's `allowedPaths`/`deniedPaths`, so the * ONLY thing that can vary the verdict is the path-scope branch. * * Deliberately broader than {@link isParentReviewRequired}: that helper only flags the gate's * "ask-user" branch, which is correct for an in-process worker (a write that would have been * "block"-worthy was already refused before it could happen, by the SAME envelope, via * `applyWorkerActions`). A self-reported claim has no such backstop -- an out-of-scope or denied * path already happened on the real filesystem whether or not this gate would allow it, so here * ANY non-"allow" verdict (in scope, out of scope, or no scope configured at all) means a human * must look, not "the write didn't happen". */ export declare function reviewManagedLaneChangedFiles(args: { changedFiles: readonly string[]; /** The immutable managed-launch profile scope to validate against. */ envelope: Pick; cwd?: string; }): { reviewRequired: boolean; reasonCode: string; }; //# sourceMappingURL=worker-claim.d.ts.map