import { type InheritedValuesSnapshot } from "./output.js"; export type VerifierExecutable = "git" | "sh" | "systemd-run" | "systemctl"; /** Error raised when a verifier-owned executable is not available at a fixed path. */ export declare class ExecutableResolutionError extends Error { readonly executable: VerifierExecutable; constructor(executable: VerifierExecutable); } /** Resolve only from fixed system locations; caller PATH is never consulted. */ export declare function resolveVerifierExecutable(executable: VerifierExecutable): Promise; /** Capture only the variables required to reach the systemd user bus. */ export declare function captureSystemdEnvironment(): NodeJS.ProcessEnv; /** Copy only declared variables into the command launcher; do not inherit arbitrary host settings. */ export declare function captureEvidenceEnvironment(names: unknown, snapshot?: InheritedValuesSnapshot): { environment: NodeJS.ProcessEnv; inherited: InheritedValuesSnapshot; missing: readonly string[]; short: readonly string[]; valid: boolean; }; /** Fallback PATH for the authored command, which is evidence rather than verifier authority. */ export declare function captureAuthoredPath(): string; export declare function isAbsoluteExecutable(value: string): boolean; /** Refuse a caller PATH that exposes a different executable before the fixed verifier path. */ export declare function pathShadowsExecutable(executable: VerifierExecutable, resolved: string, authoredPath: string): Promise;