import type { ExecutionGrant, HarnessCapability, OrchestrationProfile, ResourcePointer, RiskBudget, ToolCapabilityManifest, WorkerExecutionAuthorityContract, WorkerRole } from "../orchestration/contracts.ts"; import type { ResolvedWorkerDelegationSettings } from "../settings-manager.ts"; export interface WorkerExecutionPlan { /** Actual process and relative-tool working directory fixed at admission. */ cwd: string; toolManifests: readonly ToolCapabilityManifest[]; requiredCapabilities: readonly HarnessCapability[]; readPaths: readonly string[]; writePaths: readonly string[]; deniedPaths: readonly string[]; readMemory: boolean; writeEnabled: boolean; processEnabled: boolean; budget: RiskBudget; } export declare function workerExecutionAuthorityFromPlan(plan: WorkerExecutionPlan): WorkerExecutionAuthorityContract; /** Apply live revocations to admitted authority without allowing later settings to widen it. */ export declare function narrowWorkerExecutionPlan(admitted: WorkerExecutionAuthorityContract, current: WorkerExecutionPlan): WorkerExecutionPlan; export declare function buildWorkerExecutionPlan(args: { profile: OrchestrationProfile; settings: ResolvedWorkerDelegationSettings; cwd: string; deniedPaths: readonly string[]; foregroundMaxCostUsd?: number; memoryEnabled: boolean; workerToolAdapterNames?: readonly string[]; }): WorkerExecutionPlan; export declare function compileWorkerExecutionGrant(args: { target: { objectiveId: string; taskId: string; attemptId: string; }; profile: OrchestrationProfile; plan: WorkerExecutionPlan; resources: readonly ResourcePointer[]; }): { ok: true; grant: ExecutionGrant; } | { ok: false; reasonCodes: readonly string[]; }; /** Compile the host's durable authority record before an externally managed process is launched. */ export declare function compileManagedProcessExecutionGrant(args: { target: { objectiveId: string; taskId: string; attemptId: string; }; laneId: string; authorizationId: string; role: WorkerRole; allowedTools: readonly string[]; writePaths: readonly string[]; cwd: string; deniedPaths: readonly string[]; budget: RiskBudget; }): { ok: true; grant: ExecutionGrant; } | { ok: false; reasonCodes: readonly string[]; }; //# sourceMappingURL=worker-execution-policy.d.ts.map